Glyyd Privacy Notice

Effective Date: July 8, 2026

1. Scope and Roles

This Privacy Notice explains how Glyyd, Inc. (“Glyyd,” “we,” “us,” or “our”) collects, uses, discloses, retains, and otherwise processes personal information when people use the Glyyd website, platform, applications, dashboards, APIs, and related services (collectively, the “Services”). This Privacy Notice applies to athlete users, parents or guardians, rowing clubs, college and university personnel, coaches, and website visitors.

Glyyd is not itself a school, school district, college, or university. When Glyyd processes education records or personally identifiable information from education records on behalf of a FERPA-covered educational agency or institution, Glyyd acts only as a service provider or school official performing an institutional service or function under the direct control of that institution and only for the purposes authorized by that institution.

This Privacy Notice does not change or limit any rights that a FERPA-covered institution may have to provide institution-specific notices, obtain consents, or manage access and amendment requests under its own policies and legal obligations.

2. Platform Use Cases

Glyyd supports several private recruiting-related use cases. An athlete, or a parent and athlete together where the athlete is a minor, may create an account, upload athlete information, and manage which colleges or universities are saved in the athlete’s My Schools list. My Schools records are retained while the athlete account remains active and are deleted when the athlete removes the school or deletes the account.

A rowing club that is not affiliated with a FERPA-covered educational institution may upload athlete information where the club has obtained any permissions or consents it relies on. Colleges and universities, including rowing departments and coaches, may view athlete information within Glyyd through approved organization and team access controls, subject to access controls, permissions, and applicable law.

Glyyd’s recruiting model is based on private sharing within the Services. Athlete-directed access by a specific college to an athlete’s broader profile or data is not currently available unless and until Glyyd launches that feature and provides a separate notice or updated workflow for it. Glyyd does not offer public athlete profiles or public searchable recruiting pages as part of the current workflow described in this Privacy Notice.

3. Personal Information Collected

The personal information collected depends on how a person interacts with the Services. Categories may include account and login information, contact details, role and organization information, date of birth, parent or guardian contact details, consent records, athlete profile data, recruiting selections, rowing performance data, device and usage information, support records, and audit logs.

For athlete users, this may include uploaded or connected performance data such as stroke metrics, power metrics, boat and crew data, session-related information, and related analytics. For coaches, schools, clubs, and institutions, this may include contact and organizational information, access logs, and platform usage information.

Glyyd may also maintain records relating to privacy requests, consent workflows, authorizations, and account-verification events.

Sources of personal information. Glyyd collects personal information from the following categories of sources: directly from you, when you register for an account, upload or enter information, configure settings, communicate with us, request support, or otherwise use the Services; from parents or legal guardians, where a parent or guardian creates or authorizes a minor athlete’s account or provides consent or verification; from rowing clubs and other non-institutional organizations that upload athlete information to the Services; from colleges, universities, and FERPA-covered educational institutions, or parties acting on their behalf, that provide student-athlete information; automatically from your devices and your use of the Services, including device and usage information, access and audit logs, and performance data generated by connected equipment or sensors; and from service providers and other third parties that support the operation, security, communications, payment verification, and analytics of the Services.

Notice at Collection

This summary is provided at or before the point at which Glyyd collects personal information. It describes the categories of personal information we collect, the purposes for which we use them, whether we sell or share them, and how long we retain them.

