Privacy Policy
1. Who we are and what this covers
ReadLab Sports LLC ("we", "us") makes ReadLab Hoops, a basketball training application for Meta Quest headsets (the "App"), and the ReadLab Hoops customer portal at readlabsports.com (the "Portal"). This policy explains what information the App, the Portal and our website collect, where it comes from, how it is used, who it is shared with, how long it is kept, and the choices and rights you have. It is written to be readable by the people it affects; if any part is unclear, ask us (Section 16). We provide this policy in a form accessible to people with disabilities; contact us for an alternative format.
ReadLab Hoops is sold to Organizations. Players and coaches use the App under their Organization's account. If you are a player or a parent, your Organization decides how ReadLab Hoops is used and is your first point of contact for questions about your information (Section 2).
2. Our role: your Organization and us
For information about players and coaches (names, drill results, practice history), your Organization is the controller: it decides to use ReadLab Hoops, adds members to its roster, and is responsible for obtaining any consents the law requires, including parental consent for children. We act as the Organization's service provider under a written agreement: we handle that information only to provide the service to the Organization, never for our own marketing, and never sell or share it.
For Portal account holders' own account information, and for the technical information the App sends so that we can license, secure and operate the service, we are the business responsible.
3. Information we collect and where it comes from
We collect information from three sources: your Organization (roster and team details), you (what you do in the App and the Portal), and automatically from the headset and your connection. We also receive limited information from Meta's platform when you use multiplayer features. We do not buy information about you from anyone.
3.1 From your Organization
- Roster profile: a display name, your role (player or coach), and optionally a jersey number and an email address. Your Organization chooses what to enter and can use only a first name or nickname.
- Profile PIN: if your Organization turns on PIN locking, a short numeric PIN protects your profile on shared headsets. The PIN is stored encrypted; your Organization's administrators can set, reset and view it so they can help you if you forget it.
- Teams and practice plans: which teams you belong to and which practice plans are assigned to you.
3.2 Created when you use the App
- Drill and session results: for each drill you complete — which drill, difficulty, how long it took, hits and misses, a grade, and drill-specific results (for example, how many zones you reached or whether you read a screen correctly). Results are recorded against your profile. Nothing is sent about a drill while it is in progress; results are uploaded when a session ends.
- Profile activity: when a profile is selected on a headset, and whether a PIN was used.
- App settings and progress: settings such as court size and passthrough, and your progress through the in-app tutorial.
- Performance summaries: per-session summaries of the headset's frame rate and battery level, used to keep the App running well on your hardware.
The App uses your headset's hand tracking and position to run drills. That tracking data is processed on the headset and is not transmitted to us or stored, except as the drill results described above. The App does not record video or images.
3.3 Voice features
- Spoken coaching: the App's coaching lines are turned into speech using Meta's Voice SDK. Only the script text is sent for synthesis; nothing about you is included.
- Voice commands: if the voice-command microphone is enabled in Settings, short audio clips of your voice are sent to Meta's Voice SDK (Wit.ai) to recognize the command. We do not receive or store these recordings. You can turn the voice-command microphone off in Settings at any time; the App works fully without it.
3.4 Multiplayer
When you use multiplayer features, your position, gestures and voice are transmitted to the other players in your session through Normcore, a real-time networking service operated by Normal VR. This data passes through Normcore's servers to reach the other players and is not recorded by us.
3.5 From Meta's platform
The App runs on Meta Quest and uses Meta's platform services. On every launch the App confirms with Meta that it is entitled to run. When you use multiplayer features, the App uses your Meta user ID and profile name to show who is in the session, to set your presence, and to let you invite others or join by invitation and deep link. This information is used inside the App and by Meta; we do not store your Meta user ID or Meta profile on our servers. Meta's own privacy policy governs Meta's handling of your account.
3.6 Automatically, from the headset and your connection
Each time the App starts it sends us technical information about the headset and the installation so that we can license the App to your Organization, keep it secure, detect misuse (including unauthorized copies), and support you: a device identifier and an installation identifier; the headset model, operating system and build details; the App version and how it was installed; battery level, free storage and network type; the device's clock and time zone; and counts of any results waiting to be uploaded. When the App or the Portal contacts our servers we also record the connection's IP address and the approximate (city-level) location derived from it, the date and time, and which version of our service was used.
