Skip to main content

Privacy

Privacy policy.

What this application collects is listed accurately below. The legal positions around it are not written yet.

Draft, pending legal review

This document is a working draft. It has not been reviewed by a lawyer and no part of it should be relied on as a finished privacy policy. It is published in this state so that anyone filling in the application can see exactly what is being collected before they type it.

The application form asks for injury history in free text. That is health-adjacent information, it is the reason this page cannot be finished from a template, and a qualified reviewer has to decide what obligations attach to it before this service takes a real application.

1.Who is responsible for this data

Vanguard Training Systems, a remote pitching development service run by Jackson Thorne. There is no other person with access to an athlete's training data or application.

2.What is collected

When you apply

  • Your name and email address.
  • Your age, school and whether you are a pitcher only or a two way player.
  • Every answer on the application form: goals, training and throwing history, playing history, velocities, lift numbers, what equipment you have access to, and what you think is holding you back.
  • Your injury history, in your own words. This is free text and you decide how much of it to write.

If you are accepted and get an account

  • Your sign-in credentials, held by Supabase Auth. The password itself is never visible to the coach or stored by this application.
  • Your name and role on your profile.
  • The training assigned to you and the training you complete: sets, reps, loads, and per exercise notes.
  • Bodyweight entries you log yourself.
  • Assessment results the coach records.
  • Daily check ins: how you slept, how you feel, anything you write in.
  • Messages between you and the coach.
  • Throwing session data where a session is recorded: throw by throw, which ball was thrown, the velocity, and whether it was a warm up.

Automatically

  • Ordinary server and hosting logs, which include IP addresses.
  • A sign-in cookie, once you have an account, so that you stay signed in. It is not used for anything else.
  • As this site is currently built there is no analytics script, no advertising cookie and no third party tracker on any page.
  • Fonts are served from this site rather than from Google Fonts, so loading a page sends no request to a third party.

Awaiting review

A reviewer needs to confirm this list against the live database before it ships and to decide how it is kept current afterwards. It was written against the schema in docs/SCHEMA.md, so it is accurate now and will drift the first time a column is added without anyone updating this page.

3.What it is used for

An application is read by the coach to decide whether to offer coaching. Training data is used to write and adjust that athlete's own program.

None of it is sold. None of it is shared with anyone outside this business, and nothing here is used to build an advertising profile.

Awaiting review

A reviewer needs to state the lawful basis for each purpose, and to decide whether an athlete's training data may ever be used in an anonymised form to inform another athlete's programming. That is a real product question and the answer is currently no by default rather than by decision.

4.Who else holds it

Two service providers hold data on this business's behalf, and no others.

Supabase
The database, sign-in, and the emails that come with an account invitation.
Vercel
Hosting, and the server logs that come with it.

Awaiting review

A reviewer needs to confirm the data processing agreement with each provider below, and where each one stores data, before this clause is final.

5.How long it is kept

Awaiting review

Nothing is decided here. A reviewer needs a retention period for declined applications, for the training history of an athlete who has left, and for messages, and the answers may differ. Today nothing is deleted on a schedule, which is a default rather than a policy and should not be published as one.

6.Your rights

In the meantime, anyone who wants a copy of their data or wants it deleted can ask by email and it will be done by hand.

Awaiting review

A reviewer needs to state which rights apply, which depends on where an athlete lives, and to define how a request is made and how quickly it is answered. There is no self-service deletion in the application yet, so whatever is promised here has to be something a person can actually carry out by hand.

7.Security

Every table in the database denies access by default, and access is granted per row: an athlete can read and write their own rows and nobody else's. That is enforced by the database itself rather than by the application asking nicely.

Awaiting review

A reviewer needs to decide what is said here and what is deliberately not said. Describing security controls in public is itself a risk, and the honest version of this clause is short.

8.Athletes under 18

Awaiting review

Unresolved, and it needs resolving before launch. The service is intended for adults, the application form currently accepts ages from 5 upward, and those two facts cannot both stand. A reviewer needs to decide the minimum age, what consent is required below it, and whether children's privacy law applies.

9.Changes to this policy

Awaiting review

A reviewer needs to set how a change is notified and whether an existing athlete has to be told directly rather than by the page being updated.

10.Contact

Questions about this policy, or a request about your own data, go to 27jthorne@gmail.com.

Before this page can ship

A qualified reviewer decides the retention periods in clause 5, the rights and the request process in clause 6, and the minimum age in clause 8, and confirms what obligations attach to the injury history the application form collects. Until then this document has no effective date and is not a policy.