Soar — Privacy Policy
Effective date: [effective date] Operator / data controller: [entity name] ("Soar," "we," "us"), [mailing address] Contact: [support email] · Child-safety contact: [child safety contact]
Plain-English summary (not a substitute for the Policy): We collect what we need to run a coaching marketplace: your account info, the videos and messages you submit, and payment records (your card lives with Stripe, not us). Videos are never public — they're visible only to approved coaches, under time and status limits, and to our administration, and every access link we issue is logged. We don't sell your data. Accounts are adult-only; videos of kids exist only because a parent uploaded them, and we treat them with extra care.
1. Scope
This Policy covers the Soar mobile apps, [domain], and related services. By using Soar you agree to this Policy and our Terms of Service.
2. What we collect
Account information. Name/display name, email, password (hashed by our authentication provider), your 18+ attestation, and your acceptance of the Terms.
Content you submit. Question videos and text, answer videos and notes (coaches), message threads, ratings and comments, reports/flags you file, and the consent confirmation shown when you upload. Question videos may show your child — see Section 3.
Coach application information (coaches only). Playing-level ratings (e.g., UTR/NTRP) and proof links, playing/coaching background, a sample answer video, and screening results (Section 5). Identity verification documents are collected and held by Stripe, not by Soar.
Payment information. Handled by Stripe. We store payment tokens and transaction records (amounts, timestamps, last-4/brand of card, payout records) — never full card numbers. When you save a card, we record your stored-credential consent.
Device and usage data. App version, device type, push-notification tokens, log data (IP address, timestamps, actions), video playback logs (which account an access link was issued to, and playback events — a safety feature), and diagnostic data. We may use device, payment-method, and identity signals to link accounts operated by the same person for fraud and abuse prevention.
Website data. Our marketing site uses cookies and an advertising pixel (Meta) to measure whether our ads work — see Section 7 for exactly where it runs and how to opt out. Our apps contain no advertising trackers.
3. Children's privacy
3.1. Accounts are for adults (18+) only. Soar is not directed to children, and we do not knowingly collect personal information from children under 13 (COPPA) or allow minors to operate accounts.
3.2. Videos of minors are uploaded only by adults. A parent or legal guardian (or an adult with their documented consent) may upload videos in which a minor appears, for the purpose of receiving coaching. The uploading adult confirms, through a consent control shown at upload, that they have the rights and consents described in Terms Section 3.2.
3.3. Extra protections for this content: it is never public; it is viewable only under the visibility rules in Section 6; access is via expiring signed links; every access link we issue, and every playback event, is logged to the account it was issued to; coaches are screened (Section 5) and contractually barred from downloading, storing, or redistributing it, and their viewing patterns are monitored. Messaging exists only between the coach and the adult account holder — the product provides no messaging channel addressed to a minor, and coaches are contractually barred from directing communication to minors. Signed links are designed to prevent unauthorized access, but a person we authorized (an approved coach) could capture content during a link's validity window in violation of our Terms; we log access to deter and investigate this and act on reports. Account holders are responsible for supervising use of their account and devices.
3.4. If we learn that a child is operating an account or has submitted personal information directly, we will suspend the relevant activity, notify the account holder, and delete information a child provided directly, except where the law requires preservation.
4. How we use information
- Operate the marketplace: match questions to coaches, process holds/charges/payouts and refunds, deliver notifications (push and email), power message threads, display coach badges.
- Safety and integrity: coach screening (Section 5), automated message scanning for solicitation patterns (with human review), playback logging and viewing-pattern monitoring, fraud and card-testing prevention, cross-account abuse linking (Section 2), enforcing our Terms, and legally required child-safety reporting (Section 7).
- Support and communications: respond to you, send transactional email and receipts, and — only with your consent where required — product updates. You can opt out of non-essential email.
- Improvement and analytics: aggregate usage statistics (e.g., time-to-answer) to run and improve the service.
- Advertising measurement (website only): measuring whether our ads work — see Section 7.
We do not use your content to train AI models. We do not use videos in marketing without separate written consent.
5. Coach screening
Coach applicants are screened before approval, and each active coach is re-screened at least once every 12 months and promptly upon any credible report. Screening currently includes identity verification via Stripe, confirmation that the verified legal name matches the claimed rating profile, and a check against the U.S. Department of Justice national sex-offender public website (NSOPW). We do not currently obtain criminal background checks; screening reduces but cannot eliminate risk. We record the fact, date, and outcome of checks. If we introduce third-party background checks (consumer reports), we will first provide the standalone disclosure and obtain the separate authorization the Fair Credit Reporting Act requires.
6. Who can see your content
- Open questions: visible (video and text) only to coaches whose applications Soar has approved and whose access is in good standing, and to Soar administration. Never public, never indexed.
- Claimed/answered questions: visible only to the account holder, Soar administration, and the claiming coach — while that coach's account remains in good standing and for up to 30 days after answer delivery, after which the coach's access ends. A coach's access also ends immediately when the claim lapses, is released, or the question is removed or expires, and on any suspension, pause, removal, or deletion of the coach's account.
