1. Introduction
This Privacy Policy describes how The Purple Sector("we," "us," or "our") collects, uses, stores, and shares personal information when you use our website and services at thepurplesector.com (the "Service"). Use of the Service is also subject to our Terms of Use.
The data controller for personal information processed through the Service is The Purple Sector LLC, located at 11447 NW 34th Str, Doral, FL, 33178.
For privacy-related questions or requests, contact us at michael@thepurplesector.com.
2. Who This Policy Applies To
This policy applies to members, coaches, visitors, and anyone who creates an account or uses features of The Purple Sector, including sim coaching, live coaching, video reviews, community features, and membership subscriptions.
The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 13, or from anyone under 16. If you believe we have collected such information, please contact us and we will delete it.
3. Information We Collect
Account and profile
When you register, we collect information such as your email address, password (stored hashed by our authentication provider), first and last name, username, profile photo, bio, and onboarding preferences. If you sign in with Google, we receive profile information permitted by Google for authentication.
If you choose to sign in via Discord, you will be asked to authorize the "Join servers for you" permission. By clicking "Authorize" on the Discord screen, you opt-in to automatically joining The Purple Sector community server. We also receive your Discord identity and email address to create and maintain your account.
Coach and application data
Coaches may provide racing background, experience level, languages, pricing, availability, resumes, and related professional information. Coach applications may include additional details submitted during onboarding.
Coaching, bookings, and reviews
We store coaching session requests, scheduling details, session notes, video review uploads and metadata, payment references, and communication related to bookings.
Media and video data
When you submit a video review or upload coaching media, we store raw video footage you upload (for example, onboard or telemetry recordings) in Cloudflare R2 object storage. Processed coach feedback recordings and transcoded playback files are stored and delivered through Cloudflare Stream. We also store related metadata such as file size, duration, stream identifiers, and playback URLs needed to deliver the Service.
Community and messaging
We store posts, comments, direct messages, and uploaded images you choose to share in community and messaging features.
User-generated content in the Community Board is actively moderated by administrators. Users can report inappropriate, abusive, or unlawful content by contacting michael@thepurplesector.com, and we review reports promptly.
Usage and technical data
We collect standard technical information such as browser type, device information, IP address, and logs needed to operate, secure, and improve the Service. All connections to our Service use TLS 1.2 or higher.
4. Cookies and Tracking
We use essential cookies to maintain your login session (via our authentication provider) and to secure the Zoom connection flow (OAuth state). We also use an essential functional cookie named presence_touched_at to throttle coach availability updates when a coach has enabled presence features. This cookie is not used for advertising, analytics, or cross-site tracking.
These cookies are strictly necessary for the operation and security of the Service. We do not use third-party advertising or analytics cookies.
5. Zoom Integration
Coaches (sim coaches and pro drivers) may optionally connect a Zoom account so we can create scheduled Zoom meetings for paid sim or live coaching sessions. This integration is voluntary and limited to coaches who enable it.
Zoom OAuth scopes
When a coach authorizes our Zoom app, we request only the permissions configured in our Zoom Marketplace app. Based on current functionality, these scopes are: meeting:write:meeting, user:read:user, user:read:email.
We use these permissions solely to identify the coach's Zoom account and create scheduled meetings on their behalf after a student completes payment.
Zoom data we receive and store
- Zoom user ID— stored on the coach's profile to link their account.
- OAuth tokens — access token, refresh token, and expiration time stored securely in our database to maintain the connection and create meetings.
- Meeting details — meeting ID, join URL, and host start URL stored on coaching booking records after a session is scheduled.
We call Zoom's /users/me endpoint during connection. Zoom may return an email address for verification; we do not persist the Zoom email address in our database.
What we do not access via Zoom
- We do not record, store, or access meeting audio or video.
- We do not access meeting chat, participant lists, or recordings.
- We do not use Zoom data for advertising, profiling, or surveillance.
- We do not sell or rent Zoom-related personal data.
Disconnecting Zoom
To disconnect Zoom, users can remove the app via their Zoom Account settings. To request manual deletion of Zoom OAuth tokens from our database, please contact michael@thepurplesector.com. Requests are processed within 30 days. Previously created meeting links on past booking records may be retained for support and dispute resolution as described in Section 10.
6. How We Use Your Information
- Provide, operate, and maintain the Service.
- Process memberships, coaching bookings, and video review payments.
- Schedule coaching sessions and send booking confirmations and reminders.
