GearLocker Privacy Policy
1. Introduction & Scope
GearLocker, LLC (“we,” “us,” or “our”), a Nebraska-based company, operates gearlocker.com and associated applications (collectively, “Services”). This Privacy Policy explains how we collect, use, disclose, and protect personal information. By accessing or using our Services, you consent to this Policy.
2. Applicability
This Policy applies to all users, including students, parents, coaches, and school administrators (“you” or “Users”). If you reside in California, Nebraska, or other jurisdictions with specific privacy laws, additional provisions below apply.
3. Definitions
- “Personal Information” includes identifiers (name, email, student ID), device identifiers, IP addresses, inventory assignments, and usage metadata.
- “Sensitive Data” includes any data that requires special handling under applicable law (e.g., minors’ data).
4. Lawful Bases & Children’s Data
For Users under 13, we process Personal Information under COPPA’s School Exception. Students aged 13–17 are covered under FERPA, treated as school officials. We only use student data for inventory tracking and school administration. Consent for under-13 data is implicitly obtained through schools acting as agents. No separate parental consent is collected by GearLocker.
5. Information We Collect & How
- Data Provide Directly: Names, emails, student IDs, gear assignments entered by school staff.
- Automatically Collected: IP address, device metadata, authentication timestamps, cookies (for session management).
- Third-Party Cookies/Tracking: Marketing cookies (Google Analytics pixels, remarketing). Explicit consent for these via cookie banner.
6. Use of Information & Legal Basis
We use Personal Information for:
- Performing our contract with schools.
- Complying with legal obligations (COPPA, FERPA).
- Legitimate interests: product maintenance, support, fraud detection, security improvements.
- We do not sell or “share” data as defined by CCPA or similar laws.
7. Cookies & Tracking Measures
We distinguish between:
- Essential cookies – Required for functionality/authentication.
- Non-essential cookies – Marketing & analytics; activated post-consent.
- Users may withdraw cookie consent at any time via site settings.
8. Data Sharing & Disclosure
We do not share Personal Information with unaffiliated third parties.
Information may be disclosed to:
- Service Providers under confidentiality obligations (Azure, Auth0, Google Analytics).
- Legal Authorities where required by law (warrants, subpoenas).
- School Authorities: Administrators may access data for their affiliated students.
9. Cross-Border Transfers
All data is stored within the U.S. We may use third-party providers whose infrastructure is U.S.-based only.
10. Security Measures
We employ:
- AES‑256 encryption at rest & TLS 1.2+ in transit.
- Microsoft Entra ID + Auth0 for identity management.
- Role-Based Access Control (RBAC), least-privilege principles.
- Firewalls, intrusion detection, annual pen-tests, and vulnerability assessments.
11. Data Retention & Deletion
We retain user data while the account is active or as required by law. You may request deletion or correction by emailing support@gearlocker.com. We will respond within 30 days, and complete actions within 60 days, verifying your identity as required.
12. Data Subject Rights
You may exercise these rights:
- Access ✔
- Correction ✔
- Deletion ✔
- Restriction of processing ✔
- Opt-out of marketing trackers ✔
Please email requests to support@gearlocker.com, identify yourself, and specify your jurisdiction if requesting additional protections.
13. Third‑Party Service & Subprocessor Disclosures
- Microsoft Azure – Cloud hosting (subprocessor).
- Auth0 – Identity-as-a-Service provider.
- Google Analytics & remarketing providers – Non-essential cookies/processors.
These subprocessors are bound by our confidentiality and data protection terms.
14. Data Breach Notification
In the event of unauthorized access, we will:
- Notify appropriate users and schools within 72 hours of discovery, unless prohibited.
- Report to relevant authorities as required under U.S. statutes and regulations.
15. International & Jurisdictional Compliance
- CCPA/CPRA (California): Right to opt-out of sale, access, deletion, no discrimination for exercising rights.
- Nebraska & U.S. State Laws: Compliance with relevant consumer protections.
- Not subject to GDPR unless we expand to EU, at which point we’ll adopt EU Addendum.
16. Updates to Privacy Policy
We may update this Policy; material changes trigger email notice 30 days in advance. Continued use after changes signals acceptance.
17. Contact & DPO
For questions, privacy concerns, or to lodge complaints, contact support@gearlocker.com or write to:
GearLocker, LLC – Attn: Privacy Team
5429 Betty Lou Blvd, Lincoln, NE 68516
California Privacy Rights: You have the right to know, access, delete, and opt out of sale of your data. GearLocker does not sell data. Contact us for more info.