Glyyd Privacy Notice
Effective Date: July 8, 2026
1. Scope and Roles
This Privacy Notice explains how Glyyd, Inc. (“Glyyd,” “we,” “us,” or “our”) collects, uses, discloses, retains, and otherwise processes personal information when people use the Glyyd website, platform, applications, dashboards, APIs, and related services (collectively, the “Services”). This Privacy Notice applies to athlete users, parents or guardians, rowing clubs, college and university personnel, coaches, and website visitors.
Glyyd is not itself a school, school district, college, or university. When Glyyd processes education records or personally identifiable information from education records on behalf of a FERPA-covered educational agency or institution, Glyyd acts only as a service provider or school official performing an institutional service or function under the direct control of that institution and only for the purposes authorized by that institution.
This Privacy Notice does not change or limit any rights that a FERPA-covered institution may have to provide institution-specific notices, obtain consents, or manage access and amendment requests under its own policies and legal obligations.
2. Platform Use Cases
Glyyd supports several private recruiting-related use cases. An athlete, or a parent and athlete together where the athlete is a minor, may create an account, upload athlete information, and manage which colleges or universities are saved in the athlete’s My Schools list. My Schools records are retained while the athlete account remains active and are deleted when the athlete removes the school or deletes the account.
A rowing club that is not affiliated with a FERPA-covered educational institution may upload athlete information where the club has obtained any permissions or consents it relies on. Colleges and universities, including rowing departments and coaches, may view athlete information within Glyyd through approved organization and team access controls, subject to access controls, permissions, and applicable law.
Glyyd’s recruiting model is based on private sharing within the Services. Athlete-directed access by a specific college to an athlete’s broader profile or data is not currently available unless and until Glyyd launches that feature and provides a separate notice or updated workflow for it. Glyyd does not offer public athlete profiles or public searchable recruiting pages as part of the current workflow described in this Privacy Notice.
3. Personal Information Collected
The personal information collected depends on how a person interacts with the Services. Categories may include account and login information, contact details, role and organization information, date of birth, parent or guardian contact details, consent records, athlete profile data, recruiting selections, rowing performance data, device and usage information, support records, and audit logs.
For athlete users, this may include uploaded or connected performance data such as stroke metrics, power metrics, boat and crew data, session-related information, and related analytics. For coaches, schools, clubs, and institutions, this may include contact and organizational information, access logs, and platform usage information.
Glyyd may also maintain records relating to privacy requests, consent workflows, authorizations, and account-verification events.
Sources of personal information. Glyyd collects personal information from the following categories of sources: directly from you, when you register for an account, upload or enter information, configure settings, communicate with us, request support, or otherwise use the Services; from parents or legal guardians, where a parent or guardian creates or authorizes a minor athlete’s account or provides consent or verification; from rowing clubs and other non-institutional organizations that upload athlete information to the Services; from colleges, universities, and FERPA-covered educational institutions, or parties acting on their behalf, that provide student-athlete information; automatically from your devices and your use of the Services, including device and usage information, access and audit logs, and performance data generated by connected equipment or sensors; and from service providers and other third parties that support the operation, security, communications, payment verification, and analytics of the Services.
Notice at Collection
This summary is provided at or before the point at which Glyyd collects personal information. It describes the categories of personal information we collect, the purposes for which we use them, whether we sell or share them, and how long we retain them.
| Category collected | Purpose(s) | Sold or shared? | Retention |
|---|---|---|---|
| Account, login, and contact information | Create and secure accounts, authenticate users, communicate with you, and provide the Services. | No | Active account + 30-day cooling-off, then deleted. |
| Profile and role/organization information (incl. date of birth) | Manage profiles, permissions, recruiting access, and age/authorization verification. | No | Active account + 30-day cooling-off, then deleted. |
| Athlete performance / telemetry and boat GPS data | Deliver athlete analytics and platform functionality; longitudinal performance analysis. | No | While account/coaching active; anonymized on deletion (max period under review). |
| Recruiting selections and authorizations | Enable authorized private sharing of athlete information with selected colleges/universities, including My Schools interest lists. | No | Duration of the active account or applicable recruiting relationship |
| Consent records, support records, and audit/activity logs | Document consents and authorizations, respond to support, maintain security and audit trails. | No | Consents: account + 3 yrs; logs: 2 yrs; see Section 11. |
| Sensitive personal information (account credentials, precise geolocation, information about minors where applicable, sensor-derived motion data) | Provide the Services, secure accounts, verify authorization, and prevent fraud. Not used for targeted or cross-context behavioral advertising, and not used to limit our offering of the Services. Consumers have the right to limit use of sensitive personal information to purposes necessary to provide the Services. See Section 4 for more information. | No | Per the applicable category in Section 11. |
| Device and usage information | Operate, secure, and improve service reliability and performance. | No | Diagnostics: 7–90 days; see Section 11. |
Glyyd does not sell personal information and does not share personal information for cross-context behavioral advertising.
