Privacy notice – CanchaCoach
Last updated: 20 August 2026 · Version: 1.4
In short
CanchaCoach is a planning tool for football coaches. We process personal data about you as the coach , in practice your email address and what you create in the tool yourself.
Your email address is stored only with the login service (Supabase Auth), never in the product database. No product query, share or member list contains it, and club colleagues see only your display name.
We store no personal data about players. No player names, no dates of birth, no information about children. The squad profile in CanchaCoach is deliberately built at aggregated team level . The tool never asks who the players are, and the database has no field for it. That is a design choice, not a policy we can change quietly.
We do not sell data on, and we do not use it for advertising.
1. Who is the data controller
Cerro Arco AS (company registration number 838 175 252), Blinken 15, 1349 Rykkinn, Norway. CanchaCoach is a product of Cerro Arco AS.
Contact for privacy matters: hello@canchacoach.com
2. What we collect
2.1 Account data
| Data | Source | Why |
|---|---|---|
| Email address | You, at registration | Login, email confirmation, service messages. Stored only with the login service, not in the product database |
| Password (encrypted) | You | Login. Stored as a hash, so we cannot see your password |
| Display name (optional) | Your login service (for example the name from your Google account), or you | Shown to club colleagues in member lists. If it is missing, an anonymous code is shown instead, never your email address |
| Sharing name (optional) | You | The first name you choose to show on sessions you share publicly |
| Country (country code only) | You, or derived from your IP address at login | Adapting content to the football association where you coach. The IP address itself is never stored in the database, only the country code. You can change the country in Account |
| Club affiliation and role | You or the club administrator | Access to the club's content |
| Subscription plan and usage counters | The system | Controlling what you have access to and how many AI generations you have used |
About club invitations: if a club administrator invites you to a club, your email address is stored in the invitation until it is accepted or deleted. That applies before you have created an account too. We are moving this to an invitation link that does not need the address.
About the free demo: if you start the free demo, we store a cryptographic code derived from your email address — not the address itself — so that the same mailbox cannot claim the demo more than once. The code cannot be turned back into your address. It remains after you delete your account; otherwise the safeguard would be worthless, because it could be reset simply by creating the account again. We also record the domain of your address (the part after the @) in a technical log of demo starts, to help us recognise misuse. The address itself is stored in neither place.
2.2 Content you create
Training sessions, your own exercises, favourites, squad profiles, season plans, a coaching plan you upload yourself, notes you write about the squad, and reminders you add to the exercises in a session. This is linked to your user account.
About the free-text fields: you can write freely in squad notes and in reminders on the exercises. A reminder on a team session is visible to the team's other coaches and is printed on the session sheet. The tool never asks you for player names, and we recommend that you do not write personal data about players there. If you do anyway, it is stored as part of your note, and you can delete it at any time.
About the coaching plan: a club's coaching plan is the club's professional document, not personal data about players.
2.3 Voice notes
If you use “Speak your session”, the audio recording is sent for transcription. The audio and the raw transcript are never stored , neither by us nor by the sub-processor. They are processed in memory and discarded as soon as the fields have been extracted. Only the draft fields you confirm yourself are stored onwards, exactly as if you had typed them in.
2.4 Generated sessions (quality control)
Every session the AI creates is given a session ID (an eight-character code, shown at the bottom of the session and on the printout). The session itself is stored anonymously for 90 days together with the technical choices behind it: age group, theme, number of players and coaches, session length. This lets us check the quality of what the app actually delivers, not only what coaches choose to save, and lets you point to a specific session when you report something.
This copy is not linked to you: it contains no name, email address, account ID or team. Your free-text fields are not stored there. Match observations, match messages, squad notes, reminders on the exercises and voice notes are kept out. After 90 days the copy is deleted automatically. Because it is anonymous, it cannot be retrieved or deleted for one individual user, which is precisely why we keep free text out of it.
One more thing, said plainly: the session text the AI writes is shaped by what you typed in, and could in principle echo a phrase from it. We therefore run a name guard over the copy that masks anything that looks like a personal name. It catches common names, not all of them. So never write player names in the free-text fields. The tool never asks you for them.
The session you save yourself is a different matter: it sits under your account as ordinary content, and is deleted with the account.
2.5 Technical operations
Server logs with error messages and technical data, kept for a short time for troubleshooting and to prevent abuse.
