Privacy Policy
Virtual Clerk of Course™ · Last updated: August 2026
Overview
Virtual Clerk of Course ("the app", "we") — a registered trade name of OneNerdyCrafter LLC, an Arizona limited liability company — is a paperless meet results viewer for competitive swim meets. The data displayed in this app is official swim meet results data maintained by your host organization in Google Sheets — the same data available through the Meet Mobile App and managed via HY-TEK Meet Manager.
What Data We Access
- Google Sheets data — meet results, event listings, and session schedules maintained by your organization. This data is the same publicly available results distributed via Meet Mobile and HY-TEK.
- Scratch requests and check-ins — if you submit a scratch, intent-to-scratch, or check-in request through the app, your name, team, event, and (optionally) email are written to the organization's Google Sheet. This information is provided voluntarily.
- IP address (scratch/check-in submissions only) — when you submit a scratch, intent-to-scratch, or check-in request, we record the IP address of the submitting device alongside that request. It is used to help meet officials detect duplicate or fraudulent submissions, and it is treated as private — hidden from other viewers and shown only to verified meet admins. Admins may resolve an IP to an approximate (city/region/country) location for that same review; this approximate location is derived via the third-party service ip-api.com and is not precise or GPS-based.
- Google account (admins only) — Meet Bosses and Meet Clerks sign in via Google OAuth. We receive your name and email address from Google solely for authentication and access-control purposes.
- Google account (signed-in viewers) — Viewers who sign in to sync their favorite swimmers or opt into notifications share their name and email address from Google. We use the email to store your favorites and notification sign-ups under your account and, if you opt in, to send the email alerts you request. If you also opt into text alerts you provide your mobile number (see "Text Message (SMS) Notifications" below). Signing in is optional — viewing meet results never requires an account.
- Location — "Meets Near Me" (optional) — to show meets close to you, the app may access your device's location only when you grant permission, or you can type an address or ZIP code instead. Your location is used on your device to sort meets by distance and is not stored on our servers; an address you type is sent to our geocoding service (Google) solely to convert it to coordinates. Meet venue locations (the pool's address/coordinates) are stored to power the meet list and the "near me" sorting — these are public venue details supplied by the meet's organizer, not personal data about you.
What We Do NOT Collect
- Passwords — authentication is handled entirely by Google OAuth.
- Payment card or banking details — Meet Boss subscription payments are processed by our Merchant of Record, Paddle. Virtual Clerk of Course never receives or stores your card information; we only learn whether an account has an active subscription.
- Your device location without permission — the "Meets Near Me" feature accesses your device's location only when you explicitly allow it (or you can enter an address/ZIP instead), and it is never stored on our servers. We do not track or store your GPS location otherwise. (We do record the IP address of scratch/check-in submissions and may derive an approximate city-level location from it for meet admins — see "What Data We Access" above.)
- Tracking cookies or cross-site advertising identifiers.
- Favorites of viewers who are not signed in — if you star swimmers without signing in, those favorites are stored only on your own device and are never sent to or stored on our servers. Favorites sync to your account only when you sign in.
- Any data from viewers who do not sign in or submit a request.
How Data Is Used
- Meet results data is used only to display schedules, psych sheets, heat assignments, and results to users of the app.
- Scratch request data is used only to notify meet officials of a requested scratch or intent-to-scratch. It is written directly to the host organization's Google Sheet and is not processed, stored, or retained by Virtual Clerk of Course separately.
- Admin email addresses are used only to authenticate access and determine role permissions (Manager / Admin / Viewer). Emails are stored in a secure server-side configuration and are never exposed to other users.
- Anonymous usage statistics — when you sign in, we record an aggregate count using a one-way (irreversible) hash of your account identifier. This lets us count how many distinct people use the app and how recently, but it stores no email, name, or identifier that can be traced back to you. It is used only to understand overall usage.
Text Message (SMS) Notifications
Signed-in viewers may optionally opt in to text-message alerts by enabling "Notify Me" in the app, selecting the SMS option, and entering their own mobile number. We collect your mobile number solely to send the swim-meet notifications you requested (such as when a scratch window opens or your event is coming up). Opt-in is per-user and is never a condition of using the app.
Message frequency varies with meet activity. Message and data rates may apply. Reply STOP to any message to unsubscribe, or HELP for help. Messages are delivered through our SMS provider, Twilio, acting solely to transmit the messages you requested.
No mobile information — including your mobile phone number and your SMS opt-in/consent — will be shared with third parties or affiliates for marketing or promotional purposes. We do not sell your mobile information. Text-messaging originator opt-in data and consent are not shared with any third parties or affiliates for any purpose other than delivering the messages you requested (for example, our SMS provider Twilio, acting only to carry out delivery).
