Last Updated: August 15, 2026 · Effective Date: August 15, 2026
TrackDataLab Performance Systems LLC ("we," "our," or "us") is committed to protecting the privacy of coaches, athletes, assistant coaches, and all users of our platform. This Privacy Policy explains what data we collect, how we use it, how we secure it, and your rights over that data.
This policy is designed to comply with applicable federal and state student privacy laws, including the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and student data protection statutes including Illinois SOPPA, California AB 1584, and substantially similar laws in other jurisdictions.
If you are a school or district and require a Data Processing Agreement, please submit a request through our .
This policy applies to all users of the TrackDataLab platform:
Coaches (Account Holders) — individuals who create and manage a TrackDataLab coach account. Coaches are the primary data controllers for their teams.
Assistant Coaches — additional users added to a coach account by the head coach, with access scoped to permissions the head coach configures.
Athletes — individuals whose performance data is recorded by coaches, and who may independently access their own data through the TrackDataLab Athlete App using their own authenticated account.
Website Visitors — individuals who visit trackdatalab.com without creating an account.
2. Data We Collect
Coach account data:
Email address and bcrypt-hashed password (plaintext never stored)
Display name (optional)
Subscription plan and billing status
Session information stored server-side via encrypted cookie
Stripe customer ID (for paid plans) — no raw card data stored by TrackDataLab
Athlete data (entered or managed by coaches):
Athlete name or alias (coaches may use initials or pseudonyms)
Assessment results and profiling scores (Pro plan)
Inventory check-out records (Pro plan)
Athlete portal / app account data (when athletes create their own account):
Email address and bcrypt-hashed password
Display name (entered by the athlete at registration)
Linked roster entry (associated with coach's account via join code)
Session cookie for the mobile/web athlete portal
We do not collect:
Social Security numbers, government IDs, or financial account information about athletes
Medical records, health insurance information, or biometric identifiers
Home addresses, phone numbers, or personal email addresses of athletes (unless voluntarily provided by the coach)
Geolocation data or GPS coordinates
Behavioral tracking data, browsing history, ad identifiers, or device fingerprints
3. Coach–Athlete Relationship & Data Ownership
The coach is the data controller for all athlete performance data entered into their account. TrackDataLab acts as a data processor on the coach's behalf.
Coaches own their data. All roster entries, performance records, attendance logs, and custom metrics created by a coach belong exclusively to that coach's account.
Athletes do not have access to other athletes' data. When an athlete logs in to the Athlete Portal, they can only see their own individual performance data, their group's leaderboard standings (aggregated, not individual metric breakdowns of teammates), and workouts assigned to their group.
Coaches control what athletes can see. Coaches configure which sections (schedule, leaderboard, workout, reporting, assessment) are visible to athletes on a per-join-code basis. Coaches may restrict or expand access at any time.
Leaderboards are limited. Leaderboard views exposed to athletes show athlete names and aggregate ranking values only — not full metric breakdowns, raw trial data, or assessment profiles of other athletes.
No cross-account visibility. No coach can access any other coach's athlete data, roster, or account information under any circumstances.
4. Athlete Portal & Mobile App
TrackDataLab provides a dedicated Athlete App (available as a mobile and web application) that allows athletes to independently access data their coach has made available to them.
How athletes access the platform: Athletes receive a 6-character join code from their coach. Using this code in the Athlete App, they create an account (email + password) which links their app account to the coach's roster. Returning athletes log in directly with their email and password — no join code is required after initial registration.
When an athlete uses the Athlete App:
They can view their individual performance results and trends
They can view their personal assessment profile (if enabled by the coach)
They can view the group leaderboard (aggregate rankings, names + best score only)
They can view workouts and schedules assigned to their group
They cannot view any other athlete's individual metric history, assessment breakdown, or attendance records
They cannot view athletes in other groups unless the coach has explicitly included them
Athlete app accounts are separate from coach accounts. An athlete account can only be created via a valid coach-issued join code and is permanently tied to that coach's account and join code configuration.
