1. Who we are and what this policy covers
A-PATH is operated by GMP Global Marketing Inc., a California, United States company. This policy describes personal information handled through a-path.com and the A-PATH coaching and member service. It does not describe a separate native app or a feature that has not been launched.
Contact: info@a-path.com · +1 909-595-1588 · GMP Global Marketing Inc., 20957 Currier Rd, Ste A, Walnut, CA, USA.
Organizations using A-PATH, such as academies and coaching businesses, decide which athletes they manage, what coaching records to enter, and which people may access those records. We provide the platform and handle information for account administration, security, support, and delivery of the service. An organization may have its own privacy notice and responsibilities. Contact it about its coaching decisions and records; contact us about the platform or if you need help identifying the responsible organization. Neither party can use this distinction to avoid its obligations under applicable law.
2. Information we collect and its sources
- Account information you provide: name, email address, account type, organization membership requests, and support communications. Passwords are protected using a salted password hash; we do not store readable account passwords.
- Organization and coaching information provided by authorized users: organization names, staff assignments, athlete names and sports, classes, attendance, progress, skill scores, measurements, badges, shared notes, and associated record dates. Where a record includes an external video link, we store the link and its associated coaching details.
- Athlete photos and videos: files uploaded by authorized staff, their original embedded information, filenames, file type and size, upload time, uploader and athlete association, and records needed to control access and prevent duplicate uploads. These files are used for the athlete library and are visible only through authenticated access authorized by the organization.
- Subscription information: selected plan and billing period, Stripe customer and checkout references, subscription status and dates, and payment-related event records needed to verify access and support billing. Payment details are entered on Stripe-hosted pages; A-PATH does not store full payment card numbers or card security codes.
- Access and service information: organization invitations, membership decisions, athlete access grants, authentication events, security records, and information needed to recognize and prevent duplicate operations.
- Technical information generated when you use the service: IP addresses, browser or device information available in requests, request times and routes, errors, and essential login information. We use this information for delivery, reliability, and security, rather than advertising profiles.
- Transactional email information: recipient details, verification or invitation purpose, delivery attempts, and delivery outcomes. Verification and recovery messages contain a limited-use link. Do not share these links with others.
Do not place unnecessary medical information, government identifiers, payment card details, passwords, or other sensitive information in names, shared notes, or support messages. A free-text field can contain personal information even if the platform does not specifically request it.
3. Google sign-in
Google sign-in is optional and applies only when that feature is available and you choose it. Our integration requests basic identity scopes: openid, email, and profile. It uses your Google account identifier, name, email address, and email verification information to authenticate you, create or link an account at your direction, and protect account access. An identity token may include other basic profile claims; we do not use a profile image or request access to your Gmail messages, contacts, Drive files, or Calendar.
We store the Google account identifier and association with your A-PATH account, email verification and account-link status, and relevant security timestamps. Temporary sign-in data is used to complete and protect the login process. We do not retain Google access or refresh tokens for ongoing access to Google services.
We do not sell Google user data, use it for advertising, or disclose it for unrelated purposes. Access is limited to operating the requested account features, necessary security and support, and applicable legal obligations. Our handling of Google data must comply with the Google API Services User Data Policy. Google also processes information under its own privacy policy.
You may remove A-PATH's connection in your Google Account settings. When available, A-PATH's account security settings also let you unlink Google after confirming another recovery method. Unlinking or revoking access does not itself delete your A-PATH account or organization records. Contact us to request deletion or assistance. Email registration and recovery remain separate options; a Google-only account may need to set an A-PATH password before using password sign-in.
4. Why we use information
We use information to provide accounts and organization access; deliver coaching records and requested reports; support scheduling and communication; send account verification, invitations, recovery, and essential service notices; investigate problems and abuse; protect accounts and data; fulfill lawful requests; and manage the service. A-PATH does not use athlete ratings or badges to make employment, lending, insurance, or other eligibility decisions.
We do not sell or rent A-PATH personal information, share it for cross-context behavioral advertising, or use Google or athlete information to train general-purpose AI models. A materially different purpose requires an updated notice and any consent required by law before that new use begins.
5. Who can receive information
- Your organization and people it authorizes: staff and members can see the records their permissions allow. A member is not necessarily a parent, guardian, or the athlete concerned. Shared notes are visible to authorized people for that athlete; they are not a private support channel.
- Service providers: hosting, infrastructure, security, and communication providers receive information needed for their functions. Google Workspace is used for transactional email. Google processes the sign-in information described above when you choose that option.
- At your direction: for example, when you share an exported report or open an external link. The recipient's or external site's practices apply to its copy or service. External media may receive browser and network information when loaded.
- Legal and security recipients: where required by law, to respond to valid legal process, protect rights and safety, or investigate abuse, subject to applicable limits.
- A business successor: if the service is involved in a merger, acquisition, or transfer, information may be transferred subject to this policy, applicable law, required notice, and any required consent. Google data remains subject to Google's applicable restrictions.
