Last updated: May 8, 2026
PRIVACY POLICY
Science of Rowing, LLC (“Science of Rowing”, “we”, “us”, “our”) operates this website and the membership service it provides. We take your privacy seriously. This notice explains what personal information we collect, how we use it, who we share it with, and the rights you have over it.
Questions or requests: joe@scienceofrowing.com.
Who's the data controller
Science of Rowing, LLC is a Kansas limited liability company and is the data controller for the personal information processed through this website and our Memberful membership service. Registered address:
Science of Rowing, LLC
4601 E Douglas Ave, STE 150
Wichita, Kansas 67218
United States
What information we collect
The personal information we hold falls into three buckets:
- Account data:name, email address, country (optional), and Memberful subscription status. Collected when you sign up via Memberful.
- Payment data:handled entirely by Memberful and Stripe. We never see, store, or process your card number, CVV, or full billing details. Memberful gives us back a customer ID and a subscription status; that's all.
- Contact-form data:when you message us via the contact page, we receive your name, email, and message via Resend (our email-delivery provider).
We do not collect: phone numbers, postal addresses, social-media profile data, payment card numbers, browsing behaviour across other sites, or any sensitive personal information (health, biometric, political, religious, race/ethnicity, sexual orientation, precise geolocation).
How we use it
The purposes we process your data for, and the legal bases:
- To deliver the service you signed up for: verify you're a paying member before showing member-only content, process renewals, send transactional account emails. Legal basis: contract performance (UK / EU GDPR Art. 6(1)(b) for UK/EU subscribers; equivalent contractual necessity under US state laws).
- To respond to your contact-form messages: reply to questions, requests, and feedback. Legal basis: legitimate interests (UK / EU GDPR Art. 6(1)(f)).
- To keep the site secure and reliable: short-lived IP-based rate limiting on public APIs (60-second TTL), error tracking via Sentry to catch and fix bugs (no session replay).
- To meet legal obligations:tax and accounting record-keeping, responding to lawful requests from US, UK, and EU authorities. Legal basis: legal obligation.
What we deliberately don't do
- We don't sell or rent your personal information.
- We don't share your information for behavioural advertising.
- We don't run advertising or retargeting cookies.
- We don't share your data with social-media platforms.
- We don't profile you for marketing purposes.
- We don't track you across other websites.
Sub-processors
We use a small number of trusted vendors to operate the site. Each is bound by their own data-processing terms; we share only the minimum data needed for the function they perform.
- Memberful (Drip Holdings, Inc., USA): member accounts, authentication, subscription management. Receives: your name, email, account activity. Privacy policy.
- Stripe, Inc. (USA):payment processing. Receives: payment-card details (never seen by us), billing address, country. Privacy policy.
- Vercel, Inc. (USA):hosting and CDN. Receives: HTTP request logs (IP address, user agent, requested URL) for ~30 days. Privacy policy.
- Resend(Resend Inc., USA): outbound email (contact form, transactional notifications). Receives: name, email, message body for the email we're sending. Privacy policy.
- Anthropic, PBC (USA):Claude is used internally to classify rowing-research articles into research themes from public titles + excerpts. No member data is sent to Anthropic. Privacy policy.
- Sentry (Functional Software, Inc., USA): JavaScript error tracking (no session replay; no PII intentionally collected). Receives: error stack traces, browser version. Privacy policy.
- Upstash, Inc. (USA):Redis-backed rate-limit counters. Receives: IP address (60-second TTL, then deleted). Privacy policy.
International transfers
Science of Rowing is based in the United States. If you're in the United Kingdom, the European Economic Area, or another jurisdiction with data-export rules, your personal information is transferred to the US when you sign up with us. Where required, these transfers rely on the EU-US Data Privacy Framework (where the relevant processor is certified) or Standard Contractual Clauses under UK GDPR Article 46 and EU GDPR Article 46.
How long we keep it
- Active members:your account data is held for as long as your subscription is active, plus 12 months after cancellation (so you can resume without losing your reading history).
