Privacy Policy
Last updated: June 14, 2026
1. What this policy covers
This Privacy Policy explains how Pitchwerx collects, uses, shares, and protects information when you use our website, online portals (parent / player / trainer), the booking and messaging tools, the remote training program, and any related services (the "Service"). It applies to parents, athletes, coaches, and visitors.
2. Information we collect
Account information: parent name, email, password (stored only as a hashed value, never in plaintext); for Google or Apple sign-in, the verified email and display name returned by the provider.
Athlete information (provided by the parent): athlete name, age group, training notes, session reports, velocity and pitch-design readings logged by coaches, video the parent or athlete uploads, and recruiting-card data the parent opts to publish.
Booking and payment metadata: session time, coach, amount due, Venmo handle the parent paid (we do not receive Venmo card or bank details), discount and referral codes used.
Lead-capture data: consultation requests, the ceiling quiz, and the velo-board claim form collect parent name, email, phone, athlete age, and optionally a video URL.
Device and usage data: standard server logs (IP address, request URL, user-agent) and session cookies needed to keep you logged in. We do not use third-party advertising or behavioral-tracking cookies.
3. Children under 13 (COPPA notice)
Pitchwerx trains athletes as young as 9 years old. We do not allow children under 13 to create accounts directly. A parent or legal guardian creates the account, supplies the athlete's name and age group, and is the only party authorized to view, edit, or delete the athlete's data. The athlete may log in to a player view using a one-time access code generated by the parent.
By creating an account for an athlete under 13, you provide verifiable parental consent for Pitchwerx to collect and use the athlete's training data as described in this policy. You may revoke consent at any time by writing to carltonrbaseball@gmail.com; we will then delete the athlete's personal data within 30 days.
4. How we use information
We use the information you provide to operate the Service: confirm bookings, run programmed training, deliver coach feedback and lessons, surface velocity progress to the parent and athlete, generate the verified recruiting card if you opt in, and send transactional email (booking confirmations, password resets, coach replies).
We do not sell personal information. We do not use any of it for advertising attribution or third-party retargeting.
5. Sharing
We share information only with service providers strictly needed to run Pitchwerx:
- Netlify (hosting + state storage via Netlify Blobs)
- Resend (transactional email delivery, only when configured)
- Cloudflare Stream (video hosting, only for videos you upload)
- Google / Apple (only the data they return when you choose their sign-in)
- Venmo (you pay them directly; we receive only the confirmation a coach records)
We may disclose information if required by law or to protect the safety of an athlete or coach.
6. Public data on the leaderboard and recruiting cards
The public velo board displays an anonymized label ("First L." with age group) and a velocity reading. The athlete recruiting card (only when a parent activates it) publishes the athlete's first and last name, age group, verified velocity, arsenal, and goals at a public URL of the form /athlete/[code]. A parent can deactivate the card or de-list a leaderboard entry at any time.
7. Retention
We keep account and training data as long as the account is active. If you ask us to delete an account, we will remove personal data within 30 days, except where retention is required by law (for example, tax records of payments). De-identified historical session data may remain in aggregated reports.
8. Your choices
You may at any time:
- Review or update the data on your account in the parent portal.
- Deactivate a recruiting card.
- Request export or deletion by writing to coach Royce.
- Withdraw media consent.
9. Security
Passwords are stored as salted scrypt hashes. Session cookies are HTTP-only, SameSite=Lax, Secure in production, and HMAC-signed. Transport is HTTPS-only.
10. Changes to this Privacy Policy
We will post any changes on this page with a new "last updated" date. Material changes affecting children's data will be communicated to parents via email.
11. Contact
Privacy questions, data-access requests, and COPPA consent revocations should go to carltonrbaseball@gmail.com or 317-408-8751.