ClubKeeper
SecurityPrivacyTermsDPAAccessibilityLog in

Legal

Privacy Policy

Last updated 9 September 2026

Who we are

ClubKeeper is currently operated by Jason Cheeseman, trading as ClubKeeper (“we”, “us”), as a sole trader while a limited company is being incorporated. Once that company exists, this policy will be updated to name it as the data controller — until then, Jason Cheeseman is the controller responsible for the personal data described below. Contact: jason@clubkeeperapp.com.

Postal address:
34 Delorean Way
Brackley
Northamptonshire
NN13 6BF

What this policy covers

This policy explains how ClubKeeper collects, uses, and protects personal data when a club and its members use the platform to manage subs, finances, safeguarding records, fixtures, and communications. If you’re a parent, guardian, player, coach, or committee member of a club using ClubKeeper, this applies to you.

What data we collect

The specific data depends on your role at the club, but broadly falls into these categories:

  • Account data — your name, email address, password (stored as a secure hash, never in plain text), and profile photo if you upload one.
  • Club membership data — which club(s) you belong to, your role (e.g. Admin, Coach, Parent, Treasurer), and any secondary roles.
  • Player/child data — for registered players: name, date of birth, gender, shirt number, FA registration ID, photo, medical notes, and emergency contact details, entered by a parent/guardian or club official.
  • Safeguarding records — for coaches and staff: qualification and criminal record check status (DBS, PVG or AccessNI depending on the club’s nation), expiry dates, and any concerns raised through the platform. See “Children’s data and safeguarding” below.
  • Financial data — subs and invoice records, expense and payroll entries, and the club’s own bank account details entered by its Treasurer. Card payment details are handled directly by Stripe (see “Who we share data with”) — we never see or store your full card number.
  • Communications — messages sent through the club wall, comments, and club chat groups.
  • Tournament squad data — where a club hosts a tournament, a visiting team’s manager can submit their squad using a link the organiser sends them: player names, and dates of birth where the tournament checks age eligibility. See “Tournaments and visiting teams” below.
  • Mobile app data — if you install the ClubKeeper app and allow notifications, we store a device token so notifications can reach that device. You can revoke it by turning notifications off or signing out. There is no tracking or advertising identifier.
  • Technical and log data — sign-in timestamps, email delivery logs, and an activity log of significant actions taken within a club (e.g. who approved an invoice), used for accountability and troubleshooting.
  • Waitlist enquiries — if you ask us to tell you when ClubKeeper opens, we store the email address you give us, your club name and any note you add. This is the only data we hold about people who aren’t members of a club on the platform.

Why we process this data

We rely on the following legal bases under UK GDPR:

  • Performance of a contract — most of the above, because it’s necessary to provide the service your club has signed up for.
  • Legitimate interests — technical and log data, used to keep the platform secure, reliable and accountable; and a count of visits to our public pages, so we know whether anybody is finding the site. That count processes a visitor’s IP address briefly to tell one visit from another. It is not used to build a profile, it is never combined with a club’s data, and pages inside the app are excluded from it entirely.
  • Legal obligation — safeguarding records, which clubs are required to keep as part of their own child protection duties.
  • Consent — optional communications, such as opting in to receive certain email notifications, and waitlist enquiries. We use a waitlist email address only to tell you when ClubKeeper opens and to answer you if you asked us something; we don’t add you to a mailing list, and you can ask us to delete it at any time by replying or emailing us.

Children’s data and safeguarding

ClubKeeper is used by adults (parents, guardians, and club officials) to manage information about children — children do not create their own accounts or log in themselves. A parent or guardian provides and controls their child’s player record and can ask their club to correct or remove it at any time. Where a player is 18 or over, this section does not apply — they manage their own record directly, the same as any other adult member.

A club can also mark an adult as restricted from communications about a particular child, so that person stops receiving messages, invitations and reminders about them. This exists for situations a club is already managing under its own safeguarding policy or a court order. The decision is the club’s — we do not make it, and we are not told the circumstances behind it.

