Pool Party Pick 'Em
How It Works Events Leaderboard Scoring Try Demo
Log In Join Free

Data Breach & Security Incident Response Policy

Effective Date: September 4, 2026

Owner: Cameron Mayer, Founder

Applies To: All systems, data, and personnel involved in operating Pool Party Pick 'Em


1. Purpose

This policy establishes how Pool Party Pick 'Em ("the Company," "we," "us") detects, investigates, contains, and provides notification for security incidents that may compromise personal information belonging to our users. It is designed to satisfy the Company's obligations under applicable state data breach notification laws, given that our users reside across the United States.

2. Scope

This policy applies to all personal information collected or processed by Pool Party Pick 'Em, including account credentials, email addresses, and any payment-related data handled through our systems or third-party processors. It applies to the Company's website, backend infrastructure, hosting environment, and any third-party service providers with access to user data.

3. Definitions

  • Personal Information: Data that identifies or could reasonably be linked to an individual, such as name, email address, account credentials, or payment information.
  • Security Incident: Any suspected or confirmed event that jeopardizes the confidentiality, integrity, or availability of Company systems or the personal information they contain (e.g., unauthorized access, malware, lost credentials, misconfigured access controls).
  • Data Breach: A security incident confirmed to have resulted in the unauthorized acquisition of, or access to, personal information that compromises its security, confidentiality, or integrity, as further defined by applicable state law.

4. Roles & Responsibilities

4.1 Incident Response Lead

Cameron Mayer serves as Incident Response Lead and is responsible for coordinating detection, investigation, containment, notification, and remediation for any security incident. The Incident Response Lead may engage outside counsel, a security consultant, or the Company's hosting/infrastructure provider as needed to investigate or remediate an incident.

4.2 All Personnel and Contractors

Anyone with access to Company systems (including contractors or third-party developers) must report a suspected security incident to the Incident Response Lead immediately upon discovery, and no later than 24 hours after discovery.

5. Incident Detection & Reporting

Potential incidents may be identified through, among other things:

  • Automated alerts from hosting, authentication, or monitoring services
  • Reports from users (e.g., unrecognized account activity)
  • Reports from employees, contractors, or third-party vendors
  • Routine log review or security testing

Any suspected incident must be reported to the Incident Response Lead as soon as it is discovered, using the contact information in Section 11. Reports should include what was observed, when it was observed, and any systems or accounts believed to be affected.

6. Incident Assessment & Investigation

Upon receiving a report, the Incident Response Lead will, within 48 hours where practicable:

  • Confirm whether a security incident has occurred and is ongoing
  • Identify which systems, accounts, and categories of personal information may be affected
  • Estimate the number of individuals potentially affected and their state(s) of residence
  • Determine the likely cause and whether the incident is still active
  • Document findings in the incident log described in Section 9

If the investigation confirms that personal information was accessed or acquired without authorization, the incident is treated as a data breach and the notification process in Section 8 is initiated.

7. Containment, Eradication & Recovery

Once an incident is confirmed, the Incident Response Lead will take reasonable steps to:

  • Contain the incident (e.g., revoke compromised credentials, disable affected accounts or services, patch exploited vulnerabilities)
  • Preserve evidence and logs relevant to the investigation
  • Eliminate the root cause before restoring normal operations
  • Restore affected systems from clean backups or configurations where necessary
  • Verify that the incident has been fully resolved before closing containment activities

8. Notification Obligations

8.1 Internal Notification

The Incident Response Lead documents the incident internally regardless of severity, and treats confirmed breaches as the highest priority until resolved.

8.2 Determining Applicable Law

Because Pool Party Pick 'Em is based in North Carolina but has users nationwide, the notification requirements that apply to a given breach depend on where the affected individuals reside — not just where the Company is located. For each confirmed breach, the Incident Response Lead will identify the state(s) of residence of affected individuals and consult the applicable breach notification statute for each state (as well as North Carolina General Statute § 75-65, which governs the Company's own obligations as a North Carolina business). Requirements that commonly appear across state laws include:

  • Notice to affected individuals without unreasonable delay, subject to law enforcement or investigative needs
  • A specific outer deadline in many states (commonly ranging from 30 to 60 days from discovery, though this varies by state and some states set no fixed deadline)
  • Notice to the state Attorney General when the number of affected residents of that state exceeds a statutory threshold
  • Notice to nationwide consumer reporting agencies when a breach affects a large number of individuals (frequently a 1,000-person threshold, drawn from state law and 15 U.S.C. § 1681a note)
  • Specific required content in the notice, such as a description of the incident, categories of information involved, and steps individuals can take to protect themselves

State requirements differ in their deadlines, thresholds, and required notice content, and they change over time. This policy sets a baseline internal process; it does not substitute for a state-by-state legal review at the time of an actual incident. See Section 12.

8.3 Notification to Affected Individuals

Where a breach is confirmed to involve personal information, the Incident Response Lead will notify affected individuals by email using the address on file, in plain language, including:

  • A description of what happened and when it was discovered
  • The categories of personal information involved
  • Steps the Company has taken in response
  • Steps the individual can take to protect themselves (e.g., changing their password, monitoring accounts)
  • Contact information for follow-up questions

8.4 Notification Timing

Notification to affected individuals will be made without unreasonable delay following confirmation of the breach, and in no event later than the shortest deadline required by an applicable state law, except where law enforcement requests a delay to avoid impeding an investigation.

8.5 Regulatory Notification

The Incident Response Lead will determine, on a state-by-state basis, whether notice to any state Attorney General or other regulator is required based on the number of affected residents in that state, and will submit any required regulatory notices within the applicable deadline.

9. Documentation & Recordkeeping

The Incident Response Lead maintains a written incident log for every reported security incident, whether or not it is ultimately confirmed as a breach. Each entry includes: date reported, date discovered, description, systems and data affected, individuals affected (including state of residence, once known), containment actions taken, notifications sent (and to whom), and final resolution. Incident records are retained for at least three years.

10. Policy Review

This policy is reviewed at least annually, and promptly after any confirmed security incident, to incorporate lessons learned and to reflect changes in applicable law or in the Company's systems and vendors.

11. Contacts

Incident Response Lead: Cameron Mayer — cameronmayer0@gmail.com

Reporting Channel: Email the Incident Response Lead immediately upon discovering a suspected incident.

12. Important Note on Legal Review

This document is a general operational template, not legal advice, and it does not by itself guarantee compliance with any specific state's breach notification law. Because breach notification requirements (deadlines, thresholds, required notice content, and regulator notification rules) vary by state and change periodically, this policy — and the Company's response to any actual incident — should be reviewed by an attorney licensed in North Carolina and, where relevant, in the states where affected users reside.

© 2027 Pool Party Pick 'Em. All rights reserved. Made for fans, by fans. Play responsibly.