Privacy Policy
Originally effective July 8, 2026 · Changes effective September 13, 2026
This Privacy Policy explains how Ner-D-Bird LLC, an Alabama limited liability company operating the MusterSheet platform at mustersheet.com (the “Service”), collects, uses, shares, and protects information. It applies to account holders, to parents, to fans using our public features, and to the student roster records that booster organizations maintain through the Service. Questions? Contact us at support@mustersheet.com.
1. Who We Are and Our Role With Your Data
Ner-D-Bird LLC is the data controller for platform data — the information you give us when you create an account, register a band, judge a competition, purchase a shoutout, or otherwise use the Service. We decide how that data is used, as described in this Policy.
For student roster records entered by booster organizations (student names, grade, section, emergency-contact details, fee balances, and payment history), the booster organization — typically together with its associated school or band program — is the controller of that data, and Ner-D-Bird processes it on the organization’s behalf and under its direction. The organization is responsible for having the authority, including any required parental consent, to enter and manage that information. This does not limit privacy or security duties imposed directly on Ner-D-Bird by applicable law. Requests about org-entered student records are routed to the controlling organization (see Section 11).
2. Information We Collect
Account holders (directors, hosts, judges, announcers, volunteers, vendors, booster staff, parents)
- Registration information: your name, email address, and password. Passwords are stored only as one-way bcrypt hashes — we never store or can read your plaintext password.
- If you sign in with Google, the identity information Google provides for sign-in (your name, email address, and Google account identifier). We do not receive your Google password.
- Profile details you choose to provide, such as a display name, avatar image, band and school information, judging background, professional membership numbers, or vendor business details and documents.
- The content you submit: registrations, schedules, scores, written feedback, judge audio commentary, booster posts and comments, announcements, product feedback, uploaded logos and receipts, and similar records.
- Session and administrative-access information: a session cookie that keeps you signed in, and administrative log records relating to Support Access, including the administrator, the account accessed, when access begins, and when an administrator manually exits.
Students (as records, not users)
- Booster organizations create roster records about their students: first and last name, grade, section, active status, adult emergency-contact name, phone number and relationship, assessed fees, balances, fundraising credits, and payment history. Students do not hold accounts and do not interact with the Service directly.
- We do not create student login credentials or collect a student’s date of birth, email address, or phone number. Parent or guardian names and contact details are stored as adult account or invitation records and linked to the applicable student record.
- Parents gain access to their own students’ records only through a private email-match link, a private family link or printed QR code issued for their household, a short claim code provided by an officer, or a per-parent email invitation.
Fans (no account required)
- If you scan an event QR code, we set an anonymous fan token cookie that expires after 18 hours. It is used only to apply shoutout quotas and record Fan Favorite votes for that competition — it is not linked to your identity.
- If you purchase a shoutout, we collect the message you write and the name you sign it with; your card details go directly to Stripe (see Section 6).
Collected automatically
- Standard server request logs, including IP address, requested URL, and timing. IP addresses are also used for rate limiting (for example, on sign-in attempts).
- Coarse operational diagnostics reported by your browser: operating-system and browser families, device class (phone, tablet, desktop, or unknown), and viewport width and height bands. Our first-party script converts browser information to these fixed categories; its diagnostic values contain no raw user-agent string, exact dimensions, device identifier, or account identifier. These approximate observations accompany request logs and aggregate operational counters so we can troubleshoot errors and layout reports. A short viewport does not establish that a keyboard is open. A cookie may report an earlier observation or one from another window; a request-specific value is used for supported in-page requests.
- We do not use third-party analytics services, advertising networks, or tracking pixels.
3. How We Use Information
- To provide the Service: running competitions and registrations, scheduling, scoring and results, judges packets, shoutouts, booster finances and student accounts, calendars, and vendor listings.
- To process payments and maintain accurate financial records (amounts, status, and references — see Section 6).
- To send transactional communications: password resets, invitations, registration acceptances, score-published notices, performance reminders, and booster balance reminders. We also deliver in-app notifications and, if a booster member opts in, web-push notifications.
- To moderate content, including automated profanity screening of shoutout messages and host review before a shoutout is read aloud.
- To help users enter receipt information by extracting fields such as vendor, amount, and purchase date from an uploaded receipt. When enabled, this processing runs on infrastructure we operate; we will update this Policy before using an external AI provider for receipt processing.
- To secure and support the Service: authentication, CSRF protection, rate limiting, administrative logging, troubleshooting (including the limited Support Access described below), and preventing abuse.
- To comply with legal obligations, including financial record-keeping.