If the App crashes, a crash report (device model, operating system, App version and technical details of the crash, with no user identifiers) is sent to Unity Cloud Diagnostics, a service operated by Unity Technologies.
This technical information is sent by every copy of the App, including copies that are not signed in to any Organization; we use it to detect and investigate unauthorized distribution of the App.
3.7 Portal accounts
If your Organization gives you a Portal account, we collect your name, email address and role; how you sign in (with Google, with Microsoft, or with a link we email to you — the Portal never uses a password); whether you have set up an authenticator app (the app's secret is held by our sign-in provider and never by us); sign-in records; and an audit log of the actions you take in the Portal (for example, adding, releasing or removing a headset, inviting a colleague, or viewing a member's PIN).
4. Categories under California law
California law asks businesses to describe personal information using set categories. In the 12 months before the effective date, and going forward, we collect the following categories, for the purposes in Section 6, and disclose them only to the service providers in Section 8. We have not sold or shared personal information in any category.
| Category | Examples in ReadLab Hoops | Source | Retention (Section 9) |
|---|---|---|---|
| Identifiers | display name, email (if entered), Portal account name and email, device and installation identifiers, IP address | Organization; you; automatic | Organization data: until the Organization requests deletion. Technical records: for security and licensing purposes as described in Section 9 |
| Personal information under Cal. Civ. Code §1798.80(e) | name; email | Organization; you | as above |
| Protected classifications | none collected. Players are often under 16; we do not collect age or date of birth | — | — |
| Commercial information | the Organization's subscription and licensing records (about the Organization, not individuals) | Organization | duration of the relationship and as required by law |
| Internet or other network activity | App usage records (drill results, sessions, settings), Portal activity and audit log | you; automatic | as for Organization data |
| Geolocation data | approximate location derived from IP address (not precise geolocation) | automatic | technical-record retention |
| Audio, electronic, visual or similar information | voice-command audio processed by Meta's Voice SDK and not retained by us; multiplayer voice relayed by Normcore and not retained by us | you | not retained |
| Professional or employment information | a coach's or administrator's role at the Organization | Organization | as for Organization data |
| Education information | for school customers, roster membership and drill results may be education records under FERPA | Organization; you | as for Organization data |
| Inferences | drill performance summaries per profile (attempts, best, trend), shown to your Organization; no inferences about characteristics, preferences or behavior beyond the coaching service | derived | as for Organization data |
| Sensitive personal information | Portal sign-in credentials and profile PINs (account access credentials). Used only to secure your account and profile — never to infer characteristics, and not disclosed. We collect no precise geolocation, health, biometric, racial, religious, union, sexual-orientation or communications-content information | Organization; you | as for the account they protect |
5. Information we do not collect
Unless your Organization has enabled an optional feature under Section 3.8, we do not collect dates of birth, home addresses, photographs, precise geolocation, biometric identifiers, consumer health data, advertising identifiers, or free-text messages. We do not show advertising, do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising to students or to build profiles of students for purposes other than the coaching service.
6. How we use information
| Purpose | Information used |
|---|---|
| Provide the App and Portal to your Organization, including coaching feedback, history and assigned practice | Sections 3.1, 3.2, 3.7 |
| License the App to Organizations and their approved headsets, enforce seat limits, and keep the App working offline | Section 3.6 |
| Security, fraud and abuse detection, including detecting unauthorized copies of the App | Section 3.6 |
| Support and troubleshooting | Sections 3.2, 3.6, 3.7 |
| Improve the App using aggregated, de-identified statistics (for example, which drills are most used). We do not attempt to re-identify de-identified data | Section 3.2, aggregated |
| Comply with law, respond to lawful requests, and enforce our agreements | as required |
We do not use information about players to build profiles for any purpose other than the coaching features their Organization has chosen, and we do not make decisions about individuals by automated means that produce legal or similarly significant effects. We do not use sensitive personal information for any purpose other than providing and securing the service.