5. How We Use Data
We use collected data only to:
Provide, operate, and improve the TrackDataLab platform
Display performance data, reports, and leaderboards to authorized coaches, assistants, and athletes
Process subscription payments via Stripe (paid tiers only)
Enforce subscription plan limits (athlete roster capacity)
Ensure account security and prevent unauthorized access
Comply with legal obligations and respond to lawful requests
We never:
Sell coach, athlete, or student data to any third party
Use athlete or student data for targeted advertising or behavioral profiling
Share athlete data with third parties for commercial purposes
Use student data for any purpose other than delivering the service requested by the coach or institution
Train AI or machine learning models on any user or athlete data
6. Data Isolation & Access Controls
TrackDataLab enforces strict data isolation at every layer of the platform:
Coach accounts are fully siloed. All database queries are scoped to the authenticated user's account ID. No server route returns data belonging to another coach account.
Athlete portal access is fail-closed. If an athlete's session cannot be verified, all data requests return 401/403 — no partial data is returned.
Join codes are scoped. An athlete registered via a specific join code can only see data within the groups and sections that code grants access to.
Attendance is never public. Attendance records are excluded from all public-facing API responses, even when a coach enables public leaderboard sharing.
Public share links are coach-controlled. Public share pages expose only data the coach has configured. Coaches may enable athlete name anonymization (replacing names with "Athlete 1," etc.) on public views.
Assistants have restricted access. Assistant coaches can only access features explicitly granted by the head coach and cannot access billing, account settings, or raw data exports.
7. Payment & Billing Data
TrackDataLab uses Stripe as its payment processor. All subscriptions are billed annually (once per year). We do not offer monthly billing.
All payment card data (card number, CVV, expiry) is entered directly into Stripe's hosted checkout and is never transmitted to or stored by TrackDataLab servers.
TrackDataLab stores only the Stripe customer ID and subscription status, which are used to enforce plan limits and display account status.
Billing receipts and payment confirmations are sent by Stripe directly to the coach's email address.
Coaches may manage their subscription (cancel, view invoices) through the Stripe Customer Portal, accessible from the Coach Dashboard settings.
Free plan accounts are not required to provide any payment information.
When TrackDataLab is used by a school or educational institution, student performance data may constitute "education records" under FERPA. In such cases:
The school retains ownership and control of student education records.
TrackDataLab acts as a "school official" with a legitimate educational interest, as defined under FERPA (34 C.F.R. § 99.31(a)(1)).
We do not disclose student education records to third parties without written consent, except as permitted by FERPA.
Schools may request access to, correction of, or deletion of student records at any time through our .
Schools and districts should execute a Data Processing Agreement (DPA) with TrackDataLab before use. DPAs are available upon request — please submit a request through our .
9. Student Privacy Laws (SOPPA, COPPA & Similar)
TrackDataLab complies with applicable state student privacy statutes, including Illinois SOPPA (105 ILCS 85), California AB 1584, and substantially similar laws. Specifically:
We do not sell student data.
We do not use student data to advertise to students or other parties.
We do not build behavioral or commercial profiles on students.
Student data is used solely to provide the TrackDataLab service.
Schools and parents retain the right to request deletion of student records.
We will notify affected schools of any confirmed breach involving student data within 72 hours of discovery, as required by applicable law.
TrackDataLab is not directed at children under 13. We do not knowingly collect personal information directly from children under 13 without verifiable parental consent. All data about minors is entered by a coach or school administrator acting in an educational capacity, or by the minor themselves through the Athlete App using a coach-issued join code (in which case the school or coach is responsible for ensuring appropriate consent under applicable law).
10. Data Retention
Active accounts: Retained for as long as the account is active.
Deleted coach accounts: Upon deletion, all associated data — roster entries, performance records, attendance, share links, and athlete portal accounts linked to that coach — is permanently deleted within 30 days.
Deleted athlete portal accounts: The athlete's login credentials are deleted immediately. Roster performance data entered by the coach (not by the athlete) is retained at the coach's discretion unless the coach deletes it.
Audit logs: Security and administrative audit logs are retained for 12 months for security and compliance purposes.
Encrypted backups: Database backups may retain data for up to 30 days after deletion before being purged from the backup rotation cycle.