The safeguarding module lets a club’s Welfare Officer record coach/staff qualification and criminal record check status, and log concerns raised about a child’s welfare. ClubKeeper is a record-keeping tool for information the club is already responsible for under its own safeguarding policy — it does not replace the club’s obligation to carry out criminal record checks through the official channel for its nation, or to follow its own safeguarding procedures and legal duties.

Tournaments and visiting teams

When a club hosts a tournament, teams from other clubs enter it. The host club’s organisers can send a visiting team’s manager a link to submit their squad, and can see and print what that manager submits — typically player names, and dates of birth where the tournament is age-banded and the organiser needs to check eligibility.

Two things follow from that, and they matter. The host club decides what it asks for and what it does with it, so for that tournament the host club is the controller of those squad details, not the visiting club and not us. And the visiting team’s manager is responsible for having a proper basis to pass on their players’ details — they should tell their own parents that squad information is being shared with the organiser for entry and eligibility.

Squad lists are not shown on the public tournament page. Fixtures, results, standings and team names are public on that page; individual players’ details are visible only to the host club’s organisers. Goalscorer names appear publicly only where the organiser records who scored.

Who we share data with

We use a small number of trusted service providers (sub-processors) to run ClubKeeper:

  • Supabase — hosts our database, in the UK (London region). Every query ClubKeeper makes is scoped to the club you are signed in to; see “Security” below for how that is enforced and what we are still building.
  • Resend — sends transactional emails on our behalf (verification, password resets, invoice and invite notifications).
  • Stripe — processes card payments directly. When a club enables online payments, funds go straight to that club’s own Stripe account — we never hold or touch the money, and Stripe’s own privacy policy governs the payment data it collects.
  • Vercel — hosts the application itself, and counts visits to our public pages (the homepage, this policy, the terms, the accessibility and security pages, the public tournament directory, and the sign-in and sign-up pages). This is a page count, not a profile: it sets no cookie, stores nothing on your device, follows you to no other website, and we never see who you are. Pages inside the app are deliberately excluded — nothing about members, players, money, documents or safeguarding is counted or sent, not even the address of the page.
  • Anthropic — powers the in-app help assistant (the “?” button). When you ask it a question, your question, your role at the club, your club’s name and the page you were on are sent to Anthropic to generate an answer. No club records are ever sent — it has no access to players, members, money, fixtures, documents or safeguarding information, and cannot look anything up. It only explains how ClubKeeper works. Questions and answers are stored in our own database so we can see which parts of the app people find hardest, and are not used to train anyone’s models. If you would rather not use it, don’t open it — nothing is sent unless you ask something.
  • Sentry — collects technical error reports when something goes wrong in the app, so we can find and fix it. A report can include the page you were on, your account’s internal ID, your IP address and your browser version. It is not used to track what you do, and it isn’t analytics. Sentry processes these in the EU (Frankfurt).
  • Google (Firebase Cloud Messaging) — delivers push notifications to the ClubKeeper mobile app. This applies only if you install the app and allow notifications; it involves a device token and the contents of the notification itself. If you only use ClubKeeper in a web browser, none of this applies to you.
  • Giphy — powers the optional GIF search in club chat. Your search words are sent through our server to Giphy; and because the GIFs themselves are served from Giphy, your browser or app loads the image from them directly when one is posted in a chat you can see, which means Giphy receives your IP address at that moment. Nothing else about you is sent, and the feature is only reachable inside chat.

We do not sell personal data, and we do not share it with anyone else for marketing purposes.

Where your data is stored

Our database is hosted in the UK. Some of our service providers above operate internationally as part of their own infrastructure; where that involves a transfer outside the UK/EU, it’s covered by their own standard contractual safeguards.

How long we keep it

We keep your data for as long as you’re an active member of a club on ClubKeeper. Leaving a club does not, on its own, remove it — when a club removes someone, their account and history (invoices, posts, messages) stay on the club’s own record, the same as any other club data, because the club may still need it. If you ask us to delete your account (see “Delete my account” in your settings), we remove your personal data then, except where a club’s own safeguarding policy or a legal obligation requires certain records (such as safeguarding history) to be kept for longer. Financial records may be retained as required for accounting purposes.

Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you (see “Export your data” in your account settings, or contact us).
  • Have inaccurate data corrected.
  • Ask us to delete your data (see “Delete my account” in your account settings, or contact us), subject to the retention exceptions above.
  • Object to or restrict certain processing.
  • Receive your data in a portable format.
  • Complain to the Information Commissioner’s Office (ICO) if you think we’ve mishandled your data.

To exercise any of these rights, contact jason@clubkeeperapp.com.

Security

All traffic to ClubKeeper is encrypted in transit (HTTPS). Passwords are never stored in plain text.

Every query ClubKeeper makes is scoped to the club you are signed in to. That scoping is enforced in the application and covered by automated tests that specifically attempt to read another club’s data and check that the attempt fails. We are additionally moving that enforcement down into the database itself, as a second and independent layer; that work is in progress and is not yet in force, and we will say so here when it is.

Two-factor authentication is required for club staff accounts — Admins, Treasurers and Welfare Officers — because those are the roles that can reach children’s records, safeguarding files and club finances. It is enforced on every session — pages and data exports alike — not merely requested. Access to safeguarding records is restricted further and separately logged, so a club can see who opened what.

When we access a club’s data

Sometimes we need to look inside a club to answer a support question or investigate a fault. Two limits apply, and they are different from each other:

  • Ordinary support access ends by itself 10 minutes after we enter, whether or not we are still working. It is a hard limit from the moment of entry, not an idle timeout. Every visit is recorded in the club’s own activity log, labelled as us, where the committee can see it alongside everything their own members did.
  • Safeguarding concern records are excluded from that access entirely. Being the platform operator is not a route in. To open one at a club’s request we have to take a separate, deliberate grant that requires a written reason, lasts 60 minutes and then expires on its own. The club’s Welfare Officer is notified when it opens — as it happens, not afterwards — and the reason is kept permanently.

Qualification and criminal-record-check status is treated separately from concerns: a club Admin can see whether a check exists and when it expires, but the uploaded certificate itself stays with the Welfare Officer.

Cookies

We only use strictly-necessary cookies — the kind that exist to make the thing you asked for work. We don’t use any advertising, analytics or tracking cookies, and we don’t share anything with third parties for those purposes. That’s why you aren’t asked to accept cookies when you arrive: there is nothing here to opt out of.

We do count how many people visit our public pages, so we know whether anyone is finding us. That counting uses no cookies or similar technologies and stores nothing on your device, which is why it does not change the paragraph above — see Vercel under “Who we share data with” above, and note that pages inside the app are excluded from it entirely.

There are four, and none of them are set until you sign in or start an action yourself:

  • A session cookie, which keeps you signed in.
  • A cookie recording which club you are currently working in, for people who belong to more than one.
  • A cookie remembering the “view as” role you picked, if you use that to preview what another role sees.
  • A short-lived security cookie used only while connecting a club’s Stripe account, to confirm the request came from you.

The app also keeps four small things in your browser’s own storage rather than in a cookie, and none of them is sent to us or to anyone else: which sections of a page you last had open, the teams you marked as favourites, a marker of when you last read your club’s activity, and — only if you install the mobile app and allow notifications — the device token that lets a notification reach you. They exist to make the thing you asked for work, which is why there is still nothing here to opt out of. Clearing your browser data removes them.

Paying by card sends you to Stripe’s own checkout page, which is subject to Stripe’s cookie and privacy policies rather than ours.

Changes to this policy

We’ll update this page if how we handle data changes, and update the “last updated” date above. For significant changes, we’ll let clubs know directly.

Contact us

Questions about this policy or your data: jason@clubkeeperapp.com.

ClubKeeper — the committee’s back office for grassroots clubs. Back to home