7. Children, and notice to parents
ReadLab Hoops is used by young athletes under the supervision of their Organization. We design for that: the App needs only a display name to work; it offers a Guest profile that records nothing about a particular person; it collects no date of birth; and it never uses a child's information for advertising, for profiling beyond the coaching service, or for any purpose other than providing the service to the Organization. We do not condition a child's use of the App on providing more information than is reasonably necessary to use it.
7.1 What we collect from children
From a child using the App we collect the roster profile entered by the Organization (Section 3.1), the child's drill results and App activity (Section 3.2), voice-command audio if the Organization has left that feature enabled (processed by Meta's Voice SDK and not retained by us, Section 3.3), multiplayer voice and movement relayed to other players if the Organization uses multiplayer (Section 3.4), and the technical information every headset sends (Section 3.6). We use it only as described in Section 6 and disclose it only to the service providers in Section 8 and to the child's Organization.
7.2 Consent
The Organization is responsible for obtaining any consent the law requires before adding a child to its roster, including verifiable parental consent under the U.S. Children's Online Privacy Protection Act (COPPA) where it applies. Under COPPA, a school may consent on parents' behalf when the App is used for the school's educational purpose; the Organization agrees in its contract with us that it has done so, and we provide this notice to the Organization to pass on to parents. We do not collect personal information directly from children outside the Organization's account.
7.3 Parents' rights
A parent or guardian may review the personal information collected from their child, have it deleted, and refuse to permit any further collection or use. The fastest route is the child's Organization, whose administrators can view, correct and delete a child's profile and results directly in the Portal. You may also contact us (Section 16); we will verify that you are the child's parent or guardian, then act on the request or, where the Organization controls the information, refer it to the Organization and confirm that it has been handled. If we learn that we hold a child's personal information that an Organization was not authorized to provide, we will delete it.
7.4 Operators
The operator that collects and maintains children's personal information through the App is ReadLab Sports LLC, email privacy@readlabsports.com. The service providers in Section 8 process information on our behalf.
We do not sell or share the personal information of anyone under 16, and we have no actual knowledge of doing so.
8. How information is shared
- With your Organization. Your roster profile, results and activity are visible to your Organization's administrators and coaches in the Portal and on its headsets. That is the purpose of the service.
- With service providers that help us run ReadLab Hoops, who may use the information only to provide their service to us and are bound by contract to protect it:
| Provider | What they do | Information involved |
|---|---|---|
| Google Cloud and Firebase (Google LLC) | Hosting, storage, databases, analytics, encryption keys, Portal sign-in | All information in Section 3, stored in the United States (Section 12) |
| Neon (Databricks, Inc.) | Our operational database | Sections 3.1, 3.6, 3.7 and drill results |
| Microsoft Corporation | Portal sign-in, only if you choose to sign in with Microsoft | Your name and email address (Section 3.7) |
| Unity Technologies | Crash reporting | Crash reports (Section 3.6), no user identifiers |
| Normal VR (Normcore) | Real-time multiplayer networking | Position, gestures and voice in transit (Section 3.4) |
| Meta Platforms, Inc. | Headset platform, App entitlement, multiplayer presence and invitations, Voice SDK speech and voice commands | Sections 3.3 and 3.5 |
- For legal reasons: when required by law, legal process, or to protect the rights, safety and security of our users, our Organizations or us.
- In a business transfer: if we are involved in a merger, acquisition or sale of assets, information may be transferred as part of that transaction, subject to this policy.
We do not sell personal information, we have not done so in the preceding 12 months, and we do not share personal information for cross-context behavioral advertising. We do not disclose personal information to third parties for their own direct-marketing purposes (California "Shine the Light").
9. How long we keep information
Organization information (rosters, results, history, teams, plans, Portal accounts) is kept for as long as the Organization's account is active, and afterwards so that the Organization can return to its history if it comes back to ReadLab Hoops. An Organization can ask us to delete its information at any time: we first provide the Organization with an export, hold the information for 30 days in case the request was made in error, then permanently delete it. Individual members' information can be removed at any time by the Organization; the member's name and contact details are erased, and their results are kept only in a form that no longer identifies them.
