GritPath Privacy Policy
Version: 0.1 — pre-launch draft
Effective date: [EFFECTIVE DATE]
Last updated: July 22, 2026
Pre-launch notice: This draft is based on GritPath's approved and working privacy architecture. Bracketed items and the publication checklist at the end must be resolved before publication. It requires review by qualified U.S. youth-privacy counsel and validation against the production product, vendors, consent flows, cookies, and retention jobs.
GritPath is built for families. This Privacy Policy explains how [FULL LEGAL ENTITY NAME], doing business as GritPath (“GritPath,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information through gritpath.com, the Parent Pathfinder, GritPath family accounts, guided journeys, communications, and related services (collectively, the “Services”).
It also explains the choices available to parents, guardians, youth participants, and other users.
1. Our privacy commitments
GritPath's current product design follows these principles:
- An adult manages the family account. Youth athletes do not need their own email address or login at launch.
- The public Parent Pathfinder requests an age band, not a birth date, and does not request the athlete's name, school, team, location, email address, or an open-ended description.
- We collect and use only the information reasonably needed for the feature, purchase, safety, security, or purpose involved.
- We do not sell children's personal information.
- We do not share children's personal information for cross-context behavioral advertising or targeted advertising.
- We do not use biometrics or facial recognition.
- We do not send raw athlete answers, reflections, Pathfinder answers, or internal scores to advertising platforms, our adult marketing CRM, payment processors, or broad analytics tools.
- Formal research participation, if introduced, will be optional and governed by a separate consent process. It will not be required to buy or use the ordinary product.
2. Who the Services are for
The launch version of GritPath is designed for U.S. parents and guardians and youth athletes ages 8 through 17. Adults create and control household accounts, purchase products, create athlete profiles, and authorize youth participation.
The public Parent Pathfinder is completed by an adult about an athlete based on the adult's observations. After purchase, an authorized adult may allow an athlete to complete an age-appropriate activity or check-in on a shared or supervised device.
Direct athlete login accounts, athlete-controlled email or phone destinations, and athlete-directed marketing are not part of the initial Service. We will update this Policy and implement additional protections before introducing those features.
3. Information we collect
The information we collect depends on how you use GritPath.
A. Public website and Parent Pathfinder
We may collect:
- general device, browser, language, approximate region, referral, campaign, and interaction information;
- first-party attribution information, such as UTM parameters and the page or campaign that led you to GritPath;
- the athlete's age band, primary sport or sport context, and the number of recent observation opportunities;
- the adult's structured Pathfinder selections;
- the resulting route, recommendation, and the versions of the quiz, scoring, routing, result copy, and offer used; and
- an adult email address and consent record if the adult optionally asks us to email a result or separately opts into marketing.
The Pathfinder scope gate is designed to keep sensitive, out-of-scope concerns away from ordinary marketing and analytics systems. We do not send the selected sensitive reason to HighLevel, advertising systems, session replay, or URLs. If an adult indicates that a concern may be outside GritPath's performance-skills scope, the commercial route stops and a support-information page is shown.
B. Adult account and household information
We may collect:
- adult name, email address, authentication and account-recovery information;
- household role, membership, invitation, acceptance, and organizer-transfer records;
- contact preferences and records of consent or withdrawal;
- support requests and account communications; and
- security, authentication, audit, and fraud-prevention records.
C. Athlete profile and journey information
An authorized adult may provide or authorize collection of:
- athlete name or household nickname;
- age band and, where operationally necessary after enrollment, age or date-of-birth information approved for that feature;
- sport context and relevant preferences;
- assigned journey, content version, schedule, progress, and completion records;
- structured parent and athlete check-in responses;
- routines, goals, reflections, and exercise responses requested by the journey; and
- parent-observed and athlete-reported outcome information.
GritPath separates parent and athlete perspectives in its records. We do not treat one person's answer as if the other person provided it. We may limit verbatim sharing of optional reflections within a household where the feature is designed to preserve an appropriate degree of youth privacy.
Please do not submit medical records, detailed crisis information, custody documents, or sensitive information that a GritPath feature does not request.
D. Purchase information
We collect order, product, price, discount, tax, payment status, refund, entitlement, and transaction-reference information. Payment-card details are collected and processed by Stripe or another payment processor identified at checkout. GritPath does not receive complete card numbers.
Payment providers receive only the information needed to process and document a transaction. Athlete names, raw responses, and reflections should not be placed in payment metadata.
E. Communications and marketing
We collect adult contact details, message delivery and engagement information, preferences, consent records, and unsubscribe activity when an adult asks for a result, receives a service message, contacts support, or opts into marketing.
Requesting a Pathfinder result email does not enroll an adult in marketing. Marketing consent is separate and optional. We may use adult account, purchase, and approved product-use information to offer GritPath resources or products to the responsible adult, subject to their choices and applicable law. We do not use children's personal information for behavioral advertising.
