Privacy Policy
How AD Vantage handles information across our website, athletics analytics platform, Data Sharing Hub, and connections to AI assistants.
Effective date
September 16, 2026
Revision prepared
September 10, 2026
Entity
Core Four LLC (d/b/a AD Vantage)
Privacy contact
privacy@athleticdirectorvantage.com
The short version
AD Vantage is a business-to-business analytics platform for college athletics administrators. We handle three main categories of information:
-
Information about our customers and website visitors. Account details, contact information for sales conversations, and usage records for the people who log in to AD Vantage or connect it to an AI assistant.
-
Public-source professional information. Employment, compensation, contract, career, performance, and published work contact information about athletics personnel, obtained from the sources described in Section 4.
-
Customer-provided nonpublic information. Private salary submissions and other information supplied through the Data Sharing Hub, together with access, sharing, and audit records.
We do not sell personal information or share it for cross-context behavioral advertising. Access to our platform and MCP server requires an authorized AD Vantage customer account. Authentication is handled through WorkOS. We do not ask users to put passwords, payment card details, or unrelated sensitive information into research tools.
Contents
-
Who we are and what this policy covers
-
Three ways you reach AD Vantage
-
Information about customers and website visitors
-
Information about athletics personnel and customer-provided data
-
AI assistants and our MCP server
-
How we use information
-
Ratings, benchmarks, and predictions
-
Who receives information
-
Student data and FERPA
-
How long we keep information
-
Your choices
-
US state privacy rights
-
Additional California disclosures
-
Requests from athletics personnel about their own information
-
Security
-
Cookies and similar technologies
-
Children
-
Changes to this policy, and how to reach us
1. Who we are and what this policy covers
AD Vantage is operated by Core Four LLC, a Florida limited liability company doing business as AD Vantage (“AD Vantage,” “we,” “us”). Our mailing address is 2458 NW 31st Ave, Gainesville, FL 32605.
This policy applies to:
-
Our marketing website at athleticdirectorvantage.com, including demo requests, articles, and resources.
-
The AD Vantage platform at app.athleticdirectorvantage.com, available to licensed institutional customers.
-
The AD Vantage MCP server, which allows a customer to reach AD Vantage data from a third-party AI assistant such as ChatGPT or Claude.
-
Sales, support, and marketing communications we send in connection with those services.
It does not apply to third-party services we do not control, including the AI assistant products through which our MCP server may be reached. Those products are governed by their operators’ own privacy policies.
Our customers are colleges, universities, and athletic conferences. For information processed on an institution’s behalf, we follow the applicable customer agreement and authorized instructions. Those arrangements do not remove rights that applicable law gives individuals.
2. Three ways you reach AD Vantage
What we collect depends on how you interact with us. The following is a map to the rest of the policy.
Marketing website
Who uses it: Anyone
What we collect: Demo request form fields, pages viewed, and basic device and connection data. See Section 3.
AD Vantage platform
Who uses it: Licensed users at customer institutions
What we collect: Account identity, authentication events, in-product activity, saved reports and preferences. See Section 3.
MCP server
Who uses it: Authorized customer users, through a connected AI assistant
What we collect: Tool name, arguments, authenticated context, and usage records. Private Hub access requires additional permissions. See Section 5.
Our services also contain professional records about athletics personnel who may not be AD Vantage users, as well as nonpublic information supplied by participating customer institutions. Section 4 explains those sources and the distinction between them.
3. Information about customers and website visitors
Website visitors
When you visit our marketing site we collect:
-
Information you submit. If you request a demo or contact us, we collect your name, work email address, institution, role or title, and anything you write in a message field.
-
Usage and device data. Pages viewed, referring page, approximate location derived from IP address, browser and operating system, and timestamps.
Platform users
When your institution licenses AD Vantage and you are issued access, we collect:
-
Account identity. Your name, work email address, institution, role, and the permissions and entitlements assigned to your account, including which data modules your institution has licensed.
