Privacy Policy
We take the protection of your data as seriously as we take athlete safety.
1. Introduction
This Privacy Policy explains how Sports Impact Technologies Ltd., a company registered in Ireland, collects, uses, stores, and protects your personal data when you use the Sports Impact platform (the "Service"), including our web application and desktop application.
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Irish Data Protection Act 2018.
Data Controller
Sports Impact Technologies Ltd.
Ireland
Contact
[email protected]2. Data We Collect
2.1 Account Data
When you create an account, we collect:
- Email address
- Full name
- Password (stored as a cryptographic hash — we never store your plaintext password)
- Language preference (English or French)
2.2 Workspace & Organisational Data
When you create or join a workspace, we collect:
- Workspace name
- Your membership role (admin, coach, or member)
- Invitation records (invitee email address and assigned role)
2.3 Team & Player Data
When you manage teams and players, we collect:
- Team names, associated sport, and category
- Player names, age, sex, playing position, and team assignments
2.4 Session & Participation Data
When you record training or match sessions, we collect:
- Session type (training or match), date, and associated team
- Player attendance and participation records
2.5 Impact & Wearable Data
When wearable sensors are used during sessions, we collect:
- Linear acceleration measurements (G-force)
- Rotational acceleration measurements (rad/s)
- Impact timestamps and duration
- Wearable device identifiers (MAC addresses)
- Device battery level data
2.6 Activity Logs
We maintain audit logs of user actions within workspaces for security and accountability purposes.
2.7 Technical Data
- Authentication tokens (used to keep you signed in)
- Browser local storage preferences (theme, language, selected workspace)
- Device serial port data (desktop application only, for communicating with wearable hardware)
3. How We Use Your Data
We use the data we collect to:
- Provide the Service — manage teams, players, sessions, and workspaces on your behalf
- Monitor athlete safety — track and analyse head impact data from wearable sensors
- Generate analytics and reports — provide insights from session and impact data
- Send transactional communications — email verification, password reset links, and workspace invitations
- Maintain security — authenticate users, hash passwords, and enforce access controls
- Improve the Service — monitor performance and fix issues
4. Legal Bases for Processing
We process your personal data under the following legal bases (GDPR Article 6):
| Legal Basis | Data | Reason |
|---|---|---|
| Performance of contract | Account data, workspace data, team/player data, session data | Necessary to provide the Service you signed up for |
| Legitimate interest | Activity logs, technical data | Security, fraud prevention, and service reliability |
| Legal obligation | Data retained under applicable law | Compliance with legal requirements |
| Consent | Marketing communications (if applicable) | Only with your opt-in consent |
| Explicit consent / Substantial public interest | Impact and wearable data (health-related) | Processing of special category data for athlete safety |
5. Data Sharing
We may share data with the following categories of service providers, who act as data processors on our behalf:
| Provider Type | Purpose |
|---|---|
| Cloud infrastructure provider | Hosting the Service backend and database |
| Content delivery network (CDN) | Serving static application assets |
| Performance monitoring | Measuring page load and application performance (Vercel Speed Insights) |
All processors are bound by data processing agreements that require them to protect your data in accordance with GDPR.
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data | Until you request deletion of your account |
| Workspace, team, player, and session data | For the duration of your workspace membership |
| Impact and wearable data | For the duration of your workspace membership |
| Activity logs | Anonymised upon account deletion |
| Authentication tokens | Revoked on logout or account deletion |
When you delete your account, we will:
- Delete your account and personal profile data
- Remove your workspace memberships
- Anonymise activity logs associated with your account
- Clean up any pending invitations you sent
- Revoke all active authentication tokens
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
| Right | How to Exercise |
|---|---|
| Right of access (Art. 15) | Use "Export My Data" in Account Settings to download a copy of your data in JSON format |
| Right to erasure (Art. 17) | Use "Delete My Data" in Account Settings to permanently delete your account and associated data |
| Right to rectification (Art. 16) | Edit your profile information directly in Account Settings |
| Right to data portability (Art. 20) | Use "Export My Data" in Account Settings to receive your data in a structured, machine-readable JSON format |
| Right to restriction (Art. 18) | Contact us at [email protected] |
| Right to object (Art. 21) | Contact us at [email protected] |
| Right to withdraw consent | Where processing is based on consent, you may withdraw it at any time by contacting us |
If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC):
8. Children's Data
The Sports Impact platform may store data about athletes who are minors (for example, player age and demographic information entered by coaches or administrators).
- Workspace administrators and coaches are the data controllers for player data they enter into the platform, and are responsible for ensuring they have appropriate legal authority or parental/guardian consent to process minors' personal data.
- Sports Impact Technologies Ltd. acts as a data processor for player data entered by workspace administrators and coaches.
- If you believe a child's data has been entered without proper consent, please contact us at [email protected] and we will take steps to delete it.
9. Security
We implement appropriate technical and organisational measures to protect your data, including:
- Token-based authentication — secure session management
- Password hashing — passwords are never stored in plaintext
- Password confirmation — required for sensitive operations such as data export and account deletion
- HTTPS encryption — all data transmitted between your browser and our servers is encrypted in transit
- Role-based access control — workspace permissions restrict data access to authorised users
No system is perfectly secure. If you become aware of a security vulnerability, please contact us at [email protected].
10. Cookies & Local Storage
Cookies
The Sports Impact platform does not use tracking cookies or third-party advertising cookies.
Local Storage
We use your browser's local storage to save:
| Key | Purpose |
|---|---|
| Authentication token | Keeps you signed in between visits |
| User profile | Caches your account information locally |
| Selected workspace | Remembers your last active workspace |
| Theme preference | Stores your light/dark mode choice |
| Language preference | Stores your language selection (English or French) |
Session Storage
We use session storage for:
| Key | Purpose |
|---|---|
| Pending invite URL | Preserves workspace invitation context during sign-in |
These storage mechanisms are essential for the Service to function and do not track you across other websites.
11. International Data Transfers
Your data is primarily processed within the European Economic Area (EEA). Where data is transferred outside the EEA (for example, to infrastructure providers), we ensure appropriate safeguards are in place, such as:
- European Commission adequacy decisions
- Standard contractual clauses (SCCs)
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you via email or an in-app notice where appropriate
We encourage you to review this policy periodically. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact us at:
Sports Impact Technologies Ltd.
[email protected]