Privacy Policy
Version 2026-09-03 · Last updated 2026-09-03
This Privacy Policy explains what information Stick10 ("we", "us") collects through the Stick10 software and website (the "Service"), how we use it, and the choices you have. It applies alongside our Terms of Service. We wrote it in plain language on purpose. If anything is unclear, email [email protected].
1. Two roles: the gym and us
Stick10 is used by gymnastics facilities ("Facilities") to run their programs. The Facility decides what information to collect about its athletes, families, and staff, and why. For that information, the Facility is the data controller and we are its service provider: we store and process it on the Facility's instructions and do not use it for our own purposes beyond running and securing the Service.
For information about Facility owners and staff who sign up with us directly, and for visitors to our website, we are the controller.
If you are a parent with questions about what your gym has recorded about your child, contact the gym first. We will help them respond.
2. What we collect
Account information: name, email address, phone number, password (stored only as a salted hash), role, and the Facility you belong to.
Facility information: gym name, address, contact details, settings, and, if the Facility connects a payment processor, the credentials it provides for that processor (stored encrypted and never shown in full).
Athlete information entered by the Facility or a parent: name, date of birth, gender, family and guardian contacts, emergency contacts, allergies and medical notes the Facility chooses to record, competition level and program, skill progress, attendance, enrolment, waivers signed, and notes. We have deliberately removed insurance policy numbers and physician details from the athlete record; we ask Facilities not to store them in free-text fields either.
Billing records: invoices, payments, and balances the Facility issues to its families. Card numbers are entered directly with the payment processor and never touch our servers.
Messages and files: messages sent through the Service, product photos, and documents a Facility uploads.
Technical data: IP address, browser type, device, pages viewed, and timestamps, collected in server logs and in the record we keep when you accept the Terms.
We do not use third-party advertising trackers.
3. Children's information
Most athletes using gymnastics facilities are children, and many are under 13. We take that seriously.
- We do not knowingly collect information directly from a child under 13. Athlete records are created by the Facility or by a parent or guardian.
- The Service flags every athlete under 13 as a minor and requires the Facility to record verifiable parental consent before storing more than a name and date of birth. The Facility is responsible for obtaining that consent as the Children's Online Privacy Protection Act (COPPA) requires.
- We collect only what a gym needs to run its program safely and keep the fields for minors to a minimum.
- Parents may review, correct, or ask for deletion of their child's information through their gym, or by emailing us. We will verify the request with the Facility and act on it.
- We never sell or share children's information for marketing, and we do not use it to build profiles or train models.
4. How we use information
- to provide the Service: scheduling, attendance, billing, messaging, waivers, and the rest of what your gym uses;
- to create and secure accounts, and to detect and prevent abuse;
- to send transactional email such as invites, password resets, invoices, and class changes;
- to respond to support requests and product feedback;
- to understand aggregate usage so we can improve the Service (aggregate figures only, never individual athlete data);
- to comply with law and enforce our Terms.
We do not sell personal information. We do not use athlete or family information for advertising.
5. Who we share it with
We share information only with the providers we need to run the Service, each bound by contract to protect it:
- Railway: application hosting and the PostgreSQL database (United States).
- Stripe: payment processing, when a Facility connects it. Stripe receives payment details directly; see Stripe's privacy policy.
- Resend: sending transactional email.
- Cloudflare: file storage for uploads and network security.
Within the Service, information is visible according to role: Facility administrators and managers see their own Facility's data; coaches see the classes and athletes they are assigned; parents see only their own family. No Facility can see another Facility's data.
We may also disclose information if required by law or legal process, to protect the rights or safety of anyone, or as part of a merger, acquisition, or sale of assets, in which case we will tell you before your information becomes subject to a different policy.
6. How long we keep it
- Athlete records: kept while the athlete is enrolled, then for 2 years after the athlete reaches the age of majority or the Facility archives the record, whichever is later, unless the Facility deletes them sooner. After that they are deleted or anonymised.
- Account records: kept while the account is active and for up to 12 months after it is closed.
- Billing records, signed waivers, and terms acceptances: kept as long as the law requires for financial and legal records, generally seven years.
- Server logs: 90 days.
A Facility can export its data at any time and can ask us to delete its workspace entirely by emailing us.
7. How we protect it
All traffic is encrypted in transit (TLS). Passwords are stored only as salted hashes. Every database row belongs to one Facility and the database enforces that isolation. Payment-processor credentials are encrypted at rest. Access to production systems is limited to the people who operate the Service. No system is perfectly secure; if we learn of a breach affecting your information we will notify the affected Facility without undue delay and, where the law requires, the affected individuals.
8. Your choices and rights
You can view and update your own profile in the Service. Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to complain to a data-protection authority. To exercise these rights, contact your Facility or email [email protected]. We will respond within 30 days and may need to verify your identity. We will not discriminate against you for exercising these rights.
Account and service email (invites, password resets, invoices, changes to your profile or the Service, security notices, beta updates and feedback requests) is a condition of using the Service and cannot be switched off while your account is open; closing your account stops it. Any marketing email we may send in future will be separate and will carry an unsubscribe link.
9. Cookies
We use a small number of strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies.
10. Where information is stored
Our servers and providers are located in the United States. If you use the Service from elsewhere, your information will be transferred to and processed in the United States.
11. Changes to this policy
When we change this policy we will update the version date at the top and ask you to review and accept it the next time you sign in. Material changes affecting children's information will also be announced to Facility administrators by email.
12. Contact
Stick10 · [email protected]