Privacy Policy

ReadLab Sports LLC · Team Edition — ReadLab Hoops for Teams on Meta Quest, the ReadLab Hoops customer portal at readlabsports.com, and this website. The Public Edition sold through the Meta Horizon Store has its own policy.
Effective date: September 16, 2026 · Version 1.0 · Previous versions: none · ReadLab Hoops is currently offered in the United States.
Summary (notice at collection). ReadLab Hoops is sold to schools, clubs and academies ("Organizations"). Your Organization adds you to its roster and controls your information; we process it to run the service for them. We collect a roster profile (a display name and optional details your Organization enters), your drill results and practice history, App settings, and technical information about the headset and its connection, including its IP address, so we can license and secure the App. Voice commands, if you enable them, are recognized by Meta's Voice SDK. Multiplayer voice and movement pass through Normcore to reach other players. We keep your Organization's information until the Organization asks us to delete it, and technical records for security purposes. We do not sell personal information, do not share it for advertising, and do not use it to profile children. Your rights and how to exercise them are in Section 10.

1. Who we are and what this covers

ReadLab Sports LLC ("we", "us") makes ReadLab Hoops, a basketball training application for Meta Quest headsets (the "App"), and the ReadLab Hoops customer portal at readlabsports.com (the "Portal"). This policy explains what information the App, the Portal and our website collect, where it comes from, how it is used, who it is shared with, how long it is kept, and the choices and rights you have. It is written to be readable by the people it affects; if any part is unclear, ask us (Section 16). We provide this policy in a form accessible to people with disabilities; contact us for an alternative format.

ReadLab Hoops is sold to Organizations. Players and coaches use the App under their Organization's account. If you are a player or a parent, your Organization decides how ReadLab Hoops is used and is your first point of contact for questions about your information (Section 2).

2. Our role: your Organization and us

For information about players and coaches (names, drill results, practice history), your Organization is the controller: it decides to use ReadLab Hoops, adds members to its roster, and is responsible for obtaining any consents the law requires, including parental consent for children. We act as the Organization's service provider under a written agreement: we handle that information only to provide the service to the Organization, never for our own marketing, and never sell or share it.

For Portal account holders' own account information, and for the technical information the App sends so that we can license, secure and operate the service, we are the business responsible.

3. Information we collect and where it comes from

We collect information from three sources: your Organization (roster and team details), you (what you do in the App and the Portal), and automatically from the headset and your connection. We also receive limited information from Meta's platform when you use multiplayer features. We do not buy information about you from anyone.

3.1 From your Organization

3.2 Created when you use the App

The App uses your headset's hand tracking and position to run drills. That tracking data is processed on the headset and is not transmitted to us or stored, except as the drill results described above. The App does not record video or images.

3.3 Voice features

3.4 Multiplayer

When you use multiplayer features, your position, gestures and voice are transmitted to the other players in your session through Normcore, a real-time networking service operated by Normal VR. This data passes through Normcore's servers to reach the other players and is not recorded by us.

3.5 From Meta's platform

The App runs on Meta Quest and uses Meta's platform services. On every launch the App confirms with Meta that it is entitled to run. When you use multiplayer features, the App uses your Meta user ID and profile name to show who is in the session, to set your presence, and to let you invite others or join by invitation and deep link. This information is used inside the App and by Meta; we do not store your Meta user ID or Meta profile on our servers. Meta's own privacy policy governs Meta's handling of your account.

3.6 Automatically, from the headset and your connection

Each time the App starts it sends us technical information about the headset and the installation so that we can license the App to your Organization, keep it secure, detect misuse (including unauthorized copies), and support you: a device identifier and an installation identifier; the headset model, operating system and build details; the App version and how it was installed; battery level, free storage and network type; the device's clock and time zone; and counts of any results waiting to be uploaded. When the App or the Portal contacts our servers we also record the connection's IP address and the approximate (city-level) location derived from it, the date and time, and which version of our service was used.

If the App crashes, a crash report (device model, operating system, App version and technical details of the crash, with no user identifiers) is sent to Unity Cloud Diagnostics, a service operated by Unity Technologies.

This technical information is sent by every copy of the App, including copies that are not signed in to any Organization; we use it to detect and investigate unauthorized distribution of the App.

3.7 Portal accounts

If your Organization gives you a Portal account, we collect your name, email address and role; how you sign in (with Google, with Microsoft, or with a link we email to you — the Portal never uses a password); whether you have set up an authenticator app (the app's secret is held by our sign-in provider and never by us); sign-in records; and an audit log of the actions you take in the Portal (for example, adding, releasing or removing a headset, inviting a colleague, or viewing a member's PIN).

4. Categories under California law

California law asks businesses to describe personal information using set categories. In the 12 months before the effective date, and going forward, we collect the following categories, for the purposes in Section 6, and disclose them only to the service providers in Section 8. We have not sold or shared personal information in any category.