2.6 What we do not collect
- Personal data about players or children, in any form
- Data from third parties or data brokers
- Cross-site tracking, advertising identifiers or profiling for marketing
3. Why we process the data, and on what basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Delivering the service: account, sessions, generation, sharing | Contract, art. 6 (1) b |
| Sending necessary service messages (confirmation, password reset, service notices) | Contract, art. 6 (1) b |
| Security, troubleshooting and preventing abuse | Legitimate interest, art. 6 (1) f |
| Accounting and bookkeeping when you pay | Legal obligation, art. 6 (1) c |
We process no special categories of personal data (GDPR art. 9).
4. Who we share with
We use a small number of data processors. All are bound by a data processing agreement.
| Data processor | What they do | Where | Basis for transfer |
|---|---|---|---|
| Supabase | Database and login. Your account and content live here | EU (data at rest) | Data processing agreement |
| Anthropic | AI generation of sessions (Claude) | USA | Standard Contractual Clauses (SCC). Anthropic does not train models on data sent via the API |
| Groq | Transcription of voice notes | USA | SCC. Zero data retention (ZDR) is enabled, so Groq stores nothing from our calls |
| Vultr | Operation of the API server (compute) | Stockholm, Sweden (EEA) , the supplier is US-owned (Vultr Holdings LLC) | Data processing agreement + Standard Contractual Clauses (SCC) |
| Vipps | Subscriptions and recurring payments | Norway (EEA) | Data processing agreement. We send no personal data to Vipps: you are identified in the Vipps app, and we store only the agreement ID and the amount |
| Stripe | Card payments and subscription charges. Taken into use when card payment opens, see terms of sale section 3 | EU (Ireland) and USA | Data processing agreement + Standard Contractual Clauses (SCC). We never receive your card number; it goes directly to Stripe |
| Brevo | Outgoing email: confirmation and password reset | EU (France) | Data processing agreement |
We do not sell personal data, and we do not share it with advertisers.
We may disclose data if we are legally required to.
5. Transfers outside the EEA
Your account and content are stored in the EU.
When you use AI generation or voice notes, the content of the request is sent to providers in the USA for processing. The transfer takes place on the basis of the European Commission's Standard Contractual Clauses (SCC). None of these providers store the content: Anthropic does not train on API data, and Groq has zero retention enabled.
The API server (compute) is operated in Stockholm, Sweden (EEA) by Vultr. The operating supplier itself is US-owned (Vultr Holdings LLC), but the server and the logs are in the EEA; the transfer is covered by a data processing agreement and SCC. Data at rest is in the EU (Supabase). The only thing that leaves the EEA is the content of the individual AI or voice request to Anthropic/Groq in the USA (SCC, no retention), as described above.
6. How long we store data
| Data | Retention |
|---|---|
| Account and content | For as long as you have an account. If you delete the account, the content is deleted. One exception is listed at the bottom of this table |
| Audio recording and raw transcript | Never stored |
| Anonymous copy of generated sessions | 90 days, then deleted automatically. Not linked to you |
| Server logs | A short time, for troubleshooting and security |
| Sharing statistics | Disconnected from you when the account is deleted. The statistics remain anonymously |
| Payment data held by the payment provider | According to the provider's own retention periods (Vipps, later Stripe). We ourselves store only a receipt reference and the amount |
| Accounting records | 5 years after the end of the financial year (Norwegian Bookkeeping Act), where you have paid |
| Safeguard against repeat demos (a code derived from your email address) | Kept for as long as we offer the demo, including after you delete your account. It does not contain your address |
7. Your rights
You have the right to:
- access the data we hold about you
- rectify data that is incorrect
- delete your account and its content
- take with you your data in a machine-readable format, on request
- object to processing based on legitimate interest
- restrict the processing
You can delete your account yourself in the app, or contact us at hello@canchacoach.com. We respond within 30 days.
If you disagree with how we process your data, you can complain to the Norwegian Data Protection Authority (datatilsynet.no). We would appreciate hearing from you first.
8. Security
The data sits behind row-level access control in the database, so you reach only your own data and what your club has shared with you. All traffic is encrypted. Passwords are stored as hashes. Your email address must be confirmed before you get access to the AI features.
9. Cookies
We use only what is needed for login to work. No tracking cookies, no advertising cookies, no third-party analytics.
10. Children
CanchaCoach is a tool for adult coaches. You must be of legal age to create an account. Although the sessions are used with children on the pitch, the tool processes no personal data about them.
11. Language versions
This notice exists in Norwegian, English and Spanish. The translations are intended to say the same thing, but the Norwegian version is the legally binding one. If there is any discrepancy between the language versions, the Norwegian version prevails.
12. Changes
If we change anything material, we notify you by email or in the app before the change takes effect. The date at the top shows when the notice was last changed.
13. Contact
Cerro Arco AS · hello@canchacoach.com