Athlete Sitter — Privacy Policy
Last Updated: March 13, 2026
Athlete Sitter is operated by GBobble, LLC, an Illinois limited liability company ("GBobble," "we," "us," or "our"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use our website and services. By creating an account or using Athlete Sitter, you agree to the practices described in this Privacy Policy.
1. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information provided by parents or guardians for children.
1.1 Information You Provide
Depending on your role, you may provide the following categories of information:
All Users
- Name
- Email address
- Phone number (for SMS verification)
- ZIP code and city
- Optional profile photo (avatar)
- Messages you send through the platform
Trainers
- Sports offered and experience (sport, skill level, years of experience, primary sport)
- Profile heading and bio
- Gender and school affiliation
- ZIP code and city
- Suggested hourly rate and whether you have a car
- Training preferences (preferred athlete gender, age ranges, experience levels, training style)
- Photos for each sport
- Reviews received
- In the future, we may also allow trainers to provide availability information (such as days and times they are typically available for sessions).
Parents
- Information about your children (name, date of birth, gender, and sports)
Athletes (13+)
- Name
- Date of birth
- Sports
- Optional profile photo
Advertisers
- Business name
- Contact information
- Ad content (such as titles, descriptions, and creative)
Children Under 13
Children under 13 should not create their own accounts as athletes or trainers. A parent or legal guardian should create and manage any account used by a child under 13.
In some cases, a parent or legal guardian may create and manage an athlete profile for a child under 13. We do not knowingly collect personal information directly from children under 13 without a parent or legal guardian involved.
1.2 Automatically Collected Information
We automatically collect certain technical information when you use Athlete Sitter, including:
- A session ID (via an essential session cookie) so you can stay logged in
- Basic information about how you use the site, such as which pages you visit and when, in order to operate and debug the service
- Internal event records about actions you take in the app (for example, login events or key workflow steps)
Our hosting and infrastructure providers may also log standard technical information such as IP address, browser type, and device information as part of their normal operations.
We do not use analytics trackers, advertising trackers, fingerprinting, or third-party tracking cookies.
1.3 Photos
User photos are stored either in Supabase object storage or in our own server storage, depending on our deployment configuration. Metadata (such as the photo URL or storage path) is stored in our database.
2. How We Use Your Information
We use your information to operate, maintain, and improve Athlete Sitter, including to:
- Create and manage your account
- Authenticate your login (via SMS one-time passwords)
- Connect parents, athletes, and trainers
- Display profiles, photos, and reviews
- Facilitate messaging between users
- Moderate content and maintain platform safety
- Improve the platform and fix issues
- Communicate with you about your account or important updates
- Select which internal Athlete Sitter ads or sponsorships to show based on your role, search context, and ZIP code
We do not use your data with third-party advertising networks or for cross-site profiling.
3. Information Sharing
We do not sell your personal information. We share data only with service providers who help us operate the platform:
- Supabase – database hosting and photo storage
- Telnyx – SMS delivery for OTP codes
- Zoho Mail – our primary email server; we use Zoho to send transactional email on our behalf
- Gmail SMTP – transactional email (development and testing only)
- Resend – transactional email (optional fallback; we may use it only if needed)
- Vercel – application hosting
- Google Fonts (self-hosted) – typography
These providers only receive the minimum data needed to perform their services.
We do not use third-party analytics, third-party advertising networks, social login providers, or payment processors. Athlete Sitter ads and sponsorships you see inside the product are selected by us directly and are not served by third-party ad networks.
4. Cookies & Tracking Technologies
We use only one essential cookie to operate the service:
- Session Cookie – contains a session ID, is HTTP-only, uses SameSite=Lax, is secure in production, has a 30-day expiration, and is required for login.
We also use localStorage to remember whether you dismissed the message alert bar.
We do not use analytics cookies, advertising cookies, social media trackers, pixel tags, or fingerprinting. Because we only use essential cookies, we do not display a cookie banner today.
5. Data Storage & Security
We rely on modern, secure infrastructure to store and protect your data:
- Encryption in transit – all data sent between your device and our servers is encrypted via HTTPS.
- Encryption at rest – Supabase encrypts stored data on its managed PostgreSQL infrastructure.
- Backups & reliability – Supabase maintains automated backups and high-availability systems.
- Internal access controls – only authorized administrators may access user data for operational purposes such as support, moderation, and security.
6. Data Retention
We keep different types of data for different lengths of time. Today we do not run automated purge jobs for most long-lived data, and many records are retained until they are changed or deleted as part of a support or product change. In particular:
Short-lived data
- One-time passwords (OTPs) used for login are valid for a few minutes and then expire.
- Login sessions created for your account typically expire after about 30 days.
- Temporary signed URLs we use to serve photos from storage expire after a short period (on the order of minutes).
Long-lived data
- User accounts, trainer profile data, advertiser data, and system event logs are retained until they are changed or deleted as part of operations or support.
- Messages can be hidden or blocked in the product, but message records and related conversation history remain in our database.
- Reviews and photo metadata are retained unless we remove them (for example, due to a policy violation) or you request deletion.
- Guest or incomplete accounts and inactive accounts do not have an automatic purge schedule today.
If you would like us to delete an account or remove specific information where feasible, you can submit a request as described in the User Rights section.
7. User Rights
You can contact us at any time to ask questions about your data. Subject to applicable law, you may request that we:
- Access Your Data – ask what personal information we store about you and request a copy.
- Correct Your Data – ask us to update or correct information that is inaccurate or incomplete.
- Request Deletion – ask us to delete your account or remove identifying information from our records where feasible. Today this is a manual process handled by an administrator rather than an automated in-app feature.
- Opt Out of Marketing Emails – we do not send marketing emails today. If we introduce them in the future, you will be able to opt out.
To submit a privacy-related request, email info@athletesitter.com. We aim to respond within 30 days and will let you know if we need more time based on the complexity of your request.
8. Age Requirements & Parental Consent
Users 13 and Older
Athletes and trainers must be at least 13 years old to create and manage their own accounts. Parent and advertiser accounts are intended for adults.
Children Under 13
Children under 13 should not self-register as athletes or trainers. A parent or legal guardian should create and manage any account used by a child under 13. In the future, we may allow parents or legal guardians to create and manage athlete profiles for children under 13 directly.
We do not knowingly collect personal information directly from children under 13 without a parent or legal guardian involved.
9. Third-Party Services
We use the following service providers to help operate Athlete Sitter:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and storage | All stored data (user accounts, profiles, messages, reviews, photos, and related records) |
| Telnyx | SMS OTP delivery | Phone number, OTP code |
| Zoho Mail | Primary email server; transactional email | Email address, subject, email body |
| Gmail SMTP | Transactional email (development and testing only) | Email address, subject, email body |
| Resend | Transactional email (optional fallback) | Email address, subject, email body |
| Vercel | Hosting | Technical logs related to serving the site |
| Google Fonts (self-hosted) | Typography | None at runtime (fonts are served from our infrastructure) |
We do not use analytics providers, third-party ad networks, or social login providers.
10. Data Breach Notification
If a data breach occurs that affects your personal information, we will notify you by email and/or through other appropriate channels, consistent with applicable law.
11. Changes to This Policy
When we update this Privacy Policy, we will update the "Last Updated" date at the top of the page. If we make material changes, we will take reasonable steps to notify you, such as sending an email or showing a notice in the product.
12. Contact Us
For privacy questions or requests, contact: info@athletesitter.com