Back
Privacy Policy
LAST UPDATED SEPTEMBER 2026

This policy applies to all users of RANQD, including visitors to ranqd.app, regardless of location. We are committed to protecting your personal data in compliance with the UK GDPR, EU GDPR, and applicable data protection laws worldwide.

1. Who We Are

RANQD (“we”, “us”, “our”) is a software service for racket sports coaches and coaching academies - bookings, memberships, session management and player development. RANQD is a trading name of Paddle Sports Ltd, a company registered in England & Wales (company number 16105996), with its registered office at 128 City Road, London, EC1V 2NX. We are registered with the UK Information Commissioner’s Office under registration reference ZC239326. For data protection enquiries, contact us at hello [at] ranqd.app.

2. Who Decides What Is Held About You

Two different relationships run through this policy, and which one applies to you changes who is answerable for your data:

  • If you are a coach or a coaching business, RANQD is the controller of your account, subscription and billing data. You are dealing with us directly.
  • If you are a trainee, or the guardian of one, the coaching business you train with is the controller. It decides what to record about you and why. RANQD is its processor - we hold that data on its instructions and do not use it for our own purposes.

This matters when you want something corrected or deleted. Ask the coaching business first, because it is their decision to make. If you cannot reach them, email hello [at] ranqd.app and we will help.

3. What Data We Collect

We collect the following categories of personal data:

  • Coaching business data: the name, email address and telephone number of the coach or academy, of its staff, and of its venues
  • Trainee data: name, username, email address, telephone number, gender and date of birth
  • Guardian data: for a junior, the name, email address, telephone number and relationship of the adult responsible for them
  • Health data: medical notes, allergies and an emergency contact, where a coaching business records them so a session can be run safely. This is special category data and is dealt with separately in section 4.
  • Coaching data: bookings and attendance, memberships and credit balances, competency ratings, development plans, goals, session notes, and links to videos a coach adds
  • Credential data: for coaches and their staff - qualifications, insurance, first aid, safeguarding and criminal-record checks (DBS, PVG, AccessNI or Garda vetting), recorded as the type of check held, its reference, when it expires and, for a DBS, whether the coach reports it is on the DBS Update Service
  • Payment data: what was paid, when, and the payment reference. Card details are handled by Stripe and never reach RANQD.
  • Technical data: IP address, browser type, device information, access timestamps (via server logs)
  • Communications data: messages you send us via contact forms or email

4. Health Data, Children and Consent

RANQD Coach is built for coaching that includes children, so two categories are stated plainly here rather than left to a footnote.

  • Health data. Medical notes, allergies and an emergency contact are recorded by the coaching business so it can run a session safely and act if something goes wrong. They appear on that business’s own register and are never published. The business relies on the explicit consent of the trainee, or of their guardian; where someone cannot give consent and there is an emergency, we rely on vital interests. These four fields are erased 24 months after the last session booked, whether or not the rest of the record is deleted.
  • Juniors. A trainee under 18 has their account run by their guardian. Permission for photographs and permission for video are asked and recorded separately, because a parent may be content with one and not the other - and video permission stops the upload, not only the playback. A guardian’s access ends when the trainee turns 18 unless the now-adult chooses to keep it, and a guardian may hand control over earlier.
  • Children under 13 in the United States are out of scope. COPPA requires verifiable parental consent by prescribed methods. Consent here is recorded as the coaching business’s attested statement, which is evidence of consent but not one of the approved verification methods, so coaching businesses operating in the United States must not enrol under-13s.
  • Criminal-record and safeguarding checks. A criminal-record check is a DBS check, PVG scheme membership, an AccessNI disclosure or Garda vetting, whichever the coach's nation issues. Where a coach records one, we hold that the check exists, which scheme issued it, its reference and its expiry date - not the certificate. Whether a current check is held drives the badge on that coach’s public page, and whether their junior sessions accept bookings at all: if either lapses, new junior bookings stop immediately and bookings already made are cancelled and refunded after 30 days unless the check is renewed.

