Baseline Tennis Academy — Privacy Policy
Data controller: Baseline Tennis Academy, 40 Bargate Road, Harare, Zimbabwe
Data-protection and privacy contact: simon@bta.co.zw
Last updated: 19 August 2026
This policy is written with reference to Zimbabwe's Cyber and Data Protection Act [Chapter 12:07] ("the Act").
1. Who we are and the scope of this policy
1.1 Baseline Tennis Academy ("the Academy", "we", "us", "our"), of 40 Bargate Road, Harare, Zimbabwe, is the data controller for the personal information described in this policy. We decide why and how that information is processed.
1.2 This policy explains what personal information we collect through our booking application and associated services (the "Platform"), why we collect it, who we share it with, how long we keep it and the rights you have under the Act.
1.3 This policy covers the information of both child members and adult players. It applies to you as an account holder (a parent or guardian, or an adult player) and to the members you manage.
1.4 Our contact point for any privacy question, for exercising your rights, and for data-protection or breach matters is simon@bta.co.zw.
2. Children's data and guardian consent
2.1 Many of the members booked through the Platform are children. We treat children's information as sensitive and handle it with particular care.
2.2 Children do not hold accounts and cannot log in. Only the parent or guardian holds an account. The parent or guardian creates, edits and deletes each child member's record and controls all bookings for that child.
2.3 This parent- or guardian-controlled model is our consent mechanism for children's data. By adding a child as a member and managing that child's record, the account holder confirms that they are the child's parent or legal guardian and consents, on the child's behalf, to the processing described in this policy. At sign-up the account holder also accepts this policy through the statement "By creating an account you agree to the Terms of Service and Privacy Policy".
2.4 To hold an account you must be at least 18 years old.
3. Lawful basis for processing
3.1 We rely on the following bases under the Act, as applicable:
- Consent — the account holder's consent given at sign-up and, for a child's information, the guardian consent described in section 2. Consent may be withdrawn (see section 9), including by deleting the account.
- Performance of the service you request — processing needed to create your account, place and manage bookings, build rosters and run the activities you book.
- Legitimate interests / legal obligations — keeping accurate operational and accountability records (such as attendance history and audit logs) and meeting our obligations under the Act, balanced against your interests.
4. What information we collect and why
The table below lists the categories of information the Platform holds. We do not collect data categories beyond those listed.
| Information | Whose | Why we hold it | Who can see it |
|---|---|---|---|
| Account holder details: email, first and last name, phone number, country code, photo URL, membership type, home club | Parent / adult player | Account identity, contact, and scoping bookings to your family | You (your own record); Academy admin staff |
| Login identity: your email and the one-time sign-in codes sent to it (held by our authentication provider), and the link between your login and your account. The app has no passwords — signing in always uses a one-time email code, with optional Face ID / fingerprint unlock on your device | Account holder | To sign you in and confirm your email address | Handled by the authentication provider; our systems verify access tokens |
| Member details: first and last name, date of birth, playing level, school attended, ranking, photo URL, member flags | Child member or adult player | Age- and level-appropriate placement, school-based booking, and rosters | The managing account holder; Academy admin staff |
| Booking history: bookings and each member's participations, status, timestamps and cancellations | Members | Enrolment, capacity management, attendance and rosters | The managing account holder (own family only); admin staff |
| Session and scheduling data: series and instances, times, club or school, coach assignments | (Operational, not personal to you) | Scheduling and capacity | Customers see information free of others' personal data; admin sees all |
| In-app notifications: recipient, type, title, body, read status | Account holder | Booking and announcement messages shown in the app | The recipient; admin staff for staff notifications |
| Device records: a push-notification token, platform, a biometric-enabled flag, last-seen time | Account holder's device | Retained for possible future push notifications; no push notifications are sent today | Academy admin / system |
| Coach profile: name, coach level, photo, biography and coaching-since date shown publicly; email, phone and date of birth held for admin only | Coaches | Public coach directory; staff administration | Customers see only the public fields (name, level, photo, bio, coaching-since); contact details are admin-only |
| Staff (portal user) details: name, email, phone, role and login link | Academy staff | Portal login and role management | Admin |
| Audit log: who did what, with before/after snapshots of changed records | System accountability | To keep an accountability trail of sensitive changes | Admin / system. Note: snapshots may contain copies of personal information — see section 7 |
| Scheduling-conflict notes (free text written by admin about sessions) | Operational | Recording how scheduling conflicts were resolved | Admin |
| Public images: sponsor logos and club photos | Not personal to members | Marketing and partner content | Public |
| Biometric sign-in (Face ID / Touch ID / fingerprint) | Account holder's device | Optional convenience sign-in and confirming irreversible actions | On the device only — no biometric data ever reaches our servers. The device's operating system performs the match; the app never reads or transmits biometric templates |
| Session tokens on your device | Account holder's device | Keeping you signed in | The device only; tokens are never logged |
4.1 What we do not collect. We do not collect medical, allergy, health or emergency-contact information; we hold no free-text "notes about a child"; we do no location tracking; and we use no advertising identifiers.
4.2 No analytics or tracking. We use no analytics, tracking, advertising or crash-reporting services.
4.3 No payment data. The Platform takes no payment and stores no card, price or payment information. Payment is arranged offline with the Academy.
5. Photographs and media (opt-in)
5.1 Where we wish to photograph or film a child member, or use a child's photograph within the app or in Academy marketing, we will ask for the parent or guardian's opt-in consent for that specific child. Consent is not assumed: where no opt-in has been given, we will not use the child's image for these purposes.
