1. Introduction
Welcome to Varsity Recruiting Manager ("VRM", "we", "us", or "our"). We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application.
2. Information We Collect
2.1 Personal Information
We collect information that you provide directly to us:
- Account Information: Email address, password (encrypted), name
- Profile Information: Sport, graduation year, high school, location
- Coach Information: Coach names, schools, contact details, notes
- Interaction Data: Communication logs with coaches, dates, types of contact
- Task Information: Personal tasks and reminders you create
2.2 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent on the application
- Device Information: Browser type, operating system, device type
- Log Data: IP address, access times, errors encountered
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Send you weekly digest emails and follow-up reminders
- Alert you to NCAA recruiting period changes
- Track compliance with NCAA contact rules
- Respond to your comments and questions
- Analyze usage patterns to improve user experience
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Data Storage and Security
Your data is stored securely using Supabase (PostgreSQL database) with the following protections:
- Encryption: All data is encrypted in transit (HTTPS) and at rest
- Authentication: Passwords are hashed using industry-standard bcrypt
- Row Level Security: Database-level access controls ensure users can only access their own data
- Backups: Automatic daily backups for data recovery
5. Information Sharing
We do NOT sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Service Providers: We use trusted third-party services (Supabase for database, Resend for email, PostHog for analytics, Vercel for hosting) who are contractually obligated to protect your data
- Legal Requirements: If required by law, subpoena, or court order
- Business Transfers: In the event of a merger, acquisition, or sale of assets
- With Your Consent: Any other disclosure with your explicit permission
6. Third-Party Services
We use the following third-party services:
- Supabase: Database and authentication (Privacy Policy: supabase.com/privacy)
- Resend: Email delivery (Privacy Policy: resend.com/legal/privacy-policy)
- PostHog: Analytics (Privacy Policy: posthog.com/privacy)
- Vercel: Hosting and deployment (Privacy Policy: vercel.com/legal/privacy-policy)
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Opt-Out: Unsubscribe from marketing emails (does not apply to service emails)
- Data Portability: Export your data in a machine-readable format
To exercise these rights, please contact us at the email below.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. If you request account deletion, we will delete your data within 30 days, except where we are required to retain it for legal purposes.
9. Children's Privacy
VRM is designed for high school athletes and their parents/guardians. If a user is under 13, a parent or guardian must create and manage the account. We do not knowingly collect personal information from children under 13 without parental consent.
10. International Users
VRM is operated in the United States. If you are accessing our services from outside the US, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@[yourdomain].com
We will respond to your inquiry within 30 days.