Owner-approved operational version
AthleticsArc Privacy Policy
This policy explains how AthleticsArc handles information in the product that exists today, including FootballArc, adult Accounts, Team tools, guardian-managed athlete profiles, communications, and billing. It does not promise controls or deadlines that have not been implemented.
- Review date
- September 1, 2026
- Operational approval
- September 5, 2026
- Version
- privacy-2026-09-15-v1
- Provider
- BJC Ventures LLC, doing business as AthleticsArc
- Location
- Fairhope, Alabama, United States
1. Who we are and what this policy covers
September 18, 2026 website analytics notice: basic cookie-free visitor counts now cover public pages and the signed-in website. The account-deletion and mobile-notification policy remains in effect.
BJC Ventures LLC, doing business as AthleticsArc provides AthleticsArc, including FootballArc and related account, Team, coaching, family, communication, and administration services. This policy covers information handled through our website, iPhone, iPad and Android apps, invitations, beta-access requests, support and feedback tools, and billing flows.
A single AthleticsArc Account may have more than one relationship, such as coach, Team staff member, guardian, or Platform Administrator. Those relationships remain separate and determine which information and tools the person may access.
2. Information we collect and create
- Adult Account and identity data: name, email, authentication records, account-purpose choices, email-verification state, password-recovery events, policy versions accepted, and acceptance timestamps.
- Team and relationship data: Team names, roles, staff memberships, permissions, invitations, guardian relationships, athlete links, product entitlements, subscriptions, and Coaching Spaces.
- Athlete and roster data: guardian-managed athlete profiles and separate Team roster records, including names, jersey numbers, positions, roster status, depth-chart and personnel assignments, and Team-specific participation information.
- Coaching content: Playbooks, Plays, formations, diagrams, routes, notes, Practices, event schedules, drills, assignments, personnel packages, depth charts, print settings, and saved templates.
- Collaboration and communications: Coaches Room material, shared-play revisions, Locker Room publications, adult messages, replies, reactions, acknowledgements, mentions, read state, notification preferences, and moderation history.
- Files and visual identity: Team logos and background marks that authorized users upload. Current adult messaging does not support general file or media attachments.
- Support, feedback, and administration: feedback descriptions, current route, broad browser/device class, application/deployment version, authorized Team context, access-diagnosis metadata, audit events, and administrative reasons and outcomes.
- Billing: Stripe customer, Checkout, subscription, invoice, product/price, plan, interval, seat quantity, status, and billing lifecycle identifiers. AthleticsArc does not receive or store full payment-card numbers.
- Technical and security data: IP-derived request context, session and authentication events, rate-limit records, timestamps, request/correlation IDs, error and runtime logs, security events, and device/browser information needed to operate and protect the service.
- Mobile notifications: when enabled, device registration and push tokens connect alerts to your current Account. Tokens are removed during account deletion. Notification access is checked against current Team and conversation permissions.
We ask users not to submit medical information, passwords, invitation tokens, unnecessary youth information, or other sensitive content through public request or feedback forms.
3. Athletes and youth privacy
AthleticsArc Accounts are for adults age 18 or older. The current product does not provide youth Accounts or youth messaging, and AthleticsArc does not ask youth athletes to submit information directly. Athlete records are created and maintained by authorized adult Team staff and connected adult guardians.
Current athlete profiles and Team roster records may include an athlete's name, jersey number, primary and secondary positions, Team affiliation, roster status, and depth-chart or personnel-package assignments. These records are entered and managed by authorized adults.
AthleticsArc does not currently request a youth athlete's date of birth, personal email address, phone number, home address, precise location, government identification, biometric information, medical or health information, financial information, school records, or login credentials. Adult users should not enter these details or other sensitive youth information in messages, notes, Practice or drill fields, Locker Room publications, Coaches Room posts, support requests, or other free-text areas.
A persistent athlete profile is separate from a Team roster record. A guardian relationship does not make the guardian Team staff, and a Team role does not give a coach unrestricted control of a guardian-managed athlete profile. Removing a roster or guardian relationship does not automatically delete the underlying athlete profile, Team history, or another authorized relationship.
Athlete information is not a public profile. AthleticsArc does not sell it, use it for targeted advertising, or make it available for public youth tracking or early recruiting. Any future youth access or disclosure feature would require a separate product and legal review.
Before a future feature asks adults for additional categories of youth information, AthleticsArc will update this policy and any applicable adult permission, consent, and access controls. This statement does not claim that a future feature or control is available today.
4. How we use information
- create and secure adult Accounts and preserve one canonical Account/Person identity;
- provide requested coaching, Team, family, communication, print, and administration functions;
- resolve current permissions, Team and guardian relationships, plan capabilities, and product access;
- process invitations, trials, subscriptions, staff seats, cancellation, and payment status;
- deliver in-app notifications and requested communications;
- prevent fraud, abuse, unauthorized access, cross-Team or cross-athlete disclosure, and unsafe messaging;
- diagnose failures, maintain audit history, improve reliability, and respond to support or privacy requests;
- comply with law and protect users, AthleticsArc, and others.
We do not sell personal information. We do not use personal information for targeted or cross-context behavioral advertising. We do not use advertising SDKs or analytics that link activity across unrelated websites. Basic website analytics and optional account-linked measurement are described below.
