Privacy
Privacy Notice
Last updated 28 September 2026
This notice explains what we collect about athletes, parents and coaches who use the Program, why we collect it, who can see it and the rights you have. We've written it for parents and teenagers, not lawyers.
01Who we are
ADP by Philly McMahon (“the Program”, “we”, “us”) is run by Philly McMahon. We are the data controller for the personal data described here, which means we decide how and why it is used.
You can contact us about anything on this page at phillyadp@gmail.com.
02The short version
- We collect what's needed to coach a young athlete safely: who they are, their age, their sport, their training and their wellness check-ins.
- Athletes under 16 can't use the Program until a parent or guardian approves the account by email.
- Only the athlete, their parent or guardian, their coach and our admin staff can see an athlete's data.
- There are no public profiles, no leaderboards and no private messaging between coaches and athletes.
- We don't sell data, we don't show ads, and we don't use tracking or advertising cookies.
- You can ask for a copy of your data, or for it to be deleted, at any time.
03What we collect
- Athletes
- First name and surname, date of birth, email and password (stored hashed), sport, club, county and position if given, their coach, and training block.
- Training
- Sessions scheduled and completed, sets and reps logged, session length and effort rating (RPE), notes the athlete adds, test results and personal bests, learning modules completed, XP, streaks and badges.
- Wellness
- Short check-ins on sleep, energy, soreness, mood and stress, optional notes, and recovery logs. A parent can also submit a check-in for their child.
- Coach notes
- Notes a coach writes about an athlete's training, with a visibility setting that decides whether the athlete and parent can read them.
- Parents and guardians
- Name, email and password, your relationship to the athlete, and a record of when and how you gave consent.
- Coaches
- Name, email and password, a short bio, the athletes you coach, and the expiry dates of your Garda vetting and safeguarding certificate.
- Booking a call
- The parent's name and phone number, the athlete's age and sport, and a preferred time. This goes to our enquiries list.
- Signing up
- While you sign up, we hold the details you enter until payment goes through. Your password is stored only as a secure hash. No account exists until you've paid.
- Payments
- Stripe takes the monthly payment and holds your card or bank details; we never see them. We hold the plan, the membership status, next payment and any cancellation date, who pays, and Stripe's customer and subscription references.
- Safety and security
- Sign-in activity, an audit log of sensitive admin actions, and any safeguarding concern recorded by our staff.
We don't collect location data, and we don't ask for photos.
04Wellness and health information
Wellness check-ins and notes about soreness, injury or recovery can count as health data, which GDPR treats as a special category. We only collect it with explicit consent. For an athlete under 16 that consent comes from their parent or guardian when they approve the account. Athletes aged 16 and over give it themselves when they sign up.
We use it for one purpose: so a coach can adjust training and spot a player who may need a lighter week or a conversation. A check-in with very low energy, mood or sleep, or very high soreness or stress, is flagged to the coach. A person always decides what happens next.
This is not medical care. If you are worried about an athlete's health, speak to a doctor or physiotherapist.
05Why we use it, and our legal basis
- Running the athlete's account and programme, and the parent and coach views
- Performance of our agreement with you (Article 6(1)(b)). For under-16s, parental consent (Articles 6(1)(a) and 8).
- Wellness check-ins and injury or recovery notes
- Explicit consent (Article 9(2)(a)), given by the parent for under-16s.
- Emails: consent requests, monthly parent reports, account and service messages
- Performance of our agreement with you.
- Safeguarding: coach vetting records, concerns and incident records
- Legal obligation under the Children First Act 2015 and the National Vetting Bureau Acts (Article 6(1)(c)), and our legitimate interest in keeping children safe (Article 6(1)(f)).
- Security, audit logs and preventing misuse
- Legitimate interest in keeping accounts and data safe (Article 6(1)(f)).
- Calling you back after you book a call
- Your request (Article 6(1)(b)) and our legitimate interest in answering enquiries (Article 6(1)(f)).
- Membership payments and records
- Performance of our agreement, and legal obligation to keep tax records (Article 6(1)(c)).
06Children and parental consent
The Program is for players aged 12 to 18. Ireland's digital age of consent is 16. When someone under 16 signs up, their account stays locked until the parent or guardian they name opens our email link, confirms they are the parent or legal guardian, and approves it.
Parents of under-16s can see their child's training, progress, wellness and any coach notes shared with them, and can exercise their child's data rights on their behalf. Athletes aged 16 and 17 manage their own account and can exercise their own rights. A parent can still be linked to see their progress.
By design there are no public profiles, no leaderboards, no rankings between athletes and no direct messaging between coaches and athletes. Coaches can only see the athletes assigned to them. Every coach must hold current Garda vetting and a safeguarding certificate.
07Who can see your data
- The athlete sees their own training, progress and any coach notes shared with them.
- A linked parent or guardian sees their child's training, progress, wellness, reports and shared notes.
- The athlete's coach sees their training, including wellness flags, so they can adjust it.
- Our admin staff can see accounts to run the Program, handle consent and deletion requests, and deal with safeguarding concerns.
We use these service providers to run the Program. Each one processes data only on our instructions, under a data processing agreement:
- Supabase
- Hosts our database, handles sign-in and stores the exercise videos. Your data is stored in Ireland (EU West).
- Vercel
- Hosts the website and runs the app's code.
- Resend
- Sends our emails, such as consent requests and monthly reports.
- Stripe
- Takes the monthly membership payment and holds the card or bank details for it.
- YouTube (Google)
- Only if an exercise uses a YouTube video. We use YouTube's privacy-enhanced mode, so Google only receives data when that video is played.
Some of these providers are based in the United States and may process data there. Where they do, the transfer is protected by the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
We will share data with the Gardaí, Tusla or another authority only where the law requires it or a child's safety depends on it.
08How long we keep it
- Account, training and wellness data
- While the account is active. If an account is unused for 24 months we contact the athlete or parent, then delete it.
- After you ask us to delete an account
- Removed within 30 days. Backups are overwritten within a further 30 days.
- Unfinished sign-ups
- Deleted 30 days after they were started if payment isn't completed.
- Booking-a-call enquiries
- 12 months from our last contact, unless the athlete joins.
- Payment records
- 6 years, as Irish tax law requires.
- Safeguarding records and audit logs
- As long as needed to meet our safeguarding and legal obligations. This can be longer than the account itself.
09Your rights
Under GDPR you have the right to:
- get a copy of the data we hold about you or your child;
- have anything inaccurate corrected;
- have your data deleted;
- restrict or object to how we use it;
- receive your data in a portable format;
- withdraw consent at any time, which stops future processing but doesn't affect what happened before.
To use any of these rights, email phillyadp@gmail.com from the email address on the account. We'll reply within one month. Withdrawing consent for an under-16 athlete, or for wellness data, means we pause or close the account, because we can't coach safely without it.
If you're unhappy with how we handle your data, please tell us first. You also have the right to complain to Ireland's Data Protection Commission at dataprotection.ie.
11Security
Data is encrypted in transit and at rest. Passwords are stored hashed, never in plain text. Database rules limit each person to the records their role allows. Sensitive admin actions such as exporting or deleting an athlete's data are logged. If a breach puts your data at risk, we will tell you and the Data Protection Commission as the law requires.
12Changes to this notice
If we change how we use personal data, we'll update this page and its date. If the change is significant, we'll email account holders before it takes effect, and ask parents again for consent where the law requires it. You can also read our Terms of Use.