1. Information We Collect
1.1 Information You Provide
- Account information: name, email, password, account role
- Subscription information: plan type, billing status
- Released tool inputs: the operational selections or short text needed to use a currently available logistics, conversation, or referral tool
- Household Kitchen choices: selected and favorite recipe identifiers, household yield, grocery checkmarks, and custom grocery items. The web version stays in local browser storage; the mobile version stays in account-scoped device storage. Aspire does not receive these choices through a Kitchen write API.
- Recruiting workspace information: athlete name, school or club, graduation year, event marks, GPA or academic interest, official-results link, shortlist, outreach status, follow-up dates, and an optional unlisted resume. Free browser work stays on that device; paid cloud storage is created only after an adult-managed parent account accepts the storage disclosure.
- Historical held runner-planning records: earlier internal, TestFlight, or web workflows may have stored runner display, age, height, weight, training schedule, menu, race, symptom, or progress data. The current launch candidate does not expose those create/read/update features, but deletion remains available.
- Private Parent Support messages: general questions and Aspire replies stored under the adult-managed household account. Do not submit names, contact details, dates of birth, school identifiers, or exact lab values in this thread.
1.2 Information Collected Automatically
- Usage data: pages viewed, articles read, tool usage, timestamps
- Device and technical data: IP address, browser type, device identifiers
- Cookies and similar technologies
1.3 Held Health and Screening Workflows
Diagnostic-style screeners, calorie/body calculators, and athlete health logs are not released. Their page and data APIs fail closed. The released referral tools use neutral observation and route emergency, diagnosis, treatment, testing, supplement, and clearance decisions to the appropriate adult, school process, or qualified professional.
1.4 Runner Fuel Profile
Runner Fuel Profile, Fuel Today, profile-linked weekly Kitchen planning, Race, and Runner Ready are held from this release pending documented professional, privacy, and legal review. The current web and mobile candidates do not let an account create, read, or update those plans. A signed-in adult can still remove previously saved runner profile, plan, menu, race, and progress records without deleting the adult account.
1.5 Recruiting Workspaces
When the ranking-backed recruiting release is available, local school research and shortlists can be used without sending athlete information to Aspire. Recruiting Access lets an authenticated adult-managed parent account choose to save an athlete workspace to Aspire's database and create a revocable unlisted resume link. The unlisted page can show the athlete's name, school, graduation year, marks, academics, next race, and official-results link; it does not show billing, the family's shortlist, outreach notes, or account details. An adult can disable the link or delete the cloud workspace from the recruiting product.
2. How We Use Information
We use the information we collect to:
- Provide and operate the Services
- Deliver tool outputs and personalized educational experiences
- Improve content, tools, and user experience
- Communicate about onboarding, updates, and support
- Prevent fraud, secure the platform, enforce Terms
- Comply with legal obligations
Aspire does not sell personal information for money.
A private Parent Support thread is used only to answer that household's general implementation questions and maintain the response history. It is visible to the signed-in adult-managed household and authorized Aspire administrators, not coaches, other families, or the disabled Community boards.
3. How We Share Information
- Service providers: hosting, privacy-focused traffic measurement, consent-gated site analytics, payments, email delivery, and rate limiting — described in section 9
- Payment processing: via Stripe; we don't store full card numbers
- Legal and safety: if required by law
- Business transfers: if involved in merger/acquisition
4. Security Measures
We implement encryption in transit (TLS/HTTPS), access controls, authentication, and vendor due diligence. No method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
5. Data Retention and Deletion
Data is retained as long as necessary for Services, legal requirements, or dispute resolution.
Deletion is self-serve. Sign in and open your account page. "Download my data" gives you a JSON file of your account details, preferences, subscription record, program record, private Parent Support thread, saved Runner Fuel Profile, Fuel Ready progress, and anything you posted on a discussion board. "Delete my account" removes your login, private Parent Support thread, saved plans, activation progress, and those records immediately; if you are a coach it also deletes the program record and its code. You do not need to email us, and we do not ask you for a reason. Records we are required to keep for tax and payment purposes stay with Stripe under their retention rules.
Program staff can rotate the program code from the same account page. That does not let staff open, edit, or manage a household account or its runner data.
