Legal

Privacy Policy

Last updated: May 2025 · Athlete Journey CIC

1. Who we are

Athlete Journey CIC (“we”, “us”, “our”) is a Community Interest Company registered in England and Wales. We operate the Athlete Journey platform at athletejourney.co.uk, which connects grassroots rowers with GB-level mentors for guided, safeguarded one-to-one sessions.

Data controller contact: admin@athletejourney.co.uk

2. What data we collect

We collect the following categories of personal data:

  • Account data: name, email address, role (coach / mentor / mentee), and hashed password (never stored in plain text).
  • Profile data: date of birth (mentees), experience level, rowing goals, and gender (optional — used for matching only).
  • Guardian data: name and email address of a parent or guardian, where the mentee is under 18. Collected at registration with explicit consent.
  • Session data: dates, durations, and attendance records for mentorship sessions.
  • Message data: in-platform messages between mentors and mentees, retained for safeguarding review.
  • Usage data: standard server logs (IP address, browser, pages visited) collected automatically.
  • Cookies: authentication session cookies only. We do not use advertising or tracking cookies.

3. How we use your data

  • To provide the platform: creating accounts, scheduling sessions, and facilitating communications.
  • Safeguarding: all messages are reviewable by our safeguarding team. Users are informed of this at signup.
  • Guardian notifications: we contact the guardian email provided at signup to confirm registration and any session activity involving their child.
  • Service communications: transactional emails (session confirmations, cancellations, password resets). We do not send marketing emails without separate consent.
  • Platform improvement: aggregated, anonymised analytics to understand usage patterns.

4. Legal basis for processing

  • Contract performance — processing necessary to deliver the service you signed up for.
  • Legitimate interests — safeguarding oversight, fraud prevention, and service security.
  • Legal obligation — safeguarding duties under UK law and UK Sport requirements.
  • Consent — where we ask for it explicitly (e.g. guardian consent for under-18s).

5. Data sharing

We do not sell your data. We share data only with:

  • Supabase (database and authentication, hosted in EU region) — our primary data processor.
  • Resend (transactional email delivery).
  • Google (Google Meet and Google Calendar for session scheduling).
  • Vercel (hosting infrastructure).
  • Your coach can see that you have been nominated and have an active account. They cannot see session content or messages.
  • Our safeguarding team can review messages where there is a safeguarding concern.

All processors are bound by data processing agreements and operate under GDPR-equivalent protections.

6. Data retention

  • Account data is retained while your account is active and for up to 12 months after deletion, unless required longer by law.
  • Safeguarding-relevant messages are retained for 3 years in line with UK safeguarding guidance.
  • Server logs are retained for 90 days.

7. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erasure (“right to be forgotten”) — subject to safeguarding retention obligations.
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time (where consent is the legal basis).

To exercise any of these rights, email admin@athletejourney.co.uk. We will respond within 30 days.

You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

8. Children and under-18s

We take special care with data relating to minors. Where a mentee is under 18, we require a parent or guardian email address and send a confirmation to that address at registration. Guardians may contact us at any time to request deletion of their child's data or to raise a safeguarding concern.

9. Security

Passwords are never stored in plain text — we use industry-standard bcrypt hashing via Supabase Auth. All data is transmitted over HTTPS. Access to production data is restricted to authorised team members only.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to registered users. The “last updated” date at the top of this page will always reflect the current version.

11. Contact

Questions about this policy or how we handle your data: admin@athletejourney.co.uk