Legal

    Privacy Policy

    Last updated: 15 February 2026

    1. Introduction

    ClubRovia Technologies Ltd. ("ClubRovia", "we", "our", or "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our sports club management platform, website, and related services (collectively, the "Platform").

    ClubRovia operates as a data processor on behalf of sports clubs (our customers), who act as data controllers. Where we collect data directly from you (e.g., via our marketing website), we act as the data controller.

    This policy is designed to comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Irish Data Protection Act 2018, and all applicable Irish and EU data protection legislation.

    2. Data We Collect

    We collect and process the following categories of personal data:

    2.1 Account & Profile Data

    • Full name, email address, phone number
    • Date of birth and gender
    • Postal address
    • Profile photographs (where uploaded)
    • Role within the club (player, coach, volunteer, parent/guardian)

    2.2 Membership & Registration Data

    • Club membership details and membership tier
    • Family and household group associations
    • Emergency contact information
    • Medical information (allergies, conditions) — stored with explicit consent only

    2.3 Safeguarding & Compliance Data

    • Garda Vetting application status and NVB reference numbers
    • Safeguarding certification levels (SG1, SG2, SG3)
    • First Aid and coaching qualification records
    • Child protection declarations and consent records

    2.4 Financial Data

    • Payment transaction history
    • Fundraising contributions and lotto participation
    • Subscription and billing information
    • We do not store full credit card numbers — all payments are processed via PCI-DSS compliant third-party providers (Stripe)

    2.5 Usage & Technical Data

    • IP address and browser/device information
    • Pages visited, features used, and session duration
    • Cookies and similar tracking technologies (see Section 9)
    • Error logs and performance metrics

    2.6 Communications Data

    • Messages sent through the platform's internal messaging system
    • Email notifications and their delivery/open status
    • Support tickets and customer service interactions

    3. How We Use Your Data

    We process personal data for the following purposes:

    PurposeLegal Basis
    Platform operation & service deliveryPerformance of contract
    Member registration & managementPerformance of contract
    Safeguarding & child protection complianceLegal obligation / Vital interests
    Garda Vetting tracking & certification managementLegal obligation
    Payment processing & financial record-keepingPerformance of contract / Legal obligation
    Internal messaging & communicationsLegitimate interest
    Analytics & platform improvementLegitimate interest
    Marketing communications (with consent)Consent
    Fraud prevention & security monitoringLegitimate interest
    Compliance with Irish sports governance regulationsLegal obligation

    4. Data Sharing & Third Parties

    We do not sell your personal data. We may share data with the following categories of recipients:

    Service Providers

    • Supabase (database hosting & authentication — EU data centres)
    • Stripe (payment processing)
    • Email delivery services (transactional and marketing emails)
    • Cloud infrastructure providers (hosting and CDN)

    Club Administrators

    • Your club's designated administrators and officers can access member data relevant to their role
    • Access is controlled via Row-Level Security (RLS) policies — administrators can only view data within their own club

    Regulatory & Legal

    • We may disclose data where required by Irish law, court order, or regulatory requirement
    • This includes compliance with Sport Ireland, the National Vetting Bureau, and An Garda Síochána where legally mandated

    5. Data Security

    We implement industry-leading security measures to protect your data:

    • Row-Level Security (RLS): Every database query is scoped to the authenticated user's club, ensuring complete data isolation between organisations.

    • Encryption at Rest & in Transit: All data is encrypted using AES-256 at rest and TLS 1.3 in transit.

    • Database-Enforced Minor Protection: Hard-coded schema-level restrictions prevent direct adult-minor contact outside approved safeguarding channels.

    • PII Shadowing: Personally Identifiable Information is masked by default in all administrative views, requiring verified privilege escalation to access.

    • Immutable Audit Trail: All data access, modifications, and compliance events are logged in a tamper-proof, append-only audit log.

    • Regular Security Audits: We conduct quarterly penetration testing and annual third-party security assessments.

    6. Data Retention

    We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:

    • Active member data: Retained for the duration of membership plus 2 years after membership ends.

    • Safeguarding & vetting records: Retained for a minimum of 7 years as required by Irish child protection legislation.

    • Financial records: Retained for 6 years in compliance with Irish Revenue requirements.

    • Marketing consent records: Retained until consent is withdrawn.

    • Audit logs: Retained for 10 years for legal defence and compliance purposes.

    • Technical/usage data: Retained for 24 months in anonymised/aggregated form.

    When data is no longer required, it is securely deleted or irreversibly anonymised.

    7. Children & Minor Data

    ClubRovia takes the protection of children's data extremely seriously. Our platform includes specific safeguards for members under the age of 18:

    • Parental/Guardian Consent: Registration of minors requires verified parental or guardian consent.

    • Communication Restrictions: All messages involving minors are automatically routed through the club's designated Welfare Officer.

    • Mandatory CC: Every communication involving a minor generates a mandatory carbon-copy to the club's Child Protection Officer.

    • Restricted Data Access: Minor profiles have additional access restrictions, and PII is hidden by default from all users except verified guardians and designated safeguarding officers.

    • Age Verification: Database-level enforcement prevents the creation of minor accounts without appropriate guardian linkage.

    8. Your Rights Under GDPR

    Under the GDPR, you have the following rights in relation to your personal data:

    • Right of Access: Request a copy of the personal data we hold about you.

    • Right to Rectification: Request correction of inaccurate or incomplete data.

    • Right to Erasure: Request deletion of your data (subject to legal retention requirements).

    • Right to Restrict Processing: Request that we limit how we use your data.

    • Right to Data Portability: Receive your data in a structured, machine-readable format.

    • Right to Object: Object to processing based on legitimate interests or direct marketing.

    • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

    • Right to Lodge a Complaint: You have the right to lodge a complaint with the Data Protection Commission (DPC), the Irish supervisory authority.

    To exercise any of these rights, please contact our Data Protection Officer at dpo@clubrovia.com. We will respond to all requests within 30 days.

    ClubRovia provides a one-click Subject Access Request (SAR) feature within the platform, allowing members to generate a complete PDF report of all their personal data held on the system.

    9. Cookies & Tracking Technologies

    Our website and platform use cookies and similar technologies:

    Strictly Necessary Cookies

    • Authentication session tokens
    • Security and CSRF protection
    • These cannot be disabled as they are essential for the platform to function

    Analytics Cookies

    • Platform usage analytics (anonymised)
    • Performance monitoring
    • These are only set with your consent

    Marketing Cookies

    • Used only on our marketing website (not within the club platform)
    • Advertising and remarketing pixels
    • These are only set with your explicit consent

    You can manage your cookie preferences at any time via the cookie settings panel on our website, or through your browser settings.

    10. International Data Transfers

    ClubRovia primarily stores and processes data within the European Union. Where data is transferred outside the EEA (for example, to service providers in the United States), we ensure appropriate safeguards are in place, including:

    • EU Standard Contractual Clauses (SCCs)

    • Adequacy decisions by the European Commission

    • Binding Corporate Rules where applicable

    We will not transfer data to any jurisdiction that does not provide an adequate level of data protection without implementing supplementary measures.

    11. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of any material changes by:

    • Posting the updated policy on our website with a revised "Last Updated" date

    • Sending a notification through the platform to club administrators

    • Emailing registered users where the changes are significant

    We encourage you to review this policy periodically.

    12. Contact Us

    If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

    ClubRovia Technologies Ltd.

    Data Protection Officer

    Email: dpo@clubrovia.com

    Website: www.clubrovia.com

    You may also contact the Irish Data Protection Commission:

    Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland

    Website: www.dataprotection.ie