Basic website analytics: Vercel Web Analytics counts visitors and page views on public pages and the signed-in website by default, without analytics cookies or links to your AthleticsArc Account. Reports include page categories, referring sites, approximate location, and browser/device types. We remove query strings, fragments, and private record identifiers from page URLs before collection, and exclude administration, invitation, and authentication-callback pages. We do not send athlete details, coaching content, messages, names, or email addresses as analytics properties. Global Privacy Control and Do Not Track signals stop collection for that browser. This website integration does not collect activity inside the native mobile app.
Optional account-linked measurement: with your separate permission, we store a random browser identifier in a first-party cookie for up to 90 days. We record a broad traffic-source category, selected public coaching pages, download and trial-link clicks, and connect that record to your Account when you start a trial. We then record the first saved Play or Practice Plan and first confirmed paid subscription during that period. We do not include athlete details, Play content, messages, full referring URLs, or search terms in these records. This permission is separate from email marketing.
Account-linked measurement is off until you allow it in the Account-linked measurement control at the bottom of a public page. Turn it off there to delete this browser’s measurement record and its Account association. The same control remains available in the application while measurement is on. Global Privacy Control and Do Not Track signals disable measurement for that browser. Records expire after 90 days and are excluded from reporting; expired records are removed during subsequent measurement collection or report maintenance. We use the results to understand which resources help coaches start using FootballArc.
6. Service providers and disclosures outside AthleticsArc
Verified providers used by the current application include:
- Supabase for authentication, database, real-time features, storage, and related infrastructure;
- Vercel for application hosting, delivery, server execution, deployments, operational logs, and basic website visitor analytics;
- Stripe for hosted Checkout, the customer billing portal, payment processing, invoices, and subscription status.
- Resend for transactional email, including billing notices and account-deletion confirmation;
- Apple Push Notification service for enabled iPhone and iPad message alerts.
These providers process information for us under their own agreements and privacy notices. We may also disclose limited information when required by law, to protect rights and safety, in a corporate transaction subject to appropriate safeguards, or with the user’s direction. We do not give one Team access to another Team’s information.
7. Retention
We keep information while an Account, Team, relationship, subscription, or operational need remains active. The product often preserves coaching content, Team history, athlete identity, billing records, relationship history, message history, and audit events after access changes so that work is not silently deleted or reassigned.
Verified account deletion removes the person’s personal coaching space and playbooks, authored messages, saved print settings, associated device registrations and login. Team-owned coaching work remains with the Team after personal attribution is removed. If the person was a Team’s only owner, that Team stays archived without an owner. Other adults, managed athletes and other guardians’ relationships are preserved.
We retain minimized identifiers and history needed to preserve Team records, prevent old sessions from regaining access, document deletion and reconcile past billing. Our interim operational schedule retains closed privacy-case evidence for three years and minimized security/audit and financial evidence for seven years, subject to applicable holds and review. Payment providers may retain past financial records under their own obligations. Provider backups and operational logs expire under the providers’ configured retention schedules; active-system deletion does not promise immediate removal from every backup.
8. Security
We use role- and relationship-based access controls, database row-level security, server-side permission checks, environment separation, rate limits, signed Stripe webhooks, protected administrative access, and audit logs. Uploaded Team branding is limited, validated, normalized, and stored in Team-scoped paths.
No service can guarantee perfect security. Users should protect their password, sign out of shared devices, and report suspicious activity. We will handle legally required breach notices according to applicable law, but this draft does not promise a shorter notice deadline than the law requires.
9. Access, correction, deletion, and appeal requests
Users can correct some Account, Team, roster, athlete, notification, and relationship information through the permissions available in the product. A Team manager controls Team-specific records; a connected Guardian Manager controls only the supported guardian-managed profile fields. Those controls do not override another person’s rights or Team authority.
Start account deletion in Account settings on the website or mobile app, review its scope and confirm your current password and authenticator if enabled. The request covers the shared Account on both platforms. Our privacy team processes verified requests with a target of 30 days, resolves Team ownership, stops subscriptions billed to the Account and sends completion confirmation. Once processing starts, removals cannot be undone. You do not need to email support to initiate deletion.
For access, correction, relationship review, questions about retained records or an appeal, contact [email protected]. We verify identity and authority, honor applicable legal holds and explain any limitation or changed completion target. General automatic retention purges remain disabled; verified account-deletion requests use the protected deletion process.
10. State, regional, and consumer rights
Depending on where a user lives, law may provide rights to know, access, correct, delete, limit, or obtain a copy of personal information; opt out of certain sale, sharing, or targeted-advertising uses; and appeal a decision. AthleticsArc does not currently sell personal information or use it for targeted advertising.
We will not discriminate against a user for exercising applicable privacy rights. Authorized agents and parental/guardian requests require reasonable verification of identity and authority. Mandatory consumer protections in a user’s jurisdiction continue to apply even when these policies refer to Alabama law.
12. Policy changes and contact
We may update this policy as the product, providers, or law changes. The page will identify the current version and date. When a material change requires renewed acceptance, AthleticsArc is designed to record the specific accepted version and timestamp rather than rely on a prechecked box.
Questions and privacy requests may be sent to [email protected] for BJC Ventures LLC, doing business as AthleticsArc. See the Terms of Service for account and subscription rules.
