Privacy Policy

Last updated: September 3, 2026

1. What we collect

SportVault collects the following categories of information to operate the platform:

  • Account information: name, email address, phone number, and role (academy owner, coach, parent, or student).
  • Student information: name, date of birth, and emergency contact details — provided by parents or academy staff during enrollment.
  • Academy information: academy name, address, sport types, class schedules, and pricing.
  • Payment metadata: transaction IDs, amounts, dates, and payment status from Stripe (US) or Razorpay (India). SportVault does not store raw credit card numbers, CVVs, or bank account details. All payment processing is handled directly by Stripe or Razorpay under their respective PCI-DSS certifications.
  • Usage data: pages visited, features used, and session information — collected to improve the product.
  • Communication records: email and SMS notifications sent through the platform (for delivery tracking and troubleshooting).

2. How we use your data

  • To operate the platform: enrollment processing, attendance tracking, progress reports, payment collection, and communications.
  • To send transactional notifications: class reminders, payment confirmations, waitlist updates, and waiver requests.
  • To send marketing communications on behalf of your academy (email campaigns configured by the academy owner — not from SportVault directly).
  • To power AI features: Reena (AI receptionist) uses FAQ content and academy-specific information to answer phone inquiries. AI marketing uses enrollment data to target campaigns.
  • To improve the product: aggregated, anonymized usage analytics.

3. Data sharing

We share data only with the services required to operate the platform:

  • Stripe / Razorpay: payment processing.
  • Resend: email delivery.
  • Twilio: SMS delivery.
  • Supabase: database hosting and authentication.
  • Vercel: application hosting.
  • Sentry: error monitoring (no personal data is intentionally sent; stack traces may contain request metadata).
  • PostHog: product analytics (anonymized usage events).

We do not sell personal data to third parties. We do not share personal data for advertising purposes.

4. Data retention

When an academy cancels its SportVault subscription, all data associated with that academy is retained in read-only mode indefinitely. This means enrolled families and staff can no longer modify records, but historical data (enrollments, attendance, progress, payments) remains accessible for reference.

If you want your data permanently deleted, you can request deletion by emailing hello@sportvault.app. We will process deletion requests within 30 days.

5. Data export

Academy owners can request a full export of their academy's data at any time by emailing hello@sportvault.app. Exports are provided in standard formats (CSV/JSON) within 30 days of the request.

6. Security

All data is encrypted in transit (TLS) and at rest. Authentication is handled by Supabase Auth with row-level security enforced at the database level — every query is scoped to the authenticated user's role and academy. Admin operations use service-role credentials that are never exposed to the client.

7. Children's data

SportVault collects student names, dates of birth, and skill assessment data as provided by parents and academy staff. Students under 13 do not create their own accounts — their data is managed by their parent's account. The player portal for students is only available to students whose parent has enrolled them.

8. Contact

For privacy-related questions or requests, contact us at hello@sportvault.app.