Privacy policy
Your information, handled with care.
This policy explains how the operator of the AMS Athlete Management System (we, us or AMS) manages personal information. Your organisation—such as a club, school, university or performance program—may also have its own privacy policy because it decides how its staff use AMS.
Last updated 3 September 2026
1. Information we handle
Depending on how you use AMS, we may collect and hold:
- Identity and contact details, including your name, email address, phone number, date of birth, organisation, squad, sport, team and position.
- Account and access information, including account identifiers, roles, memberships, invitations, sign-in records and workspace preferences.
- Health and other sensitive information, including injuries, illnesses, medical notes, treatment and rehabilitation details, menstrual-status information, wellbeing check-ins, sleep, soreness, stress, fatigue and mood.
- Training and performance information, including programs, attendance, session logs, training load, body-mass measurements, test results, survey responses, athlete and coach notes, and adjustments.
- Calendar and booking information, including availability, event times and locations, connected-calendar account details, imported events and guest booking contact details. For coach calendars, AMS is designed to import busy times without retaining event titles or descriptions.
- Technical information, such as authentication cookies, device and browser information, IP address, request logs, diagnostics and basic usage or performance data.
Health information is sensitive information. We collect it only where permitted by law, including with consent where required, and only when reasonably necessary for the service or your organisation’s activities.
2. How we collect and hold information
We usually collect information directly from you when you create an account, complete a check-in or survey, log training, make a booking, connect a calendar, upload a file, or contact us. We may also receive it from authorised coaches, administrators, medical or performance staff, your organisation, connected Google or Microsoft calendars, ICS calendar publishers, and other users who record information as part of managing a squad.
If you provide information about someone else, you must be authorised to do so and should ensure they understand how it will be handled. If required information is not provided, some AMS functions may not work or your organisation may be unable to manage your participation.
AMS uses essential cookies and similar browser storage to keep you signed in, protect sessions and remember preferences. We do not use this information for third-party advertising.
3. Why we use and disclose information
We use personal information to provide, secure, maintain and improve AMS; authenticate users; manage organisations, squads and permissions; plan and deliver training; monitor availability, wellbeing and performance; coordinate bookings and calendars; communicate with users; investigate misuse; comply with law; and protect people, AMS and participating organisations.
Information is disclosed only as reasonably required for those purposes, including to authorised staff and athletes within the relevant organisation, to service providers that host or support AMS, to connected calendar providers at your direction, to professional advisers, or where required or authorised by law. Role-based access is intended to limit information to people who need it, but your organisation controls its user access and is responsible for assigning appropriate roles.
Readiness scores, trend bands and alerts support human review. They are not medical advice, injury predictions or solely automated decisions about an athlete’s rights or participation. Coaches and qualified health professionals should apply their own judgement.
We do not sell personal information or use health information for targeted advertising.
4. Storage, security and overseas recipients
Information is stored electronically using contracted hosting, authentication, database, deployment and monitoring providers. We use reasonable technical and organisational safeguards, including access controls, encrypted connections, protected credentials, audit-oriented records and separation of user roles. No online service can guarantee absolute security; please tell us promptly if you suspect unauthorised access.
Some providers, including Supabase, Vercel, Google and Microsoft, may process or store information outside Australia. The countries involved can vary according to the provider, your organisation’s configuration and the connected service. They may include the United States and other countries in which those providers or their subprocessors operate. Before making a cross-border disclosure, we take reasonable steps required by Australian Privacy Principle 8 or rely on an applicable legal exception.
We keep information only for as long as needed for the purposes above, to meet legal or contractual obligations, resolve disputes and maintain necessary records. Retention periods can also be set by your organisation. When information is no longer required, we take reasonable steps to delete it or de-identify it, subject to backups and lawful retention requirements.
5. Your choices and rights
You may ask to access personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also ask about withdrawal of consent, deletion or restriction of information. These rights are subject to applicable law, safety considerations and legitimate record-keeping requirements.
You can update some profile details in AMS. For other requests, contact your organisation administrator first; they can correct operational records or send the request to the AMS privacy contact identified in your organisation’s AMS agreement or account invitation. We may need to verify your identity and clarify the scope of your request. We will respond within a reasonable period and, if access or correction is refused, provide written reasons and available complaint options where required by law. We do not charge for correction requests.
If you are under 18, a parent or guardian may make a request for you where appropriate. We consider your maturity, capacity, safety and applicable law when handling information and requests involving young people.
6. Questions and complaints
Send a privacy question, access or correction request, or complaint to your organisation administrator or to the AMS privacy contact named in your organisation’s AMS agreement or account invitation. Include your name, organisation, preferred contact details and enough information for us to understand the issue, but do not send detailed health information by ordinary email.
We will acknowledge a privacy complaint and aim to provide a substantive response within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner. The OAIC generally asks that you complain to us first and allow 30 days for a response.
7. Changes to this policy
We may update this policy when AMS, our providers or legal obligations change. The current version will be published here with its effective date. We will provide additional notice where a change materially affects how we handle information.