We do not sell, rent, license, or exchange personal information or student information for money or other valuable consideration, and we do not share it for cross-context behavioral advertising. We do not use student information for targeted advertising or to build a profile about a student except as needed to provide the Service. We send marketing about MusterSheet itself, if at all, only to account holders in connection with their use of the Service.
Administrative Support Access
Solely when reasonably necessary to provide support requested by a user or an authorized representative of the user’s organization, or to diagnose, reproduce, or resolve a reported problem, an authorized MusterSheet administrator may initiate a temporary session that permits the administrator to access the Service through a user’s account (“Support Access”). During Support Access, the administrator may see personal information and other records available to that account and may take actions using that account’s permissions. The administrator does not need, receive, or view the user’s plaintext password.
Support Access is limited to authorized administrators, is time-limited, and is not used for routine monitoring or for purposes unrelated to support. We record identifying information about Support Access sessions, including the administrator, the account accessed, and when access begins, in our administrative logs. When an administrator manually ends a Support Access session, that exit is also recorded. We use information viewed through Support Access only to provide the requested support.
4. Our Bases for Using Information
In plain language, we use information because:
- You asked us to — providing the Service you signed up for, or processing a purchase you chose to make, requires it (performance of our agreement with you).
- A booster organization directed us to — for org-entered student records, we process on the organization’s documented instructions.
- We have a legitimate operational need — keeping the Service secure, preventing fraud and abuse, moderating public content, and supporting users.
- The law requires it — retaining financial records and responding to lawful requests.
- You consented — for optional features such as web-push notifications, which you can withdraw at any time.
5. Children’s Privacy
- The Service is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13.
- Accounts may not be created by anyone under 16 (see the Terms of Service). Fan features do not require an account and operate on anonymous, short-lived tokens.
- Student roster records are about students — often minors — but they are entered and controlled by the student’s booster organization and linked parents, not by the student. The organization is responsible for obtaining any authorization or parental consent required to maintain those records, and parents can review their own students’ records through their parent account.
- If a school or local educational agency will provide education records to MusterSheet or direct use of the Service for school purposes, it must contact us before doing so so that the parties can document their roles, permitted uses, deletion obligations, and any contract required by FERPA or applicable state student-privacy law.
- If you believe personal information about a child has been provided to us in a way that is inconsistent with this Policy, contact us at support@mustersheet.com and we will work with you and the controlling organization to address it, including deletion where appropriate.
6. Payment Information
- Card payments are processed by Stripe, Inc. on Stripe-hosted payment pages. Card numbers never touch our servers. Stripe’s handling of your data is described in its privacy policy at stripe.com/privacy.
- We store only payment amounts, payment status, and payment references (such as Stripe session, payment, and event identifiers) needed to keep accurate records and reconcile refunds.
- Payments to competition hosts and booster organizations are direct charges on their own Stripe Connect accounts; for those payments the host or organization is the merchant of record and also receives the associated payment records.
- Cash and check payments recorded in the Service are handled physically by event or organization staff; we store only the record of the payment.
7. How Information Is Shared
We do not sell personal information or student information, and we do not share it with advertising networks or data brokers or for cross-context behavioral advertising. Limited disclosures needed to operate the Service are not permission for a recipient to use the information for its own advertising, profiling, or unrelated purposes. Information is disclosed only as follows:
- Service providers (subprocessors). Stripe processes payments. Google provides sign-in when you choose “Sign in with Google,” and Google’s Gmail service may transmit our outbound email when configured as our mail relay. The Service is hosted on infrastructure operated for Ner-D-Bird in the United States. Our optional receipt-extraction processing runs on infrastructure we operate; we will update this Policy before engaging an outside AI subprocessor for it.
- Within the platform, by role. Event hosts and their staff see the data of their own event (registrations, schedules, check-in details, scores, shoutouts). Judges’ scores, written feedback, and audio commentary are delivered to the performing band’s director. Booster staff see their own organization’s records, and parents see their own students’ records. Published results, public schedules, band profiles, and vendor directory listings are visible to the audiences those features are designed for.
- Legal reasons. We may disclose information if we believe in good faith it is required by law, subpoena, or other legal process, or necessary to protect the rights, safety, or property of Ner-D-Bird, our users, or the public.
- Business transfers. If Ner-D-Bird is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction only subject to this Policy’s commitments, including the prohibition on selling personal information and student information for advertising, profiling, data-broker, or other independent commercial use.
