Aligen Sports OS Privacy Notice
This notice explains how Sports OS handles data for academies, staff, athletes, guardians, and people who communicate with an academy.
Last updated: August 29, 2026
1. Roles and academy responsibility
The academy or sports organization decides which operational data to enter and why. It is responsible for collecting that data lawfully, giving any required notices, and managing staff access. ALIGEN LTD provides Sports OS and processes that customer data to deliver and secure the service.
2. Data Sports OS can store
The exact data depends on the features the academy uses.
- Organization, plan, owner, staff, coach, role, invite, and account identifiers.
- Athlete or member name, phone, email, date of birth, sport, level, team, tags, preferences, guardian details, and emergency-contact details.
- Programs, teams, sessions, bookings, attendance, memberships, freezes, renewals, notifications, and operational notes.
- WhatsApp and Instagram account identifiers, conversations, message content, comments, delivery state, and provider event identifiers.
- AI inputs, outputs, proposal state, model/provider audit fields, usage, cost, and trace identifiers when AI features are used.
- Security, audit, job, webhook, error, and first-party product analytics events.
3. Athletes, minors, and guardians
Sports OS can store dates of birth, guardian contact details, and emergency contacts, so an academy may use it for minors. The academy must decide whether and how it may collect a minor's data and involve a parent or guardian. Sports OS does not replace the academy's safeguarding or consent process. Authorized academy staff can access this data for operations, and access or deletion requests should normally be made through the academy or support@aligen.app.
4. Sensitive and free-text data
Sports OS has emergency-contact fields and free-text notes. Those notes could contain injury, medical, health, or other sensitive information even though there is no dedicated medical-record feature. Academies should enter only what is necessary, restrict staff access, and avoid detailed medical records unless they have an appropriate lawful process. Role and organization boundaries protect application access, but no system can eliminate every security risk.
5. Why data is used
We use data to authenticate users; operate organizations, teams, sessions, attendance, memberships, and support; connect selected messaging channels; generate user-requested AI assistance; prevent duplicate or abusive activity; diagnose failures; secure the service; and understand first-party acquisition and activation. We do not sell customer data.
6. Providers and international processing
Current or intentionally supported providers are Supabase (authentication and database), Vercel (web hosting), Render (API and worker hosting), Meta (WhatsApp and Instagram), OpenAI and Anthropic (configured AI processing), Google (sign-in and optional website analytics), Resend (configured transactional email), Sentry (configured error monitoring), and Stripe only when an operator enables a hosted billing workflow. Providers may process data in other countries under their own infrastructure and contractual terms. The public trial does not collect a card or charge automatically.
7. Analytics, logs, and retention
First-party growth analytics use a random identifier, page/session data, referrer domain, and allowlisted UTM values; they do not intentionally store raw IP addresses, browser fingerprints, or form contents. Anonymous growth events are purged after 180 days. Separately, Google Analytics 4 is optional and is not loaded until you choose Accept in Analytics settings. If accepted, it may process page URLs, referrer domains, device and browser types, approximate location, and general events such as page views, scrolls, outbound clicks, and file downloads. Form interactions and internal site-search measurement are disabled; we do not send athlete, guardian, message, name, email, phone, or free-form data; and advertising storage and personalization remain disabled. You can withdraw consent at any time using Analytics settings. Customer operational data remains while the account needs the service or as required for security, disputes, backup, or legal obligations. Deletion from active systems may not immediately remove protected backups.
8. Access, correction, deletion, and security
Users should first ask their academy to correct, export, restrict, or delete academy-controlled records. The academy or user may contact support@aligen.app when product assistance is needed. We use tenant boundaries, role-based access, encryption in transit, restricted secrets, audit records, and provider controls. Never send passwords, access tokens, or unnecessary sensitive data to support.
9. Changes and contact
We may update this notice as Sports OS or its providers change. Material updates will be published here. Privacy and support contact: support@aligen.app. This notice is provided in Arabic and English with the same substantive scope and requires professional legal review before reliance for a particular jurisdiction.