← Back to PEAK

Privacy Policy

Last updated: 2026-05-28

PEAK Suite ("PEAK", "we", "us") is a basketball team-management and game-tracking application. This Privacy Policy explains what data we collect, why we collect it, and how we handle it.

Data we collect

  • Account data: email address, hashed password, sign-in timestamps. Stored in our authentication provider (Supabase).
  • Organisation & team data: team names, age groups, seasons, player names + jersey numbers, optional measurements (height, weight, etc.) and notes. Provided by you.
  • Game data: in-game events you log during games (shots, rebounds, fouls, substitutions, etc.) including their timestamps and on-court coordinates.
  • Schedule & attendance data: calendar items, attendance records.
  • Local device data: a local copy of your saved games is kept in your browser's localStorage so the app works offline.

Data we do not collect

  • We do not require or collect player birthdates, photos, addresses, phone numbers, government IDs, or medical records. Optional fields you choose to fill (DOB, notes) are stored as you enter them.
  • We do not run third-party advertising trackers, social-media pixels, or session-replay tools.
  • We do not sell your data.

How your data is stored

Account and team data live in a managed PostgreSQL database (Supabase, hosted in the EU). Access is gated by Row-Level Security so only signed-in members of an organisation can read or modify that organisation's data.

Saved games are mirrored from your device to the cloud database via the same access rules so multiple coaches can see the same game history.

Subprocessors

  • Supabase — managed Postgres + authentication. Hosted in the EU.
  • Vercel — static site + edge hosting for the application.
  • Stripe — payment processing (once paid plans are active).

Your rights (GDPR / CCPA)

  • Access — you can see your stored data at any time inside the app.
  • Correction — edit any field, anywhere.
  • Export — branded PDF / PNG exports cover the game and player data; raw JSON export can be requested by email.
  • Deletion — Settings → Delete account permanently removes your user, your memberships, and any orgs you solely owned. Cascade deletion removes teams, players, games, schedules, and attendance for those orgs.

Children's data

PEAK is a coaching tool. We assume the operator is an adult coach or club administrator. We do not knowingly collect personal data from anyone under 13 (US) / 16 (EU) directly. Player profiles created in the app describe the player but are operated by the coach/club.

Security

All traffic uses HTTPS. Passwords are hashed by Supabase Auth. The application enforces Row-Level Security policies in the database so a coach in one org cannot read another org's data.

Changes

If we change this policy materially we will surface the change in the app and update the date above.

Contact

Questions? privacy@peakbasketball.app