Sub-processors.
Effective: July 27, 2026 · Operator: CJ3 Legacy Holdings, LLC · Jurisdiction: Texas, USA
1. What a Sub-processor Is
A sub-processor is a company we use to help operate the Service that may process personal information on our behalf — for example, our hosting provider, our database, or our email delivery service. The Program Suite ("we," "us," or "our") remains responsible for the personal information these providers process for us. We do not sell personal information, and we do not authorize any sub-processor to use the data we entrust to it for its own purposes.
Where a school or program authorizes our collection of student data on behalf of parents, our sub-processors process that student data only for the educational purpose the school directs, consistent with the Federal Trade Commission's COPPA school-authorization guidance and our Children's Privacy (COPPA) notice.
2. Current Sub-processors
The following sub-processors are engaged as of the effective date above:
| Sub-processor | Purpose | Categories of data | Location |
|---|---|---|---|
| Supabase | Database, file storage, and user authentication | Account, athlete, program, communication, and health/medical records; uploaded files | United States |
| Vercel | Application and marketing-site hosting; privacy-first page analytics | HTTP request data; aggregate, non-identifying page analytics | United States |
| Resend | General transactional and notification email (account invitations, password resets, service notices) | Recipient name and email address; email subject and body content | United States |
| Postmark | Delivery of internal injury and clearance-status notifications between athletic training staff and coaches | Sender/recipient name and email address; injury and participation-clearance details, which may include health/medical information, and any attached notes | United States |
| Cloudflare | CDN, DDoS protection, and security filtering | IP address and request metadata (processed transiently for security) | United States / global edge network |
| Upstash | API rate limiting | IP address, held only for the duration of the rate-limit window | United States |
| Stripe | Payment processing (when billing is enabled) | Billing contact and payment card data (processed by Stripe; not stored by us) | United States |
| OpenAI | AI image generation for Studio and athlete creations | Prompts, captions, and any reference images the user provides | United States |
| Push notification delivery for the iOS app (Firebase Cloud Messaging); AI analysis of coach-provided video links for drill and exercise import (Gemini) | Device push token (for notification delivery); coach-provided video URLs and derived drill/exercise metadata | United States | |
| Apple | iOS app distribution via the App Store and push notification delivery (Apple Push Notification service); weather data for scheduling and event planning (WeatherKit) | Device push token (for notification delivery); event or venue location coordinates (no personal identifiers) | United States |
| Inngest | Background job and workflow processing (scheduled and event-driven tasks) | Data included in queued jobs, such as record identifiers and notification payloads | United States |
| Meta Platforms | Publishing program-authored content to connected Facebook and Instagram accounts | Content the program chooses to publish and the connected account's credentials/tokens | United States / global |
Some sub-processors are engaged only when a related feature is used (for example, Stripe when billing is enabled, or Meta Platforms when a program connects a social account). Providers that act only as transient infrastructure for security or performance — and do not durably store personal information — are noted as such above.
3. How We Vet Sub-processors
Before engaging a sub-processor, and on an ongoing basis, we require that it:
- Enters a written agreement (a data processing agreement or equivalent terms) that limits processing to our documented instructions
- Maintains administrative, technical, and physical safeguards appropriate to the data it processes
- Is bound by confidentiality obligations covering the personal information it handles
- Does not use personal information we provide for its own purposes, including advertising or model training
- Supports our obligations to schools and districts under applicable student-privacy law, including FERPA, COPPA, and state student-privacy statutes such as the Texas Education Code
4. Changes to This List
We may add or replace sub-processors as the Service evolves. When we do, we will update this page and revise the effective date above. Where a data privacy agreement with a school or district requires advance notice of new sub-processors and an opportunity to object, we will provide that notice as agreed in that contract.
To be notified of changes to this list, or to ask about a specific sub-processor, contact us at privacy@theprogramsuite.com.
5. Contact
Questions about our sub-processors or data processing practices may be directed to:
The Program Suite
Attn: Privacy
5900 Balcones Drive, Suite 29102, Austin, TX 78731
Email: privacy@theprogramsuite.com