Privacy Policy

Last updated: 2026-05-06

Template — review by counsel required before production use.

These pages are starter content for a youth-sports athletic-injury platform. Real deployment requires customization by a qualified attorney for your jurisdiction, your school district's legal posture, the actual subprocessors you've signed agreements with, and the specific risks of your operation. Atlerts (the software) does not constitute legal advice.

Atlerts is a product of Bridgelines Inc., a Delaware corporation. On this page, “Atlerts” and “the Service” mean the software, and “we”, “us” and “our” mean Bridgelines Inc. — the company that provides it and the party to any agreement with your school.

What we collect

We collect the following categories of information:

  • Account information: name, email, phone, role at the school, hashed password.
  • Athlete demographics: name, date of birth, gender, photo (optional), insurance carrier and policy number.
  • Parent/guardian: contact info, address, emergency contact, pickup-authorized contacts.
  • Pre-participation health: concussion history, allergies, medications, other conditions, signed consent forms, uploaded documents (e.g. physical exam form).
  • Care records: injuries, training-room visits, treatment plans and rehabilitation logs, appointments, concussion return-to-play stage progress, medical clearances.
  • Operational records: sport registrations, audit log entries (who accessed what, when), MFA factors, server logs minimized to non-PHI.

Why we collect it

To provide the Service to your school: to maintain participation eligibility records, to document care delivered by athletic trainers, to keep parents and athletes informed, and to satisfy school athletic association and applicable state-law obligations.

Legal basis (school relationship)

For students enrolled at K-12 schools, your school is the data controller of educational records about students. We are the school's service provider. Records are subject to FERPA. Where the school is a covered entity under HIPAA, we operate as a Business Associate under a signed Business Associate Agreement.

Where federal and state requirements differ, we apply whichever is stricter, as one policy, to every district we serve — including districts whose records are not protected health information in their own hands. See Security and Compliance.

Subprocessors

We rely on the following subprocessors to deliver the Service. Each is bound by a written agreement that prohibits use of your data outside the scope of providing services to us.

  • Supabase (database, authentication, file storage) — United States.
  • Vercel (web hosting) — United States.
  • Resend (transactional email) — United States.
  • Twilio (transactional SMS) — United States.

We will provide thirty (30) days' notice before adding or replacing a subprocessor. The current list is available on request.

How long we keep records

Athlete records are retained for as long as the school directs. After a student leaves the school, records are retained per the school's records-retention schedule and applicable law (typically seven years after the last date of athletic participation, or longer where state law or insurance coverage requires). Audit log entries are retained for at least six years to satisfy HIPAA §164.316(b)(2).

Security

  • All data is encrypted in transit (TLS 1.2+) and at rest.
  • Access controls are enforced via row-level security keyed to school and role.
  • Two-factor authentication is required for all staff accounts.
  • An immutable, append-only audit log records access to and changes of athlete records.
  • Regular backups are taken; point-in-time recovery is available on production tiers.

Your rights

Subject to school policies and applicable law, you may:

  • Inspect and review the records we hold about you or your child;
  • Download an electronic copy of the record (HIPAA §164.524 / FERPA §99.10);
  • Request correction of inaccurate information;
  • Withdraw consent for non-required disclosures;
  • File a complaint with your school's FERPA officer or, where HIPAA applies, with the U.S. Department of Health & Human Services Office for Civil Rights.

Use the “Download record” button on your child's dashboard to obtain an electronic copy.

Children

We collect health information about students under 18, including some students under 13. See our COPPA Disclosure. We do not use student data for advertising, profiling outside the educational purpose, or sale to third parties.

Breach notification

In the event of a breach of unsecured PHI or educational records, we will notify the affected school and individuals without unreasonable delay and in no case later than 30 days after discovery. HIPAA §164.410 allows a business associate 60 days; we commit to 30 everywhere, because a number of states require 30 or fewer and one timeline is easier to keep than several. Where a shorter period is required, the shorter period governs. Notice follows §164.404 and §164.410 where they apply.

Contact

Privacy questions: atlerts@gmail.com