Category collectedPurpose(s)Sold or shared?Retention
Account, login, and contact informationCreate and secure accounts, authenticate users, communicate with you, and provide the Services.NoActive account + 30-day cooling-off, then deleted.
Profile and role/organization information (incl. date of birth)Manage profiles, permissions, recruiting access, and age/authorization verification.NoActive account + 30-day cooling-off, then deleted.
Athlete performance / telemetry and boat GPS dataDeliver athlete analytics and platform functionality; longitudinal performance analysis.NoWhile account/coaching active; anonymized on deletion (max period under review).
Recruiting selections and authorizationsEnable authorized private sharing of athlete information with selected colleges/universities, including My Schools interest lists.NoDuration of the active account or applicable recruiting relationship
Consent records, support records, and audit/activity logsDocument consents and authorizations, respond to support, maintain security and audit trails.NoConsents: account + 3 yrs; logs: 2 yrs; see Section 11.
Sensitive personal information (account credentials, precise geolocation, information about minors where applicable, sensor-derived motion data)Provide the Services, secure accounts, verify authorization, and prevent fraud. Not used for targeted or cross-context behavioral advertising, and not used to limit our offering of the Services. Consumers have the right to limit use of sensitive personal information to purposes necessary to provide the Services. See Section 4 for more information.NoPer the applicable category in Section 11.
Device and usage informationOperate, secure, and improve service reliability and performance.NoDiagnostics: 7–90 days; see Section 11.

Glyyd does not sell personal information and does not share personal information for cross-context behavioral advertising.

5. How Personal Information Is Used

Glyyd uses personal information to provide and operate the Services, create and secure accounts, deliver athlete analytics, manage permissions and recruiting access, process transactions, communicate with users, respond to support requests, maintain logs, and improve service reliability and security.

Glyyd may also use personal information to verify age and authorization status, administer minor-account workflows, document consents and attestations, enforce platform rules, comply with contracts and legal obligations, and create de-identified or aggregated information for product improvement and business planning.

Glyyd does not use school-sourced education records to create recruiting recommendations, rankings, or similar inferences unless authorized by the relevant institution, the applicable user, or applicable law.

6. How Personal Information Is Shared

Glyyd may share personal information with service providers that support hosting, infrastructure, authentication, communications, analytics, logging, payment processing, customer support, and security, subject to contractual restrictions and data-protection obligations.

Glyyd may share athlete information with selected colleges or universities when that sharing is directed or authorized through the Services by the athlete, a parent or guardian acting for a minor athlete, or another person or organization with authority to make that sharing available through the platform.

Glyyd may also disclose information to schools, clubs, parents or guardians, professional advisers, counterparties in a corporate transaction, regulators, or law enforcement where necessary for the Services, to comply with law, or to protect rights, safety, and security.

Glyyd does not sell personal information and does not share personal information for cross-context behavioral advertising. California consumers have the right to opt out of sale or sharing at any time. To exercise this right, visit our Do Not Sell or Share My Personal Information page or submit a request to privacy@glyyd.com.

7. FERPA and School-Sourced Records

FERPA applies to education records that are directly related to a student and maintained by an educational agency or institution or by a party acting for that agency or institution.

When Glyyd receives student-athlete information from a FERPA-covered institution or from a party acting on that institution’s behalf, and that information constitutes education records or personally identifiable information from education records, Glyyd processes that information only for institutional purposes authorized by the institution and under the institution’s direct control.

Requests to inspect, review, amend, or challenge FERPA-covered records must generally be directed to the relevant educational institution. Glyyd may assist the institution in responding where appropriate and authorized.

8. Rowing Clubs and Non-Institutional Uploads

Rowing clubs that use the Services are generally treated as non-school organizations unless Glyyd has a separate written agreement establishing a different role. Glyyd does not assume that a rowing club is a FERPA-covered institution merely because it uploads athlete information to the Services.

A club or other non-institutional uploader is responsible for obtaining any permissions, notices, consents, or other rights on which it relies before providing athlete information to Glyyd or making athlete information available to coaches through the Services.

10. Cookies and Similar Technologies

Glyyd uses cookies and similar technologies to operate, secure, and improve the Services. The categories below describe the types of technologies we use, why we use them, and how long they persist. We do not use cookies or similar technologies for targeted advertising or cross-context behavioral advertising.

