Privacy Policy

GMAX Trackstars Mobile App — Athletics Training Academy

Last updated: April 2026  •  Charity Registration No. 1138783  •  gmaxtrackstars.com

GMAX Trackstars (“we”, “us”, “our”) is committed to protecting your privacy and the privacy of young athletes in our care. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our mobile application (“the App”).

GMAX Trackstars is a registered charity (Charity No. 1138783) based at 22a, 24 Sydenham Rd, London SE26 5QW. We are the data controller for all personal data collected through the App.

Our Data Protection contact is Ryan Fernandes. You can reach them at: [email protected]

1. Who This Policy Applies To

This policy applies to all users of the GMAX Trackstars mobile app, including:

  • Athletes aged 13 and over who register directly
  • Parents or guardians who register on behalf of children under 13
  • Coaches and administrators using the App

The App is intended for use in the United Kingdom only.

Children Under 13

Important — Parental Consent Required If you are under 13 years old, you must not register for an account yourself. A parent or guardian must create and manage an account on your behalf. By registering a child account, the parent or guardian confirms they are authorised to provide consent for the child’s data to be processed as described in this policy.

For users aged 13–17, we apply stricter privacy protections by default, including limiting visibility on leaderboards and restricting analytics processing.

2. What Personal Data We Collect

When you use the App, we may collect the following categories of personal data:

Account & Identity Data

  • Full name
  • Email address
  • Date of birth
  • Gender
  • Profile picture (optional)

Health & Fitness Data (Special Category)

The App tracks athletic performance data, which may constitute health-related data under UK GDPR. This includes:

  • Training session records and attendance
  • Athletic performance metrics and progress logs
  • Event participation and results

Account Login Data

You may choose to register and log in using a third-party account (e.g., Google or Apple). In this case, we receive limited profile information from that provider (typically name and email address) as permitted by their own privacy policies.

Usage & Technical Data

We use analytics tools (Microsoft Clarity and PostHog) to collect anonymised or pseudonymised usage data, such as:

  • App screens visited and features used
  • Session duration and interaction patterns
  • Device type and operating system

This data helps us improve the App. We do not use analytics to profile individual users for marketing purposes. Users under 13 are excluded from analytics processing.

3. How We Use Your Data

We use your personal data only for legitimate purposes related to running the GMAX Trackstars programme. Our lawful bases under UK GDPR are:

Contract Performance

  • Managing your account and App access
  • Processing session bookings and event registrations
  • Displaying your progress and leaderboard position
  • Enabling coach messaging functionality

Legitimate Interests

  • Improving the App through anonymised analytics
  • Maintaining the security and integrity of the platform

Legal Obligation

  • Complying with safeguarding obligations for young people
  • Responding to lawful requests from authorities where required

Consent (for Special Category / Children’s Data)

  • Processing health and fitness data for users aged 13–17
  • All data processing for children under 13 (parental consent required)

4. Data Sharing & Third Parties

We do not sell your personal data. We do not share your data with sponsors or partners for marketing purposes.

We share data only with the following trusted third-party service providers who process data on our behalf:

  • Supabase — Secure cloud database and authentication (servers located in the UK/EU)
  • Microsoft Clarity — App analytics and user experience insights
  • PostHog — Product analytics (EU region)
  • Google / Apple — If you choose third-party login (governed by their own privacy policies)

All third-party processors are bound by data processing agreements and are required to handle your data securely and in accordance with UK GDPR.

Admin and owner accounts can access all athlete data for the purposes of programme administration and safeguarding. Coaches do not have direct access to individual athlete data profiles.

5. Data Storage & Security

Your data is stored securely on UK/EU-based servers provided by Supabase. We implement appropriate technical and organisational measures to protect your data, including:

  • Encrypted data storage and transmission (HTTPS/TLS)
  • Access controls restricting who can view personal data
  • Regular review of our data handling practices

While we take all reasonable steps to protect your data, no system can be 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours and affected users without undue delay.

6. Data Retention

We retain your personal data only for as long as necessary to provide the service and fulfil our legal obligations:

  • Active accounts: Data is retained for the duration of your membership
  • Inactive accounts: Data is deleted or anonymised after 2 years of inactivity
  • Children’s accounts: Deleted upon request or when the child reaches adulthood and does not renew consent
  • Analytics data: Retained in aggregated/anonymised form only

7. Your Rights

Under UK GDPR, you (and parents/guardians acting on behalf of children) have the following rights:

Right to Access
Request a copy of the personal data we hold about you
Right to Rectification
Ask us to correct inaccurate or incomplete data
Right to Erasure
Request deletion of your data (“right to be forgotten”)
Right to Restrict
Ask us to limit how we use your data
Right to Portability
Receive your data in a machine-readable format
Right to Object
Object to processing based on legitimate interests
Withdraw Consent
Withdraw consent at any time where processing is consent-based

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.

8. Future Features

We intend to add new features to the App over time, including push notifications, in-app payments, social features, and SMS communications. When these are introduced, this Privacy Policy will be updated and you will be notified. Any new processing activities will be clearly communicated and, where required, will require your renewed consent.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via the App. Continued use of the App after changes are posted constitutes your acceptance of the revised policy. The “Last Updated” date at the top of this document reflects the most recent revision.

10. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy, please contact:

Data Protection Contact

Ryan Fernandes

Email: [email protected]

Post: GMAX Trackstars, 22a, 24 Sydenham Rd, London SE26 5QW

Charity Registration Number: 1138783