Legal
Last updated 18 August 2026
Draft — not yet in force. This policy still contains unfilled placeholders. Complete src/lib/legal.ts and have a lawyer review it before relying on this page.
This policy explains what [TODO: your legal entity or full name] (“HoopDrills”) collects when you use https://hoopdrills.org, why we collect it, and what control you have. We sell nothing to advertisers and run no advertising trackers.
For the purposes of the GDPR, the data controller is [TODO: your legal entity or full name], [TODO: your registered address]. You can reach us about anything in this policy at [TODO: your privacy email].
Under the GDPR we must have a lawful basis for each use. Ours are:
We do not sell your personal data. We share it only with providers who help us run HoopDrills, each handling it under contract and only on our instructions:
Embedded videos are served by YouTube, TikTok or Instagram, which may set their own cookies and see your IP address when a video loads. Those platforms’ own privacy policies apply to that. We may also disclose data where legally required, or to protect the rights and safety of our users.
Your username, avatar, bio, links, and any content you mark public are visible to everyone, including people who are not signed in. Content marked private is visible only to you. Your email address is never shown to other users.
HoopDrills is for coaches and trainers aged 16 or over, and accounts are not intended for children. We do not knowingly collect data from children.
Coaches work with young players, so this matters here more than on most services: if you upload material in which a young player is identifiable, you are responsible for holding the consent of their parent or guardian, and you act as the controller of that material. If you believe a child has created an account, or that a child’s personal data has been posted without consent, email [TODO: your privacy email] and we will remove it promptly.
Account and content data is kept while your account is open. If you delete your account we remove your profile and content, except records we must retain for legal or accounting reasons — notably purchase and payout records, which are typically kept for the period required by tax law. Server logs are kept for a short operational window and then discarded.
Under the GDPR you have the right to:
You can edit your profile and delete your content or your account in the app at any time. For anything else, email [TODO: your privacy email] — we will respond within one month, as the GDPR requires.
If you are unhappy with how we handle your data you may complain to the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), or to the authority in your own EU country.
Access to your data is enforced at the database level, so users can only reach what they are entitled to, and traffic is encrypted in transit. No system is perfectly secure. If a breach is likely to result in a risk to your rights we will notify the supervisory authority within 72 hours and tell you directly where the risk is high, as the GDPR requires.
Our hosting and payment providers are US-based, so your data is transferred outside the European Economic Area. Those transfers rely on the safeguards in each provider’s data processing terms — Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You can ask us for details of the safeguards that apply at [TODO: your privacy email].
If we make a material change to this policy we will give notice in the app or by email. Questions or requests: [TODO: your privacy email], [TODO: your legal entity or full name], [TODO: your registered address].