Billing records: Stripe transaction records and invoice history are retained for 7 years as required by financial regulations. These are held by Stripe, not by TrackDataLab.
11. Data Security
TrackDataLab implements the following security controls:
All data is transmitted over HTTPS/TLS 1.2 or higher.
Passwords are hashed using bcrypt (cost factor 12) and are never stored or transmitted in plaintext.
Sessions are stored server-side in a PostgreSQL session store, signed with a secret key, and expire after 30 days of inactivity.
Authentication endpoints are rate-limited to prevent brute-force and credential-stuffing attacks.
All database queries are parameterized to prevent SQL injection.
Each account's data is isolated at the query level — all data access is scoped to the authenticated user ID.
Athlete portal sessions use a separate authentication flow from coach sessions; a coach session cannot be used to authenticate as an athlete, and vice versa.
No payment card data is processed by TrackDataLab infrastructure — all card processing is handled by Stripe's PCI-DSS Level 1 certified systems.
Cross-account data contamination is prevented by a session fingerprint system that detects and halts writes when the authenticated session does not match the expected user ID.
If you discover a security vulnerability in our platform, please report it responsibly through our . We commit to acknowledging all reports within 48 hours.
12. Your Rights
Coaches (and schools or parents acting on behalf of athletes) have the following rights:
Access — request a copy of all data stored in your account. Coach data is exportable as CSV from the Management tab at any time.
Correction — update or correct any data through the Coach Dashboard or Athlete App at any time.
Deletion — permanently delete your account and all associated data via Settings → Profile → Delete Account, or by submitting a request through our . Deletion is permanent and irreversible.
Portability — export athlete and performance data as CSV from the Management tab at any time without contacting support.
Restriction — request that we limit processing of specific data. Note that certain processing is required to provide the service.
Objection — object to processing in cases where processing is based on legitimate interests.
Athletes with an Athlete Portal account may request deletion of their login credentials at any time by contacting their coach or submitting a request through our . Note that performance data entered by a coach is controlled by the coach, not the athlete.
13. Third-Party Services
TrackDataLab uses the following third-party services to operate the platform:
Hosting & Database:Replit — our application servers and PostgreSQL database run on Replit's infrastructure, which is SOC 2 Type II compliant.
Payment Processing:Stripe — all subscription billing is handled by Stripe. No raw payment card data touches our servers. Stripe is PCI-DSS Level 1 certified. See stripe.com/privacy.
Transactional Email: SMTP email delivery via our configured mail provider — used only for account creation confirmations, password resets, and billing alerts. No athlete data is included in email content.
Fonts:Google Fonts (fonts.googleapis.com) — loads typefaces for the web interface. Google may log font request metadata (IP, browser) per their standard CDN logging. No personal or athlete data is transmitted.
We do not use Google Analytics, Facebook Pixel, Mixpanel, Segment, Intercom, or any other behavioral analytics or advertising technology. We do not place third-party advertising cookies.
14. Cookies & Session Data
TrackDataLab uses a single first-party session cookie (tdl.sid) to authenticate logged-in sessions. This cookie:
Is HttpOnly — not accessible to JavaScript; cannot be read by browser extensions or injected scripts.
Is Secure — only transmitted over HTTPS encrypted connections.
Is SameSite=None (with Secure) — required for cross-origin access from the Athlete mobile app running on its own domain.
Expires after 30 days of inactivity (or immediately on explicit logout).
Contains only an encrypted session identifier — no personal information is stored in the cookie itself.
We do not use advertising cookies, tracking pixels, or any third-party cookies. No cookie consent banner is required because we do not place non-essential cookies.
15. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal obligations. When we make material changes, we will notify coaches by email to the address on file and update the "Last Updated" date at the top of this page. Continued use of TrackDataLab after the effective date of an updated policy constitutes acceptance of the revised terms.
For questions about what constitutes a "material change," please reach out through our .
Privacy Questions & Data Requests
For privacy questions, data access or deletion requests, Data Processing Agreements, FERPA inquiries, security disclosures, or breach reports — use our contact form. We aim to respond to all privacy requests within 5 business days.
TrackDataLab Performance Systems LLC · trackdatalab.com