CoachTools app privacy policy

This policy explains how personal data is processed when clubs, teams, coaches, athletes, guardians and other authorised users use the CoachTools web app at coachtools.app or its packaged mobile apps. The website privacy policy covers the marketing website and its forms separately.

1. Who is responsible for the data?

Plan&Care Sports Oy (Finnish Business ID 2845110-2), Lahti, Finland, provides CoachTools. Privacy enquiries can be sent to dev@coachtools.net.

For a club subscription, the club is the customer and generally the controller of its coaching data: it decides who participates, what information is collected, who may access it and how it is used. For an independent team or coach subscription, the person or organisation that actually decides these purposes may be the controller. The contract and information provided to members should identify that party; a team name alone does not establish a separate legal entity. Plan&Care Sports Oy processes customer-controlled coaching data on that controller’s behalf as a processor under the customer agreement and data processing agreement.

Plan&Care Sports Oy is a controller for its own customer relationships, invoicing, service administration, account security, support and direct communications. In some situations our role may differ according to the service arrangement. Contact us if you need to know which organisation is responsible for a particular record.

2. Whose data may be processed?

The platform may contain data about athletes, including children; guardians; coaches; team and club staff; other authorised users; and customer contacts. An organisation or authorised user may enter information about someone else, such as an athlete’s contact details, attendance or test result.

3. What information does the app process?

Depending on the features used and the permissions set by the organisation, the platform may process:

  • Accounts and membership: name, contact details, language, profile image, login credentials, roles, team and club affiliations, guardian relationships and account status.
  • Planning and participation: calendars, practice and game plans, groups, lineups, invitations, attendance or availability responses, and associated notes.
  • Coaching content: drills, drawings, documents, files, photos, videos, clips, tags, collections and information about how these are shared.
  • Athlete feedback and development: questionnaire responses, perceived effort, mood and wellbeing feedback, training duration and load, goals, development plans, coach notes and test results. Free-text responses may contain information the athlete or coach chooses to provide.
  • Communication: team chat, comments, mentions, feedback discussions and support messages, including attached or linked media.
  • Technical and security information: IP address, device and browser information, session and login records, error logs, notification tokens and records needed to operate and protect the service.

Questionnaires created by users, absence reasons and free-text notes may contain voluntarily disclosed health or injury information. The app does not prevent such entries. The responsible controller should limit questions and access to what is necessary and identify both a lawful basis under Article 6 GDPR and an applicable condition under Article 9 before collecting special-category data. Joining a team or using the app is not by itself consent to health-data processing.

4. Where does the information come from?

Information may be provided by the user, a guardian, a coach or another authorised staff member, or by the customer when it creates teams and accounts. Athletes and guardians receive an email invitation when added with their email address; athletes can accept or decline the invitation to join the team. Other information is produced when users respond to events or questionnaires or otherwise use the app. Technical information is generated through use of the service.

5. Why is information processed?

Organisation-controlled data is processed to provide the functions the customer chooses to use: managing teams and events, planning training, recording participation, sharing coaching material, collecting feedback, following development, and enabling communication between authorised users. The customer organisation is responsible for identifying and explaining the lawful bases for its purposes of processing, including any additional condition required for special-category data.

Plan&Care Sports Oy processes its own controller data to manage customer contracts and billing, provide support, administer accounts, maintain service security and reliability, and comply with legal obligations. Depending on the activity, the lawful basis is performance of a contract (Article 6(1)(b) GDPR), legitimate interests in providing and securing the service and managing customer relationships (Article 6(1)(f)), a legal obligation (Article 6(1)(c)), or consent when a specific activity requires it (Article 6(1)(a)). We assess legitimate interests against the rights of the people concerned. Consent can be withdrawn without affecting earlier lawful processing.

6. Who can see the information?

Access depends on roles, team or club affiliation and feature settings. Coaches generally have the broadest access to their team’s coaching information. General chat and event discussions are visible to members who have access to the relevant conversation or event. Individual feedback discussions are between the athlete and coaching staff. Club staff can see certain information across teams; some views remove athlete names, but a person may still be identifiable from other details or a small group. Athletes and guardians see information made available to their respective accounts; their access may differ. Users should check the audience before posting in shared spaces.