Portal accounts of people who leave. When a person is removed from an Organization's Portal, they lose access at once. We keep their email address and sign-in account for 30 days, so that a removal made by mistake or without authority can be looked into, and then erase them: the sign-in account is deleted and the email address is replaced, and our audit records keep only an anonymous reference to what the person did. A removed person may ask us to erase this sooner (Section 10.3).
Technical information (Section 3.6) is kept for the security and licensing purposes described in Section 6; the criteria for keeping it are the need to identify headsets licensed to Organizations and to detect misuse over time. Audit logs are kept to demonstrate who did what with your information. Backup copies are kept for a limited period on their own schedule and cannot be altered before that period ends. Where the law of your state or region sets shorter limits, we apply them.
10. Your rights and choices
10.1 Choices in the App and Portal
- Use the Guest profile to play without a personal record.
- Turn the voice-command microphone off in Settings.
- Sign the headset out of your Organization in Settings.
- Organization administrators can view, correct, export and delete any member's information in the Portal.
10.2 Your privacy rights
Depending on where you live, you may have the right to: know what personal information we collect, use and disclose and receive a copy in a portable form; correct inaccurate information; delete your information; opt out of the sale or sharing of personal information and of targeted advertising (we do none of these); limit the use of sensitive personal information (we use it only to provide and secure the service); and not be discriminated against for exercising these rights. We will not deny you service, charge a different price or provide a different level of service because you exercised a right.
10.3 How to make a request
Because your Organization controls roster and results information, requests about that information are best made to your Organization, which can act on them directly in the Portal. You may also submit a request to us by email at privacy@readlabsports.com. We will confirm receipt within 10 business days and respond within 45 days; if we need up to 45 more days we will tell you why. There is no charge unless requests are excessive.
Verification. To protect your information, we match the details in your request against what we hold (for Portal users, a message from your account email; for players, confirmation through your Organization; for parents, confirmation that you are the child's parent or guardian). We will not verify by asking for more personal information than necessary. Authorized agents may submit requests with your signed permission; we may ask you to confirm directly. Appeals. If we decline a request, you may appeal by replying to our decision; we will respond within 45 days with the reasons, and you may then contact your state's Attorney General.
11. How we protect information
Information is encrypted in transit and at rest. Profile PINs are stored encrypted and, on headsets, only as one-way hashes. Access to information is limited to staff who need it, protected by multi-factor authentication, and recorded in an audit log. Portal owners and administrators must confirm their sign-in with an authenticator app before they can make changes to their Organization's headsets or people. Backups are stored separately and cannot be altered or deleted before their retention period ends. On headsets, information is stored in the App's private storage. No method of transmission or storage is completely secure; if we learn of a breach affecting your information, we will notify affected Organizations and individuals, and authorities where required, without undue delay and within the time the law requires.
12. Where information is stored
Information is stored and processed in the United States. If we offer service to Organizations in other regions, we will store their members' information in that region and will not transfer it outside that region except under safeguards recognized by law. Our service providers in Section 8 are contractually bound to equivalent protections.
13. Cookies, tracking signals and "Do Not Track"
The Portal and our website use only the cookies and similar browser storage that are strictly necessary to sign you in and keep the site secure. We do not use advertising or third-party analytics cookies or trackers, and no third party collects personal information about your online activities over time and across websites through our services. Because we do not sell or share personal information or track you across sites, there is nothing for a "Do Not Track" browser setting or a Global Privacy Control signal to opt you out of; we treat both as confirmation of the choice we already apply to everyone.
14. Changes to this policy
We review this policy at least once a year and whenever the App, the Portal, our service providers or the law change. We post changes here with a new version number and effective date, keep previous versions available, and notify Organizations of material changes through the Portal or by email before they take effect.
16. How to contact us
ReadLab Sports LLC
Privacy requests: privacy@readlabsports.com
Security issues: security@readlabsports.com