- Answer videos: visible only to the account holder who asked, the coach who answered (subject to the same good-standing limits), and Soar administration. Delivered answers remain available to the purchasing account holder even if the coach later leaves the platform.
- Message threads: visible only to the two participants and Soar administration (including automated safety scanning). Threads become read-only 7 days after answer delivery; the coach's read access ends when their content access ends (above).
- Ratings: stars and comments may appear on the coach's profile in aggregate once minimum volume is met; they are attributed to your display name unless you choose otherwise in-app.
- Playback logging: every access link we issue, and every playback event, is logged with the identity of the account it was issued to — visible to Soar administration and used for safety auditing.
All video access uses expiring, signed links. Direct/unsigned access to video files is disabled.
7. When we share information
- Service providers (processors): Supabase (database, authentication, hosting), Cloudflare (video storage/streaming), Stripe (payments, coach identity verification and payouts, tax forms), Expo (push notifications), Resend (email), and Vercel (website hosting). Each receives only what its function requires.
- Advertising measurement (website only). The Meta pixel runs only on our public marketing pages; we configure it not to run on login, signup, account, or account-deletion pages or any signed-in area, and we do not enable automatic advanced matching. Some state privacy laws treat this as "sharing" personal information for cross-context behavioral advertising. You can opt out on the website via the "Do Not Sell or Share My Personal Information" control or by using a browser opt-out signal such as Global Privacy Control, which we honor. No data from your Soar account — videos, messages, questions, payments — is sent to Meta.
- Coaches/students: as described in Section 6 (that's the product working).
- Legal compliance and safety: we disclose information when required by law — including reports of apparent child sexual abuse material to NCMEC (with preservation of associated data for the legally required period, currently one year), responses to valid legal process, and disclosures necessary to protect any person's safety.
- Business transfers: if Soar is acquired or merged, information transfers with the business, subject to this Policy's commitments.
- We do not sell your personal information. Other than the website ad-measurement pixel described above, we do not share personal information for cross-context behavioral advertising.
8. Retention
- Account information: retained while your account is active and deleted on the normal schedule after account deletion (backups purge within ~35 days), subject to the carve-outs below.
- Question/answer videos, threads, ratings: retained while your account is active so you can revisit your coaching history. Threads become read-only 7 days after delivery. Delivered answer videos are retained for the purchasing account holder even after the answering coach's account is deleted.
- Reported/flagged content: preserved for the duration of the investigation, and — for content reported to NCMEC — for the legally required period (currently 1 year), in restricted storage.
- Transaction records: retained as required for tax, accounting, and payment-network rules (typically 7 years), even after account deletion.
- Screening records: the fact/date/outcome of checks, retained while you remain a coach and for 2 years after.
- Enforcement and safety records (strikes, flags, refund decisions, terminations, safety actions): retained for 5 years after account closure and matched against new registrations to prevent evasion of enforcement.
- Device, log, and playback data: routine server logs (including IP addresses) are retained approximately 90 days; push-notification tokens are deleted when you log out or delete your account; video playback logs are retained for at least 2 years as a safety record, and longer where part of an enforcement, safety, or reported-content record above.
9. Your choices and rights
- Delete your account in the app (Settings → Delete account) or at [domain]/delete-account.
- Withdraw or remove specific content: withdraw an unclaimed question in the app or via [support email]; request removal of other content at [support email] (requests involving a minor are prioritized).
- Access or correct your account information in the app, or request help at [support email].
- If you are not a Soar user and believe your — or your child's — image or information appears in content on the service, contact [support email] or [child safety contact]. We verify such requests by means appropriate to the request and will remove or restrict access to a minor's imagery on a verified request from the minor's parent or guardian.
- Push notifications: control in your device settings. Email: unsubscribe links in non-essential email.
- Cookies/pixel (website): use the website's "Do Not Sell or Share My Personal Information" control, your browser settings, or Global Privacy Control (which we honor); our apps do not serve third-party ads.
- U.S. state privacy rights (e.g., California): you may request access, deletion, or correction, and you will not be discriminated against for exercising rights. Submit requests to [support email]; we verify against your account email. We respond within 45 days (extendable once by 45 days with notice). If we deny a request, you may appeal by replying "Appeal" to our decision; if the appeal is denied you may contact your state Attorney General. An authorized agent may act for you with written permission.
10. Security
We use encryption in transit, database-level access rules, expiring signed video links, server-side-only handling of payment and administrative actions, audit logs on the access links we issue and on administrative decisions, and production-data access restricted to the operator. These measures are designed to protect your information, but no system is perfectly secure — if a breach affects your data, we will notify you as the law requires.
11. Where data lives
Our services are hosted in the United States. If you use Soar from elsewhere, you consent to processing in the U.S.
12. Changes
We'll post updates here and, for material changes, notify you in-app or by email at least 14 days before they take effect. The current version is always at [domain]/privacy.
13. Contact
Privacy questions or requests: [support email] Child-safety concerns: [child safety contact] (if a child is in immediate danger, call 911) Mail: [entity name], [mailing address]