F. Information collected automatically
We and our service providers may collect IP address, device and browser type, operating system, timestamps, pages or features used, referring page, error and performance records, cookie or similar identifier, and security signals.
Sensitive forms and youth-response areas should not use advertising pixels or unrestricted session replay. Product analytics should use pseudonymous identifiers and minimum necessary events rather than raw answers or reflection text.
4. How we use information
We use personal information to:
- provide, personalize, and maintain the Services;
- score and route the Parent Pathfinder using versioned, deterministic rules;
- deliver results, guided journeys, exercises, reminders, and progress features;
- create and protect guardian-managed accounts and household permissions;
- process purchases, refunds, route switches, and entitlements;
- communicate with adults about the Services and provide support;
- send marketing to an adult who has opted in or where otherwise permitted by law;
- maintain security, prevent abuse, investigate incidents, and enforce our Terms;
- debug, measure, and improve usability, accessibility, content, and product fit;
- create aggregate or deidentified insights that do not reasonably identify a person;
- comply with law, preserve evidence, and respond to lawful requests; and
- conduct separately approved research only under an additional, optional consent and youth-assent process when applicable.
We do not use a Pathfinder response to diagnose an athlete. We do not use generative AI to invent a psychological interpretation of a Pathfinder result. [BEFORE PUBLICATION: DOCUMENT AND DISCLOSE ANY OTHER AI PROCESSING USED IN THE PRODUCTION SERVICE.]
5. When we disclose information
We may disclose personal information in the following limited circumstances.
Service providers
We use companies that help provide hosting, databases, authentication, content management, payments, customer communications, adult CRM, product analytics, error monitoring, security, and support. Current planned providers include Vercel, Supabase, Stripe, HighLevel, PostHog, and the infrastructure used to operate Payload CMS, subject to final production configuration.
These providers may process information only for authorized business purposes under contractual and technical restrictions appropriate to their role. Not every provider receives every category of information. In particular:
- HighLevel may receive an adult's email, adult consent and marketing preferences, approved attribution fields, Pathfinder route or offer code, and purchase-funnel events. It must not receive raw Pathfinder answers, internal scores, sensitive scope-gate reasons, athlete details, or youth reflections.
- Stripe may receive adult customer and transaction information needed for payment. It must not receive youth responses or reflections.
- Product analytics may receive pseudonymous events and approved context. Sensitive answers and free-text youth content must not be placed in broad analytics.
Authorized household members
We disclose household and athlete information according to account roles and feature permissions. A Family Organizer may invite another adult who confirms authorization and accepts GritPath's Terms and Privacy Policy. Role labels describe GritPath access; they do not establish legal custody or guardianship.
We may restrict access while reviewing a credible dispute, compromised account, privacy concern, or safety risk.
Legal, safety, and security reasons
We may disclose information if we reasonably believe it is necessary to comply with law or valid legal process; protect the rights, safety, and security of an athlete, user, GritPath, or another person; investigate fraud or misuse; or respond to an emergency. GritPath is not a crisis-monitoring service and does not promise that a person reviews every response.
Business transactions
We may disclose information in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and applicable law. We will provide notice if a successor intends to use personal information in a materially different way.
At your direction
We may disclose information when an authorized adult directs us to do so or provides specific consent.
Aggregate and deidentified information
We may use and disclose aggregate or deidentified information that cannot reasonably be used to identify an individual. We will not attempt to reidentify information that is maintained as deidentified except to test whether deidentification controls work, where permitted by law.
6. No sale or behavioral advertising using children's data
GritPath does not sell children's personal information. GritPath does not disclose children's personal information for targeted advertising, cross-context behavioral advertising, or advertising based on activity across unrelated services.
GritPath may use information about an adult's relationship with GritPath—including an adult's purchases, account status, and approved lifecycle events—to communicate directly with that adult about GritPath products and resources. We do not provide raw athlete data, Pathfinder answers, youth responses, or youth reflections to advertising platforms for that purpose.
[BEFORE PUBLICATION: COMPLETE A COOKIE, PIXEL, AND AD-PLATFORM DATA-flow audit and ensure the site's “sale,” “sharing,” and targeted-advertising statements match actual configuration and applicable state-law definitions.]
7. Cookies and similar technologies
We may use cookies and similar technologies that are necessary to keep the Services secure, remember settings, preserve a Pathfinder session, measure performance, understand first-party attribution, and improve the Services.
Where required, we will ask for consent before using non-essential cookies. Available controls may include a cookie-preference tool and browser settings. Blocking necessary cookies may prevent some features from working.
GritPath should honor legally required opt-out preference signals where applicable. [BEFORE PUBLICATION: LINK THE PRODUCTION COOKIE NOTICE AND “YOUR PRIVACY CHOICES” MECHANISM, IF REQUIRED.]