5.2 The in-app photo and media consent step is being introduced. Until it is available in the app, media consent for a child is arranged with the Academy directly, and any withdrawal of consent is honoured by the Academy.
6. Who processes your information (service providers)
6.1 We use a small number of reputable service providers to run the Platform. They process information only on our instructions and for the purposes below.
| Provider | Role | Information involved |
|---|---|---|
| Supabase | Database, authentication and file storage | All account, member, booking and related data above; login emails and one-time sign-in codes; public image files |
| Railway | Hosting our application programming interface (the service the apps talk to) | All traffic to the service, including personal information in transit and processing |
| Cloudflare | Content delivery and edge protection in front of our services | Traffic details such as IP addresses, and cached responses |
| Resend | Sending transactional email | For a welcome email: your email and first name. For class-reminder emails: your email, the member's and account holder's names, and the class name and time |
6.2 Cross-border processing. Some of these providers process information on servers outside Zimbabwe. We use reputable cloud providers and rely on their security safeguards. Where information is transferred outside Zimbabwe, we rely on the conditions for cross-border transfer permitted under the Act.
6.3 Our authentication provider (Supabase) also sends the one-time sign-in code emails and is, to that extent, an email processor.
6.4 We use no other third parties: no analytics providers, no advertising networks, no payment processors and no mapping services.
7. Retention — how long we keep information
7.1 We keep information as follows:
| Information | Retention |
|---|---|
| Anonymised booking and participation history (after an account is deleted, or in the ordinary course) | Kept indefinitely in anonymised form, so that historical rosters and attendance records stay accurate |
| Scrubbed account and member rows (identifying fields removed on deletion) | Kept indefinitely in scrubbed form; there is no scheduled purge |
| Audit logs | Kept for 2 years |
| Notifications and operational records | Kept for the life of the account and, in anonymised form, thereafter as above |
7.2 When you delete your account, your directly identifying information is removed promptly as described in section 8. What remains is anonymised history that can no longer identify you or your members.
7.3 Audit-log residual snapshots. The audit log's before/after snapshots may contain copies of personal information captured before an account was scrubbed. A step to redact those snapshots on account deletion is being introduced. Until it is in place, such residual snapshots remain within the 2-year audit-log retention window and are removed when that window expires.
8. Deleting your account (how it works)
8.1 You can delete your account at any time from within the app. Deletion is immediate and irreversible. It is carried out in a single operation as follows:
- Your account record is scrubbed, not deleted. Your first and last name are replaced with "Deleted Account"; your email, phone, country code, photo link and login link are removed; and the record is marked as deleted.
- Every child member's record is scrubbed. Names are replaced with "Deleted Member"; date of birth, photo and school link are removed; and the record is marked as deleted.
- Future bookings are cancelled, which releases those places to others. Past participations are kept but now point to the anonymised member records, so past rosters keep their integrity.
- Your login is deleted from our authentication provider. Even if that step does not complete, your account is already unusable because the link to it has been removed.
- You are signed out.
8.2 The overall effect is that your and your members' identifying information is removed, while booking history survives only in anonymised form.
9. Your rights under the Act
9.1 Subject to the Act, you have the right to:
- be informed about how we use your and your members' information (this policy);
- access the information we hold about you and your members;
- ask us to correct information that is inaccurate or incomplete;
- ask us to delete information — including by deleting your account, which removes identifying information as described in section 8;
- withdraw consent you have given, including consent for a child's data and any photo/media opt-in; and
- object to or restrict certain processing.
9.2 To exercise any of these rights, contact simon@bta.co.zw. You also have the right to lodge a complaint with Zimbabwe's supervisory authority, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).
10. Keeping information secure
10.1 We design the Platform to be private by default. Each account can access only its own family's information; access controls are enforced on our servers, so one family cannot see another's records. Personal information is not written to our logs, biometric data never leaves your device, and access to information is limited to what each role needs.
10.2 No system can be guaranteed completely secure, but we take reasonable technical and organisational measures appropriate to the sensitivity of the information, including that of child members.
11. Data-breach notification
11.1 If a personal-data breach occurs, we will assess it and, where the Act requires, notify the supervisory authority and affected individuals. Our designated data-protection and breach contact is simon@bta.co.zw.
12. Previous system (Bubble) and legacy data
12.1 The Platform was migrated from a previous system built on Bubble. Imported records retain a copy of the original data for continuity.
12.2 The previous Bubble system is being decommissioned. It is kept available for about one month after go-live as a fallback for testing, and is then shut down and its hosted data deleted. Legacy-system data is therefore deleted within about a month of migration.
13. Marketing and notifications
13.1 At launch we send transactional email only — a welcome message when you sign up and reminder emails before a booked class. We do not send marketing or newsletter email.
13.2 We do not send push notifications at launch.
13.3 If in future we wish to send marketing communications or push notifications, we will update this policy and, where the Act requires, obtain your consent (an opt-in) first.
14. Changes to this policy
14.1 We may update this policy from time to time, for example when the Platform changes or to meet legal requirements. When we make a material change we will make the updated policy available in the app and on our website and update the date at the top.
15. Contact
Questions about this policy, or requests to exercise your rights, may be sent to simon@bta.co.zw, or by post to Baseline Tennis Academy, 40 Bargate Road, Harare, Zimbabwe.