-
Authentication records. Account and sign-in information, sessions, and security events processed through WorkOS. We process access tokens and related account information to authenticate requests and enforce permissions; we do not store user passwords.
-
Product activity. Features used, reports generated, searches and filters applied, documents viewed or downloaded, saved views, watchlists, and preferences.
-
Support communications. Messages you send us and our replies.
-
Diagnostic data. Application errors, logs, and performance traces processed through Sentry and our hosting services. These records may include request, device, account, and error context. We filter selected fields and events, but diagnostic records may still contain personal information.
Billing
Institutional customers are invoiced against purchase orders or agreements. Billing records may include contact names, business addresses, purchase order references, invoices, and payment status. Our platform does not offer a payment-card checkout.
Information you should not submit
Please do not include government identification numbers, health information, financial account or payment card details, biometric data, precise geolocation, or unrelated sensitive personal information in research inputs, uploaded materials, or support messages. Do not put passwords, API keys, or one-time codes into tool arguments. Authentication tokens used by the service are handled separately from research inputs.
4. Information about athletics personnel and customer-provided data
Our research dataset supports comparisons of college athletics staff, contracts, performance, and department finances. We distinguish records obtained from public sources from nonpublic information supplied by customers.
Public-source professional information
-
Name, current and former employing institutions, job titles, and dates of service.
-
Compensation and contract terms as disclosed in employment agreements and institutional reporting: base salary, supplemental and outside income, bonus and incentive structures, term length, buyout and termination provisions.
-
Career history, coaching lineage and professional connections, and educational background.
-
Team and program performance results associated with a person’s tenure.
-
Professional email addresses and telephone numbers published in staff biographies or directories on the person’s own institution’s website.
Sources of public research information
-
Public records requests. Records obtained from public institutions under applicable public-records and open-records laws, including employment agreements and compensation schedules.
-
Published institutional and regulatory reporting. Publicly available athletics financial, academic, and other institutional reports, including EADA filings, NCAA publications, and IRS Form 990 filings where available. A reporting requirement alone does not mean every underlying submission is public; information supplied privately by customers is treated separately.
-
Institutional publications. University and conference websites, staff directories, media guides, and press releases.
-
Published reporting. News coverage and industry publications.
Published contact details and incidental information
We obtain professional email addresses and telephone numbers from staff biographies or directories published by the person’s own institution. We use those details as professional contact information. Public availability does not make the information anonymous, and applicable privacy protections may still apply. Source documents and biographies can contain incidental information beyond the structured fields we use. Contact us if a record appears inaccurate, unrelated to a professional purpose, or inappropriate for inclusion.
Some information lawfully available from government records or other public sources may be excluded from particular privacy-law definitions. We assess those exclusions where applicable; we do not assume that every record, derived inference, or customer-provided submission is exempt. Section 14 explains how athletics personnel can request access, correction, or review.
We do not use our professional research dataset for consumer advertising, license it to data brokers, or combine it with purchased consumer or household profiles.
Nonpublic customer information
Participating institutions may submit nonpublic salary and related employment information through the Data Sharing Hub. We process it to provide the authorized service under the applicable customer agreement and instructions. It is not treated as public merely because the person also appears in our public research dataset.
Access depends on permissions, entitlements, and sharing grants. Where an institution authorizes sharing, permitted users at other participating institutions may receive the authorized information or analyses derived from it. We keep relevant provenance, submission, authorization, and disclosure records. A permitted user may also access authorized Hub results through a connected AI assistant.
5. AI assistants and our MCP server
An authorized AD Vantage customer user can connect our Model Context Protocol (MCP) server to an AI assistant such as ChatGPT or Claude. Sign-in, enabled MCP access, and applicable data permissions are required. Data Sharing Hub tools require additional Hub permissions.
The AI assistant operator is a separate company
Your conversation takes place in the assistant’s product, which is governed by its operator’s own privacy policy and terms. The MCP interface does not automatically receive your full conversation history or the assistant’s private reasoning. It receives tool calls and their arguments; those arguments may include information or wording from your request.
