athleteGPS Privacy Policy (Encrypted Storage Architecture)
Last updated: August 16, 2026
1. Overview
athleteGPS (“we,” “our,” “the platform”) is designed to support youth athletes while protecting their privacy. We intentionally minimize the collection and storage of personally identifiable information (PII) and use industry‑standard encryption for all sensitive data.
We do store guardian phone numbers and email addresses, but only in encrypted form using AES‑256‑GCM. We also store SHA‑256 hashes of these identifiers for secure matching and duplicate detection.
Twilio and SendGrid are used only to deliver messages (SMS and email). They do not store guardian contact information on our behalf.
2. Information We Collect
Athletes (Minors)
We collect only non‑identifying information necessary to operate the platform, such as:
username
athlete activity data
performance indicators
hashed account password
We do not collect or store minor names, addresses, birthdates, phone numbers, or email addresses.
Parents & Guardians
Guardians may provide a phone number or email address for communication purposes. These identifiers are stored in our database only in encrypted form:
AES‑256‑GCM ciphertext for phone numbers and emails
SHA‑256 hashes for inbound SMS matching and “on file” detection
We do not store plaintext phone numbers or emails, except where technically required:
login usernames (email‑based)
temporary invite emails (until consumed or encrypted)
3. How We Use Information
Encrypted guardian contact information is used to:
send guardian consent messages
deliver athlete alerts
notify guardians of important updates
manage opt‑in and opt‑out preferences
securely match inbound SMS replies
All SMS delivery is handled by Twilio. All email delivery is handled by SendGrid.
4. SMS Messaging & Consent
a. SMS Communications
athleteGPS, operated by Athlead Partners LLC, provides optional SMS alerts to parents, coaches, and school administrators who participate in school‑managed athletic programs. SMS messages are strictly informational and sent only to individuals who have provided explicit consent.
b. How We Collect Consent
Guardians enter their mobile number inside the athleteGPS app. After submission, athleteGPS sends a consent request SMS asking the guardian to reply “YES” to confirm opt‑in. Only after replying YES are SMS alerts activated. Consent is never implied, shared, transferred, or pre‑checked.
c. Message Frequency and Costs
Message frequency varies based on user role and program activity. Message and data rates may apply depending on your mobile carrier plan.
d. Opt‑Out and Support
You may opt out at any time by replying STOP to any athleteGPS message. For assistance, reply HELP or visit athletegps.app/support.
e. Mobile Number Use and Sharing
Athlead Partners LLC does not sell, rent, or share mobile phone numbers with third parties or affiliates for marketing or promotional purposes. Encrypted mobile numbers are used solely to deliver athleteGPS SMS alerts.
f. Data Handling
Mobile numbers and emails are stored encrypted using AES‑256‑GCM and used only for the messaging purposes described in this policy. We retain SMS consent records as required for compliance and verification.
5. Non‑Sharing of Mobile Numbers
We do not sell, rent, or transfer guardian mobile numbers or email addresses. Encrypted contact information is used only for message delivery and consent management.
Twilio and SendGrid deliver messages but do not store guardian contact information on our behalf.
6. Data Storage & Security
athleteGPS uses a secure, minimal‑PII architecture:
AES‑256‑GCM encryption for phone numbers and emails
SHA‑256 hashes for matching inbound SMS
No minor PII collected
Plaintext usernames only where required for login
Temporary invite emails stored in plaintext until consumed or encrypted
All passwords hashed
All communication encrypted in transit
Encryption keys stored outside the database
If our database were compromised, encrypted contact information would remain unreadable.
7. Children’s Privacy (COPPA Compliance)
athleteGPS complies with the Children’s Online Privacy Protection Act (COPPA) by:
collecting no minor PII
requiring guardian consent for communication
encrypting all guardian contact information
allowing guardians to revoke consent at any time
8. Opt‑Out & Account Control
Guardians may:
opt out of SMS alerts by replying STOP
request deletion of athlete accounts
revoke consent for communication
request removal of encrypted contact records
request removal of SendGrid unsubscribe records
9. Changes to This Policy
We may update this Privacy Policy as needed. The latest version will always be available on this page.
10. Contact Us
For questions or requests related to privacy:
