AT A GLANCE
Sherpa provides business-to-business sports intelligence services. We do not sell personal information. We do not use Customer Data to train shared or generally available AI models unless the Customer expressly opts in through a separate written agreement. Schools and other Customers generally control the records they place in Sherpa.
Scope and Who We Are
This Privacy Policy explains how Sherpa Clouds Inc., doing business as Sherpa Sports AI ("Sherpa," "we," "us," or "our"), collects, uses, discloses, and protects personal information through sherpasports.ai, our hosted platform, applications, APIs, demonstrations, events, sales and support interactions, and related services (collectively, the "Services"). This Policy applies to website visitors, prospects, customers, organizational administrators and users, athletes, student-athletes, recruits, agents, coaches, staff, partners, and other people whose information is processed through the Services. It does not apply to third-party products or websites governed by their own privacy notices. Customer-controlled data. When a school, team, league, agency, club, employer, or other organization ("Customer") submits or connects personal information to the Services, Sherpa generally processes that information on the Customer's behalf as a service provider or processor. The Customer determines the purposes and means of processing and is the appropriate first contact for requests concerning those records. Our contract, Data Processing Addendum ("DPA"), FERPA terms, or other signed agreement controls if it conflicts with this Policy. Sherpa-controlled data. Sherpa acts as a business or controller for information used to operate our website and business, manage accounts and contracts, market the Services, secure our systems, and comply with law.
Personal Information We Collect
2.1Information You or a Customer Provides
- Account and contact information, such as name, work email, phone number, title, organization, team, role, username, authentication details, and administrator settings.
- Athlete, student-athlete, recruit, roster, and scouting information, such as biographical details, school and team affiliations, position, measurements, eligibility status, academic or recruiting records, evaluations, notes, communications, video references, performance data, and roster history.
- Contract, NIL, agency, and financial operations information, such as deal terms, contract documents, payment or commission records, budgets, scholarship data, approvals, audit trails, and compliance records. Full payment-card numbers should be processed by designated payment providers, not stored in ordinary Sherpa fields.
- Support, sales, and communication content, including demo requests, messages, meeting details, feedback, survey responses, and support tickets.
- Inputs, files, prompts, and other content submitted to AI-enabled features, together with generated responses and user feedback on those responses.
2.2Information Collected Automatically
- Device and network information, such as IP address, browser, operating system, device identifiers, language, approximate location derived from IP, and referring URLs.
- Usage and log information, such as pages viewed, features used, clicks, timestamps, session activity, API requests, authentication events, error logs, and security telemetry.
- Cookie and similar-technology data used for essential functionality, preferences, analytics, security, and—where enabled and legally permitted—business marketing measurement.
2.3Information from Other Sources
- Customer-authorized integrations and data providers, including scouting, video, performance, academic, compliance, CRM, communications, identity, accounting, payroll, and other systems selected by the Customer.
- Publicly available sources and licensed sports-data providers, subject to applicable terms and law.
- Partners, event organizers, referral sources, and business contacts. We may combine information from these sources and treat the combined information as described in this Policy.
How We Use Personal Information
- Provide, configure, operate, maintain, support, and improve the Services.
- Authenticate Users, manage permissions, connect integrations, synchronize data, and fulfill Customer instructions.
- Generate Customer-requested analytics, summaries, recommendations, alerts, forecasts, classifications, and other AI-assisted outputs.
- Process transactions, administer contracts, invoice Customers, and manage business relationships.
- Respond to inquiries, provide demonstrations and support, deliver service communications, and personalize Customer experiences.
- Monitor reliability, troubleshoot, measure performance, prevent fraud and abuse, investigate incidents, and protect people, data, and systems.
- Comply with law, enforce agreements, establish or defend legal claims, respond to valid process, and support audits.
- Send business marketing communications where permitted. Recipients may unsubscribe from promotional email; operational or contractual messages may continue.
- Create de-identified or aggregated information for analytics, benchmarking, security, and product improvement, using reasonable measures designed to prevent re-identification. Where required, our legal bases may include performance of a contract, legitimate interests, compliance with legal obligations, protection of vital interests, and consent. We do not use Customer Data to train shared or generally available AI models unless the Customer expressly opts in through a separate written agreement.