What we receive when a tool is called
-
The tool name invoked, such as a staff search or a financial summary.
-
The parameters supplied for the call, such as a person’s name, search phrase, institution, sport, conference, reporting year, or selected record identifiers.
-
Your authenticated account context, so we can confirm your institution licenses the data being requested.
What we return
Tool responses may include professional employment, compensation, contract, financial, performance, and career information, with source links and relevant record identifiers. Authorized Hub responses may also include nonpublic customer-provided salary information and its provenance. We omit structured email and telephone fields from staff records returned through MCP. This field omission does not redact original contract text or linked source documents. Responses may include status and error information; authentication tokens are not intended to be returned as tool data.
Logging and analytics
MCP operational logging
AD Vantage records operational logs, which may include sanitized tool inputs and account context. When MCP usage analytics is enabled, the invoked tool name and an internal user identifier are sent to RudderStack. Tool inputs and results are not included in those MCP analytics events.
Operational logs support troubleshooting, access enforcement, and security investigations. Sanitization filters selected input fields; it is not a guarantee that all personal information is removed from every log or error message. MCP usage analytics measures which tools customers use. Its user identifier is assigned by AD Vantage and can be associated with an account. The web platform separately sends account identification and product activity to RudderStack as described in Section 8.
Use of models
We do not use customer account information, private customer submissions, or MCP tool inputs and results to train or fine-tune our predictive models. We use professional research information to produce the analytics described in Section 7. Some platform features use external AI services to generate insights. That processing is distinct from model training and is described in Section 8. Your connected assistant’s handling of its own conversation data is governed by that provider’s terms and privacy policy.
Prohibited inputs
Tool inputs should be limited to the supported athletics research task. Do not submit payment card data, health information, government identifiers, authentication secrets, or unrelated personal information. If you believe such information was submitted, contact us so we can investigate and address it under our data-handling procedures and applicable obligations.
6. How we use information
Providing the platform and MCP server
What we use: Account identity, entitlements, authentication, tool calls, public research, and authorized customer-provided data
Producing benchmarks, comparisons, and analyses
What we use: Professional research data, authorized Hub data, searches, and saved views
Security, abuse prevention, and entitlement enforcement
What we use: Operational logs, authentication records, account context
Diagnosing and fixing defects
What we use: Error reports, performance traces, operational logs
Understanding which features are used
What we use: Product activity; MCP tool names and internal user identifiers
Sales, onboarding, renewal, and support
What we use: Contact and account information, support messages, CRM records
Marketing to institutional prospects
What we use: Business contact information and demo request details
Billing and business records
What we use: Billing contacts, purchase orders, invoices, agreements
Legal compliance and dispute resolution
What we use: Whatever is relevant and necessary
Our tools provide research and decision support. Customers remain responsible for decisions they make using the information, including decisions involving employment. Section 7 describes the intended role of analytical outputs.
7. Ratings, benchmarks, and predictions
AD Vantage produces performance ratings, peer comparisons, modeled compensation estimates, and other research outputs from professional athletics information. Hub tools can also calculate comparisons and aggregates from customer-provided information within the caller’s authorized scope.
Ratings and predictions are estimates and may be incomplete or inaccurate. They support research, budgeting, benchmarking, and market analysis; they do not determine an individual’s suitability or eligibility for a job or benefit. AD Vantage does not make hiring, promotion, compensation, credit, insurance, or housing decisions for customers.
Customers are responsible for complying with applicable law and their agreements when using our services. Our services are not offered as a substitute for legally required employment screening or consumer-reporting processes. Where applicable law provides rights relating to profiling or automated decision-making, you may contact us as described in Sections 12 and 14.
8. Who receives information
We use service providers for hosting, storage, authentication, analytics, diagnostics, communications, and related operations. The following describes the principal recipients and processing categories associated with our services. Which services receive information depends on the feature and configuration in use.