CategoryPurposeExamples / sourceRetention
Strictly necessary/essentialEnable core platform functions, keep you signed in, maintain session integrity, and help protect against fraud, abuse, and security threats. These cannot be switched off through our preference tool.Authentication and session cookies (e.g., Supabase Auth); edge security and WAF (e.g., Cloudflare).Session cookies expire when you close your browser. Persistent essential cookies persist for up to 12 months or until manually deleted by the user, whichever comes first.
FunctionalRemember your settings and preferences to improve and personalize your experience.No functional cookies are collected or used.No functional cookies are collected or used.
Analytics/performanceUnderstand aggregate, privacy-friendly usage to improve reliability and performance.Plausible Analytics (sets no cookies and uses no persistent identifiers or stored raw IP addresses).Not applicable; no cookies are set for analytics.

Managing your preferences. Where required by law, Glyyd presents choices for non-essential cookies and similar technologies through a consent management tool that you can access at any time. You can also control or delete cookies through your browser settings; if you block essential cookies, parts of the Services may not function. For the retention of any personal information associated with these technologies, see Section 11 (Data Retention).

Do Not Track. Some web browsers offer a "Do Not Track" (DNT) setting that signals a preference not to have your online activity tracked. There is no common industry standard for how online services should respond to DNT signals. Because Glyyd does not track users across third-party websites or services and does not engage in cross-context behavioral advertising, Glyyd does not take any separate action in response to DNT signals or similar mechanisms.

Do Not Sell or Share My Personal Information. Glyyd does not sell personal information as defined by California Civil Code Section 1798.140(ad) and does not share personal information for cross-context behavioral advertising as defined by Section 1798.140(ah). California consumers may submit a request to limit use of sensitive personal information or opt out of sale or sharing by visiting Do Not Sell or Share My Personal Information or contacting privacy@glyyd.com.

Tracking by other parties. Glyyd does not authorize third parties to collect personal information about your online activities over time and across different websites or online services when you use the Services. Glyyd's analytics are configured to collect only aggregated, privacy-friendly usage information.

11. Data Retention

Glyyd retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Notice, to comply with contractual and legal obligations, to resolve disputes, and to enforce agreements.

The table below sets out the retention period, or the criteria used to determine it, for each category of personal information. When information is no longer needed, Glyyd deletes, anonymizes, or de-identifies it using reasonable technical and organizational measures. FERPA-covered institutional data is retained only as permitted by the relevant institutional agreement and applicable law.

Category of Personal InformationRetention Period (or criteria)
Account, login, and authentication information (including account credentials)Authentication and session tokens expire automatically at the end of each session. Account records are retained for the duration of the active account plus a 30-day cooling-off period, after which they are deleted.
Profile and contact information (name, email, date of birth, school or organization, role, parent/guardian contact details)Duration of the active account plus a 30-day cooling-off period, then hard-deleted.
Athlete performance and telemetry data (stroke, power, boat and crew data, session data) and boat GPS/track dataRetained while the account and coaching relationship remain active plus 2 years after account deletion or last user activity, whichever comes first. On account deletion, direct identifiers are removed and the data is anonymized.
Crew name and athlete identifierDuration of consent; removed from future collection on consent withdrawal or account deletion.
Recruiting selections and sharing authorizationsDuration of the active account or recruiting relationship.
Consent records and upload consent attestationsDuration of the account plus 3 years following deletion, retained in anonymized form (timestamps without identifiers).
Privacy / data subject rights request records3 years from the date of the request.
Breach notification records3 years from the notification date.
Activity and audit logs (records of who accessed what data)2 years (baseline; subject to ongoing FERPA review).
CARA session records (where applicable to NCAA institutions)Duration of the athletic career plus 1 year.
Error monitoring and diagnostic dataApplication error events 90 days; session replays 30 days; server function logs 7 days (provider defaults).
Data export filesNot stored on Glyyd's servers; generated and delivered only at the time of a request.
Marketing and prospect contact data (CRM)Until opt-out, or until a periodic review determines there is no continued business need.
Website analyticsAggregated, privacy-friendly analytics collected without cookies, persistent identifiers, or stored raw IP addresses; retention is managed by the analytics provider.

When information is no longer needed, Glyyd deletes, anonymizes, or de-identifies it using reasonable technical and organizational measures.