Email Notifications
Virtual Clerk of Course sends a small number of emails related to your use of a meet: a confirmation when you submit a scratch or check-in request (and when you cancel one), and a notice to staff when a Meet Boss adds them to a meet (with their role and a sign-in link). These are transactional messages sent to the email address on the request or your account email, and replies are routed to the meet's manager. Signed-in viewers may also optionally opt in to email alerts about swimmers they follow; those are per-user, never a condition of using the app, and can be turned off in Notifications Settings. Email is delivered through our email provider, Resend, acting solely to transmit the messages described here. We do not sell your email address or share it for marketing.
Data Storage
All meet data lives in Google Sheets spreadsheets controlled by the host organization. Authentication tokens for signed-in users are stored locally on your device using platform-secure storage (iOS Keychain / Android Keystore / browser localStorage).
Meet Boss credential storage — when a Meet Boss connects a Google Sheet to Virtual Clerk of Course, the app stores a Google OAuth refresh token server-side in Netlify's secure Blob storage. This token is scoped to per-file Drive access only (https://www.googleapis.com/auth/drive.file), which grants the app access solely to files it created or that you explicitly picked for it — not to anything else in your Google Drive. It is used only to allow Meet Clerks and Viewers to write to the connected spreadsheet on the manager's behalf, without each individual needing Google credentials. The token is stored server-side only and is never exposed in the browser or transmitted to any third party. To revoke this access at any time: Google Account → Security → Third-party apps with account access → remove Virtual Clerk of Course.
Saved favorites — Any signed-in user (regardless of role) can star swimmers to follow them. Your favorited swimmer names are synced across your devices and are associated with your Google account — identified by your email address / Google account ID. This data (swimmer names only, no other personal information) is stored server-side in Netlify Blob storage keyed to your Google account and the meet spreadsheet ID. You may sign out, or use "Delete my data" in the app, at any time to stop syncing and remove it.
Third-Party Services
- Google Sheets API — data is read from and written to spreadsheets you provide. Subject to Google's Privacy Policy.
- Google OAuth 2.0 — used for authentication. Meet Bosses additionally grant per-file Drive access (drive.file), limited to files the app created or that they picked for it; Admins and Viewers grant identity scope (email/profile) only.
- Netlify — hosts the app, serverless functions, and secure server-side Blob storage for owner credentials and viewer favorites. Netlify is SOC 2 Type II certified. Subject to Netlify's Privacy Policy.
- Twilio — delivers opt-in text-message (SMS) notifications. We provide Twilio only the mobile number and message needed to deliver each alert; Twilio does not use it for any other purpose, and your mobile information and SMS consent are not shared for marketing or promotional purposes. Subject to Twilio's Privacy Notice.
- Resend — delivers the transactional and opt-in email described above. We provide Resend only the recipient email address and message needed to deliver it; it is not used for any other purpose or shared for marketing. Subject to Resend's Privacy Policy.
- Paddle (Merchant of Record) — sells and processes optional Meet Boss subscription payments, including sales-tax handling. We share only the subscriber's email to verify an active subscription; card details are handled solely by Paddle. Subject to Paddle's Privacy Notice.
- ip-api.com — when a meet admin reviews scratch/check-in submissions, the submitting IP addresses are sent to ip-api.com solely to resolve an approximate (city/region/country) location for that review. Subject to ip-api.com's terms.
Children's Privacy
Swim meet results and psych sheet data may include the names, ages, and times of athletes including minors. This information is the same data published by the host organization through official channels (Meet Mobile, HY-TEK, heat sheets). Virtual Clerk of Course does not independently collect data from minors. If you are a parent or guardian with concerns about your child's information, please contact the host organization directly.
Your Rights
To remove your Meet Boss credential token from Virtual Clerk of Course's servers: revoke Virtual Clerk of Course in Google Account → Security → Third-party apps, or contact the meet host.
To permanently delete your viewer data (synced favorites and notification sign-ups): in the app, open Settings → Account → Delete my data, or follow the instructions at Delete My Data. You may also contact virtualswimclerkofcourse@gmail.com.
For all other meet data (results, event listings, scratch records), requests should be directed to the organization that hosts your meet's Google Sheet, as Virtual Clerk of Course does not independently control that data.
Contact
Virtual Clerk of Course is a registered trade name of OneNerdyCrafter LLC, an Arizona limited liability company. Questions about this privacy policy can be directed to: virtualswimclerkofcourse@gmail.com