Legal
Privacy Policy
What changed on August 31, 2026: We clarified the difference between a team roster profile and a signed-in Rundown account. Player accounts use an email address, and the account, purchase, and deletion sections apply to them too. We also explain the age screen and the limited eligibility record kept for new accounts. Under-13 account and roster access remain closed.
This policy describes how Rundown handles personal information today. If you have a privacy question, email us at privacy@rundownsports.app.
1. Who We Are
Rundown is operated by Rundown Sports ("Rundown," "we," "us," "our"), a sole proprietorship operated by Ben Meachen in Vancouver, British Columbia, Canada. Our website is rundownsports.app. You can reach us at privacy@rundownsports.app.
Our Privacy Officer (as required by PIPEDA and BC PIPA) is Ben Meachen, reachable at privacy@rundownsports.app.
2. Scope of This Policy
This policy explains what information we collect, how we use it, who we share it with, and your rights. It applies to signed-in Player and Coach accounts, team roster profiles, people using the free sample, and parents or guardians managing their own accounts. If you are a parent of a player under 13, please also read our Parents Corner.
This policy is intended to comply with:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
- British Columbia's Personal Information Protection Act (BC PIPA)
- The U.S. Children's Online Privacy Protection Act (COPPA)
- The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
- Where applicable, the EU/UK GDPR
3. What We Collect for Signed-In Accounts
Creating a Rundown account uses your own email address. New accounts start with the Player role. Existing-account sign-in does not create an account. A roster profile that a coach creates for a player is a separate record; adding someone to a roster does not itself collect that player's email address.
- Email address
- A random Rundown user identifier, account role, and account creation and update times
- For new accounts, a declaration that the account holder is 13 or older, the notice version, and the declaration time. We do not receive or save the exact age entered on the account screen.
- Sign-in records and session information for secure email-link authentication and pre-created password-protected App Review accounts. Regular Rundown accounts do not need a password. Rundown does not log or store review passwords in readable form; Supabase processes them as credentials.
- App Store product, transaction, original transaction, purchase, expiry, renewal, refund, and revocation information from Apple. We also use a random app-account token to connect an App Store transaction to the signed-in Rundown account.
- Device and session information (browser type, IP address, timestamps) for security and fraud prevention
For Coach accounts, we also hold the name supplied for the account, adult and coach confirmations, and the team name, sport, season label, and roster structure the coach creates. For web season passes, we hold payment status and transaction identifiers from Stripe.
A parent or guardian managing an account uses their own email address. That account is not a record of verified parental consent for an under-13 player. Under-13 roster access remains closed.
To authorize new account creation, our server temporarily keeps an email fingerprint, a random one-use token, the eligibility declaration, the notice version, and their creation and expiry times. The token expires after five minutes and is removed when used. Unused records are removed by a cleanup job every 15 minutes or sooner when another signup request runs. These records are not used for marketing. Account deletion also removes pending records for that email.
Rundown does not receive or store your full card number, Apple Account payment credentials, or App Store password.
3a. Support and Diagnostic Information
If you contact support or submit a report, we receive the message and any other content you choose to include. An in-app report may also include your Rundown user identifier, app version, build number, device and browser type, screen name, timestamp, and an error code. This information is connected to your account when you are signed in and is used only to provide support, diagnose faults, secure the service, and improve App Functionality.
Rundown does not use this information, purchase history, user identifiers, names, gameplay content, or account information to track you across other companies' apps or websites. We do not sell it or use it for advertising.
3b. What We Collect from Email-Update Contacts
The email-updates list is for adult coaches and parents. We collect the adult's email address, whether they identify as a coach or parent, browser language or region, referral source, and signup time. We use this information to send product updates and coaching notes as permitted by law. Players should ask a parent or coach to join with the adult's email address.
4. Team Roster Profiles and Player Accounts
For each player on an active roster, we collect:
- First name and, if the coach adds it, one last initial (no full surname)
- Jersey number and fielding position, if supplied
- The coach's confirmation that the player is 13 or older
- Gameplay answers, scores, sport, position, and round times, stored against an internal server-side identifier (UUID)
When a player joins a roster through a signed-in account, we link the account identifier to that roster profile. The coach can see the roster profile and its recorded practice results. The account email, sign-in records, and purchase information described in section 3 are separate from the roster fields above.
