Varsity Forever

Privacy Policy

Effective August 12, 2026

This Privacy Policy explains how Patrick Frayer ("Varsity Forever", "we", "us") collects, uses, shares and protects personal information when you use the Varsity Forever website and mobile applications (the "Service").

1. Information we collect

Account information. Your name, email address, password credentials or third-party sign-in identifier (for example Google), and any profile details you choose to add.

Athlete assessment responses. Your sport background, training history, available days and equipment, goals, and the free-text answers you give about injuries and physical limitations.

Training logs. Workouts scheduled and completed, sets, reps, load, RPE, session notes, and progress over time.

Automatic and device data. IP address, device and browser type, operating system, app version, language, referring pages, and usage events such as sign-up, assessment completion and workout completion.

Payment status. We receive subscription status, plan, renewal date and the last four digits or brand of a card from our payment processors. We never receive or store full payment card numbers.

2. Sensitive and consumer health information

Injury and limitation answers, and other information you enter about your physical condition, may be treated as sensitive personal information or consumer health data under laws such as the Washington My Health My Data Act, the Nevada consumer health data law, and comparable state privacy statutes.

We collect this information only to adapt your training programme and keep sessions appropriate for you. We do not sell it, we do not share it for cross-context behavioural advertising, and we exclude it from analytics payloads. Where the law requires consent for collection or sharing of consumer health data, we ask for it before collecting, and you may withdraw consent at any time by contacting us at frayerathletics@gmail.com.

3. How we use information

We use personal information to:

  • create and secure your account and authenticate you;
  • build, personalise and adapt your training programme;
  • display your history, progress and analytics;
  • operate subscriptions, billing, receipts and entitlements;
  • send service messages, such as billing and account notices;
  • send marketing messages where permitted, which you can decline at any time (see Section 7);
  • diagnose faults, prevent abuse and fraud, and improve the Service;
  • comply with legal obligations and enforce our terms.

Our legal bases, where the GDPR or UK GDPR applies, are performance of a contract with you, our legitimate interests in operating and improving the Service, your consent (for marketing and for health-related data), and compliance with legal obligations.

4. How we share information

Service providers. Hosting and managed database providers, authentication providers, email delivery providers, payment processors — Paddle.com, our Merchant of Record and reseller for web purchases, which handles payments, subscription management, tax compliance and invoicing; and Apple and Google via RevenueCat in the mobile apps — error monitoring and product analytics providers. They may process personal information only on our instructions and for the purposes we specify.

Legal recipients. Law enforcement, regulators, courts or other parties where we reasonably believe disclosure is required by law or legal process, or is necessary to protect the rights, safety or property of any person.

Successor entities. If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal information may be transferred as part of that transaction, subject to this policy or a successor policy with equivalent protections.

We do not sell personal information and we do not rent it to third parties.

5. Retention

We keep account, assessment and training data for as long as your account is active. If you delete your account or ask us to delete your data, we remove or irreversibly anonymise it within 30 days, except where we must keep records to meet legal, tax, accounting or fraud-prevention obligations, or to resolve disputes. Backup copies are purged on their ordinary rotation schedule.

6. Cookies and analytics

We use cookies and similar technologies that are strictly necessary to sign you in and keep your session secure, and a limited set of first-party product analytics events to understand which features are used. We do not use third-party advertising cookies or cross-site tracking for advertising purposes.

You can block or delete cookies in your browser settings; strictly necessary cookies cannot be disabled without breaking sign-in. We honour Global Privacy Control signals where applicable law requires it.

7. Your rights and choices

Depending on where you live, you may have the right to access the personal information we hold about you, correct inaccurate information, request deletion, obtain a portable copy (export), object to or restrict certain processing, withdraw consent, and not be discriminated against for exercising these rights.

You can update your profile and assessment answers in the app at any time. To make any other request, contact us at frayerathletics@gmail.com. We will verify your identity by reference to the email address on your account before acting, and we respond within the period required by applicable law. You may use an authorised agent where the law allows, and you may appeal a refused request by replying to our decision.

Marketing opt-out. Every marketing email includes an unsubscribe link, and you can opt out at any time by writing tofrayerathletics@gmail.com. We will still send essential service and billing messages.

8. Security

We use encryption in transit, encryption at rest for stored data, row-level access controls so that each account can reach only its own records, private file storage with short-lived signed links, and least-privilege access for staff. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities where the law requires.

9. Children

The Service is not directed to children and is intended for users aged 18 and over. We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, contact frayerathletics@gmail.com and we will delete it.

10. International transfers

We operate from the United States and our providers may process personal information in the United States and other countries whose data protection laws differ from those where you live. Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with the UK Addendum.

11. Changes to this policy

We may update this policy as the Service changes. We will post the revised version with a new effective date and, for material changes, notify you by email or in the app before the change takes effect. Continued use after the effective date means you accept the updated policy.

12. Contact us

Patrick Frayer
21416 Coastal Gateway Blvd, Gulf Shores, AL 36542
frayerathletics@gmail.com