8. Children's and teens' privacy
GritPath is designed to place an adult in control of the household account and youth participation. For an athlete under 13, we will provide the responsible adult with required notice and obtain verifiable parental consent before collecting personal information online directly from the child, unless an applicable legal exception allows the specific collection.
The responsible adult may review the child's personal information, request correction or deletion, refuse further collection or use, and withdraw consent, subject to legal and operational exceptions. If consent is withdrawn, some or all youth-facing features may no longer be available.
For athletes 13 through 17, GritPath will continue to use a guardian-managed model at launch and will provide age-appropriate privacy explanations and meaningful choices for optional activities. We will seek youth assent where appropriate even when an adult's authorization is the legal basis for participation.
If we learn that we collected children's personal information without required authorization, we will take reasonable steps to delete it or obtain legally sufficient consent. Contact [PRIVACY EMAIL] if you believe a child has used GritPath or provided information without appropriate permission.
9. Your choices and privacy rights
Subject to identity, authority, and legal verification, you may ask us to:
- confirm whether we process personal information about you or an athlete you are authorized to represent;
- provide access to or a portable copy of eligible information;
- correct inaccurate information;
- delete eligible information;
- withdraw consent or stop future optional collection;
- opt out of marketing communications;
- opt out of sale, sharing, targeted advertising, or certain profiling where those rights apply; and
- appeal a denied privacy request where applicable.
To make a request, contact [PRIVACY EMAIL] or use [PRIVACY REQUEST FORM/URL]. We will verify the request and the requester's authority without asking for more information than reasonably necessary. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct identity confirmation.
We will not discriminate against you for exercising a privacy right. We may deny or limit a request where permitted by law—for example, when we cannot verify authority, must preserve transaction or security records, need information to establish or defend a legal claim, or must protect another person's privacy. We will explain the basis for a denial and any available appeal process.
Marketing emails include an unsubscribe link. Service, security, purchase, and account messages may still be sent when needed to provide the Services.
10. Retention and deletion
We retain personal information only as long as reasonably necessary for the purpose collected, the active relationship, security, legal obligations, dispute resolution, and enforcement. GritPath's current provisional schedule is:
- active account, household, athlete, entitlement, and journey information: while the relevant purpose and account relationship remain active;
- expired invitation tokens and equivalent secret material: removed promptly after use or expiration;
- minimal invitation audit metadata: generally up to 12 months;
- security, membership, organizer-transfer, and support audit records: generally up to 12 months, unless an incident or legal hold requires longer;
- consent evidence: for the active relationship and generally three years after account closure;
- approved deletion requests: removed from live systems generally within 30 days after verification and resolution of any required exception;
- rolling backups: overwritten on a cycle not expected to exceed 35 days; and
- payment, tax, fraud, and transaction records: for the period required by financial, tax, consumer-protection, and legal obligations.
Deleted information may remain temporarily in restricted backups until overwritten. We may preserve a narrowly scoped record when required by law, a legal hold, security incident, unresolved dispute, chargeback, or request to prevent re-enrollment or further contact.
We do not retain personal information indefinitely merely because storage is available. [BEFORE PUBLICATION: VERIFY EACH PERIOD AGAINST PRODUCTION JOBS, PROVIDER SETTINGS, TAX REQUIREMENTS, INCIDENT POLICY, AND COUNSEL ADVICE.]
11. Security
We use administrative, technical, and physical safeguards designed to protect personal information. Planned controls include guardian-controlled authentication, household-based authorization, least-privilege access, encryption in transit, provider access controls, environment separation, audit records, rate limits, secret management, backups, and incident-response procedures.
No system is perfectly secure. You are responsible for protecting your credentials and shared devices. Contact [SECURITY EMAIL] promptly if you suspect unauthorized access or a security vulnerability. Do not include sensitive youth information in an initial unencrypted report.
12. Data location and U.S. use
GritPath's launch Service is intended for use in the United States. We and our service providers may process information in the United States and other locations where providers operate. [BEFORE PUBLICATION: CONFIRM HOSTING REGIONS, CROSS-BORDER PROCESSING, AND WHETHER ACCESS OUTSIDE THE UNITED STATES WILL BE BLOCKED OR MERELY UNSUPPORTED.]
13. Third-party links and services
The Services may link to resources or services operated by others. Their privacy practices are governed by their own policies. Review those policies before providing information to an unrelated third party.
14. Changes to this Policy
We may update this Policy to reflect changes in the Services, vendors, practices, or law. We will post the revised Policy and update the “Last updated” date. If a change materially affects youth information, parental choices, or previously collected information, we will provide additional notice and obtain new consent when required.
15. Contact us
For privacy questions or requests:
[FULL LEGAL ENTITY NAME]
Attn: Privacy
[MAILING ADDRESS]
[PRIVACY EMAIL]
[PRIVACY REQUEST FORM/URL]
[PHONE/TOLL-FREE NUMBER, IF REQUIRED]