Roster forms do not ask for a player's full last name, home address, email address, phone number, or date of birth. A signed-in Player account does use an email address. We do not collect the following through player registration or rostered play:
- Date of birth
- Photos, videos, or voice recordings
- Precise geolocation
- Biometric data
- Persistent device identifiers, advertising IDs, or cross-site tracking cookies
- Any behavioural or interest data for advertising purposes
4a. Swing Lab: Camera Features That Run On Your Device
Swing Lab lets a player (or a parent or coach) film or upload a short swing video and get checkpoint feedback. Here is exactly what happens to that video:
- The video is analyzed entirely on your device, in your browser. It is never uploaded. Rundown never receives it, never stores it, and cannot see it.
- The analysis produces body-position estimates ("pose landmarks") in your device's memory. These are discarded when the analysis finishes. They are never transmitted to us or anyone else, and never saved.
- The only thing kept is a short summary of the results (checkpoint tally, date, sport, age group, and the first suggested fix), stored in your browser's local storage on your own device so you can compare sessions. We do not receive it. Clearing your browser data deletes it.
- Swing Lab requires no account and runs no analytics. Close the tab and everything except your on-device summary is gone.
- To run, the page downloads the swing-reading software and the body-position model file from other servers. Section 4c lists exactly which ones. Like any web request, those servers see your IP address and browser type. No video, no body-position data, and no result is ever included in those requests.
This is why the list above remains true: Rundown does not collect photos, videos, voice recordings, or biometric data. That includes Swing Lab. If that architecture ever changes, we will update this policy first and, for players under 13, obtain new parental consent before any change takes effect.
4b. The Website's Free Practice Leaderboard
The free practice game on the website has a public leaderboard. The iPhone app keeps its free-practice name and scores on the device; it does not post them to this public leaderboard. Signed-in team practice can save results to the coach's roster as described in section 4.
- The name box is optional. Leave it blank and the score posts as "Guest". Nothing else on the screen changes.
- If a name is typed, we keep the first word only, up to 12 characters. Anything after the first space is dropped before the score is sent, so a last name cannot reach us even if one is typed. Letters and numbers only.
- Alongside it we keep the score, the fielding position chosen, the sport, and the time of the round.
- That entry is published. Anyone using the app can see the leaderboard, so treat the name box as public. This is the one place in Rundown where something a player types is shown to other people.
- No account, no email address, and no device identifier is attached to a leaderboard entry, so we cannot tell you which rows are yours. To have one removed, email support@rundownsports.app or use our support page with the name shown and the rough date, and we will delete it.
- Leaderboard entries are deleted 12 months after they are posted.
If you would rather your child not appear on a public list, have them leave the name box blank. The game plays exactly the same.
4c. What the App Loads From Other Servers
Rundown serves its own type, so no font service is contacted from any Rundown page. Two parts of the app load code or a model file from a third party. Those servers see your IP address and browser type, as they would for any web request. No gameplay answer, no video, no body-position data, and no result is ever included in those requests.
| Part of the app | Loaded from | What it is |
|---|---|---|
IQ Game (/app/) | jsDelivr | The database and sign-in library |
Swing Lab (/app/swing/) | jsDelivr, and Google (storage.googleapis.com) | The swing-reading software, and the body-position model file it runs on your device |
Coaches Corner (/app/corner/) | Nothing | Loads entirely from Rundown |
5. Players Under 13
Under-13 roster access is not currently open. Rundown does not currently run a parent-consent signup flow or collect a separate parent contact for that purpose. A parent's own account email is account information described in section 3. The database blocks a roster profile marked under 13 from being claimed or saving practice activity unless consent has been recorded. We will update this policy before opening that flow.
Before showing account email or password fields, the account screen asks for age in years. An answer below 13 closes account entry and leaves the free sample available. The exact age stays on the device and is not saved. A local refusal flag prevents account entry from reopening after a reload; it contains no age or email and is not sent to Rundown. If local storage is unavailable, account entry stays closed.
For an eligible new account, Rundown records only the declared eligibility, notice version, and declaration time described in section 3. This is a declaration, not verified age or verified parental consent. A parent uses their own account and email; this does not create a child account or open under-13 roster access. Existing accounts are not assigned an eligibility declaration retroactively.
