1. Two different roles we play
This matters, because your rights depend on which applies.
| Situation | Who decides how data is used | Our role |
|---|---|---|
| You contact us, or you are a customer of ours | We do | Controller |
| You are a player, parent or student whose details sit in an academy's system | The academy does | Processor, acting on the academy's instructions |
If you are a player or a parent and you want your records changed or deleted, contact your academy, not us. They control that data. We will help them act on your request, but we cannot act on it without them.
2. Data we hold as controller
About our own customers and enquirers:
- Contact details — name, business name, email, phone, country. Used to answer enquiries and provide the service. Lawful basis: contract, or legitimate interest in responding to you.
- Billing details — invoices, amounts, payment references. Lawful basis: contract and legal obligation (tax records).
- Support correspondence — emails you send us. Lawful basis: legitimate interest in running a support service.
- Server logs for our marketing site — IP address, page, timestamp, user agent. Lawful basis: legitimate interest in security and in knowing the site works.
We do not sell this data, and we do not share it for advertising.
3. Data we process for academies
Each academy gets its own separate database. We process what they put into it, which typically includes:
- Student name, date of birth, level, and notes the coach writes
- Parent or guardian email and phone number
- Attendance records, including whether a session was held, rained off or cancelled
- Prepaid lesson balances and expiry dates
- Invoices and payment status
- Booking requests submitted through the academy's public booking page — name, email, phone, chosen slot and any message
We process this only on the academy's instructions. We do not use it for our own purposes, do not sell it, do not use it for advertising, and do not use it to train machine learning models.
4. Children's data
Coaching academies teach children, so most records in the system relate to a child. We treat this as the most sensitive thing we handle.
- The academy is the controller and is responsible for obtaining consent from a parent or guardian where the law requires it.
- Our public booking page asks for a player's name and a contact email. It is designed to be completed by a parent or guardian, and says so.
- We do not knowingly collect data directly from children for our own purposes, and our marketing site is not directed at children.
- The system does not profile children, does not target advertising at them, and has no social features.
- Academies should not record health, medical or other special category data without taking their own advice.
[If you will have customers in the United States, take advice on COPPA. If in the EU or UK, confirm your position on the age of digital consent, which varies between 13 and 16 by member state.]
5. Sub-processors and hosting
We use a small number of providers. We do not add one without updating this list.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and authentication for each academy's instance | Region chosen per customer |
| Netlify | Hosting and delivery of the panel and booking page | Global edge network |
| Resend | Sending transactional email, such as booking notifications | [confirm region] |
Each is bound by its own data processing terms. We will give customers at least [30] days' notice before adding or replacing a sub-processor, so they can object.
6. Where data is stored
We create each academy's database in the region closest to them, so a South African academy's records need not sit in the United States. Tell us your preferred region at setup and we will use it where the provider offers one.
Where personal data is transferred out of the UK, the EEA or another region with transfer restrictions, we rely on [Standard Contractual Clauses / UK IDTA / adequacy — confirm which applies to you].
7. How we protect it
- Separation, not filtering. Every academy has its own database. There is no shared table holding several academies' students, so a filtering mistake cannot expose one academy's records to another.
- Row level security is enabled on every table. An unauthenticated visitor can read published booking slots and submit a booking request, and nothing else. They cannot read a single student record, invoice, or anyone else's booking.
- Privileged keys stay on the server. Service role keys live only in server-side environment variables and are never included in a page sent to a browser.
- Traffic is encrypted in transit with TLS. Data is encrypted at rest by our hosting providers.
- Text submitted by the public is escaped before display, so a booking cannot inject content into a coach's panel.
- Access to customer databases by our staff is limited to what is needed to set up or support an instance.
8. How long we keep it
| Data | Kept for |
|---|---|
| Academy records, while a subscription is active | As long as the academy keeps them |
| Academy records, after termination | Available for export for [30] days, deleted from live systems then, and from backups within [90] days |
| Our billing and tax records | [6-7] years, as tax law requires |
| Enquiries that do not become customers | [24] months |
| Marketing site server logs | [90] days |
9. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent.
- If you are a player or parent: contact your academy. They control your records. Every academy can export or delete a student's data themselves from within the panel.
- If you are our customer or enquirer: contact us at the address below. We will respond within one month.
You can complain to your data protection regulator — for example the ICO in the UK, your national authority in the EEA, the Information Regulator in South Africa, or NDPC in Nigeria.
10. Cookies and tracking
Our marketing site sets no cookies and runs no analytics, advertising or third-party tracking scripts. That is why you were not shown a cookie banner. The demos store their sample data in your browser's local storage so your changes survive a refresh; it never leaves your device and the Reset button clears it.
An academy's panel uses local storage to keep you signed in and to queue writes made while offline. That is necessary for the service to work.
[If you later add analytics, this section must change and you will probably need a consent banner in the EU and UK.]
11. Breach notification
If we become aware of a personal data breach affecting an academy's instance we will notify that academy without undue delay and in any event within [72] hours, with what we know, what we are doing, and what they may need to tell their regulator or their families. As controller, the academy is responsible for notifying its regulator and the people affected.
12. Changes
We will update this policy when what we do changes. Material changes are notified to customers by email at least [30] days before they take effect. The version and date at the top always reflect the current text.
13. Contact
[REGISTERED COMPANY NAME]
[REGISTERED ADDRESS]
Privacy enquiries: sleektechsport@gmail.com
+1 346 5100 7207
[Data Protection Officer and EU/UK representative, if you
are required to appoint one]