Plain-language beta policy

STRIDE OS Privacy Policy

This policy explains what STRIDE OS collects, why it collects it, and what choices coaches, teams, schools, parents, and athletes have.

Not legal advice. This is an operational beta privacy policy for launch comfort. It should be reviewed by qualified counsel before broad school or district sales.

1. Short version

2. Information we collect

CategoryExamplesWhy we collect it
Account informationEmail address, display name, team name, login metadataAuthentication, support, account management, and security.
Athlete roster informationName or identifier, age, grade, sex, event focus, roster statusRoster management and coach workspace features.
Performance and training dataRace results, times, race dates, workouts, notes, check-ins, importsPace calculations, forecasts, event fit, training groups, lineup tools, exports, and product improvement.
Billing informationStripe customer ID, plan, subscription status, checkout historyPaid plans, trials, invoices, refunds, subscription portal, and fraud prevention. Stripe handles payment card data.
Technical informationIP address, browser/device metadata, logs, error diagnosticsSecurity, debugging, abuse prevention, and keeping the service working.
Optional integrationsConnection identifiers and activity data if you connect an integrationOnly to provide the connected feature you choose to use.

3. How we use information

We use information to provide STRIDE OS, save and sync rosters, calculate paces and forecasts, support paid subscriptions, secure the service, troubleshoot bugs, improve accuracy, respond to requests, and meet legal obligations.

4. Student data, schools, and FERPA posture

STRIDE OS may store student-athlete information entered by a coach or authorized staff member. If a school or district uses STRIDE OS, that school or district remains responsible for its own student-data privacy process and compliance decisions.

Our posture: STRIDE OS is built to support school review by limiting access by workspace, avoiding ads and data sales, supporting export/deletion, and using athlete data only to provide and improve the service. We do not claim blanket "FERPA compliant" status without the school/district review and any required written agreement.

For school or district purchases, a separate data processing agreement, student data privacy agreement, or district vendor terms may be needed.

5. Children under 13

STRIDE OS is intended for coaches and authorized adults. We do not knowingly collect information directly from children under 13. Before entering personal information for an athlete under 13, the coach must have parent/guardian permission or school/district authorization where legally permitted.

Parents or guardians may ask to review or delete information tied to their child by contacting us. We may need to verify the request with the coach, team, school, or account owner before acting on it.

6. Research, AI, and de-identified data

By default, STRIDE OS does not train outside AI models on identifiable athlete data. We may use de-identified or aggregate data to understand whether formulas, forecasts, or product workflows are working. We will seek explicit permission before using identifiable athlete data for external research, model training, publication, or data sharing beyond service operations.

7. How we share information

We share information only as needed to run STRIDE OS, comply with law, protect rights and security, or honor a written agreement.

8. Subprocessors

Current core subprocessors include Supabase for database/authentication, Vercel for hosting, and Stripe for payments. A working subprocessor list is maintained at docs/legal/SUBPROCESSORS.md.

Marketing measurement: the public marketing pages may use a Meta (Facebook) advertising pixel to measure how people find STRIDE OS. It runs for signed-out visitors only — it is disabled whenever a coach session exists, it never runs inside the coach workspace, and it never receives roster, athlete, or performance data. This does not change the commitments above: no ads inside the product, and no athlete data used for advertising.

9. Security

STRIDE OS uses HTTPS, Supabase authentication, row-level security, role-based access patterns, and service-side controls for sensitive operations. No security program can guarantee perfect safety, but the product is built to reduce unnecessary access and support account-level deletion/export.

10. Retention, export, and deletion

Coaches can export account data from the app's Data & Privacy screen. Coaches can also request account deletion in the app. Deletion removes the coach profile and associated athlete data from active use; some records may remain briefly in backups, logs, or legally required records before they age out.

Billing records may be retained through Stripe and accounting systems as required for tax, fraud, legal, or payment-dispute reasons.

11. Your choices

12. Changes

We may update this policy as the product changes. If a change materially affects saved athlete data or paid users, we will try to provide notice and may ask users to accept updated terms.

13. Contact

Privacy questions, school review requests, parent requests, and deletion/export help can be sent to thelabstrength@gmail.com.

Last updated: July 2, 2026 | Status: beta draft, not yet lawyer-reviewed