6. How We Use Information
- To operate and secure the service
- To process web season passes and verify App Store subscription access
- To respond to support requests and diagnose app faults
- To send account holders transactional messages (receipts, sign-in links, service announcements)
- To send commercial electronic messages under CASL only where we have express consent or a valid implied-consent basis
- To comply with legal obligations (CRA tax records, dispute resolution, court orders, breach notification under PIPEDA and COPPA)
- To improve the product using aggregate, de-identified usage data
The aggregate usage data in that last line is a small set of first-party counters we keep ourselves, such as how many practice rounds start in a day and how many results get shared: each one is a running total for a calendar day with no name, no account, no device identifier, no IP address and no cookie attached, it counts events rather than people, and nothing in it can be traced back to a player.
We do not use player information for advertising, profiling, or sale.
7. Service Providers (Sub-Processors)
We use the following vendors. Each has its own privacy practices and a Data Processing Agreement with us where applicable. Most of our sub-processors are located in the United States. Personal information may be transferred to, processed, and stored in the United States.
| Vendor | Location | Purpose | Data Shared |
|---|---|---|---|
| Supabase | United States (N. Virginia, us-east-1) | Database and authentication | Player and Coach account information, parent-managed account email, roster profiles and practice results, purchase and access records, and deletion requests |
| Stripe | United States + Canada | Payment processing | Coach billing details |
| Apple | Canada, United States, and other regions where Apple operates | App Store purchase processing, subscription verification, refunds, and server notifications | App Store transaction information and the random app-account token tied to the signed-in Rundown user |
| Netlify | United States | Website and first-party API hosting | Website requests and information sent to Rundown's API, including account authentication, purchase verification, support reports, and deletion requests |
| Resend | United States | Transactional and commercial email | Recipient email address and message content for account messages and adult email updates |
| Anthropic | United States | Language processing for the support assistant | The support message, recent chat, and a short-lived support-session identifier after the visitor presses Ask |
We take reasonable safeguards (PIPEDA Principle 4.7) to protect personal information, including signed DPAs, encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, and vendor security reviews. We do not share player data with any third party for advertising. We do not sell player data.
8. Your Rights Under PIPEDA and BC PIPA (Canadian Residents)
- Access the personal information we hold about you.
- Correct inaccurate personal information.
- Withdraw consent for collection, use, or disclosure, subject to legal or contractual restrictions.
- Complain to the Office of the Privacy Commissioner of Canada (
priv.gc.ca) or the BC OIPC (oipc.bc.ca) if you believe we have mishandled your information.
To exercise these rights, email privacy@rundownsports.app. We will verify your identity and respond within 30 days.
9. Parental Rights Under COPPA (US Residents)
Under-13 roster access is closed. If you believe Rundown holds personal information about your child, including an account created by mistake, you can ask us to:
- Review the personal information we have collected from your child
- Direct us to delete the information
- Refuse further collection or use of the information
We do not disclose player information to third parties for marketing purposes regardless. Email privacy@rundownsports.app to exercise these rights.
10. California Residents (CCPA / CPRA)
California residents have the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of cross-context behavioural advertising (not applicable: we do not do this). Non-discrimination for exercising rights.
11. EU / UK Residents (GDPR / UK GDPR)
We do not target EU or UK residents. If you use the service while located there: our lawful bases are contract (for coaches), parental consent (for children under 16, Member-State-specific), and legitimate interest (for security). You have rights of access, rectification, erasure, restriction, portability, and objection.
12. Data Retention and Deletion
We keep personal information only as long as it is needed for the reason it was collected, and we do not hold a child's information indefinitely. The schedule below is the whole of it: what we hold, why we collected it, why we need to keep it at all, and when it is deleted.
