Legal

Privacy Policy

Effective Date: March 1, 2026  ·  Version 1.0

This Privacy Policy describes how AthleteForge Inc. collects, uses, and protects your personal information. By using the Platform, you agree to the practices described here. Contact us at privacy@athleteforge.com with any questions.

1. Who We Are & How to Contact Us

AthleteForge Inc. is the data controller responsible for your personal information.

  • Email: privacy@athleteforge.com
  • Website: athleteforge.com/privacy
  • Platform: athleteforge.com

2. Information We Collect

2.1 Information You Provide

  • Identity data: name, username, date of birth
  • Contact data: email address, phone number
  • Profile data: sport, school or university, position, athletic statistics
  • Business data (brands): company name, website, industry, campaign budgets
  • Financial data: payment information processed securely by Stripe (we do not store raw card numbers)
  • Content: photos, videos, bio text, and campaign briefs you upload
  • Communications: messages sent through the Platform
  • Waitlist / survey responses: role, interests, feedback

2.2 Information Collected Automatically

  • Log data: IP address, browser type, OS, pages visited, referring URLs
  • Usage data: features used, clicks, time on page, search queries
  • Device data: device identifiers, screen resolution
  • Cookie data: session tokens, preference cookies (see Section 7)

2.3 Information from Third Parties

  • Google (via Google Sign-In): name, email address, profile photo, Google account ID
  • Stripe (payments): transaction amounts, payment status, Stripe account identifiers
  • Social media platforms: follower counts and engagement metrics (only if you connect accounts)

3. How We Use Your Information

  1. To provide and operate the Platform, including matching athletes with brands.
  2. To process transactions and send payment notifications.
  3. To communicate with you about your account, deals, and Platform updates.
  4. To send marketing communications (you may opt out at any time).
  5. To verify eligibility and identity for NIL compliance purposes.
  6. To generate tax documents (1099-NEC) and NIL compliance reports as required by law.
  7. To improve, personalise, and develop the Platform.
  8. To detect fraud, abuse, and security incidents.
  9. To comply with legal and regulatory obligations.

4. How We Share Your Information

4.1 With Other Users

Athlete public profiles (name, sport, school, bio, social stats) are visible to registered brand and agent users. Financial and contact details are never visible to other users.

4.2 With Service Providers

We share data with trusted providers operating under data processing agreements:

  • Turso / libSQL — encrypted database hosting (US-based)
  • Google — OAuth authentication, analytics
  • Stripe — PCI DSS-compliant payment processing
  • Resend — transactional email delivery
  • Bunny.net — video hosting and content delivery
  • Firebase / Google Cloud — application hosting and infrastructure

4.3 Legal & Safety Disclosures

We may disclose information when required by law, court order, or government regulation, or to protect the safety of AthleteForge, our users, or the public.

4.4 Business Transfers

In the event of a merger, acquisition, or asset sale, your information may be transferred. We will notify you before your data becomes subject to a different privacy policy.

4.5 We Do NOT Sell Personal Data

AthleteForge does NOT sell, rent, or trade your personal information to third parties for their marketing purposes. Your data is used solely to provide and improve our Platform.

5. Data Retention

We retain personal information for as long as your account is active or as needed to provide services, comply with legal obligations (e.g. tax records for 7 years), resolve disputes, or enforce agreements. When data is no longer required, we delete or anonymise it securely.

6. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate or incomplete data.
  • Deletion — request deletion of your personal data (subject to legal retention obligations).
  • Portability — receive your data in a machine-readable format.
  • Objection / Restriction — object to or restrict certain processing.
  • Opt-out of marketing — unsubscribe from marketing emails via the link in any email or contact privacy@athleteforge.com.

California residents have additional rights under the CCPA, including the right to know what categories of personal information we collect and share. To exercise any rights, contact privacy@athleteforge.com. We will respond within 30 days.

7. Cookies & Tracking Technologies

  • Essential cookies — required for authentication (session tokens) and security. Cannot be disabled.
  • Functional cookies — remember your preferences (language, settings).
  • Analytics cookies — measure usage patterns to improve the Platform. You may opt out.

You can control cookies through your browser settings. Disabling essential cookies will impair sign-in functionality.

8. Children's Privacy (COPPA)

The Platform is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with information, please contact privacy@athleteforge.com immediately and we will delete the information.

Users between 13 and 17 may use the Platform only with verifiable parental or guardian consent.

9. Data Security

We implement industry-standard security measures including:

  • TLS encryption in transit for all Platform communications.
  • Encryption at rest for database contents.
  • HTTP Strict Transport Security (HSTS) with a 2-year preload directive.
  • Content Security Policy (CSP) headers.
  • Session-based authentication with secure, HttpOnly cookies.
  • Regular security reviews and dependency patching.

No method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact support@athleteforge.com immediately.

10. International Data Transfers

AthleteForge is based in the United States. If you access the Platform from outside the US, your information may be transferred to and processed in the US, where privacy laws may differ from your country. By using the Platform, you consent to this transfer.

11. Third-Party Links

The Platform may link to third-party websites. This Privacy Policy applies only to our Platform. We are not responsible for the privacy practices of third-party sites.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by email or prominent notice on the Platform at least 14 days before they take effect.

Last Updated: March 1, 2026. For GDPR compliance, a Data Processing Agreement (DPA) may be required with EU/EEA users. Contact privacy@athleteforge.com with any questions.
Privacy Policy | NIL Match