WorkOS
Role: Identity and authentication
What it receives: Account identity, organizations, sign-in and session information, and authentication events
Vercel and Render
Role: Hosting and delivery
What it receives: Request and application data, hosted content, database information where applicable, and logs
Google Cloud Storage
Role: Document and asset storage
What it receives: Stored documents, source files, and related assets
Sentry
Role: Diagnostics
What it receives: Error reports, logs, performance traces, and associated request, device, or account context
RudderStack
Role: Usage analytics
What it receives: Web platform: account identifiers, name, email, and page/feature activity. MCP: tool names and internal user identifiers; no tool inputs or results in those MCP analytics events
HubSpot
Role: CRM and marketing
What it receives: Business contacts, demo requests, correspondence, and website visit information that may be linked to contact records
Perplexity
Role: Generated staff insights
What it receives: Professional staff descriptors and research prompts supplied by enabled insight features
Caching and workflow infrastructure
Role: Processing support
What it receives: Data needed for configured caching and background tasks; deployment may use Upstash and Hatchet
Processing locations depend on the provider, service, and account configuration. Information may be processed in the United States and other countries where the relevant providers operate, subject to applicable agreements and legal requirements.
Other disclosures
-
Your institution. Account administrators at your institution can see the accounts, entitlements, and in some cases the activity of users under their license.
-
Other participating institutions. Customer-provided Hub information may be shared with authorized users at other institutions according to applicable sharing permissions and agreements.
-
AI assistant operators. When you use the MCP server, tool responses are returned to the assistant you connected, which is governed by its operator’s policies.
-
Professional advisors. Auditors, accountants, and lawyers under duties of confidentiality.
-
Corporate transactions. A counterparty in a merger, acquisition, financing, or sale of assets, subject to this policy’s continued application to the transferred information.
-
Legal obligations. Where required by law, subpoena, or court order, or where necessary to protect our rights or the safety of others. Because many of our customers are public institutions, records they hold may themselves be subject to public disclosure laws.
9. Student data and FERPA
Our customers are educational institutions, so it is worth being explicit about what we do and do not handle.
Our services are designed for institutional and professional athletics research and are not intended to collect individual student education records. Do not submit student-level records through ordinary product features or MCP tools.
The personnel dataset is focused on coaches, administrators, and other athletics staff. Student education records require separate consideration even when the institution is already an AD Vantage customer.
Academic measures such as Academic Progress Rate, Graduation Success Rate, and Federal Graduation Rate are presented as published team-, sport-, or institution-level statistics. These features are not intended to provide individual student records.
Any proposed processing of student-level education records requires a separate written arrangement addressing FERPA and other applicable obligations before transmission. Please contact us before sharing such information.
10. How long we keep information
Retention depends on the information, the purpose for which it is held, applicable customer instructions, and legal obligations. The following criteria describe how retention is determined. Contact us for information about retention applicable to your account or a particular record.
Account and customer records
Retention criteria: For the customer relationship and subsequent offboarding, security, and recordkeeping needs under applicable agreements.
Authentication, security, and audit events
Retention criteria: For security, access review, and audit purposes under the relevant system’s configured retention and applicable obligations.
Operational logs and diagnostics
Retention criteria: For troubleshooting and service monitoring, under the relevant logging and diagnostic retention settings.
Usage and website analytics
Retention criteria: For measuring usage and improving service, under the settings of the analytics service and configured destinations.
CRM, marketing, and support records
Retention criteria: For the relationship, support history, and relevant follow-up; minimal suppression records may be retained to respect opt-outs.
Contracts, invoices, and tax records
Retention criteria: For applicable business, tax, accounting, and legal recordkeeping obligations.
Public professional research
Retention criteria: For historical and longitudinal research, subject to corrections, applicable rights, and review of continued relevance.
Nonpublic Hub data and sharing records
Retention criteria: Under applicable customer instructions, sharing arrangements, and legal or audit obligations; separately from public research history.
Backups, caches, and exports
Retention criteria: Under their relevant lifecycle schedules and applicable customer or legal obligations.