Artificial Intelligence and Automated Processing
Sherpa's AI features may analyze Customer-authorized data and User instructions to produce recommendations, summaries, rankings, forecasts, draft language, and other outputs. We process Inputs and Outputs to provide and secure the requested feature, maintain appropriate logs, investigate misuse, and improve the Customer's configured Services. AI outputs are probabilistic and may be inaccurate, incomplete, outdated, or biased. Sherpa does not intend its AI features to make final decisions about recruiting, admission, eligibility, scholarships, employment, compensation, contracts, health, safeguarding, or legal compliance. Customers must establish appropriate human review, validation, notices, permissions, appeal processes, and recordkeeping for their use cases. We do not use education records, athlete profiles, contracts, scouting notes, or other Customer Data to train a shared foundation model or generally available model without the Customer's express written optin. A Customer-specific configuration or retrieval process does not change ownership of Customer Data.
How We Disclose Personal Information
We may disclose personal information only as described below:
- Customers and authorized Users. Information is made available according to Customer instructions, account permissions, and organizational roles.
- Service providers and subprocessors. Vendors may provide cloud hosting, AI infrastructure, identity, security, analytics, communications, customer support, e-signature, payment, and professional services. They are contractually restricted to authorized purposes and appropriate safeguards.
- Customer-selected integrations. We exchange information with third-party systems that a Customer or User authorizes. Those third parties' own notices may apply.
- Professional advisors and business partners. We may share information with auditors, insurers, attorneys, accountants, and partners subject to confidentiality obligations.
- Legal and safety purposes. We may disclose information when reasonably necessary to comply with law or valid legal process; protect rights, safety, and security; investigate misuse; or enforce agreements.
- Corporate transactions. Information may be transferred in connection with a merger, financing, reorganization, bankruptcy, acquisition, or sale of assets, subject to appropriate confidentiality and applicable law.
- At your direction or with consent. We may disclose information for another purpose that is disclosed when information is collected or that you or the Customer authorizes. Sherpa does not sell personal information for money. Sherpa does not knowingly sell or share personal information of individuals under 16 for cross-context behavioral advertising. If our practices change in a way that creates a legal right to opt out, we will provide the required notice and mechanism before that use.
Cookies and Similar Technologies
We use essential technologies for authentication, security, session continuity, preferences, load balancing, and core functionality. We may use analytics technologies to understand website and product usage. We may use marketing technologies on public website pages where permitted, but not to target advertising based on education records or Customer-controlled athlete data. Where required, a consent manager will allow visitors to accept or reject non-essential technologies. Browser settings can also limit cookies, but disabling essential technologies may impair the Services. We honor legally required opt-out preference signals, such as Global Privacy Control, where they apply to our processing.
Student Records and FERPA
When Sherpa receives education records from an educational agency or institution under FERPA's schoolofficial exception, Sherpa acts to perform an institutional service or function for which the institution would otherwise use employees; remains under the institution's direct control regarding use and maintenance of those records; uses records only for the purpose for which they were disclosed; and does not redisclose them except as authorized by the institution or permitted by law. The educational institution determines legitimate educational interests, provides required notices, manages consent where needed, and controls access to education records. Students and parents should generally direct access, correction, or deletion requests involving institution-controlled records to the institution. Sherpa will reasonably assist the institution in responding. Sherpa will not use education records for targeted advertising, build advertising profiles of students, sell education records, or use them to train shared or generally available AI models without a legally sufficient separate written authorization.
Children and Minors
The public website and independently registered Services are not directed to children under 13, and we do not knowingly collect personal information online directly from a child under 13 without legally sufficient authorization. A school or organization may authorize use in an educational context only where applicable law permits and required notices and consents have been provided. Where COPPA applies, Sherpa and the Customer will allocate responsibilities in a written agreement. Sherpa will collect only information reasonably necessary for the authorized educational purpose, will not condition participation on unnecessary collection, will not use children's information for targeted advertising, and will retain it only as long as necessary for the authorized purpose or legal obligations. A parent or guardian who believes a child submitted information outside an authorized school deployment may contact privacy@sherpaclouds.com. We may need to verify identity and coordinate with the relevant institution before acting.