Organization membership, a family relationship, or a request to support does not automatically grant access to another person's records. We must verify the relevant authority before disclosing them.
6. Cookies, storage, and tracking choices
A-PATH uses essential cookies to keep you signed in and protect authentication. The account session cookie is normally valid for up to eight hours. The optional Google sign-in flow uses a separate short-lived cookie, normally up to ten minutes. These are security functions, not advertising cookies. Blocking essential cookies may prevent login.
Our current Web release does not include advertising pixels, cross-site behavioral analytics, or an offline draft and synchronization service. It does not persist coaching drafts in browser local storage. Ordinary browser caching of public images, fonts, or pages is different from an offline data service.
Because we do not conduct cross-context behavioral advertising, a Do Not Track or Global Privacy Control signal does not change the essential processing described here. Such signals do not turn off cookies needed to operate a requested account session. We will honor any applicable opt-out obligations if our practices change. Third-party websites opened from A-PATH have their own cookie and tracking practices.
7. Access to accounts and athlete records
A-PATH does not use a platform age threshold or guardian-consent process to activate accounts and does not provide a guardian-consent record feature. Account sign-in and access to athlete records remain separately controlled by identity verification and organization authorization.
Creating an athlete record does not automatically create a login account for that athlete. Organizations and users must still have authority to enter and share the relevant information. Membership or a claimed family relationship does not automatically grant access to another person's records. Data requests follow the identity and authority checks described below; this feature change does not alter rights or obligations under applicable law.
8. Retention, account closure, and deletion
We retain information for the purposes described in this policy, considering whether the account or organization relationship remains active, the nature of the coaching record, valid organizational instructions, applicable legal requirements, security needs, unresolved disputes, and requests to exercise privacy rights. We do not set one universal retention period for every category of record.
Leaving an organization, disabling a login method, or closing an account does not automatically erase organization-owned coaching records or all security records. Request review, correction, export, or deletion by contacting us. We will verify the request, determine the records and legal exceptions involved, coordinate with the organization where appropriate, and explain the outcome. We do not promise immediate deletion of every copy.
Backups and retained recovery copies may contain information that has been removed from the active system. They must remain restricted to legitimate recovery, security, or legal purposes. Approved deletion and restriction requests must be considered before restored data returns to ordinary use. A fixed backup deletion schedule is not represented as an existing service by this policy.
Removing a photo or video from an athlete library removes ordinary access to that file and frees its upload slot. Restricted original and backup copies may remain for recovery or a reviewed retention purpose. For a request to permanently erase retained copies, contact us using the details below; removal from the library alone does not represent erasure of every copy.
9. Security and processing locations
We use measures such as encrypted HTTPS connections, password hashing, restricted service credentials, authenticated sessions, and organization-level access controls. No internet service or security measure can guarantee absolute security. Please protect your account credentials and report suspected unauthorized access promptly.
The service is operated by a United States company. Information may be processed in the United States and other locations used by our hosting or communication providers. We do not promise that information stays in California or in the country where you live. Where applicable law requires particular protections for international transfers, those protections must be in place before the relevant transfer.
10. Your requests and privacy rights
Contact info@a-path.com or +1 909-595-1588 to ask about access, correction, an available copy of your information, account closure, deletion, or a concern about our practices. We may ask for information reasonably necessary to verify you and your authority, but do not send a password, verification code, or government identification in an ordinary email unless a secure, necessary process has been arranged.
Depending on where you live and which law applies, you may have additional rights to know or access information, correct it, delete it, obtain a portable copy, withdraw consent, object to or restrict processing, opt out of certain disclosures or profiling, appeal a decision, or complain to a regulator. California residents have applicable statutory privacy protections; rights under the CCPA/CPRA apply where that law covers the business and request. We do not represent that every provision applies to every user or organization.
An authorized agent may submit a request where permitted by law, with appropriate proof of authority. We respond within applicable legal time limits, explain applicable exceptions or verification issues, and do not unlawfully discriminate because you exercise privacy rights. If an organization controls a requested record, we will explain the appropriate route and provide assistance consistent with our obligations.
11. Features not currently active
SMS verification through Twilio is not active in the current release. We will provide the applicable phone-data, provider, consent, retention, and message terms before enabling it. We do not collect a phone number through an active SMS registration service under this policy.
Stripe-hosted subscription checkout and athlete photo/video uploads are available when enabled for your organization. Stripe handles payment information under its Privacy Policy. Uploaded athlete files are stored on A-PATH's restricted hosting infrastructure and shared according to organization permissions. Offline draft storage and synchronization are not currently enabled.
12. Updates and contact
The effective date and version appear at the top of this policy. Material changes will receive appropriate notice, such as a prominent website notice or an account email, and any consent required by law. We will not silently apply a new, incompatible use to previously collected information.
GMP Global Marketing Inc. · A-PATH · info@a-path.com · +1 909-595-1588 · 20957 Currier Rd, Ste A, Walnut, CA, USA.