Historical professional records support longitudinal research, so an older contract or appointment may remain relevant after it is superseded. This does not mean all customer-provided private information is retained as public research history. Private Hub data is handled under applicable customer instructions, sharing arrangements, and retention obligations.
We may retain records for legal obligations, disputes, security investigations, or enforcement of agreements where appropriate. Backup and archival copies may expire through separate lifecycle schedules. Retention also applies to copies held by service providers and configured analytics destinations; disconnecting an assistant does not itself delete those records.
11. Your choices
Marketing email
Every marketing message includes an unsubscribe link. You will still receive transactional messages about your account.
Cookies
Manage cookies through your browser settings. See Section 16.
Disconnecting an AI assistant
You can disconnect AD Vantage in your assistant’s settings to stop using that connection. Contact your account administrator or AD Vantage if you need account access or an authorization revoked. Previously recorded logs and analytics are handled under Section 10, and copies already held by the assistant remain subject to that provider’s policies.
Account information
Update your details in the platform, or ask your institution’s account administrator. Some fields are controlled by your institution.
12. US state privacy rights
Depending on where you live, the information involved, and whether the relevant law applies to AD Vantage and the processing, you may have some or all of the rights below. Exceptions and verification requirements may apply.
Know and access
Confirm whether we process your personal information and obtain a copy, including the categories collected, the sources, the purposes, and the categories of recipients.
Correct
Have inaccurate personal information corrected.
Delete
Request deletion of personal information we hold about you, subject to exceptions in the applicable law.
Portability
Receive a copy in a portable, readily usable format where technically feasible.
Opt out of sale or targeted advertising
We do not sell personal information or share it for cross-context behavioral advertising. You may contact us about marketing preferences or any opt-out rights that apply to your information.
Opt out of profiling
Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. See Section 7.
Limit sensitive data
Where applicable law grants rights concerning sensitive personal information, you may contact us to exercise those rights. Please do not submit sensitive information that is unrelated to our services.
Non-discrimination
We will not deny service, charge different prices, or provide a different quality of service because you exercised a privacy right.
Appeal
If we decline a request and applicable law provides a right to appeal, reply to our decision or email privacy@athleticdirectorvantage.com with “Privacy Appeal” in the subject line. We will explain the appeal outcome and provide any further information required by that law.
Making a request
Email privacy@athleticdirectorvantage.com or write to 2458 NW 31st Ave, Gainesville, FL 32605. Describe your request and provide enough information to help us locate the relevant records. We will respond within the period required by applicable law and explain any permitted extension.
We may need to verify your identity and authority before acting. For account users, we may verify through their account. For other requests, we seek information reasonably needed to match the requester to the records. We will explain if we cannot verify a request or if an exception applies.
An authorized agent may submit a request on your behalf with written permission signed by you, or a valid power of attorney. We may contact you to confirm the authorization.
If you are covered by our dataset rather than a customer
Athletics personnel whose professional information appears in AD Vantage may use the process in Section 14, whether or not they are customers. That process supplements any applicable statutory rights.
13. Additional California disclosures
The following describes categories of information associated with our services for purposes of California disclosures where the CCPA applies. Public-source records, private customer submissions, and derived inferences may require different treatment.
Categories of information:
Identifiers
Collected: Names, published professional contacts, customer account identifiers, and connection data
Source: You, your institution, institutional publications, and automatic collection
Commercial information
Collected: License and entitlement records, purchase orders, invoices
Source: You; your institution
Internet or network activity
Collected: Pages viewed, product activity, tool calls, logs
Source: Automatically
Professional or employment information
Collected: Roles, titles, employment history, and compensation information
Source: You, public research sources, and authorized customer submissions
Education information
Collected: Educational background of athletics personnel
Source: Public sources
Inferences
Collected: Ratings, peer groupings, and modeled compensation estimates for athletics personnel
Source: Derived from professional research or authorized customer information, depending on the feature
Geolocation
Collected: Approximate location from IP address only. No precise geolocation.