Sensitive Information
Depending on Customer configuration, the Services may process information treated as sensitive under applicable law, including precise identifiers, financial details, student records, account credentials, or information concerning health or biometrics. Customers must not enable collection of sensitive information unless necessary, authorized, and configured with appropriate safeguards and consent. Sherpa does not infer or use sensitive personal information to discriminate unlawfully. The Services are not designed to store protected health information subject to HIPAA unless Sherpa and the Customer have signed a Business Associate Agreement. Biometric identification or verification features may be used only if expressly included in a signed agreement and legally required notices and consent mechanisms are implemented.
Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, meet contractual commitments, maintain security and audit records, comply with law, resolve disputes, and enforce agreements. Retention depends on the type of information, Customer instructions, sensitivity, operational need, legal requirements, and third-party licensing restrictions. Customer Data is retained during the subscription and for the export period stated in the applicable agreement. If the agreement is silent, Customers may request export before termination or within 30 days afterward, after which Sherpa may delete Customer Data from active systems according to standard deletion cycles unless law requires retention. Encrypted backups are isolated from ordinary use and deleted or overwritten according to backup schedules.
Security
Sherpa maintains administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit and at rest, authentication controls, logging, vulnerability management, personnel confidentiality, incident response, and business-continuity measures appropriate to the risk. No system is completely secure, and we cannot guarantee absolute security. Customers are responsible for configuring permissions, protecting credentials, reviewing integrations, and promptly disabling unnecessary access. Suspected security incidents should be reported to security@sherpaclouds.com. Contractual security and incident-notification obligations are set out in the applicable agreement, DPA, security exhibit, or SLA.
International Data Transfers
Sherpa and its service providers may process information in the United States and other countries where they operate. Where required, we use lawful transfer mechanisms and supplementary safeguards, which may include standard contractual clauses, data-transfer addenda, and security measures. Customers may request applicable transfer documentation through privacy@sherpaclouds.com.
Privacy Rights and Requests
Depending on where you live and subject to legal exceptions, you may have rights to confirm processing; access, correct, delete, or obtain a copy of personal information; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive information; withdraw consent; and appeal a denied request. We will not unlawfully discriminate against you for exercising a privacy right. To submit a request concerning Sherpa-controlled information, email privacy@sherpaclouds.com with the subject “Privacy Request” and describe the right you wish to exercise. We may verify identity and authority, request additional information, or use an authorized-agent process. If we deny a request, you may appeal by replying with the subject “Privacy Appeal.” You may also contact the relevant regulator or attorney general where applicable. For Customer-controlled records, including education, roster, recruiting, contract, and organizational records, contact the Customer that collected or provided the information. Sherpa will forward or support requests as required by our agreement and law, but we generally cannot override a Customer's lawful instructions.
U.S. State Privacy Disclosures
During the preceding 12 months, Sherpa may have collected the categories described in Section 2; used them for the purposes in Sections 3 and 4; and disclosed them to the recipient categories in Section 5. These categories may include identifiers, customer records, commercial information, Internet or network activity, approximate geolocation, professional or employment information, education information, audio or visual information, inferences, and sensitive information when a Customer configures such processing. We do not sell personal information for money. We do not knowingly use Customer-controlled education records, athlete profiles, or data from children for cross-context behavioral advertising. California and other state residents may exercise applicable rights through Section 13. We will disclose any legally required metrics, financial incentives, or materially different practices if they become applicable.
Business Communications
We may use business contact information to send product information, event invitations, newsletters, and other communications relevant to your professional role, where permitted. You may opt out through the unsubscribe link or by emailing privacy@sherpaclouds.com. Opting out does not stop account, security, billing, contractual, or other non-promotional messages.
Changes to This Policy
We may update this Policy to reflect changes in the Services, law, or our practices. We will post the revised Policy with an updated date and provide additional notice of material changes where required. Material changes affecting Customer-controlled information will be handled consistently with the applicable agreement and DPA. Archived versions will be retained as reasonably necessary to document our practices.
Contact Us
Privacy questions and requests: info@sherpaclouds.com Sherpa Clouds Inc. d/b/a Sherpa Sports AI United States