Legal

Sub-processors.

Effective: July 27, 2026 · Operator: CJ3 Legacy Holdings, LLC · Jurisdiction: Texas, USA

This page lists the third-party service providers ("sub-processors") that The Program Suite engages to process personal information, including student data, on our behalf. It supplements our Privacy Policy and the data privacy agreements we sign with schools and districts. Each sub-processor is bound by contract to process data only on our documented instructions and to maintain appropriate security.

1. What a Sub-processor Is

A sub-processor is a company we use to help operate the Service that may process personal information on our behalf — for example, our hosting provider, our database, or our email delivery service. The Program Suite ("we," "us," or "our") remains responsible for the personal information these providers process for us. We do not sell personal information, and we do not authorize any sub-processor to use the data we entrust to it for its own purposes.

Where a school or program authorizes our collection of student data on behalf of parents, our sub-processors process that student data only for the educational purpose the school directs, consistent with the Federal Trade Commission's COPPA school-authorization guidance and our Children's Privacy (COPPA) notice.

2. Current Sub-processors

The following sub-processors are engaged as of the effective date above:

Sub-processorPurposeCategories of dataLocation
SupabaseDatabase, file storage, and user authenticationAccount, athlete, program, communication, and health/medical records; uploaded filesUnited States
VercelApplication and marketing-site hosting; privacy-first page analyticsHTTP request data; aggregate, non-identifying page analyticsUnited States
ResendGeneral transactional and notification email (account invitations, password resets, service notices)Recipient name and email address; email subject and body contentUnited States
PostmarkDelivery of internal injury and clearance-status notifications between athletic training staff and coachesSender/recipient name and email address; injury and participation-clearance details, which may include health/medical information, and any attached notesUnited States
CloudflareCDN, DDoS protection, and security filteringIP address and request metadata (processed transiently for security)United States / global edge network
UpstashAPI rate limitingIP address, held only for the duration of the rate-limit windowUnited States
StripePayment processing (when billing is enabled)Billing contact and payment card data (processed by Stripe; not stored by us)United States
OpenAIAI image generation for Studio and athlete creationsPrompts, captions, and any reference images the user providesUnited States
GooglePush notification delivery for the iOS app (Firebase Cloud Messaging); AI analysis of coach-provided video links for drill and exercise import (Gemini)Device push token (for notification delivery); coach-provided video URLs and derived drill/exercise metadataUnited States
AppleiOS app distribution via the App Store and push notification delivery (Apple Push Notification service); weather data for scheduling and event planning (WeatherKit)Device push token (for notification delivery); event or venue location coordinates (no personal identifiers)United States
InngestBackground job and workflow processing (scheduled and event-driven tasks)Data included in queued jobs, such as record identifiers and notification payloadsUnited States
Meta PlatformsPublishing program-authored content to connected Facebook and Instagram accountsContent the program chooses to publish and the connected account's credentials/tokensUnited States / global

Some sub-processors are engaged only when a related feature is used (for example, Stripe when billing is enabled, or Meta Platforms when a program connects a social account). Providers that act only as transient infrastructure for security or performance — and do not durably store personal information — are noted as such above.

3. How We Vet Sub-processors

Before engaging a sub-processor, and on an ongoing basis, we require that it:

  • Enters a written agreement (a data processing agreement or equivalent terms) that limits processing to our documented instructions
  • Maintains administrative, technical, and physical safeguards appropriate to the data it processes
  • Is bound by confidentiality obligations covering the personal information it handles
  • Does not use personal information we provide for its own purposes, including advertising or model training
  • Supports our obligations to schools and districts under applicable student-privacy law, including FERPA, COPPA, and state student-privacy statutes such as the Texas Education Code

4. Changes to This List

We may add or replace sub-processors as the Service evolves. When we do, we will update this page and revise the effective date above. Where a data privacy agreement with a school or district requires advance notice of new sub-processors and an opportunity to object, we will provide that notice as agreed in that contract.

To be notified of changes to this list, or to ask about a specific sub-processor, contact us at privacy@theprogramsuite.com.

5. Contact

Questions about our sub-processors or data processing practices may be directed to:

The Program Suite

Attn: Privacy

5900 Balcones Drive, Suite 29102, Austin, TX 78731

Email: privacy@theprogramsuite.com