← Back to CompDay

CompDay Privacy Policy

DRAFT — details filled in, but not yet legally reviewed. Do not publish before attorney review.

Effective date: July 18, 2026
Last updated: July 18, 2026

CompDay ("CompDay", "we", "us", or "our"), operated by Cypri Group, LTD, an Illinois limited liability company based in Chicago, Illinois, USA, provides software for managing ski-jumping competitions — including athlete records, equipment control, body measurements, competition scheduling, and results. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices available to you.

Because CompDay handles athletes' body measurements and equipment data, we treat that information as sensitive and hold it to a higher standard of care, even where the law does not strictly require it.


1. Who this policy covers

This policy applies to:

  • Officials and staff who use CompDay to run competitions (equipment controllers, judges, organizers, admins, super-admins).
  • Athletes whose records, measurements, equipment, and results are stored in CompDay.
  • Visitors to CompDay's public/marketing website.

CompDay is primarily used by ski-jumping organizations, clubs, and officials. For athlete data, those organizations typically decide what is collected and why; in many cases we act as a service provider / data processor on their behalf. See "Your rights" for how to exercise data requests.

2. Information we collect

Account information (officials/staff). Name, email address, the authentication provider you use to sign in (Google, Apple, Microsoft, or email magic-link), your assigned role, and division/club association. We do not store passwords — authentication is handled by your chosen provider.

Athlete information. Depending on how an organization uses CompDay, this may include: name, date of birth / age class, club and division, nationality/ federation, FIS or national-body identifiers, body measurements (e.g. height, weight, body length, arm length, inseam), equipment records (skis, bindings, suit), competition entries, equipment-control (EC) measurements and pass/fail results, and competition results.

Usage and device information. Basic technical data needed to operate the service securely and offline — for example device/session identifiers, sync timestamps, and audit logs of who recorded or changed a measurement and when.

Website information. If you visit our marketing site, we may collect standard web analytics (see "Cookies and analytics").

We do not intentionally collect information beyond what is needed to run competitions and operate the service.

3. How we use information

We use information to:

  • Authenticate users and enforce role-based access to data.
  • Record and manage athlete records, equipment, and body measurements.
  • Run equipment control and determine compliance (e.g. BMI/minimum-weight, ski-length, binding, and suit rules) against the applicable FIS rules.
  • Manage competitions, schedules, start lists, and results.
  • Keep an audit trail of measurement records and changes for integrity and dispute resolution.
  • Operate the service offline and synchronize data when connectivity returns.
  • Secure the service, prevent abuse, and comply with legal obligations.

We do not sell personal information, and we do not use athlete measurement data for advertising.

4. Sensitive data and role-based access

Athlete measurement data is personal and sensitive. Access is strictly role-gated:

  • Users only see the data their role and division permit.
  • Some roles (e.g. organizers) see pass/fail outcomes and names but not the underlying measurement numbers.
  • Access changes and account revocations are enforced, and revocation takes effect immediately on the write/access path.

We aim to minimize how much sensitive data any device stores at rest, consistent with the offline nature of comp-day operations.

5. How we share information

We share information only:

  • Within a competition's ecosystem — with the officials, organizations, and federations involved in running the event, as needed for compliance and results, subject to role-based access.
  • With service providers (sub-processors) who host and support CompDay under confidentiality obligations — for example cloud hosting and infrastructure, authentication providers, and email delivery. A current list will be maintained by us and provided on request via the contact below. Current sub-processors include: Amazon Web Services (cloud hosting and infrastructure); Anthropic (AI/assistant tooling used to operate the project); the authentication providers you use to sign in (Google, Apple, Microsoft); and our email-delivery provider. We will keep this list current as vendors change.
  • For legal reasons — to comply with law, enforce our terms, or protect the rights, safety, and integrity of athletes, users, and the service.
  • In a business transfer — if CompDay is involved in a merger, acquisition, or asset sale, subject to this policy.

We do not sell or rent personal information to third parties.

6. Data retention

We retain personal information for as long as needed to run competitions, maintain historical results and audit integrity, and meet legal obligations. Organizations that use CompDay may set their own retention expectations for athlete data; we honor documented deletion requests except where we must retain records (e.g. results integrity or legal requirements).

7. Minors

Ski jumping includes athletes under 18. Where CompDay stores a minor's data, we rely on the organization, club, coach, or parent/guardian — as mediated by the relevant federation or event — to obtain any consent required by law. By entering a minor's data into CompDay, the organization and its officials represent that they have obtained any parental/guardian consent required by applicable law and by the governing federation's rules. We do not knowingly collect data directly from children through the public website. If you believe a minor's data has been provided without proper consent, contact us and we will address it.

8. Security

We use administrative and technical safeguards including role-based access control, authentication via trusted providers (no stored passwords), encryption in transit, audit logging, and least-privilege data caching on devices. No system is perfectly secure, but we treat athlete data with the level of care its sensitivity warrants.

9. Your rights

Depending on where you live (e.g. under GDPR or CCPA/CPRA), you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. Because much athlete data is entered and controlled by the organizations that run competitions, some requests may be directed to that organization. To make a request or ask a question, contact us at jess@compday.io. We will respond as required by applicable law.

10. International users

CompDay may process and store information in the United States. If you access CompDay from another country, you consent to processing there, and we apply appropriate safeguards where required.

11. Cookies and analytics

Our app uses cookies/local storage necessary to keep you signed in and to work offline. Our marketing website may use privacy-respecting analytics cookies to understand aggregate site usage; we do not use advertising cookies or sell any data. The specific analytics provider will be identified here once the marketing site is live, and this section updated accordingly. You can control cookies through your browser settings.

12. Changes to this policy

We may update this policy. We will revise the "Last updated" date and, for material changes, provide a more prominent notice. Continued use after changes take effect constitutes acceptance.

13. Contact us

Cypri Group, LTD
2101 W Summerdale Ave, Chicago, IL 60625, USA
jess@compday.io