Privacy Policy
Short version: Forge.tennis stores tennis-performance data you log (UTR, matches, practices, assessments, sleep + nutrition). We use it to operate the app and surface insights for you. We don't sell it. You can export everything anytime, change consent anytime, and delete the account anytime.
1. Who we are
Forge.tennis ("we", "us") is the data controller for personal data processed through this service.
2. What we collect
- Account data — email, display name, password hash (when set), age acknowledgement, date of birth.
- Google sign-in (if used) — your Google account's verified email, your Google-provided display name, profile picture URL, and the stable Google subject identifier (used to recognize you on future sign-ins even if your email changes). We never receive your Google password.
- Tennis data you log — matches, tournaments, practices, fitness benchmarks, nutrition + sleep entries, TennisIQ attempts.
- Derived data — UTR estimate, skill mastery scores, streak counters, integrity hashes for sealed records.
- Consent records — every consent change is logged with timestamp, IP, and user agent (Art. 7 GDPR).
- Operational logs — request timing, errors. Not linked to identifiable data unless required for incident response.
3. Why we process it
- Service operation (legitimate interest / contract performance) — running your account.
- Personalization (consent) — Skills Pyramid, recommendations, dashboard widgets.
- Improvement (consent — analytics opt-in) — anonymized usage data.
- Communication (consent — marketing opt-in) — product update emails.
4. Who we share it with
We don't sell your data. We share it only with infrastructure providers needed to run the service: Google Cloud Platform (hosting), Resend (transactional email delivery), Google Identity Services (used only when you choose to sign in via Google — Google sees only that you authenticated, never your tennis data), and Mapbox (used only when you type into a venue field or tap "Use my location" — Mapbox sees the text you type and, if you grant permission, your device's GPS coordinates, in order to return a list of matching venues. Mapbox never sees your tennis data — practice logs, match results, opponents, or any other content.) When you generate a shared report (coach report, college recruit packet) it goes only to the recipient you specify, and is sealed with a SHA-256 integrity hash.
5. International transfers
Forge.tennis is hosted on Google Cloud Platform. Data may be processed in the United States with appropriate safeguards (Standard Contractual Clauses).
6. Your rights
- Access & portability — export everything as JSON from Profile → Privacy.
- Rectification — edit any record from its source page.
- Erasure — delete your account from Profile → Account & Sign-in.
- Object / withdraw consent — toggle optional consents from Profile → Privacy.
- Lodge a complaint — with your local data protection authority.
7. Retention
We keep your data for as long as your account is active. When you delete the account, we erase identifiable data immediately. Audit-shadow records (who-changed-what trail) are retained anonymously for legal traceability, with no personal identifiers attached.
8. Children's Privacy (COPPA)
Forge.tennis supports junior tennis athletes of every age. Athletes 13 and overcan create their own account directly (we recommend parent or guardian awareness for users under 18, and the signup flow includes an age acknowledgement). For athletes under 13, Forge offers Family Accounts: a parent or legal guardian creates the account, provides verifiable parental consent under the U.S. Children's Online Privacy Protection Act (COPPA), and manages all data on the junior's behalf until the junior turns 13.
What we collect for managed juniors
- Display name and date of birth (provided by the guardian).
- Tennis profile — dominant hand, backhand style, skills, goals.
- Practice logs, match logs, tournament results, fitness benchmarks the junior enters.
What we never collect for managed juniors
- No email address for the junior — every transactional email goes to the guardian's inbox.
- No marketing data — Forge has no advertising, and we never send promotional email about a managed junior.
- No third-party sharing — junior data is never sold, traded, or transmitted to advertisers, data brokers, or AI training datasets.
- No behavioral profiling — we don't build advertising or marketing profiles of any junior, ever.
How we verify parental consent
Forge uses the "email-plus" method permitted by COPPA: the guardian is required to be logged into a confirmed Forge account, must check an explicit consent box that names the junior at the moment of account creation, and receives a follow-up transactional email confirming the addition. The full consent — including version, IP address, user agent, and timestamp — is recorded in our consent ledger and tied to the junior's profile so we can demonstrate consent at any later date (COPPA §312.5(b); GDPR Art. 7).
Guardian rights, going both ways
- Review — see every piece of data Forge holds about the junior at any time, from the Family tab.
- Export — download the junior's data as a JSON file, anytime, alongside the guardian's own.
- Delete — remove the junior's account immediately. Soft-deletion makes the account inaccessible right away; full erasure completes within 90 days.
- Withdraw consent — pause the junior's account immediately and delete their data within 90 days unless you ask us to retain it.
- Transfer — hand guardianship to another adult via the Family tab.
We honor every guardian request within 30 days. To exercise any of these rights, log in and visit Profile → Family, or email hello@forge.tennis.
What happens when a junior turns 13
On the junior's 13th birthday, we email the guardian inviting them to either hand over the account (the junior receives a one-time link to set their own email and password) or keep managing it. There is no automatic transition; the guardian decides if and when to graduate the junior. Once a junior claims their own account, the guardian no longer has access — the full audit trail is preserved across the transition for legal traceability, but no new on-behalf-of actions are possible.
Filing a COPPA complaint
If you believe Forge is collecting or maintaining personal information from a child under 13 without verifiable parental consent, email hello@forge.tennis. You may also contact the U.S. Federal Trade Commission at reportfraud.ftc.gov.
9. Contact
Questions, requests, complaints — hello@forge.tennis.
10. Changes
When this policy materially changes we bump the consent version and ask everyone to re-consent on next sign-in. Material changes will not be applied retroactively to historical data without separate notice.