- Cancelled accounts (after 12 months): Memberful retains an anonymised audit record for accounting purposes; identifiable account data is deleted.
- Contact-form messages:kept in our editorial inbox for as long as the conversation is ongoing, then archived. You can ask us to delete them at any time.
- Server logs:Vercel retains HTTP request logs for ~30 days, then deletes them.
- Rate-limit data:Upstash holds your IP address for 60 seconds while the limit window is open, then deletes it.
- Tax + financial records:Stripe transaction records are retained as long as US federal and state tax law requires (typically 7 years), in anonymised form once the underlying account is deleted.
Your rights (US, UK, and EU)
We respect the same set of core privacy rights for everyone, whatever jurisdiction you're in. To exercise any of these rights, email joe@scienceofrowing.com. We aim to respond within 30 days.
- Access:ask for a copy of the personal information we hold about you.
- Correction:fix anything that's wrong.
- Deletion:“right to be forgotten”, subject to our legal obligations to retain financial records for tax purposes.
- Restriction:pause processing while a dispute is resolved.
- Portability:receive your data in a structured, machine-readable format.
- Objection:object to processing based on legitimate interests.
- Withdraw consent:where we relied on consent (currently nowhere on this site).
- Non-discrimination:we won't treat you differently for exercising any of these rights.
California residents (CCPA / CPRA)
California residents have the rights listed above. Specifically under the California Consumer Privacy Act (as amended by the California Privacy Rights Act): the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing of personal information, and the right to limit use of sensitive personal information. We do not sell or share personal information for behavioural advertising,and we do not process sensitive personal information for any purpose beyond what's needed to deliver the service. There is no “Do Not Sell or Share” toggle on this site because there is nothing to opt out of.
UK and EU residents (UK GDPR / EU GDPR)
UK and EU subscribers have all the rights above, plus the right to lodge a complaint with your supervisory authority. In the UK, that's the Information Commissioner's Office (ico.org.uk); in the EU, your national data protection authority. Because Science of Rowing is established outside the UK and EU but processes data of UK/EU residents in connection with offering them paid services, the UK GDPR and EU GDPR apply on a territorial basis (UK GDPR Art. 3(2), EU GDPR Art. 3(2)).
Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, and any other US state with a comprehensive privacy law have the equivalent rights granted by their state's law. Use the same email address above to exercise them.
Marketing emails
We don't currently send marketing emails. Memberful sends you transactional account emails (welcome, payment receipts, renewal reminders, cancellation confirmations). These are necessary to operate your subscription, not marketing, so they continue while your account is active. If we ever start sending marketing emails, we'll ask for your explicit opt-in consent first under both CAN-SPAM and PECR, with a clear unsubscribe link in every send.
Cookies
We use only strictly-necessary functional cookies (login session + CSRF protection). No analytics, advertising, or tracking cookies. Full cookie inventory: /cookies.
Children
Science of Rowing is aimed at coaches, athletes, and researchers. We don't knowingly collect personal information from anyone under 16 (UK/EU), or under 13 (US, under the Children's Online Privacy Protection Act). If you believe we have, email joe@scienceofrowing.com and we'll delete it.
Security
We hold your information using industry-standard technical and organisational safeguards: HTTPS-only transport, hashed and salted authentication tokens, JWT-based sessions with HttpOnly + Secure + SameSite cookies, content security policies on every page, and strict access controls on admin systems. No system is ever fully secure; if a breach occurs that puts your data at material risk, we'll notify you within 72 hours of becoming aware (UK/EU GDPR Art. 33-34) and within the timelines required by US state law where applicable.
Changes to this notice
We'll update the “last updated” date at the top of this page whenever this notice changes. For material changes (new sub-processor, new lawful basis, new category of data), we'll also email active members at the address on file.
Contact
Privacy contact: Joe DeLeo, joe@scienceofrowing.com.
Postal:
Science of Rowing, LLC
4601 E Douglas Ave, STE 150
Wichita, Kansas 67218
United States