5. How We Use Your Data

We process your personal data for the following purposes and legal bases:

  • Running the service (contract performance) - creating and managing coaching businesses, trainee accounts, bookings, memberships and payments
  • Coaching (contract performance, on the coaching business’s instruction) - recording attendance, progress, development plans and session notes so a coach can teach
  • Safety (explicit consent, or vital interests in an emergency) - holding health information and emergency contacts, and refusing junior bookings where a coach’s safeguarding check has lapsed
  • Communications (contract performance for service messages; consent for marketing) - booking confirmations, cancellations, refunds and reminders always send, because they are part of the service. Promotional email is opt-in and can be withdrawn at any time.
  • Service improvement (legitimate interest) - understanding usage patterns to improve RANQD
  • Legal compliance (legal obligation) - retaining records where required by law

6. Data Sharing

We do not sell your personal data. We use the following processors to run the service, each under a data processing agreement:

  • Vercel - application hosting. The service runs in Vercel’s London region.
  • Neon - the PostgreSQL database holding the coaching business’s data, hosted in London.
  • Upstash - rate limiting on sign-in and signup attempts, hosted in London (AWS eu-west-2).
  • Stripe - twice over, and the two are separate. Stripe takes the coaching business’s own subscription payment to RANQD. Separately, where a business charges its trainees for sessions or credit packs, that business holds its own Stripe connected account and is the merchant of record. RANQD does not see or store full card details in either case.
  • Resend - transactional email such as invitations, receipts and reminders, sent from Ireland.
  • YouTube and Vimeo - only where a coach has linked a video, and only once you choose to play it. The player is not loaded until then, so opening a page that contains a video does not contact either provider. Video then loads from YouTube’s no-cookie domain, and from Vimeo with tracking disabled.
  • Legal authorities - where required by law or to protect our rights.

All third-party processors are contractually required to handle your data in compliance with applicable data protection law.

7. International Data Transfers

Your data is stored and processed in the United Kingdom, and transactional email is sent from Ireland. Two things routinely leave the UK and the EEA: Stripe, which operates internationally, and - only where you choose to play a linked video - YouTube or Vimeo, both in the United States. Where a transfer outside the UK or EEA occurs, we rely on appropriate safeguards: Standard Contractual Clauses, or an adequacy decision recognised by the UK ICO.

8. Data Retention

We retain personal data only as long as necessary:

  • Health data - medical notes, allergies and emergency contact: 24 months after the last session booked, or 24 months after the record was created for someone who never booked
  • A coaching business and everything in it - 90 days after its subscription ends
  • Routine audit entries - 30 days. Security-relevant entries are kept, up to 500 per business.
  • Email delivery log - 30 days
  • Sign-in links - 15 minutes, and single use
  • Server logs - up to 12 months
  • Financial records - 7 years (UK legal requirement)

Two things are kept deliberately. The consent record - every permission given and every one withdrawn - is kept for as long as the coaching business exists, because deleting it would destroy the evidence that consent was ever given. Bookings and payment records are kept because a coaching business may need them for tax and for disputes; erasing them is that business’s decision, and there is a control in its settings that does it on demand.

9. Your Rights

Under UK GDPR and EU GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectification of inaccurate or incomplete data
  • Erasure (“right to be forgotten”) in certain circumstances
  • Restriction of processing in certain circumstances
  • Data portability - receive your data in a machine-readable format
  • Object to processing based on legitimate interest
  • Withdraw consent at any time where processing is consent-based

If you are a trainee or a guardian, exercise these rights with the coaching business that holds your data - see section 2. Otherwise, or if you cannot reach them, email hello [at] ranqd.app. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local supervisory authority if you are in the EEA.

10. Cookies

We use cookies and similar technologies. See our Cookie Policy for full details.

11. Changes to This Policy

We may update this policy from time to time. We will notify active users of material changes by email or in-app notice. The “Last updated” date at the top reflects the most recent revision.

Terms of ServiceCookie Policy