5. How Personal Information Is Used
Glyyd uses personal information to provide and operate the Services, create and secure accounts, deliver athlete analytics, manage permissions and recruiting access, process transactions, communicate with users, respond to support requests, maintain logs, and improve service reliability and security.
Glyyd may also use personal information to verify age and authorization status, administer minor-account workflows, document consents and attestations, enforce platform rules, comply with contracts and legal obligations, and create de-identified or aggregated information for product improvement and business planning.
Glyyd does not use school-sourced education records to create recruiting recommendations, rankings, or similar inferences unless authorized by the relevant institution, the applicable user, or applicable law.
7. FERPA and School-Sourced Records
FERPA applies to education records that are directly related to a student and maintained by an educational agency or institution or by a party acting for that agency or institution.
When Glyyd receives student-athlete information from a FERPA-covered institution or from a party acting on that institution’s behalf, and that information constitutes education records or personally identifiable information from education records, Glyyd processes that information only for institutional purposes authorized by the institution and under the institution’s direct control.
Requests to inspect, review, amend, or challenge FERPA-covered records must generally be directed to the relevant educational institution. Glyyd may assist the institution in responding where appropriate and authorized.
8. Rowing Clubs and Non-Institutional Uploads
Rowing clubs that use the Services are generally treated as non-school organizations unless Glyyd has a separate written agreement establishing a different role. Glyyd does not assume that a rowing club is a FERPA-covered institution merely because it uploads athlete information to the Services.
A club or other non-institutional uploader is responsible for obtaining any permissions, notices, consents, or other rights on which it relies before providing athlete information to Glyyd or making athlete information available to coaches through the Services.
9. Consent, Age Verification, and Minor Accounts
Users under 18 may use the Services only with parent or legal guardian authorization and subject to Glyyd’s registration, age-verification, and consent procedures.
As part of Glyyd’s current product design, Glyyd may require a parent or legal guardian verification process for all minor accounts, including a nominal verification transaction processed by a third-party payment processor.
11. Data Retention
Glyyd retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Notice, to comply with contractual and legal obligations, to resolve disputes, and to enforce agreements.
The table below sets out the retention period, or the criteria used to determine it, for each category of personal information. When information is no longer needed, Glyyd deletes, anonymizes, or de-identifies it using reasonable technical and organizational measures. FERPA-covered institutional data is retained only as permitted by the relevant institutional agreement and applicable law.
| Category of Personal Information | Retention Period (or criteria) |
|---|---|
| Account, login, and authentication information (including account credentials) | Authentication and session tokens expire automatically at the end of each session. Account records are retained for the duration of the active account plus a 30-day cooling-off period, after which they are deleted. |
| Profile and contact information (name, email, date of birth, school or organization, role, parent/guardian contact details) | Duration of the active account plus a 30-day cooling-off period, then hard-deleted. |
| Athlete performance and telemetry data (stroke, power, boat and crew data, session data) and boat GPS/track data | Retained while the account and coaching relationship remain active plus 2 years after account deletion or last user activity, whichever comes first. On account deletion, direct identifiers are removed and the data is anonymized. |
| Crew name and athlete identifier | Duration of consent; removed from future collection on consent withdrawal or account deletion. |
| Recruiting selections and sharing authorizations | Duration of the active account or recruiting relationship. |
| Consent records and upload consent attestations | Duration of the account plus 3 years following deletion, retained in anonymized form (timestamps without identifiers). |
| Privacy / data subject rights request records | 3 years from the date of the request. |
| Breach notification records | 3 years from the notification date. |
| Activity and audit logs (records of who accessed what data) | 2 years (baseline; subject to ongoing FERPA review). |
| CARA session records (where applicable to NCAA institutions) | Duration of the athletic career plus 1 year. |
| Error monitoring and diagnostic data | Application error events 90 days; session replays 30 days; server function logs 7 days (provider defaults). |
| Data export files | Not stored on Glyyd's servers; generated and delivered only at the time of a request. |
| Marketing and prospect contact data (CRM) | Until opt-out, or until a periodic review determines there is no continued business need. |
| Website analytics | Aggregated, privacy-friendly analytics collected without cookies, persistent identifiers, or stored raw IP addresses; retention is managed by the analytics provider. |
When information is no longer needed, Glyyd deletes, anonymizes, or de-identifies it using reasonable technical and organizational measures.