6. Minor Users (COPPA and Youth Protections)
Aspire accounts must be created and managed by an adult. A minor runner may use private household planning only through an account managed and supervised by a parent, legal guardian, or other adult responsible for that household. A coach may distribute general educational resources and a program code, but does not manage the household runner account or receive its private profile, body inputs, menus, symptoms, or race plan. We do not ask minors to create separate credentials or provide date of birth through public signup. The Services are not directed to children under 13, and children under 13 may not submit personal information to Aspire. If we learn that personal information was submitted directly by a child under 13 without authorization required by law, we will delete it. We do not sell minor personal data, use it for targeted advertising, or profile minors for legal or similarly significant decisions. We limit known-minor data to the disclosed service purpose and retain it only as reasonably necessary for that purpose.
7. Program Access Data Handling (FERPA)
We do not require schools to upload official student records. Student personal data is treated with heightened care. Coaches control program-level settings: from the account page a coach can rotate the program code so an old code stops working and delete the whole program record by deleting their own account. Those controls do not expose or manage a household account or its runner data. For anything beyond that, or for a school-wide request, email luke@aspireperformancerd.com.
8. Colorado Privacy Act (CPA) Disclosures
Colorado residents have the right to: access their personal information; correct inaccurate data; request deletion; obtain a portable copy of their data; and opt out of certain processing (e.g., sale or targeted advertising). Aspire does not sell personal information. To exercise your rights, contact luke@aspireperformancerd.com.
9. Subprocessors
The principal outside companies that process data on Aspire's behalf for the current website and companion app are listed below.
- Vercel — website and application hosting, server logs, and Web Analytics. Web Analytics records anonymous page-view data such as page or route, referrer, coarse location, browser, operating system, and device type for aggregate traffic reporting; it does not use third-party cookies.
- Google Analytics — optional website traffic measurement. Its script loads only after a visitor selects Accept, may set a first-party
_ga identifier, and may process page activity, approximate location, and browser or device information. Aspire does not send Runner Fuel Profile answers to Google Analytics. - Stripe — payment processing and the billing portal. Stripe collects and stores card details directly; Aspire never receives or stores a full card number.
- Resend — sends transactional and follow-up email (account setup, program workspace details, requested resources).
- Upstash — Redis for rate limiting, and QStash for scheduling the follow-up emails you opt into.
Authentication runs on NextAuth inside our own application; it is a library, not an outside company, and no login data is sent to a third party by it.
10. Cookies and Tracking
Aspire uses first-party cookies and local browser storage, and Google Analytics may add measurement storage after consent. The current uses are:
- Session cookie — set when you sign in, so you stay signed in. Removed when you sign out.
aspire_funnel_id — a signed random identifier set on your first visit and kept for 180 days. We use it to see which pages lead to a purchase. It is not linked to an advertising profile and is not shared with anyone.aspire_checkout_intent — short-lived, only during checkout, so you land back where you left off if you sign in partway through.aspire_mobile_webview — a non-sensitive session marker created by an authenticated app-to-web handoff. It keeps the public-site analytics and consent clients out of the protected in-app WebView.- Google Analytics storage — Google Analytics is off unless you select Accept. If accepted, Google may set the first-party
_ga cookie and related measurement storage. Declining leaves the Google Analytics script unloaded. - Consent preference — your Accept or Decline choice is kept in first-party local browser storage so the site can respect it.
- Household Kitchen — selected recipes, favorites, household yield, grocery checkmarks, and custom grocery items are kept in an account-scoped first-party browser key. They are not sent to Aspire through a Kitchen write API. Clearing site storage clears this browser list.
Vercel Web Analytics runs outside the protected mobile WebView and sends anonymous page-view data to Vercel for aggregate reports without using cookies. Google Analytics also stays out of the protected mobile WebView and does not load in a regular browser until the visitor accepts analytics. Stripe's payment script loads only where it is needed for checkout.
You can block or clear cookies in your browser. If you block the session cookie you will not be able to stay signed in. You can decline Google Analytics in the consent prompt; if you previously accepted, clear this site's cookies and local storage to reset the choice. Declining or clearing this site's storage prevents Aspire's Google Analytics tag from loading. Aspire does not sell personal information for money.
11. Your Rights and Choices
You have the right to:
- Update account info in settings
- Download a portable copy of your data, or delete your account outright, from your account page — no request or email needed
- Request correction of anything you cannot change yourself
- Opt out of non-essential emails; follow-up email is only sent if you tick the opt-in box yourself, and every email has an unsubscribe link
12. International Users
Aspire is based in the United States. Data is processed and stored in the US.