Legal

Privacy Policy

Last updated: April 20, 2026

Rally Sports Management (“Rally,” “we,” or “us”) builds software for sports venues, clubs, coaches, and athletes. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to rallyhq.co, app.rallyhq.co, and all Rally apps and services (the “Service”).

1. Information we collect

We collect three kinds of information:

  • Account information you provide directly — name, email, phone number, password hash, organization name, and role. Venues and teams also provide business details such as address, timezone, and billing contacts.
  • Content you upload — rosters, schedules, bookings, waivers, documents, photos, messages, trainer profiles, and payment-method details. For card processing, card numbers are sent directly to Stripe and never touch our servers; we store only Stripe customer, subscription, and payment IDs plus last-four/brand metadata.
  • Usage data — device and browser information, IP address, pages viewed, actions taken, and timestamps, which we use to keep the Service running and improve it. We collect this through logs, analytics, and essential cookies.

2. How we use information

  • Provide, secure, and improve the Service.
  • Process payments, dues, and subscription billing through Stripe.
  • Send transactional messages — booking confirmations, RSVP reminders, payment receipts, calendar invites, and password resets — by email through Resend and (if enabled) SMS through Twilio.
  • Detect and prevent fraud, abuse, and violations of our Terms of Service.
  • Respond to support requests and legal process when required.
  • Send occasional product announcements to account admins; you can opt out of non-transactional mail at any time.

We do not sell personal information. We do not use Your Content to train third-party AI models.

3. How we share information

We share information only in these ways:

  • With your organization. When you join a venue, team, or tournament, its admins can see data relevant to your participation (roster entries, bookings, RSVPs, payment status).
  • Service providers that help us run Rally: Stripe (payments), Supabase (database & hosting), Resend (email), Twilio (SMS, optional), and Vercel (hosting). Each processes data only on our instructions.
  • Legal and safety. When required by law, to enforce our Terms, or to protect the rights, property, or safety of Rally, our users, or the public.
  • Business transfers. In the event of a merger, acquisition, or asset sale, user information may be transferred to the successor entity subject to this Policy.

4. Cookies and similar tech

We use essential cookies to keep you signed in, remember your active workspace, and protect your account. We may also use first-party analytics to understand how the Service is used. Most browsers let you control or clear cookies; disabling cookies may prevent you from signing in.

5. Data retention

We retain account and content data for as long as your account is active, or as needed to provide the Service. If you close your account we delete or anonymize personal information within a reasonable period, except where we must keep records for financial, legal, or fraud-prevention reasons (for example, Stripe payment records).

6. Security

Rally uses encryption in transit (TLS) and at rest, row-level access controls, hardened authentication, audit logging, and regular dependency patching. No method of transmission or storage is 100% secure, but we work hard to protect your data and will notify affected users of any confirmed data breach consistent with applicable law.

7. Your rights and choices

You can access, update, export, or delete your account information from within Rally at any time, or by emailing support@rallyhq.co. Depending on where you live — including California (CCPA/CPRA) and the EU/UK (GDPR) — you may also have the right to object to processing, request portability, or lodge a complaint with a supervisory authority. We will verify your identity before fulfilling access or deletion requests.

8. Children’s privacy

Rally is intended for adults (18+) who run venues, teams, or tournaments, or who book services. We do not knowingly collect personal information from children under 13 through accounts created on Rally. Coaches, parents, and guardians may, however, add youth players as roster entries. They are responsible for providing any required parental consent and for the information they enter about minors, consistent with the Children’s Online Privacy Protection Act (COPPA). If you believe we have collected personal information from a child in a way that requires parental consent we have not obtained, contact us and we will delete it.

9. International transfers

Rally is operated from the United States. By using the Service you understand that your information may be processed in the United States and other countries that may have different data protection rules than your own. Where required, we rely on standard contractual clauses or equivalent safeguards.

10. Changes to this Policy

We may update this Policy from time to time. If we make a material change we will notify you through the Service or by email before the change takes effect. The “Last updated” date at the top of this page always reflects the current version.

11. Contact us

Questions, concerns, or requests about your data? Email support@rallyhq.co and we will respond within one business day.