When you request account deletion, there is a 30-day recovery period before your data is permanently deleted. This gives you time to change your mind or recover from accidental deletion requests. During this period, your data is marked for deletion and is not used for any new purposes. You can cancel the deletion request at any time within the 30-day window.
12. Privacy Rights and Requests
Subject to applicable law and exceptions, individuals may have rights to request access, correction, deletion, portability, objection, withdrawal of consent, or limitation of certain processing activities.
Glyyd will not discriminate or retaliate against you for exercising any of your privacy rights. Glyyd will not deny you the Services, charge you a different price or rate, or provide you a different level or quality of the Services because you exercised your rights, except where a difference is permitted by law and is reasonably related to the value provided to Glyyd by your data. Glyyd will not retaliate against any employee, applicant, or independent contractor for exercising their rights under the CCPA.
Glyyd may verify the identity or authority of a requestor before acting on a request, including by using existing account authentication methods or requesting additional information where reasonably necessary. California regulations require reasonable verification procedures and prohibit charging a fee merely to verify a consumer privacy request.
If a request relates to FERPA-covered education records maintained by or for an educational institution, the request may need to be directed to that institution rather than handled solely by Glyyd.
Privacy requests may be submitted through our data subject request form or sent to privacy@glyyd.com.
13. De-Identified and Aggregated Information
Glyyd may create and use de-identified or aggregated information for analytics, product development, research, security, and business planning. When Glyyd de-identifies data, Glyyd takes steps designed to remove direct identifiers and reduce the likelihood of re-identification in light of available technology and the context of processing.
Glyyd does not attempt to re-identify de-identified data except as permitted by law for testing, security, or compliance purposes.
14. Regional Privacy Notices
California
For California residents, Glyyd provides the notices and rights required by the CCPA as amended by the CPRA, including rights to know, delete, correct, opt-out of sale or sharing, limit use of sensitive personal information, and obtain information about the categories of personal information collected, used, disclosed, and retained, subject to applicable exceptions. Glyyd does not discriminate against California consumers who exercise their privacy rights.
Glyyd does not sell personal information and does not share personal information for cross-context behavioral advertising. Glyyd may disclose personal information to service providers, contractors, and other recipients for limited business purposes subject to appropriate contractual restrictions.
EEA and United Kingdom
For individuals in the EEA and United Kingdom, Glyyd may process personal data on the basis of contract performance, legitimate interests, consent, and other lawful bases recognized by applicable law. Glyyd may transfer data to the United States using an appropriate transfer mechanism where required, such as Standard Contractual Clauses or another valid transfer tool.
Canada
For individuals in Canada, Glyyd may process personal information in accordance with PIPEDA and applicable provincial privacy laws, including British Columbia and Alberta private-sector privacy laws and Quebec requirements where applicable.
15. Changes to This Privacy Notice
Glyyd may update this Privacy Notice from time to time to reflect changes in the Services, legal requirements, or operational practices. If Glyyd makes material changes, Glyyd will update the effective date at the top of the Privacy Notice and provide notice through the Services or by other appropriate means as required by applicable law. The revision history table is for transparency only and does not limit Glyyd’s right to make future updates. For clarity, the version in effect is the most recently posted Privacy Notice with the latest effective date. For material changes that affect how Glyyd processes sensitive personal information or minor data, Glyyd will provide advance notice and obtain renewed consent where required by law.
16. Contact Information
Questions about this Privacy Notice or privacy requests may be sent to privacy@glyyd.com.
Revision History
This table tracks material versions of the Privacy Notice. The effective date at the top of the notice should match the most recent revision date for the public version.
| Date | Summary of Changes | Revision Notes |
|---|---|---|
| June 17, 2026 | Initial public release of the Glyyd Privacy Notice. | Aligned notice to current product and California CPRA disclosures. |
| June 22, 2026 | Updated recruiting-access language to match current implementation. | Current revision for launch-state accuracy. |
| July 8, 2026 | Update sensitive personal information processing for California users, and data retention periods | Aligned notice to Glyyd’s current state functionality. |