Plan&Care Sports Oy personnel and service providers may access information where necessary to operate, maintain, secure or support CoachTools, subject to appropriate restrictions. The customer should explain any access it grants to other organisations, such as a federation, and any sharing that it independently arranges.

7. Service providers and international transfers

We use Amazon Web Services (AWS) for app infrastructure in the Stockholm and Frankfurt regions, for content delivery through CloudFront, for transactional email through Simple Email Service (SES), and for video processing through MediaConvert. Firebase Cloud Messaging is used to deliver mobile push notifications. Reverb supports real-time app communication. Basic operational logs are kept; the Apple App Store and Google Play may provide app-store analytics. We do not currently use an external customer-support provider. The customer data processing agreement and subprocessor list should describe each provider’s processing purpose and location in greater detail.

The Stockholm and Frankfurt AWS regions do not establish that every related service, including content delivery or push messaging, processes data only in the EU or EEA. Where a transfer outside the EU or EEA occurs, the responsible party must assess and apply an appropriate transfer mechanism and safeguards. Processing locations and mechanisms for CloudFront and Firebase require confirmation before publication.

8. Notifications and device permissions

Users may receive service notifications about app activity, subject to the app and device settings. A mobile device may ask permission for notifications or access to its camera, photos or files when a user chooses a relevant function. Device permissions can be changed in device settings. Notification delivery may involve a device token and a notification provider. The information shown in a notification should be appropriate for the device’s lock screen.

9. Retention and deletion

The customer controller determines how long it needs coaching records, subject to law and the customer agreement. Leaving a team or removing app access does not automatically erase records the controller is entitled or required to retain. When a customer relationship ends, records are returned, deleted or genuinely anonymised under the agreed process, with documented treatment of backups and lawful exceptions. Identifiable records must not be kept indefinitely merely to preserve team statistics.

Plan&Care Sports Oy retains its own customer, billing, support and security records only for as long as needed for the relevant purpose or required by law. Different categories may have different retention periods. Contact the responsible organisation or us for details about a particular record.

To request deletion of your account or personal data, contact dev@coachtools.net. We will verify the request as necessary, act on data we control, and assist or direct you to the relevant customer controller for coaching records. We will explain any lawful retention and respond without undue delay, normally within one month. Removing an account and deleting customer-controlled historical records may be separate steps. A public web request page and an in-app way to initiate account deletion are being planned; this draft must be updated with the real routes before publication.

10. Security

We use technical and organisational safeguards appropriate to the nature of the data, including access controls, protected communications, restricted staff access and processes for handling security incidents. Users and organisations should manage their own access rights, keep credentials confidential and avoid posting sensitive information in content shared broadly.

11. Children’s information

CoachTools is used in youth sport. For children under 13, we recommend a junior account without the child’s own email, linked through a parent or guardian account. This is a product recommendation, not a universal legal age rule. The responsible controller should inform athletes and guardians clearly, manage their access and permissions, and apply the rules of the relevant country. A guardian’s visibility does not replace the athlete’s privacy rights. If a particular activity relies on consent, the controller must determine whose consent is required and record it.

12. Your rights

Depending on the circumstances and applicable law, you may request access to your personal data, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent where processing is based on consent. These rights can be subject to conditions and exceptions.

For coaching data controlled by your club or organisation, contact that organisation first. You can also write to dev@coachtools.net, and we will direct or assist with the request as appropriate. For information controlled by Plan&Care Sports Oy, send the request directly to that address. We may need to verify your identity. You may complain to a competent supervisory authority; in Finland this is the Office of the Data Protection Ombudsman.

13. Changes

We may update this policy as the app, processing arrangements or law changes. The current version and its date will be published on this page. Material changes may also be brought to users’ attention through the service or customer organisations when appropriate.