TrackDataLab ("we," "our," or "us") is committed to protecting the privacy of coaches, athletes, and students who use our platform. This Privacy Policy explains what data we collect, how we use it, how we protect it, and your rights regarding that data.
This policy is designed to comply with applicable federal and state student privacy laws, including the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and student data protection laws including Illinois SOPPA, California SOPPA (AB 1584), and substantially similar statutes in other states.
If you are a school or district, please review our Data Processing Agreement, available upon request at privacy@trackdatalab.com.
1. Who This Policy Covers
This policy applies to:
Coaches (Account Holders) — individuals who create and manage a TrackDataLab account.
Assistant Coaches — additional users added to an account by a head coach.
Athletes / Students — individuals whose performance data is entered and managed by coaches. Athletes do not directly interact with or log in to TrackDataLab.
Website Visitors — individuals who visit trackdatalab.com without creating an account.
2. Data We Collect
Account data (coaches):
Email address and hashed password
Display name (optional)
Subscription plan and billing status
Session information (encrypted cookie)
Athlete / student data (entered by coaches):
Athlete name or alias (as entered by the coach — coaches may use aliases or initials)
Group or team membership
Athletic performance metrics (times, distances, scores, test results)
Attendance records (practice check-in status)
Schedule and competition events
Assessment results (Pro plan)
Inventory check-out records (Pro plan)
We do not collect:
Social Security numbers, government IDs, or financial information about athletes
Medical records, health insurance information, or biometric data
Home addresses, phone numbers, or email addresses of athletes
Geolocation data
Behavioral tracking data, browsing history, or advertising identifiers
3. How We Use Data
We use collected data only to:
Provide and operate the TrackDataLab service
Display performance data, reports, and leaderboards to authorized coaches and assistants
Ensure account security and prevent unauthorized access
Comply with legal obligations
We never:
Sell student or athlete data to any third party
Use student data for targeted advertising or behavioral profiling
Share athlete data with third parties for commercial purposes
Use student data for any purpose other than providing the educational service requested by the school or coach
4. Data Isolation and Access Controls
Every coach account is fully isolated. Coaches can only access data they have entered. Assistant coaches can only access features the head coach has explicitly permitted. No coach can view another coach's athlete data.
Public share links, if enabled by a coach, expose only the specific data the coach has configured. Attendance records are never included in public-facing responses. Coaches may enable athlete anonymization on public links, replacing real names with "Athlete 1," "Athlete 2," etc.
5. FERPA Compliance
When TrackDataLab is used by a school or educational institution, student performance data entered into the platform may constitute "education records" under FERPA. In such cases:
The school (as the educational agency) retains ownership and control of student education records.
TrackDataLab acts as a "school official" with a legitimate educational interest, as defined under FERPA (34 C.F.R. § 99.31(a)(1)).
We do not disclose student education records to third parties without the school's written consent, except as permitted by FERPA.
Schools may request access to, correction of, or deletion of student records at any time.
Schools using TrackDataLab should execute a Data Processing Agreement (DPA). Contact privacy@trackdatalab.com to obtain one.
6. Student Privacy Laws (SOPPA, COPPA, and Similar)
TrackDataLab complies with state student online privacy protection statutes, including Illinois SOPPA (105 ILCS 85), California AB 1584, and substantially similar laws. Specifically:
We do not sell student data.
We do not use student data to advertise to students.
We do not build profiles on students for non-educational purposes.
Student data is used solely to provide the TrackDataLab service to the school or coach.
We support the right of schools and parents to request deletion of student data.
We will notify affected schools of any confirmed data breach involving student data within 72 hours of discovery, as required by applicable law.
TrackDataLab is not directed at children under 13. We do not knowingly collect personal information directly from children under 13. All data about minors is entered by their coach or school administrator, not by the student directly.
7. Data Retention
Active accounts: Data is retained for as long as the account remains active.
Deleted accounts: When a coach account is deleted (by the coach or by an administrator), all associated data — including athlete records, performance data, attendance, and public share links — is permanently deleted from our databases within 30 days.
Audit logs: Security and administrative audit logs are retained for 12 months for security and compliance purposes.
Backups: Encrypted database backups may retain data for up to 30 days after deletion before being purged from backup rotation.
8. Data Security
All data is transmitted over HTTPS/TLS.
Passwords are hashed using bcrypt (cost factor 12) and never stored in plaintext.
Sessions are stored server-side in an encrypted PostgreSQL session store with a 30-day expiry.
Access is rate-limited on all authentication endpoints to prevent brute-force attacks.
Each coach's data is logically isolated at the database query level — all queries are scoped to the authenticated user's ID.
Attendance data is never included in public-facing API responses.
9. Your Rights
Coaches (and schools on behalf of athletes) may:
Access — request a copy of all data associated with their account.
Correction — update or correct any data at any time through the app.
Deletion — permanently delete their account and all associated data from Settings → Profile → Delete Account, or by contacting us at privacy@trackdatalab.com. Deletion is permanent and irreversible.
Portability — export athlete and performance data as CSV from the Management tab at any time.
Objection — request that we stop processing specific data. Note that certain processing is required to provide the service.
10. Third-Party Services
TrackDataLab uses a small number of third-party services to operate:
Hosting: Replit — our application servers and database run on Replit's infrastructure. Replit is SOC 2 compliant.
Email delivery: Resend (via SMTP) — used for transactional emails only (account creation, billing, security alerts). No athlete data is included in emails.
Fonts: Google Fonts (loaded from fonts.googleapis.com) — no personal data is transmitted.
We do not use Google Analytics, Facebook Pixel, or any other behavioral tracking or advertising technology.
11. Cookies and Session Data
We use a single first-party session cookie (tdl.sid) to keep coaches logged in. This cookie:
Is HttpOnly (not accessible to JavaScript)
Is Secure (only transmitted over HTTPS)
Expires after 30 days of inactivity
Contains no personal information — only an encrypted session identifier
We do not use advertising cookies, tracking pixels, or third-party cookies of any kind.
12. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will notify coaches by email and update the "Last Updated" date above. Continued use of TrackDataLab after the effective date constitutes acceptance of the updated policy.
Contact & Data Requests
For privacy questions, data deletion requests, Data Processing Agreements, or breach reports: