Privacy Policy
Last updated: 15 February 2026
1. Introduction
ClubRovia Technologies Ltd. ("ClubRovia", "we", "our", or "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our sports club management platform, website, and related services (collectively, the "Platform").
ClubRovia operates as a data processor on behalf of sports clubs (our customers), who act as data controllers. Where we collect data directly from you (e.g., via our marketing website), we act as the data controller.
This policy is designed to comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Irish Data Protection Act 2018, and all applicable Irish and EU data protection legislation.
2. Data We Collect
We collect and process the following categories of personal data:
2.1 Account & Profile Data
- Full name, email address, phone number
- Date of birth and gender
- Postal address
- Profile photographs (where uploaded)
- Role within the club (player, coach, volunteer, parent/guardian)
2.2 Membership & Registration Data
- Club membership details and membership tier
- Family and household group associations
- Emergency contact information
- Medical information (allergies, conditions) — stored with explicit consent only
2.3 Safeguarding & Compliance Data
- Garda Vetting application status and NVB reference numbers
- Safeguarding certification levels (SG1, SG2, SG3)
- First Aid and coaching qualification records
- Child protection declarations and consent records
2.4 Financial Data
- Payment transaction history
- Fundraising contributions and lotto participation
- Subscription and billing information
- We do not store full credit card numbers — all payments are processed via PCI-DSS compliant third-party providers (Stripe)
2.5 Usage & Technical Data
- IP address and browser/device information
- Pages visited, features used, and session duration
- Cookies and similar tracking technologies (see Section 9)
- Error logs and performance metrics
2.6 Communications Data
- Messages sent through the platform's internal messaging system
- Email notifications and their delivery/open status
- Support tickets and customer service interactions
3. How We Use Your Data
We process personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Platform operation & service delivery | Performance of contract |
| Member registration & management | Performance of contract |
| Safeguarding & child protection compliance | Legal obligation / Vital interests |
| Garda Vetting tracking & certification management | Legal obligation |
| Payment processing & financial record-keeping | Performance of contract / Legal obligation |
| Internal messaging & communications | Legitimate interest |
| Analytics & platform improvement | Legitimate interest |
| Marketing communications (with consent) | Consent |
| Fraud prevention & security monitoring | Legitimate interest |
| Compliance with Irish sports governance regulations | Legal obligation |
4. Data Sharing & Third Parties
We do not sell your personal data. We may share data with the following categories of recipients:
Service Providers
- Supabase (database hosting & authentication — EU data centres)
- Stripe (payment processing)
- Email delivery services (transactional and marketing emails)
- Cloud infrastructure providers (hosting and CDN)
Club Administrators
- Your club's designated administrators and officers can access member data relevant to their role
- Access is controlled via Row-Level Security (RLS) policies — administrators can only view data within their own club
Regulatory & Legal
- We may disclose data where required by Irish law, court order, or regulatory requirement
- This includes compliance with Sport Ireland, the National Vetting Bureau, and An Garda Síochána where legally mandated
5. Data Security
We implement industry-leading security measures to protect your data:
• Row-Level Security (RLS): Every database query is scoped to the authenticated user's club, ensuring complete data isolation between organisations.
• Encryption at Rest & in Transit: All data is encrypted using AES-256 at rest and TLS 1.3 in transit.
• Database-Enforced Minor Protection: Hard-coded schema-level restrictions prevent direct adult-minor contact outside approved safeguarding channels.
• PII Shadowing: Personally Identifiable Information is masked by default in all administrative views, requiring verified privilege escalation to access.
• Immutable Audit Trail: All data access, modifications, and compliance events are logged in a tamper-proof, append-only audit log.
• Regular Security Audits: We conduct quarterly penetration testing and annual third-party security assessments.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
• Active member data: Retained for the duration of membership plus 2 years after membership ends.
• Safeguarding & vetting records: Retained for a minimum of 7 years as required by Irish child protection legislation.
• Financial records: Retained for 6 years in compliance with Irish Revenue requirements.
• Marketing consent records: Retained until consent is withdrawn.
• Audit logs: Retained for 10 years for legal defence and compliance purposes.
• Technical/usage data: Retained for 24 months in anonymised/aggregated form.
When data is no longer required, it is securely deleted or irreversibly anonymised.
7. Children & Minor Data
ClubRovia takes the protection of children's data extremely seriously. Our platform includes specific safeguards for members under the age of 18:
• Parental/Guardian Consent: Registration of minors requires verified parental or guardian consent.
• Communication Restrictions: All messages involving minors are automatically routed through the club's designated Welfare Officer.
• Mandatory CC: Every communication involving a minor generates a mandatory carbon-copy to the club's Child Protection Officer.
• Restricted Data Access: Minor profiles have additional access restrictions, and PII is hidden by default from all users except verified guardians and designated safeguarding officers.
• Age Verification: Database-level enforcement prevents the creation of minor accounts without appropriate guardian linkage.
8. Your Rights Under GDPR
Under the GDPR, you have the following rights in relation to your personal data:
• Right of Access: Request a copy of the personal data we hold about you.
• Right to Rectification: Request correction of inaccurate or incomplete data.
• Right to Erasure: Request deletion of your data (subject to legal retention requirements).
• Right to Restrict Processing: Request that we limit how we use your data.
• Right to Data Portability: Receive your data in a structured, machine-readable format.
• Right to Object: Object to processing based on legitimate interests or direct marketing.
• Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
• Right to Lodge a Complaint: You have the right to lodge a complaint with the Data Protection Commission (DPC), the Irish supervisory authority.
To exercise any of these rights, please contact our Data Protection Officer at dpo@clubrovia.com. We will respond to all requests within 30 days.
ClubRovia provides a one-click Subject Access Request (SAR) feature within the platform, allowing members to generate a complete PDF report of all their personal data held on the system.
10. International Data Transfers
ClubRovia primarily stores and processes data within the European Union. Where data is transferred outside the EEA (for example, to service providers in the United States), we ensure appropriate safeguards are in place, including:
• EU Standard Contractual Clauses (SCCs)
• Adequacy decisions by the European Commission
• Binding Corporate Rules where applicable
We will not transfer data to any jurisdiction that does not provide an adequate level of data protection without implementing supplementary measures.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of any material changes by:
• Posting the updated policy on our website with a revised "Last Updated" date
• Sending a notification through the platform to club administrators
• Emailing registered users where the changes are significant
We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
ClubRovia Technologies Ltd.
Data Protection Officer
Email: dpo@clubrovia.com
Website: www.clubrovia.com
You may also contact the Irish Data Protection Commission:
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie