Skip to main content
Vantage

PRIVACY POLICY

Last updated July 10, 2026

This Privacy Notice for Vantage Benchmarking LLC ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") personal information when you use our services ("Services"), including when you:

  • Visit our website at https://vantagebenchmarking.com or any website of ours that links to this Privacy Notice
  • Register for or use the Services on behalf of a participating institution
  • Contact us regarding access, support, or commercial inquiries

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at legal@vantagebenchmarking.com.

INSTITUTIONAL CUSTOMERS AND AUTHORIZED USERS

The Services are offered to collegiate athletic departments and other participating institutions (each, an "Institution"). This Privacy Notice applies primarily to personal information about Authorized Users (individuals who access the Services on an Institution's behalf) and institution contacts (for example, billing or administrative contacts).

Institutional benchmarking data that your Institution submits through the Services ("Submitted Data") is generally business information about the athletic department's revenue-sharing allocations, not consumer marketing data. We use Submitted Data as described in our Terms of Service and in Section 1 below. Consortium benchmarking outputs provided to other members are anonymized so other Institutions cannot identify your Institution without your written consent.

Definitions. In this Privacy Notice: (a) "Institution" means a subscribing organization; (b) "Authorized User" means an individual permitted to access the Services for an Institution; (c) "Account" means the Institution's workspace on the Services; and (d) "Submitted Data" means allocation and related data the Institution submits for benchmarking.

Letter of Intent. If an Institution executes a non-binding Letter of Intent before subscribing, contact information and institutional identity provided in that LOI are processed under this Privacy Notice and the LOI's confidentiality terms. We do not identify LOI signatories by name in external outreach; we may reference athletic conference names and non-identifying LOI counts only, as described in the Letter of Intent.

When we say "you," we mean Authorized Users and institution contacts, as applicable. Institutional obligations (for example, ensuring personnel comply with this Notice) rest with the Institution.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice. You can find more detail in the sections below.

What personal information do we process? We process personal information about Authorized Users and institution contacts (such as name, email, job title, and account credentials) and limited technical information (such as IP address and access logs) when you use the Services. We also process Submitted Data submitted by or for your Institution.

Do we process sensitive personal information? We collect account log-in credentials (email and password) to operate Accounts. We use those credentials only to provide and secure the Services. We do not collect certain categories of sensitive personal information (such as race, religion, sexual orientation, or health information) and we do not collect other categories of sensitive personal information except account credentials as described in this Notice and in Section 9.

Do we collect personal information from data brokers or social networks? We do not buy personal information from data brokers. We collect personal information directly from you, your Institution, and from service providers that host or support the Services on our behalf.

Do we sell or share personal information for advertising? We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising.

How do we process your information? We process information to provide and secure the Services, communicate with you, comply with law, and—with consent where required—for optional marketing. See Section 2 for legal bases and purposes.

Who do we share personal information with? We share personal information with service providers that process data on our behalf under contract. We may share information in connection with a business transfer or when required by law. A current subprocessor register is maintained by Vantage and is available on request by contacting legal@vantagebenchmarking.com.

How do we keep your information safe? We use technical and organizational safeguards such as encryption in transit and at rest, access controls, and secure authentication. See Section 5 for more detail. No method of transmission or storage is 100% secure.

What are your rights? Depending on where you live, you may have rights to access, correct, delete, or limit certain processing of your personal information.

How do you exercise your rights? Contact us at legal@vantagebenchmarking.com. We respond within the timeframes required by applicable law (for example, 45 days for many U.S. state requests).

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE PROCESS YOUR INFORMATION?
  3. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  4. HOW LONG DO WE KEEP YOUR INFORMATION?
  5. HOW DO WE KEEP YOUR INFORMATION SAFE?
  6. DO WE COLLECT INFORMATION FROM MINORS?
  7. WHAT ARE YOUR PRIVACY RIGHTS?
  8. COOKIES AND SIMILAR TECHNOLOGIES
  9. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
  10. UNITED STATES SERVICES
  11. DO WE MAKE UPDATES TO THIS NOTICE?
  12. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
  13. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you or your Institution provide to us, and limited technical information when you use the Services.

We collect personal information that you voluntarily provide when you request access, register for an Account, use the Services, or contact us.

Personal information provided by you or your Institution may include:

  • names
  • email addresses
  • job titles
  • passwords (stored in hashed form by our authentication provider)
  • contact or authentication data
  • billing addresses and invoicing contact details for the Institution

Submitted Data (Institutional benchmarking data). Authorized Users may submit athletic department revenue-sharing allocation data and related information through intake forms. Submitted Data is primarily institutional business information. We design intake forms to avoid collecting personally identifiable information about individual athletes beyond what is necessary for the Services. The Institution is responsible for ensuring submissions comply with its policies and applicable law.

Sensitive information. We collect account log-in credentials (email and password) as described above. We do not intentionally collect other categories of sensitive personal information (such as government ID numbers, precise geolocation, racial or ethnic origin, religious beliefs, health data, or biometric identifiers). We do not use sensitive personal information for purposes other than providing and securing the Services.

Information collected automatically

When you access the Services, we and our service providers may automatically collect limited technical information, such as:

  • Internet Protocol (IP) address
  • browser type and version
  • device type and operating system
  • dates and times of access
  • pages or features viewed and actions taken (for example, errors and performance logs)

We use this information to operate, secure, and troubleshoot the Services. We do not use this information for cross-context behavioral advertising.

Third-party fonts. Our website may load fonts from third-party infrastructure (for example, Google Fonts via our hosting provider). Your browser may send your IP address to that provider when fonts are loaded. We do not use font requests for advertising.

All personal information you provide must be true, complete, and accurate, and you must notify us of material changes.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide and secure the Services, communicate with you, comply with law, and—with consent where required—for optional marketing.

Legal bases and purposes. We process personal information when:

  • Contract: it is necessary to provide the Services under our agreement with your Institution (including Account creation, authentication, benchmarking features, and support).
  • Legitimate interests: it is necessary for security, fraud prevention, service improvement, and internal analytics in a way that does not override your rights (for example, reviewing error logs).
  • Legal obligation: we must comply with law or respond to lawful requests.
  • Consent: you have agreed (for example, optional marketing email where consent is required).

We process personal information for purposes including:

  • To facilitate account creation and authentication and otherwise manage Accounts. So Authorized Users can log in and use the Services.
  • To deliver the Services to the Institution. Including benchmarking, reporting, and related features using Submitted Data.
  • To respond to inquiries and offer support. Including access requests and technical support.
  • To send administrative and transactional communications. Including invitations, password resets, access approvals, security notices, and changes to our terms or policies. These messages are not promotional marketing unless clearly labeled as such.
  • To request feedback. When appropriate, we may ask for product feedback about the Services.
  • To send marketing and promotional communications (optional). Only where permitted by law and, where required, with your consent or in accordance with your preferences. You may opt out at any time.
  • To protect our Services. Including fraud monitoring, abuse prevention, and enforcement of our terms.
  • To comply with legal obligations. Including responding to legal process and regulatory requirements.

3. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We share personal information with service providers under contract, when required by law, or in connection with a business transfer. We do not sell personal information or share it for cross-context behavioral advertising.

Service providers and contractors. We may share personal information with vendors, service providers, contractors, or agents ("service providers") who perform services for us under written agreements that require them to protect personal information and use it only for our instructions. Categories of service providers include:

  • cloud computing and data storage providers
  • user account registration and authentication services
  • website hosting and content delivery providers
  • email and transactional communication providers

A current subprocessor register (service providers that process personal information on our behalf) is maintained by Vantage and is available on request by emailing legal@vantagebenchmarking.com.

Other sharing. We do not share personal information with third parties for their own independent marketing purposes. We may share personal information:

  • As required by law. Such as to comply with subpoenas, court orders, or regulatory requests.
  • To protect rights and safety. When we believe disclosure is necessary to protect us, our users, or others.
  • Business transfers. In connection with, or during negotiations of, a merger, sale of assets, financing, or acquisition of all or part of our business.

Institutional agreements. Where required by applicable U.S. law or an institutional agreement, we may enter into a supplemental written agreement with your Institution governing the handling of personal information and Submitted Data.

4. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep personal information only as long as needed for the purposes in this Notice, then delete or anonymize it, subject to legal retention requirements.

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Notice, unless a longer period is required or permitted by law (for example, tax, accounting, or litigation holds).

For account-related personal information (Categories A, B, and I in Section 9), we generally retain data for the duration of the active subscription and up to two (2) years following Account termination for legal, contractual, fraud-prevention, and dispute-resolution purposes.

Active systems. Upon termination of an Account, we will delete or anonymize personal information in active production systems within thirty (30) days, except where retention is required by law or for legitimate purposes described above.

Backups and archives. Personal information may persist in encrypted backups or archives for a limited period. Backup copies are isolated from routine processing and deleted or overwritten in accordance with our backup retention schedule, in no event later than two (2) years following Account termination unless a longer period is required by law.

When we have no ongoing legitimate business need to process personal information, we will delete, anonymize, or isolate it as described above.

5. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We use organizational and technical measures designed to protect personal information, including encryption, access controls, and secure authentication.

We implement commercially reasonable technical and organizational security measures designed to protect personal information we process. Without limiting the foregoing, our security program is designed to include, as applicable:

  • Encryption in transit. Use of industry-standard encryption (such as TLS) for personal information transmitted to and from the Services.
  • Encryption at rest. Encryption of personal information stored with our cloud infrastructure providers.
  • Access controls. Role-based access for Authorized Users and institution-scoped access controls so users can access only their Institution's Account data; limitation of our personnel access to personal information to those with a need to know.
  • Authentication. Industry-standard handling of account credentials (including storage of passwords in hashed form through our authentication provider).
  • Operational security. Logical separation of production environments; periodic review of access rights; and logging or monitoring of security-relevant events where reasonably practicable.
  • Continuity. Encrypted backups and archives subject to the retention limits in Section 4, isolated from routine processing except as required for security, disaster recovery, or legal compliance.

Where an Institution has executed a Data Sharing Agreement with us, additional contractual security commitments for institutional Submitted Data are set forth in that agreement.

In the event of a confirmed security breach affecting personal information we process, we will notify the affected Institution in writing within seventy-two (72) hours of becoming aware of the breach where required by applicable law or our agreements, and will take prompt remedial action.

However, no electronic transmission over the Internet or storage technology can be guaranteed to be 100% secure. Transmission of personal information to and from the Services is at your own risk. Access the Services in a secure environment.

6. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market to anyone under 18.

We do not knowingly collect personal information from children under 18 years of age. The Services are not directed to minors. By using the Services, you represent that you are at least 18 years of age. If we learn that we collected personal information from a user under 18, we will deactivate the Account and take reasonable steps to delete such information. Contact us at support@vantagebenchmarking.com if you believe we have collected information from a minor.

7. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: You may have rights to access, correct, delete, or restrict certain processing depending on where you live.

Withdrawing consent. Where we rely on your consent, you may withdraw it at any time by contacting us. Withdrawal does not affect processing that occurred before withdrawal, or processing we are required to carry out under applicable law.

Marketing opt-out. You may opt out of promotional communications at any time by contacting us at support@vantagebenchmarking.com or using an unsubscribe link in a marketing email. We may still send transactional and service-related messages (for example, invitations, security alerts, and policy updates).

Account information. Authorized Users may review or update certain Account information in the Services settings. To terminate an Account or request deletion, contact us at support@vantagebenchmarking.com. Institutions should coordinate termination and data requests through their administrative contact where appropriate.

Upon a verified deletion request, we will deactivate or delete personal information from active systems as described in Section 4. We may retain limited information where required by law or for fraud prevention, security, or enforcement of our agreements.

Institution requests. Institutions may contact us regarding Authorized Users affiliated with their Account. We may require verification that the requester is authorized to act for the Institution.

Response timing. We aim to respond to privacy requests within forty-five (45) days of receipt, or the timeframe required by applicable law. We may extend that period where permitted by law with notice.

If you have questions about your privacy rights, email us at legal@vantagebenchmarking.com.

8. COOKIES AND SIMILAR TECHNOLOGIES

In Short: We use essential cookies to operate the Services. We do not use advertising or cross-site analytics cookies.

What are cookies? Cookies are small data files placed on your device. We use cookies and similar technologies (such as session storage managed through your browser) where necessary to operate the Services.

Cookies we use

TypePurposeExamples
Essential / authenticationSign-in, session management, securityCookies set by our authentication provider to keep you logged in
FunctionalRemember preferences needed for the ServicesFiscal year selection and similar in-app preferences

We do not use cookies for cross-context behavioral advertising. We do not use third-party advertising or analytics cookies (such as Google Analytics) on the Services as of the date of this Notice.

Your choices. Most browsers let you block or delete cookies. Blocking essential cookies may prevent you from using the Services.

Do-Not-Track. Some browsers transmit "Do Not Track" (DNT) signals. Because we do not engage in cross-site tracking for advertising, we do not respond to DNT signals in a distinct way beyond our general privacy practices. California law requires us to disclose that we do not track users across third-party websites for advertising purposes.

9. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: Residents of certain U.S. states may have additional rights regarding personal information.

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or other states with comprehensive privacy laws, you may have the rights described below, subject to applicable exceptions.

Categories of personal information we collect

The table below shows categories of personal information we have collected in the past twelve (12) months. Examples are illustrative. For details, see Section 1.

CategoryExamplesCollected
A. IdentifiersName, email, online identifier, IP address, Account nameYES
B. California Customer RecordsName, contact information, employment-related contact details, billing address and invoicing recordsYES
C. Protected classification characteristicsRace, ethnicity, gender, age, disability, etc.NO
D. Commercial informationSubscription and invoicing recordsYES
E. Biometric informationFingerprints, voiceprintsNO
F. Internet or similar network activityInteraction with our Services (for example, access logs, pages viewed, actions taken)YES
G. Geolocation dataPrecise physical locationNO
H. Audio, electronic, sensoryCall or video recordingsNO
I. Professional or employment-relatedJob title, business contact detailsYES
J. Education informationStudent records (FERPA)NO
K. InferencesProfiles derived from personal information for advertisingNO
L. Sensitive personal informationAccount log-in and password (for Account operation only)YES

Sources of personal information

We collect personal information directly from you, your Institution, automatically through use of the Services, and from service providers as needed to operate the Services. See Section 1.

Sensitive personal information — limit on use (California)

We collect Category L information (account log-in credentials) only to provide and secure Accounts, prevent fraud, and comply with law. We do not use sensitive personal information for purposes that require a "limit the use" opt-out under California law. You may contact us at legal@vantagebenchmarking.com with questions about our use of sensitive personal information.

How we use and share personal information

See Sections 2 and 3. We use personal information for business purposes described in this Notice. We disclose categories A, B, D, F, I, and L to service providers under written contracts in the preceding twelve (12) months. We have not sold personal information. We have not shared personal information for cross-context behavioral advertising in the preceding twelve (12) months.

Your rights

Subject to exceptions under applicable law, your rights may include:

  • Right to know whether we process your personal information and to access it
  • Right to correct inaccurate personal information
  • Right to delete personal information
  • Right to obtain a portable copy of personal information you provided
  • Right to non-discrimination for exercising privacy rights
  • Right to opt out of the sale of personal information (we do not sell)
  • Right to opt out of sharing for cross-context behavioral advertising (we do not share for that purpose)
  • Right to limit use and disclosure of sensitive personal information (as described above)

Depending on your state, you may also have rights to know categories of third parties, specific third parties, or profiling information, as applicable.

How to exercise your rights

Email legal@vantagebenchmarking.com or use the contact details in Section 12. Describe your request with enough detail for us to understand and verify it. We will respond within the time required by your state's law (typically 45 days).

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We may require proof that the agent is validly authorized and verify your identity.

Request verification. We verify requests using information we already maintain. If needed, we may request additional information for verification and security.

Appeals. If we decline your request, you may appeal by emailing legal@vantagebenchmarking.com. We will explain our decision in writing. If your appeal is denied, you may contact your state attorney general where applicable.

California "Shine the Light." California residents may request information about disclosures to third parties for their own direct marketing purposes once per year by contacting us at legal@vantagebenchmarking.com.

10. UNITED STATES SERVICES

The Services are offered to Institutions and Authorized Users in the United States only. We do not market or offer the Services to individuals in other countries.

If an Authorized User temporarily accesses the Services from outside the United States (for example, while traveling), data is still processed and stored in the United States under this Privacy Notice and our agreements with the Institution. Occasional access from abroad does not change the U.S.-focused nature of the Services.

11. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we may update this Notice to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date. If we make material changes, we may notify you by posting a notice on the Services or by email to the Institution's designated contact. Review this Notice periodically.

12. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

For questions, concerns, privacy requests, or subprocessors list requests, contact us at:

Vantage Benchmarking LLC
2 Trafalgar Pl Durham, NC 27707 United States
legal@vantagebenchmarking.com

Institutions should provide a billing contact and an administrative or legal contact for notices and security incidents.

13. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on applicable law, you may request access to, correction of, or deletion of personal information we hold about you, and you may withdraw consent where processing is consent-based.

To submit a request, email legal@vantagebenchmarking.com with the subject line "Privacy Request" and describe your request. We will verify your identity and respond within the timeframe required by applicable law.

For Submitted Data belonging to your Institution, deletion or export may require coordination with your Institution's administrator, because the Institution controls benchmarking submissions.