Privacy Policy

How we collect, use and protect your data.

Version 2026-08-15 · Last updated: 15 August 2026

SprtIQ ("we", "us") provides a sports management platform to schools, clubs and academies ("Organisations"). This policy explains what personal data we process, why, and the choices and rights available to you. Each Organisation is the data controller for the information it manages within SprtIQ (it decides what data to collect and why); SprtIQ acts as the data processor on the Organisation's behalf, as set out in our Data Processing Addendum. If you have a question about your own data, your Organisation's administrator is usually the fastest place to start — we support their request either way.

We serve Organisations in multiple countries. Where a specific law applies to you — the UK/EU General Data Protection Regulation (GDPR), South Africa's Protection of Personal Information Act (POPIA), or the US Children's Online Privacy Protection Act (COPPA) — the relevant section below tells you how we meet it. This policy does not limit any right you have under the law of your own country that isn't explicitly listed.

1. Data we process

  • Account details: name, email, phone, role, and Organisation membership.
  • Athlete data: performance results, training load, attendance, wellness check-ins, goals, and (where your Organisation uses these modules) injury records, medical documents, return-to-play status, and body measurements.
  • Guardian/contact data: parent or guardian names and contact details, and the athlete(s) they are linked to.
  • Financial data: fee and billing records; card details themselves are handled by our PCI-compliant payment processor and are never stored on our servers.
  • Device & usage data: IP address, browser/device type, and in-app activity logs, needed to operate, secure and troubleshoot the Service.
  • Wearable & health-app data: only if your Organisation or you explicitly connect a wearable device, Apple Health, or Google Health Connect — and only the specific metrics (e.g. heart rate, sleep, training load) that integration is configured to share.
  • Communications: messages sent through the Service's in-app messaging and notification tools.

2. How we use it, and on what legal basis

We use this data to operate the Service: authentication, dashboards, insights, notifications you've opted into, billing, and keeping the platform secure. We never sell personal data. Depending on your jurisdiction, we (or your Organisation, as controller) rely on:

  • Contract — processing needed to provide the Service your Organisation has subscribed to.
  • Consent — for optional features (e.g. connecting a wearable device or Apple Health/Google Health), and wherever else consent is the applicable basis for a minor's data under GDPR, POPIA, or COPPA.
  • Legitimate interests — for security monitoring, service improvement, and preventing fraud or misuse, balanced against your rights.
  • Legal obligation — where we must retain or disclose data to comply with the law (e.g. tax records).

3. Special category / health data

Wellness, injury, medical document, and body-measurement records are treated as a special, higher-sensitivity category of data under GDPR ("special category data") and POPIA ("special personal information"). We apply additional access controls to these records — role-based permissions, audit logging, and encryption in transit and at rest — and your Organisation is responsible for ensuring it has a valid lawful basis (typically explicit consent from the athlete, parent, or guardian) before entering this category of data into the Service.

4. Minors & parental consent

Many athletes on SprtIQ are under 18. Organisations are responsible for obtaining appropriate consent from parents or guardians before creating or activating a minor's account, in line with applicable law in their jurisdiction. Parent/guardian accounts can only see data for the athletes they are explicitly linked to by the Organisation.

US users (COPPA): for a child under 13, we require verifiable parental consent before collecting personal information directly from the child, and a parent can review, request deletion of, or refuse further collection of their child's information at any time by contacting their Organisation administrator or info@sprtiq.com.

5. Who we share data with

We share personal data only as needed to run the Service, never to sell it:

  • Within your Organisation — with the coaches, medical staff, and administrators your Organisation has given the relevant permissions to.
  • Sub-processors — vetted providers who host or process data on our behalf under contract (cloud hosting and database infrastructure, transactional email/SMS delivery, payment processing, and error monitoring). We keep an up-to-date sub-processor list available on request.
  • Third-party integrations you enable — e.g. a connected wearable platform, Apple Health, or Google Health Connect; data only flows to these if you or your Organisation explicitly connect them.
  • Legal & safety — where required by law, or to protect the safety of an athlete or the public (for example, a safeguarding disclosure obligation).

6. International data transfers

Our infrastructure may process data in a different country from where you or your Organisation are located. Where we transfer personal data out of the UK/EEA or another jurisdiction with transfer restrictions, we rely on an approved transfer mechanism (such as Standard Contractual Clauses) with our processors, as detailed in our Data Processing Addendum.

7. Retention & deletion

We retain Customer Data for as long as your Organisation's account is active, plus a limited period afterwards to allow for export and to meet legal/tax obligations, after which it is deleted. Your Organisation can export a full copy of its data at any time via Admin → Institution Settings → Data & Compliance → “Export Organisation Data”, and any signed-in user can download a copy of just their own account data via “Download My Data” in the same section. Deleting an athlete, team, or the whole Organisation removes the associated records from active systems, including linked medical, performance and talent-sharing data.

8. Security

We use encryption in transit (TLS) and at rest, role-based access control scoped to each Organisation (“tenant”), audit logging of sensitive actions, and rate-limiting on authentication endpoints. See our Security page for more detail, and our responsible-disclosure contact if you believe you've found a vulnerability.

9. Cookies & similar technologies

We use strictly necessary cookies to keep you signed in and to protect the Service against cross-site request forgery. Where enabled, push notifications use your browser's or device's native subscription mechanism (Web Push), which you can revoke at any time from your browser or device settings. We do not use third-party advertising trackers on the authenticated application.

10. Your rights

Subject to the law that applies to you, you can request to:

  • Access a copy of your personal data;
  • Correct inaccurate data;
  • Delete your data, or restrict/object to certain processing;
  • Receive your data in a portable format; and
  • Lodge a complaint with your local data protection regulator.

Exercise any of these by contacting your Organisation's administrator, or by emailing info@sprtiq.com. We respond within the timeframe required by applicable law (typically 30 days).

California residents

We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act. California residents have the rights described above, plus the right to non-discrimination for exercising them.

11. Changes to this policy

We may update this policy from time to time. For material changes, we will notify Organisation administrators before the change takes effect, in the same way described in our Terms of Service.

Contact

Email info@sprtiq.com with any privacy question, or to reach us about a specific data subject request.