- Create Zoom meetings for coaches who have connected Zoom.
- Facilitate coach payouts through Stripe Connect.
- Send transactional emails about your account, bookings, and application status.
- Enforce our policies, prevent fraud, and protect the security of the Service.
- Improve features and fix technical issues.
We use personal information only for purposes reasonably related to providing and improving the Service as described in this policy and our App Marketplace listing.
7. Legal Bases for Processing (EEA/UK)
If you are in the European Economic Area or United Kingdom, we process personal data under:
- Contract — to provide the Service you request (account, bookings, payments).
- Legitimate interests — to secure, maintain, and improve the Service, subject to your rights.
- Consent — where required, such as optional integrations (e.g., connecting Zoom) or marketing communications if offered.
- Legal obligation — where we must comply with applicable law.
8. Sub-Processors and Third Parties
We share personal information with service providers who process data on our behalf under contractual obligations to provide equal or greater protection for personal data than the protections described in this policy. These include:
Supabase
Authentication, database, file storage, and realtime infrastructure. Stores account, profile, coaching, community, and Zoom token data. See Supabase Privacy Policy.
Stripe
Payment processing for memberships, coaching bookings, and on-demand video reviews. Card and payment method data are collected directly by Stripe via hosted Checkout; we do not store full card numbers on our servers. We store Stripe customer, subscription, and payment intent identifiers. Coaches receiving payouts use Stripe Connect; identity and banking information for Connect is collected directly by Stripe. See Stripe Privacy Policy.
Resend
Transactional email delivery (confirmations, reminders, account notifications). Emails may include your name, session details, and Zoom join links for coaching sessions. See Resend Privacy Policy.
Zoom
Meeting creation and OAuth for coaches who connect Zoom. See Zoom Privacy Statement.
Cloudflare
Video file storage (R2) and video processing and delivery (Stream) for coaching uploads, video reviews, and related media. See Cloudflare Privacy Policy.
Vercel
Cloud hosting and infrastructure for our website and application. See Vercel Privacy Policy.
Other providers
We may use Google and Discord for optional sign-in. Authentication confirmation and password-reset emails are sent through Supabase Auth.
9. Data Sharing
We do not sell or rent your personal information.
We do not use personal information for third-party advertising or to build advertising profiles of Zoom users.
We do not use personal information for surveillance purposes or to assist others in conducting surveillance.
We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition with appropriate safeguards.
10. Data Retention
| Data type | Retention period |
|---|---|
| Account and profile | While your account is active, plus up to 30 days after deletion for backup and fraud prevention. |
| Video uploads and processed feedback | For the life of the review or media record, until you delete the content or your account, subject to backup and legal retention windows described elsewhere in this section. |
| Zoom OAuth tokens | Until you disconnect Zoom (by request) or delete your account. |
| Zoom meeting URLs and IDs | For the life of the booking record, plus up to 12 months after the session for support and dispute resolution. |
| Payment records (Stripe IDs) | As required for accounting, tax, and legal obligations; Stripe retains data per its own policies. |
| Transactional email logs | Up to 30 days via our email provider. |
11. Security
We use industry-standard measures to protect personal information, including encryption in transit (TLS 1.2 or higher), access controls, and secure hosting. OAuth tokens and sensitive credentials are stored in our database and are not exposed in client-side application code.
Data is encrypted at rest at the infrastructure level using AES-256 encryption controls provided by our host, Supabase.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately.
12. Your Rights
Depending on your location, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing.
To exercise these rights, email michael@thepurplesector.com with the subject line "Privacy Request." We will respond within 30 days.
Zoom Data Deletion
Upon a verified deauthorization or account deletion request, we delete Zoom OAuth tokens and the linked Zoom user ID from our active database within 30 days. Historical meeting IDs and join URLs on past booking records may be retained for the periods described in Section 10 (Data Retention) unless you explicitly request their deletion.
Upon verified account deletion request, we will delete or anonymize personal data in our systems, subject to legal retention requirements. Residual data held by sub-processors (Stripe, Resend, Supabase, Cloudflare, Vercel) will be handled according to their policies and our agreements with them.
EEA/UK residents may lodge a complaint with their local data protection authority.
13. Changes and Contact
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Material changes may be communicated by email or in-app notice where appropriate.
Questions about this policy: michael@thepurplesector.com
The Purple Sector LLC · 11447 NW 34th Str, Doral, FL, 33178