Source: Automatically
Sensitive personal information
Collected: Authentication information for account access; unrelated sensitive information is not solicited for research
Source: You and authentication services; incidental information may appear in submitted or source materials
Biometric, health, or genetic data
Collected: Not solicited for the service
Source: Please do not submit
Each category is collected for the business purposes in Section 6 and disclosed only to the recipients in Section 8.
Sale and sharing
We do not sell personal information or share it for cross-context behavioral advertising. Section 8 describes disclosures for operating the service and authorized customer data sharing.
Publicly available information
Some lawfully public information may be excluded from the CCPA’s definition of personal information. The exclusion does not automatically extend to nonpublic Hub submissions or every inference derived from public information. We review requests under the applicable rules.
Shine the Light
California Civil Code section 1798.83 permits residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
14. Requests from athletics personnel about their own information
If you are a coach, administrator, or staff member whose professional record appears in AD Vantage, you can contact us directly at privacy@athleticdirectorvantage.com. You do not need to be a customer.
See your record
You may request access to information we hold about you and information about its sources. We will review the request subject to applicable law, verification, customer instructions, and protections for other people’s information.
Correct an error
Tell us what is inaccurate and, where possible, provide the relevant source or correction. We may re-check source material, correct a structured record, or annotate a disputed record. For information provided privately by an institution, we may coordinate with that institution.
Ask for removal
You may ask us to review or remove information that is inaccurate, unrelated to the professional purpose, improperly included, or subject to a deletion right. We will assess the source, applicable law, customer instructions, and any legitimate retention obligations, and explain the outcome.
Contact details
Professional contact details are obtained from institutional biographies or staff directories. Structured email and telephone fields are omitted from staff records returned through MCP; original source documents are not redacted by that omission. Contact us if a detail is incorrect or should be reviewed.
We will explain any verification steps, applicable timing, and the outcome of your request.
15. Security
We maintain administrative, technical, and physical safeguards appropriate to the information we hold, including:
-
Encryption of service connections using TLS and storage protections provided by our hosting and storage services.
-
Authentication through WorkOS, with single sign-on and multi-factor authentication available according to the account and identity-provider configuration.
-
Role and entitlement controls, including authorization checks for MCP access and underlying tools.
-
Access controls for customer and administrative operations.
-
Filtering of selected sensitive input fields in MCP operational logs, with diagnostic collection as described in Sections 3 and 5.
-
Audit records for supported authorization and administrative actions, including private-data disclosures.
-
Service-provider arrangements appropriate to the processing involved.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any required authority as the law requires. Report a suspected vulnerability to privacy@athleticdirectorvantage.com.
16. Cookies and similar technologies
We use cookies and similar technologies for authentication, preferences, and measurement:
-
Strictly necessary. Session and authentication cookies, security tokens, and load balancing. The service does not work without these.
-
Preferences. Remembering settings such as saved views and display choices.
-
Analytics and attribution. Our marketing website uses HubSpot tracking to understand visits and demo requests; visit history may be associated with a contact record after a form submission. Our signed-in platform also uses RudderStack to measure page and feature activity and associate that activity with an account.
Our use of analytics is for understanding site and product usage, not cross-context behavioral advertising. You can manage cookies through your browser and any controls provided on the relevant site. Blocking essential cookies may prevent sign-in. You may contact us to exercise applicable privacy choices.
17. Children
AD Vantage is intended for authorized institutional users and is not directed to children. Our research focuses on professional athletics personnel. Please do not submit children’s personal information or individual student records through ordinary product features. Contact us if you believe such information has been included so we can review and address it as appropriate.
18. Changes to this policy, and how to reach us
We may update this policy as our practices change. The published version will show its effective date. We will provide additional notice of material changes where required by law or applicable agreements.
Privacy requests and questions
Address: privacy@athleticdirectorvantage.com
Security reports (same inbox)
Address: privacy@athleticdirectorvantage.com
Address: Core Four LLC, d/b/a AD Vantage, 2458 NW 31st Ave, Gainesville, FL 32605