When you request account deletion, there is a 30-day recovery period before your data is permanently deleted. This gives you time to change your mind or recover from accidental deletion requests. During this period, your data is marked for deletion and is not used for any new purposes. You can cancel the deletion request at any time within the 30-day window.

12. Privacy Rights and Requests

Subject to applicable law and exceptions, individuals may have rights to request access, correction, deletion, portability, objection, withdrawal of consent, or limitation of certain processing activities.

Glyyd will not discriminate or retaliate against you for exercising any of your privacy rights. Glyyd will not deny you the Services, charge you a different price or rate, or provide you a different level or quality of the Services because you exercised your rights, except where a difference is permitted by law and is reasonably related to the value provided to Glyyd by your data. Glyyd will not retaliate against any employee, applicant, or independent contractor for exercising their rights under the CCPA.

Glyyd may verify the identity or authority of a requestor before acting on a request, including by using existing account authentication methods or requesting additional information where reasonably necessary. California regulations require reasonable verification procedures and prohibit charging a fee merely to verify a consumer privacy request.

If a request relates to FERPA-covered education records maintained by or for an educational institution, the request may need to be directed to that institution rather than handled solely by Glyyd.

Privacy requests may be submitted through our data subject request form or sent to privacy@glyyd.com.

13. De-Identified and Aggregated Information

Glyyd may create and use de-identified or aggregated information for analytics, product development, research, security, and business planning. When Glyyd de-identifies data, Glyyd takes steps designed to remove direct identifiers and reduce the likelihood of re-identification in light of available technology and the context of processing.

Glyyd does not attempt to re-identify de-identified data except as permitted by law for testing, security, or compliance purposes.

14. Regional Privacy Notices

California

For California residents, Glyyd provides the notices and rights required by the CCPA as amended by the CPRA, including rights to know, delete, correct, opt-out of sale or sharing, limit use of sensitive personal information, and obtain information about the categories of personal information collected, used, disclosed, and retained, subject to applicable exceptions. Glyyd does not discriminate against California consumers who exercise their privacy rights.

Glyyd does not sell personal information and does not share personal information for cross-context behavioral advertising. Glyyd may disclose personal information to service providers, contractors, and other recipients for limited business purposes subject to appropriate contractual restrictions.

EEA and United Kingdom

For individuals in the EEA and United Kingdom, Glyyd may process personal data on the basis of contract performance, legitimate interests, consent, and other lawful bases recognized by applicable law. Glyyd may transfer data to the United States using an appropriate transfer mechanism where required, such as Standard Contractual Clauses or another valid transfer tool.

Canada

For individuals in Canada, Glyyd may process personal information in accordance with PIPEDA and applicable provincial privacy laws, including British Columbia and Alberta private-sector privacy laws and Quebec requirements where applicable.

15. Changes to This Privacy Notice

Glyyd may update this Privacy Notice from time to time to reflect changes in the Services, legal requirements, or operational practices. If Glyyd makes material changes, Glyyd will update the effective date at the top of the Privacy Notice and provide notice through the Services or by other appropriate means as required by applicable law. The revision history table is for transparency only and does not limit Glyyd’s right to make future updates. For clarity, the version in effect is the most recently posted Privacy Notice with the latest effective date. For material changes that affect how Glyyd processes sensitive personal information or minor data, Glyyd will provide advance notice and obtain renewed consent where required by law.

16. Contact Information

Questions about this Privacy Notice or privacy requests may be sent to privacy@glyyd.com.

Revision History

This table tracks material versions of the Privacy Notice. The effective date at the top of the notice should match the most recent revision date for the public version.

DateSummary of ChangesRevision Notes
June 17, 2026Initial public release of the Glyyd Privacy Notice.Aligned notice to current product and California CPRA disclosures.
June 22, 2026Updated recruiting-access language to match current implementation.Current revision for launch-state accuracy.
July 8, 2026Update sensitive personal information processing for California users, and data retention periodsAligned notice to Glyyd’s current state functionality.