Privacy Policy

Last updated: 17 July 2026

This Privacy Policy explains how Tatami(“we”, “us”, the “controller”), which operates Tatami(the “Service”), collects, uses, and protects your personal data. We are the data controller for the personal data described here and comply with the UK GDPR and the Data Protection Act 2018.

1. Who we are

Tatami is operated by Tatami. For any privacy question or to exercise your rights, contact us at alexanderizotov225@gmail.com.

2. The data we collect

  • Account data: your name, email address, and password (stored only as a secure hash). If you sign in with Google, we receive your name, email, and profile identifier from Google.
  • Learning data: the club you belong to, your display name, chosen belt, syllabus progress, and flashcard review history.
  • Coach & billing data: if you run a club, the club details you enter and, where you subscribe, billing information processed by Stripe. We store a Stripe customer identifier and subscription status; we do not store your card number.
  • Security & technical data: IP address, browser/device (user-agent), session records, and a log of security-relevant events (sign-in, password or email changes, account deletion). We use this to keep your account secure and to show you your own recent activity.

3. How and why we use your data (lawful bases)

  • To provide the Service — creating your account, running clubs, and tracking progress. Lawful basis: performance of a contract.
  • To keep the Service secure — authentication, rate limiting, and the security audit log. Lawful basis: legitimate interests (protecting users and the Service).
  • To take payment from coaches who subscribe. Lawful basis: performance of a contract and compliance with legal (accounting) obligations.
  • To communicate with you — transactional emails such as password resets and account-deletion confirmations. Lawful basis: performance of a contract and legitimate interests.

We do not sell your personal data, and we do not use it for advertising.

4. Processors we share data with

We use trusted third parties to run the Service. Each processes personal data only on our instructions and under a data-processing agreement:

  • Neon — managed PostgreSQL database hosting (stores your account and learning data).
  • Vercel — application hosting and privacy-friendly, cookieless analytics.
  • Stripe — payment processing for coach subscriptions.
  • Upstash — Redis used for rate limiting (stores short-lived request counters keyed by account or IP).
  • Resend — delivery of transactional emails (where configured).
  • Google — only if you choose to sign in with Google.

Where a processor is located outside the UK/EEA, transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.

5. How long we keep it

We keep your account and learning data for as long as your account is active. When you delete your account, we erase your personal data from our systems, and cancel any active subscription. Some records may persist for a short period in encrypted backups before being overwritten, and we may retain limited billing records where the law requires it.

6. Your rights

Under the UK GDPR you have the right to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased (“right to be forgotten”);
  • data portability;
  • object to or restrict certain processing.

You can exercise the main rights yourself from your account settings: update your name and email, export a machine- readable copy of your data, and permanently delete your account. For anything else, contact alexanderizotov225@gmail.com. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO), ico.org.uk.

7. Children

Judo clubs often include children. Where a member is a minor, the Service is intended to be set up and used with the involvement and consent of a parent, guardian, or the child’s club, who are responsible for that consent under applicable law. If you believe a child’s data has been provided to us without appropriate consent, contact alexanderizotov225@gmail.com and we will delete it.

8. Security

We protect your data with encryption in transit, hashed passwords, scoped database access, session management, and rate limiting. No system is perfectly secure, but we take reasonable and appropriate measures to safeguard your information.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above, and where appropriate we will notify you.

10. Contact

Questions about this policy or your data? Email alexanderizotov225@gmail.com.