8. Cookies and Similar Technologies
We use a small set of first-party cookies and browser storage for application functions and operational diagnostics, with no advertising cookies:
- Session cookie (
mustersheet_session) — keeps you signed in; expires with your session. - CSRF cookie — protects forms against cross-site request forgery.
- Fan token cookies — per-competition anonymous tokens set when you scan an event QR code; they expire after 18 hours and enforce shoutout quotas and one-vote-per-fan Fan Favorite voting.
- Theme preference (
mustersheet-theme) — your System Default, Light, or Dark choice is kept in your browser’s localStorage. On mustersheet.com and its Help Center subdomain, the same functional value is also stored for one year in a first-party cookie and sent with requests to those sites so your choice stays in sync. It contains no account or session data. - Operational diagnostics (
ms-device-context) — a session cookie limited to the current host, containing only the categories described in Section 2. It has no unique identifier or timestamp. It carries the browser’s last reported observation with requests; another window can update it. Blocking this diagnostic cookie does not prevent core workflows, and missing observations are recorded as unknown. Supported in-page requests may report the same coarse categories directly.
Blocking required sign-in or security cookies in your browser will prevent parts of the Service (such as signing in) from working.
9. Data Retention
- Account data and the records you create are kept for the life of your account, and afterward as needed to resolve disputes, enforce agreements, and satisfy record-keeping obligations.
- Financial records and associated financial audit logs (including payments, refunds, ledgers, reconciliations, and change history) are retained for at least seven (7) years after the end of the fiscal year to which the record relates, even if an account is closed. We may retain a record longer if required by law or reasonably necessary for a legal claim, investigation, or active dispute.
- Records of legal acceptance are retained for the life of the account and for as long as the associated account record is otherwise retained, so we can document the agreement and resolve disputes.
- Fan tokens expire after 18 hours. The diagnostic cookie has no persistent expiry and follows the browser’s session lifecycle; browsers may restore session cookies when restoring a session.
- The application’s administrator log view holds the latest 5,000 records in memory and resets when the process restarts. Server output logs are subject to infrastructure rotation; this Policy does not specify a fixed retention duration for those logs. Operational counters in application memory reset at restart. Production metrics storage is configured for up to 15 days with an 8 GB size cap, so older metrics may be removed sooner.
- You may request deletion of your account and personal information at support@mustersheet.com; we will honor the request except where retention is legally required (and will tell you if so).
- Deletion requests concerning org-entered student records are routed to the controlling booster organization, and we will assist it in fulfilling them.
10. Security
We use safeguards appropriate to the data we handle, including:
- passwords stored only as bcrypt hashes;
- TLS encryption for data in transit;
- role-based access controls, so users see only the data their role permits (per event, per organization, per student link);
- administrative logging of sensitive events, including Support Access sessions;
- CSRF protection, rate limiting, and security headers; and
- routine, verified backups.
No system is perfectly secure, and we cannot guarantee absolute security. Please use a strong, unique password and contact us immediately if you suspect unauthorized access to your account.
11. Your Rights and Choices
- Access and correction. You can view and update most of your information in your account settings. For anything else, email us and we will provide a copy of the personal information we hold about you or correct it.
- Deletion. Request deletion of your account and personal information by emailing support@mustersheet.com. See Section 9 for what we must retain.
- Export. You may request an export of your personal information in a portable format; certain records (such as booster ledgers) also have built-in export tools.
- Student records. If your request concerns a student record entered by a booster organization, we will route it to that organization, which controls the data, and assist in fulfilling it. Parents can also raise these requests directly with their organization.
- Notifications. You can manage in-app and web-push notification preferences in your settings; transactional email (such as password resets) is inherent to operating your account.
We honor rights requests sent to support@mustersheet.com regardless of where you live, and we will respond within any timeline applicable law requires. We will never discriminate against you for exercising a privacy right.
12. Breach Notification
If a security breach results in unauthorized acquisition of your personal information, we will notify affected users — and, for org-entered student records, the controlling booster organization — without unreasonable delay and within the timelines required by applicable law, including the Alabama Data Breach Notification Act. Notice will describe what happened, what information was involved, and what steps we and you can take.
13. Where Data Is Stored
The Service is operated from, and your information is stored in, the United States. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
14. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy at this page and update the “Last updated” date above. For material changes — especially any change affecting student records or expanding how information is shared — we will provide advance notice to account holders by email or in-app notification. Your continued use of the Service after a change takes effect constitutes acceptance of the revised Policy.
15. Contact Us
Ner-D-Bird LLC, an Alabama limited liability company, operating the MusterSheet platform at
mustersheet.com.
Email: support@mustersheet.com