| What we hold | Why we collect it | Why we keep it | When it is deleted |
|---|---|---|---|
| Player records on a team roster First name, optional last initial and jersey number, fielding position if supplied, the coach's 13-or-older confirmation, linked account identifier, answers, scores, and round times |
To run the situation training the coach signed the team up for, and to show the coach what the team is reading well and badly | A player's own history is what makes a coach's Team Read worth reading across a season | 12 months after that player's last recorded activity |
| Rosters on teams that stop being used | Same as above | Nothing, once a team stops using Rundown | 13 months after the team's last activity, the team's player records are deleted |
| Free practice leaderboard entries Optional first name, score, fielding position, sport, time of the round (section 4b) |
To show the public high-score list in the free game | A leaderboard is only worth anything while the scores on it are current | 12 months after the entry is posted |
| Aggregate usage counters One number per calendar day for each thing the app counts, such as a practice round starting or a result being shared (section 6) |
To see whether the product is being used at all, without collecting anything about who is using it | A day total only means something read next to the days around it | Retained as anonymous daily totals. A row holds a date, a word and a number, so there is nothing in it belonging to a person to delete. |
| Signed-in Rundown account Email, user identifier, role, sign-in records, account timestamps, and the new-account eligibility declaration, notice version, and time; for coaches, name, coach confirmations, team and roster structure |
To sign in, verify and restore access, and connect a Player or Coach account to the right team | The account is needed for signed-in features. The free sample does not need an account. | While the account is open. A verified in-app deletion normally completes immediately. If a temporary service failure prevents immediate deletion, we queue the request and complete it within 30 days. |
| Payment records Payment status and transaction identifiers from Stripe; product, transaction, subscription-state, expiry, refund, and revocation information from Apple |
To take payment, verify paid access, and handle refunds, disputes, fraud, and subscription-state changes | Tax, accounting, fraud-prevention, and dispute rules require us to keep a limited record | 6 years (CRA) or 7 years (IRS), whichever is longer |
| Support and diagnostic records Messages, user identifier when signed in, app version, build, device or browser type, screen, timestamp, and error code |
To answer support requests, diagnose faults, and keep the service secure | We need the history while a request or fault is being investigated | 24 months, unless a longer period is required for an active security incident or legal claim |
| Parent contacts for under-13 consent | Not collected today. Under-13 roster access is not open. A parent's own account email is covered by the signed-in account row above. | Not applicable | Not applicable |
| Security and access logs IP address, timestamps, browser type |
To keep accounts secure and to investigate abuse | An incident is usually only visible looking backwards | 12 months |
| Email-updates list Adult email address, coach or parent, region, referral source, signup time |
To send the product updates and coaching notes the person asked for | We need the address to send what was asked for | Until you unsubscribe or ask to be removed. Unsubscribing stops the email straight away. |
| Consent records under CASL That someone agreed to email, and how |
To prove we had permission before emailing | Canadian anti-spam law requires us to be able to prove it | 3 years after last activity |
Deleting a player record deletes the answers and scores attached to it. Numbers already counted into an anonymous total cannot be traced back to a player and are not affected.
You can request account deletion inside the signed-in app or by emailing privacy@rundownsports.app. A verified in-app request normally deletes the account and associated roster, gameplay, and entitlement data immediately. If a temporary service failure prevents immediate deletion, the request is queued and completed within 30 days. Records we must keep for tax, accounting, fraud prevention, disputes, or other law are separated from the deleted account and retained only in limited or pseudonymous form.
Deleting a Rundown account does not cancel an Apple subscription. Cancel it in your Apple Account settings before deleting your Rundown account if you do not want Apple to renew it.
13. Security
TLS 1.2+ in transit, AES-256 at rest, role-based access controls, least-privilege service accounts. We maintain a breach response plan and will notify affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible where a breach creates a "real risk of significant harm" (PIPEDA standard).
14. Children Under 13
Under-13 roster access is not currently open. The free sample does not require a player account, and Swing Lab can run locally on a family's device without uploading video or results. See our Parents Corner for the plain-language explanation.
15. Cross-Border Transfers
The service is operated from Canada. Most of our technical service providers are located in the United States. By using the service, you acknowledge that your information may be transferred to, processed in, and stored in the United States and other countries, where data-protection laws may differ from those in your country of residence. We take contractual and technical safeguards to protect your information regardless of where it is processed.
16. Changes to This Policy
We will post material changes on this page, update the "Last Updated" date, and notify account holders by email. For children under 13, we will obtain new parental consent before applying any material change that expands collection or use.
17. How to Contact Us
Privacy Officer: Ben Meachen (privacy@rundownsports.app)
General: support@rundownsports.app
Legal: legal@rundownsports.app
Mail: Rundown Sports, 1568 Nootka St, Vancouver, BC V5K 3K5, Canada