CategoryExamples in ReadLab HoopsSourceRetention (Section 9)
Identifiersdisplay name, email (if entered), Portal account name and email, device and installation identifiers, IP addressOrganization; you; automaticOrganization data: until the Organization requests deletion. Technical records: for security and licensing purposes as described in Section 9
Personal information under Cal. Civ. Code §1798.80(e)name; emailOrganization; youas above
Protected classificationsnone collected. Players are often under 16; we do not collect age or date of birth
Commercial informationthe Organization's subscription and licensing records (about the Organization, not individuals)Organizationduration of the relationship and as required by law
Internet or other network activityApp usage records (drill results, sessions, settings), Portal activity and audit logyou; automaticas for Organization data
Geolocation dataapproximate location derived from IP address (not precise geolocation)automatictechnical-record retention
Audio, electronic, visual or similar informationvoice-command audio processed by Meta's Voice SDK and not retained by us; multiplayer voice relayed by Normcore and not retained by usyounot retained
Professional or employment informationa coach's or administrator's role at the OrganizationOrganizationas for Organization data
Education informationfor school customers, roster membership and drill results may be education records under FERPAOrganization; youas for Organization data
Inferencesdrill performance summaries per profile (attempts, best, trend), shown to your Organization; no inferences about characteristics, preferences or behavior beyond the coaching servicederivedas for Organization data
Sensitive personal informationPortal sign-in credentials and profile PINs (account access credentials). Used only to secure your account and profile — never to infer characteristics, and not disclosed. We collect no precise geolocation, health, biometric, racial, religious, union, sexual-orientation or communications-content informationOrganization; youas for the account they protect

5. Information we do not collect

Unless your Organization has enabled an optional feature under Section 3.8, we do not collect dates of birth, home addresses, photographs, precise geolocation, biometric identifiers, consumer health data, advertising identifiers, or free-text messages. We do not show advertising, do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising to students or to build profiles of students for purposes other than the coaching service.

6. How we use information

PurposeInformation used
Provide the App and Portal to your Organization, including coaching feedback, history and assigned practiceSections 3.1, 3.2, 3.7
License the App to Organizations and their approved headsets, enforce seat limits, and keep the App working offlineSection 3.6
Security, fraud and abuse detection, including detecting unauthorized copies of the AppSection 3.6
Support and troubleshootingSections 3.2, 3.6, 3.7
Improve the App using aggregated, de-identified statistics (for example, which drills are most used). We do not attempt to re-identify de-identified dataSection 3.2, aggregated
Comply with law, respond to lawful requests, and enforce our agreementsas required

We do not use information about players to build profiles for any purpose other than the coaching features their Organization has chosen, and we do not make decisions about individuals by automated means that produce legal or similarly significant effects. We do not use sensitive personal information for any purpose other than providing and securing the service.

7. Children, and notice to parents

ReadLab Hoops is used by young athletes under the supervision of their Organization. We design for that: the App needs only a display name to work; it offers a Guest profile that records nothing about a particular person; it collects no date of birth; and it never uses a child's information for advertising, for profiling beyond the coaching service, or for any purpose other than providing the service to the Organization. We do not condition a child's use of the App on providing more information than is reasonably necessary to use it.

7.1 What we collect from children

From a child using the App we collect the roster profile entered by the Organization (Section 3.1), the child's drill results and App activity (Section 3.2), voice-command audio if the Organization has left that feature enabled (processed by Meta's Voice SDK and not retained by us, Section 3.3), multiplayer voice and movement relayed to other players if the Organization uses multiplayer (Section 3.4), and the technical information every headset sends (Section 3.6). We use it only as described in Section 6 and disclose it only to the service providers in Section 8 and to the child's Organization.

7.2 Consent

The Organization is responsible for obtaining any consent the law requires before adding a child to its roster, including verifiable parental consent under the U.S. Children's Online Privacy Protection Act (COPPA) where it applies. Under COPPA, a school may consent on parents' behalf when the App is used for the school's educational purpose; the Organization agrees in its contract with us that it has done so, and we provide this notice to the Organization to pass on to parents. We do not collect personal information directly from children outside the Organization's account.

7.3 Parents' rights

A parent or guardian may review the personal information collected from their child, have it deleted, and refuse to permit any further collection or use. The fastest route is the child's Organization, whose administrators can view, correct and delete a child's profile and results directly in the Portal. You may also contact us (Section 16); we will verify that you are the child's parent or guardian, then act on the request or, where the Organization controls the information, refer it to the Organization and confirm that it has been handled. If we learn that we hold a child's personal information that an Organization was not authorized to provide, we will delete it.

7.4 Operators

The operator that collects and maintains children's personal information through the App is ReadLab Sports LLC, email privacy@readlabsports.com. The service providers in Section 8 process information on our behalf.

We do not sell or share the personal information of anyone under 16, and we have no actual knowledge of doing so.

