Privacy policy
Client records deserve a firm boundary.
What myski.pro handles, why, who it goes to, and the choices available when a record concerns an adult or a child.
Last updated August 18, 2026
1. Scope and roles
myski.pro is a recordkeeping and productivity service for adult ski instructors. This policy covers the app and this website.
For the client records an instructor enters, the instructor is ordinarily the controller (GDPR) or business (CCPA/CPRA): they decide which clients to record, what to write, and how long to keep it. myski.pro is ordinarily the processor or service provider, handling those records on the instructor’s behalf and under their instructions. For an instructor’s own account information, myski.pro is the controller. The exact legal role can vary by jurisdiction and by an instructor’s relationship with a ski school.
The terms governing that processing relationship are in the Data Processing Agreement, which forms part of the Terms. The plain-language Kids & Family Data page is part of our public explanation and should be read alongside section 5.
2. Information we handle
- Instructor account: name, email address or mobile number, password verifier, certification and home-resort details, profile information, and account status.
- Client identity: first and last name, exact age, optional date of birth, gender where entered, mobile number, and internal identifiers.
- Guardian and safety details: guardian name and mobile number, and free-text medical, allergy, dietary, or emergency context the instructor chooses to record.
- Lesson information: date, duration, session label, ability, terrain, drills, strengths, areas to improve, next focus, goals, preferences, confidence and equipment notes, co-instructors, and lesson history.
- Instructor-private fields: tip amount and an instructor’s own “would teach again” judgment. These are never included in shared artifacts.
- Selected media: photos or videos an instructor deliberately attaches.
- Account and technical: authentication tokens, device and app version, diagnostics, support messages, and limited service logs.
- Location: with your permission, the app requests when-in-use location and stores the derived home state or region on your instructor profile. We store that derived region, not a continuous position log — the product does not build route or movement history. You can decline the permission and still use the app.
3. How we use it
- To provide the app: storing, syncing, and retrieving skier profiles and lesson history.
- To authenticate instructors and keep accounts secure.
- To operate instructor-directed sharing (SkiLink) when an instructor chooses to hand off context.
- To respond to support and privacy requests.
- To diagnose failures, prevent abuse, and meet legal obligations.
We do not use client records for advertising, profiling, or scoring, and we do not use them to train machine-learning models.
4. Who it goes to
We do not sell personal information and we do not share it for cross-context behavioral advertising. Personal information reaches only:
- Microsoft Azure — application hosting and database services (sub-processor).
- Apple — app distribution and, where applicable, sign-in and receipt handling, under Apple’s own terms.
- Recipients an instructor chooses — another instructor or a family member, only through a deliberate SkiLink action.
- Legal and safety recipients — where required by law, or to protect a person from harm.
The app ships without third-party analytics, advertising, attribution, or tracking SDKs, and its App Store privacy manifest declares no tracking and no tracking domains.
This list is the complete set of sub-processors. Before we add one, we update this section and the Data Processing Agreement, and the app’s App Store disclosures change with it.
5. Children’s data
A large share of ski lesson clients are minors, so records about children are a normal part of this service. The Kids & Family Data page states these practices in plain language; this section states them formally.
Not directed to children. myski.pro is a professional tool intended solely for adults aged 18 or over. Children do not create accounts, sign in, or otherwise use the app. We do not knowingly permit anyone under 18 to register.
Not an online collection from a child. Information about a minor is entered by an adult instructor in a professional capacity, in the context of an offline lesson relationship. We do not direct the app to children, and we do not collect personal information from children online through the app, within the meaning of the U.S. Children’s Online Privacy Protection Act (COPPA).
App Store positioning. The app is not submitted to, and is not intended for, the App Store Kids Category, and it is designed not to fall within Apple’s App Review Guideline 5.1.4 (Kids) requirements for child-directed apps.
We do not market to children. myski.pro is not advertised, promoted, or otherwise directed to children in any channel, and it will not be. No part of the app or this site is designed to appeal to a child audience. This is a standing commitment, not a description of current practice only.
Parental consent obligation. Instructors must obtain parent or guardian permission before recording information about a minor, and must have any further authority required by their employer, ski school, contract, or local law. This is a condition of use under the Terms.
