Company: Nrich INC (“NRICH”)
This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our sites, use our apps, or interact with the NRICH platform.
1) Scope & roles
- When we process Customer Data (e.g., program, coach, parent/child information) on behalf of a Customer, NRICH acts as a processor and the Customer is controller.
- For NRICH’s own account, billing, support, analytics, and marketing data, NRICH is the controller.
2) Information we collect
You provide:
- Account & profile: name, email, phone, role, organization.
- Business settings: locations, schedules, pricing, consents, onboarding requirements.
- Coach onboarding: IDs/certifications/photos you upload per Customer request.
- Parent/guardian & child profiles: child name, age/grade, school, allergy/medical notes (limited, non-diagnostic), emergency contacts, consents.
- Transactions: enrollment details; Stripe-managed payment tokens (NRICH does not store full card numbers).
- Communications: messages, templates, delivery status.
We collect automatically:
- Device & usage: IP, device/browser, app version, logs, diagnostic events, session metadata.
- Cookies & similar tech: see our Cookie Policy.
From third parties (per your settings):
- Stripe Connect, email/push/SMS providers, calendaring, and maps services (e.g., Google Maps).
3) How we use information
- Provide the Service: build seasons, run schedules, attendance, messaging, consents, payments/payouts.
- Operate & secure: authentication, fraud prevention, debugging, incident response.
- Communicate: service notices, product updates, support.
- Improve: analytics, usage insights, new features.
- Marketing (controller data only): with your permissions and opt-out choices.
- Legal: comply with laws, enforce Terms, handle disputes.
4) Legal bases (EEA/UK)
- Contract: to deliver the Service to Customers.
- Legitimate interests: security, product improvement, analytics (balanced against your rights).
- Consent: where required (e.g., marketing, certain cookies).
- Legal obligation: tax, accounting, compliance.
5) Sharing information
We share with:
- Service providers/sub-processors: e.g., Stripe (payments), email/push/SMS (SendGrid/Resend/OneSignal/Twilio/WhatsApp Business), cloud hosting, analytics, error monitoring, maps and geocoding.
- Customers: Data about their programs, coaches, and families (per role-based access).
- Legal & safety: to comply with law, protect rights, prevent harm.
- Business transfers: merger, acquisition, financing, or sale of assets.
We do not sell personal information. For certain regions, we honor “Do Not Sell or Share” choices as required.
6) Children’s privacy
NRICH is used by adults (parents/guardians, staff, coaches) who manage children’s profiles. We collect children’s data from and with consent of parents/guardians on behalf of Customers. If you believe a child provided data without consent, contact us at [privacy@nrich.com].
7) Retention
We retain personal information only as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Customers control retention of Customer Data; NRICH follows Customer instructions and our standard retention schedules.
8) Security
We use industry-standard administrative, technical, and physical safeguards, including encryption in transit, access controls, and logging. No system is perfectly secure—report concerns to [security@nrich.com].
9) Your rights
Depending on your region, you may request to access, correct, delete, port, or restrict processing of your data, or object to certain uses.
- EEA/UK: GDPR rights; contact NRICH (controller data) or the relevant Customer (processor data).
- California & certain US states: rights to know, delete, correct, opt-out of “sale/share,” limit sensitive data uses. Use in-product controls or email [privacy@nrich.com].
We may verify your identity and deny manifestly unfounded or excessive requests as allowed by law.
10) International transfers
We may transfer data internationally, including to the United States. Where required, we use Standard Contractual Clauses or other legal mechanisms.
11) Cookies & tracking
See our Cookie Policy for details, controls, and retention. We honor Global Privacy Control (GPC) where applicable.
12) Third-party links
Our Service may contain links to third-party sites/services. Their privacy practices are governed by their own policies.
13) Changes to this policy
We may update this Policy. If changes are material, we’ll provide notice (e.g., email or in-product). Continued use after the effective date means you accept the changes.