8. How information is shared

ProviderWhat they doInformation involved
Google Cloud and Firebase (Google LLC)Hosting, storage, databases, analytics, encryption keys, Portal sign-inAll information in Section 3, stored in the United States (Section 12)
Neon (Databricks, Inc.)Our operational databaseSections 3.1, 3.6, 3.7 and drill results
Microsoft CorporationPortal sign-in, only if you choose to sign in with MicrosoftYour name and email address (Section 3.7)
Unity TechnologiesCrash reportingCrash reports (Section 3.6), no user identifiers
Normal VR (Normcore)Real-time multiplayer networkingPosition, gestures and voice in transit (Section 3.4)
Meta Platforms, Inc.Headset platform, App entitlement, multiplayer presence and invitations, Voice SDK speech and voice commandsSections 3.3 and 3.5

We do not sell personal information, we have not done so in the preceding 12 months, and we do not share personal information for cross-context behavioral advertising. We do not disclose personal information to third parties for their own direct-marketing purposes (California "Shine the Light").

9. How long we keep information

Organization information (rosters, results, history, teams, plans, Portal accounts) is kept for as long as the Organization's account is active, and afterwards so that the Organization can return to its history if it comes back to ReadLab Hoops. An Organization can ask us to delete its information at any time: we first provide the Organization with an export, hold the information for 30 days in case the request was made in error, then permanently delete it. Individual members' information can be removed at any time by the Organization; the member's name and contact details are erased, and their results are kept only in a form that no longer identifies them.

Portal accounts of people who leave. When a person is removed from an Organization's Portal, they lose access at once. We keep their email address and sign-in account for 30 days, so that a removal made by mistake or without authority can be looked into, and then erase them: the sign-in account is deleted and the email address is replaced, and our audit records keep only an anonymous reference to what the person did. A removed person may ask us to erase this sooner (Section 10.3).

Technical information (Section 3.6) is kept for the security and licensing purposes described in Section 6; the criteria for keeping it are the need to identify headsets licensed to Organizations and to detect misuse over time. Audit logs are kept to demonstrate who did what with your information. Backup copies are kept for a limited period on their own schedule and cannot be altered before that period ends. Where the law of your state or region sets shorter limits, we apply them.

10. Your rights and choices

10.1 Choices in the App and Portal

10.2 Your privacy rights

Depending on where you live, you may have the right to: know what personal information we collect, use and disclose and receive a copy in a portable form; correct inaccurate information; delete your information; opt out of the sale or sharing of personal information and of targeted advertising (we do none of these); limit the use of sensitive personal information (we use it only to provide and secure the service); and not be discriminated against for exercising these rights. We will not deny you service, charge a different price or provide a different level of service because you exercised a right.

10.3 How to make a request

Because your Organization controls roster and results information, requests about that information are best made to your Organization, which can act on them directly in the Portal. You may also submit a request to us by email at privacy@readlabsports.com. We will confirm receipt within 10 business days and respond within 45 days; if we need up to 45 more days we will tell you why. There is no charge unless requests are excessive.

Verification. To protect your information, we match the details in your request against what we hold (for Portal users, a message from your account email; for players, confirmation through your Organization; for parents, confirmation that you are the child's parent or guardian). We will not verify by asking for more personal information than necessary. Authorized agents may submit requests with your signed permission; we may ask you to confirm directly. Appeals. If we decline a request, you may appeal by replying to our decision; we will respond within 45 days with the reasons, and you may then contact your state's Attorney General.

11. How we protect information

Information is encrypted in transit and at rest. Profile PINs are stored encrypted and, on headsets, only as one-way hashes. Access to information is limited to staff who need it, protected by multi-factor authentication, and recorded in an audit log. Portal owners and administrators must confirm their sign-in with an authenticator app before they can make changes to their Organization's headsets or people. Backups are stored separately and cannot be altered or deleted before their retention period ends. On headsets, information is stored in the App's private storage. No method of transmission or storage is completely secure; if we learn of a breach affecting your information, we will notify affected Organizations and individuals, and authorities where required, without undue delay and within the time the law requires.

12. Where information is stored

Information is stored and processed in the United States. If we offer service to Organizations in other regions, we will store their members' information in that region and will not transfer it outside that region except under safeguards recognized by law. Our service providers in Section 8 are contractually bound to equivalent protections.

13. Cookies, tracking signals and "Do Not Track"

The Portal and our website use only the cookies and similar browser storage that are strictly necessary to sign you in and keep the site secure. We do not use advertising or third-party analytics cookies or trackers, and no third party collects personal information about your online activities over time and across websites through our services. Because we do not sell or share personal information or track you across sites, there is nothing for a "Do Not Track" browser setting or a Global Privacy Control signal to opt you out of; we treat both as confirmation of the choice we already apply to everyone.

14. Changes to this policy

We review this policy at least once a year and whenever the App, the Portal, our service providers or the law change. We post changes here with a new version number and effective date, keep previous versions available, and notify Organizations of material changes through the Portal or by email before they take effect.

16. How to contact us

ReadLab Sports LLC
Privacy requests: privacy@readlabsports.com
Security issues: security@readlabsports.com