Rights of parents and guardians. A parent or guardian may request access to, correction of, or deletion of a record about their child by emailing brandonfoster@me.com. We aim to acknowledge within two business days and to complete a verified request within 30 days. We may require reasonable verification of identity, guardianship, or authority, and where the instructor is the controller we may need to route the request through them.
GDPR and GDPR-K. Where the GDPR or UK GDPR applies, processing of a child’s personal data rests on the instructor’s lawful basis as controller, including any consent required under Article 8 for children below the applicable age of digital consent. Special-category data such as health, allergy, or dietary information requires an appropriate Article 9 condition, which the instructor is responsible for establishing.
If we learn that a person under 18 has created an instructor account, we will close it and delete the associated records.
6. Security
Passwords are hashed with Argon2id and are never stored in readable form. Sessions use short-lived access tokens with longer-lived refresh tokens, and tokens are held in the iOS Keychain on device, excluded from iCloud backup. Traffic runs over HTTPS, and database connections are encrypted with certificate validation enforced in production.
Every request is scoped to the authenticated account on the server, so one instructor’s records are not reachable from another instructor’s session. SkiLink share tokens are random 32-byte values stored only as hashes, expire within 24 hours, are use-limited, can be revoked, and can only be created for a record the caller already owns.
No system is perfectly secure. To report a vulnerability, email brandonfoster@me.com rather than filing a public issue.
7. Breach notification
If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, in line with Article 33 of the GDPR. Where the breach is likely to result in a high risk to people’s rights and freedoms, we will also notify the affected individuals without undue delay under Article 34.
Where an instructor is the controller of the affected records, we act as processor: we will notify that instructor without undue delay after becoming aware, and give them the information they need to meet their own notification duties. Where records about children are involved, we will say so explicitly in that notice.
We keep an internal record of breaches, their effects, and the remedial action taken, whether or not notification was required.
8. Retention and deletion
Client records remain until the instructor deletes them or deletes their account — an instructor’s working history is not useful on a timer. Everything else runs to a fixed schedule:
- Account and client records: kept until you delete them or delete your account. On account deletion, removal from the active service completes within 30 days, and normally within seconds.
- Authentication sessions: access tokens expire in 15 minutes and refresh tokens in 30 days. Sessions are cleared on sign-out or account deletion.
- SkiLink share tokens: expire within 24 hours, and are use-limited and revocable.
- Attached photos and video: kept while the record exists, and deleted with it. Deleted media is purged from backups within 90 days.
- Error and service logs: 90 days, then deleted.
- Support and privacy correspondence: 24 months, so we can evidence how a request was handled.
- Backups: rolling, and overwritten within 90 days.
We hold no product analytics or telemetry, because the app collects none.
Authenticated account deletion, performed from inside the app, removes the account credentials and the synced client, guardian, lesson, attachment, SkiLink, and support records under that account from the active service. See Delete Your Account for the exact steps.
An anonymized identity tombstone and limited security, legal, and infrastructure copies may persist where we are required to keep them. Copies held offline on a device, exports, and records already received by another instructor are not retrieved automatically. Signing out or deleting the app does not delete server-side records.
9. Your rights
Depending on where you live, you may have rights to know, access, correct, delete, restrict, object, or receive a portable copy of personal information, and to appeal a refused request. These rights may be exercised by instructors, adult clients, and by parents or guardians on behalf of a child.
The Utah Consumer Privacy Act provides rights to Utah residents. The CCPA/CPRA provides rights to California residents, including the right to confirm that personal information is not sold or shared for cross-context behavioral advertising — we do neither, and we do not offer financial incentives for personal information. The GDPR and UK GDPR provide rights in the EU and UK, including the right to lodge a complaint with a supervisory authority.
Email brandonfoster@me.com. We aim to acknowledge within two business days and to complete verified requests within 30 days, subject to any extension the law allows. We may verify identity or authority first, and we will explain any appeal route that applies.
10. International transfers
Our infrastructure is operated on Microsoft Azure. Where personal data is transferred out of the EEA or UK, we rely on an appropriate transfer mechanism such as the European Commission’s Standard Contractual Clauses together with our hosting provider’s data protection terms. The Data Processing Agreement sets out the transfer terms that apply between an instructor and myski.pro.
11. Changes
If this policy changes we update the date at the top of this page, and we will give more prominent notice for a material change that affects client or family records.
12. Contact
Privacy requests, app support, and questions about this policy all reach us at brandonfoster@me.com.