Privacy Policy
Version: PRIVACY_2026.1
Effective Date: February 25, 2026
1. Introduction
This Privacy Policy explains how Clubnizer ("we," "us," or "our") collects, uses, shares, and protects personal data when you use our platform for sports club management ("Service"). We are committed to protecting your privacy and handling your data responsibly. This policy applies to all users of Clubnizer, including Club administrators, members, and guardians.
2. Data Controller vs Data Processor Roles
Understanding who is responsible for your data depends on the context:
2.1 Club Data (Clubnizer as Data Processor)
For data processed within Clubs, the Club acts as the Data Controller. This means the Club (through its administrators) determines why and how member data is processed within their organization. Clubnizer acts as a Data Processor, processing Club data only on behalf of and under the instructions of the Club. We do not independently determine the purposes of processing Club member data.
2.2 Account Data (Clubnizer as Data Controller)
For data related to your Clubnizer account (such as your login credentials and account settings), Clubnizer acts as the Data Controller and processes such data to provide and maintain the Service.
3. Data We Collect
3.1 Account Data
- Email address
- Display name
- Password (stored as a secure hash)
3.2 Profile Data
You may optionally provide:
- Profile photo (may be taken with your device camera or selected from your photo library)
- Phone number
- Date of birth (required for Youth Members)
3.3 Club Membership Data
- Club and group associations
- Roles within the Club (e.g., player, coach, admin)
- Guardian relationships (for Youth Members)
3.4 Youth Member Data
For Youth Members (users under 16):
- Name
- Date of birth
- Guardian contact information
3.5 Event and Attendance Data
- Event RSVPs and responses
- Attendance records
- Participation history for statistical purposes
3.6 Payment Data
- Payment card details are processed by our payment provider (Stripe)
- We store transaction records and payment status
- We do not store full credit card numbers
3.7 Usage Data
- App interactions and feature usage
- Device information (platform, app version)
- Error logs and performance data
Note: Clubs are responsible for obtaining guardian consent before adding Youth Members. Clubnizer does not independently verify that such consent has been obtained.
3.8 Images and Media
The app allows you to upload images in the following contexts:
- Profile photos — a personal image associated with your account
- Club logos — an image representing your club
- Group images — an image representing a group within a club
Camera and Photo Library Access
To upload images, the app may request access to your device camera or photo library. This permission is requested only when you actively choose to upload an image. You can decline this permission and still use all other features of the app.
Image Storage
Uploaded images are stored using Firebase Storage (Google Cloud). Uploaded images may be accessible via a direct URL, meaning anyone who obtains the link to an image may be able to view it. You should not upload images containing sensitive or personal information you do not want to be publicly accessible.
Purpose
Images are used solely to personalize your profile or club within the app. We do not use uploaded images for advertising, analytics, or any purpose beyond providing the core functionality of the Service.
4. How We Use Data
We use the data we collect to:
4.1 Provide the Service
- Create and maintain your account
- Enable Club administration and member management
- Facilitate event scheduling and communications
- Process payments
4.2 Improve the Service
- Analyze usage patterns to improve features
- Fix bugs and resolve technical issues
- Develop new functionality
4.3 Communicate with You
- Send notifications about events and Club activities
- Deliver invitation emails
- Provide customer support
4.4 Ensure Security
- Prevent unauthorized access
- Detect and prevent fraud
- Enforce our Terms of Service
5. Legal Basis for Processing
We process personal data based on: contract performance (to provide the Service), legitimate interests (security, fraud prevention, service improvement), controller-determined basis (for Club member data, the Club determines the applicable lawful basis), and legal obligations as required by applicable laws.
6. Youth Members and Guardian Consent
Youth Members (users under 16 years of age) must be associated with a Guardian in the system. Youth Members cannot create accounts directly. Clubs and their administrators are solely responsible for obtaining appropriate consent from Guardians before adding Youth Members, ensuring Guardians are informed about data processing, and maintaining accurate Guardian contact information.
Clubnizer does not independently verify that guardian consent has been obtained. We rely on Clubs to fulfill this responsibility. Guardians may exercise data subject rights on behalf of their Youth Members.
7. Data Sharing
7.1 With Your Club
Your data is shared with the Club(s) you belong to, as determined by Club administrators. Club administrators can view member information as necessary for Club administration.
7.2 With Other Club Members
Certain information (such as name, profile photo, email, and role) may be visible to other members within the same Club, as configured by Club administrators.
7.3 With Sub-Processors
We share data with service providers who process data on our behalf:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Infrastructure, authentication, database, image storage | USA/EU |
| Stripe | Payment processing | USA/EU |
| [Email Provider] | Transactional email delivery | [Location] |
7.4 Legal Requirements
We may disclose data when required by law or to:
- Comply with legal processes
- Protect our rights and safety
- Prevent fraud or security threats
7.5 No Selling of Data
We do not sell your personal data to third parties.
8. International Data Transfers
Your data may be processed in countries other than your country of residence, including the United States and other countries where our service providers operate. When we transfer data internationally, we implement appropriate safeguards as required by applicable data protection laws. We cannot guarantee that data protection laws in all countries where data is processed will be equivalent to those in your jurisdiction.
9. Data Retention
9.1 Active Accounts
We retain your data while your account remains active and as necessary to provide the Service.
9.2 Inactive Memberships
- When you leave a group, are removed from a Club, or your membership becomes inactive, your membership record is soft-deleted and marked as inactive
- A 30-day grace period applies, during which a Club administrator can reactivate your membership
- After 30 days, inactive membership records are permanently deleted by an automated cleanup process
- Any outstanding membership fees associated with the membership are cancelled upon removal
9.3 Account Deletion ("Delete My Account")
You can delete your own account at any time using the "Delete My Account" option in your Profile settings within the app. Account deletion is immediate and permanent — there is no recovery period.
Pre-conditions
Before you can delete your account, you must meet all of the following conditions:
- Leave all groups — you cannot have any active group memberships.
- Not hold a club-admin role — another club admin must remove you as club admin first.
- Not be a guardian of active youth players — contact a club admin to remove the guardian association first.
If any of these conditions are not met, the app will inform you of the specific steps required.
What is deleted immediately
- Your Firebase Authentication account (login credentials)
- Your user profile document (name, email, phone, profile photo reference, preferences)
- Your in-app notifications
What is NOT deleted by account deletion
- Club membership records — these are managed by the Club and follow the inactive membership lifecycle described in Section 9.2. Since you must leave all groups before deleting your account, these records will already be in the soft-deleted state.
- Event and attendance data — historical event responses and attendance records you contributed while active may be retained by the Club for administrative purposes.
- Payment and transaction records — retained as required by law and by our payment processor (Stripe) for financial compliance.
- Anonymized usage data — aggregated, non-identifiable analytics data may be retained.
9.3a Admin-Deactivated Accounts
If your account is deactivated by an administrator rather than self-deleted, a 60-day grace period applies. During this period, the account may be reactivated. After 60 days, the account is permanently deleted by an automated cleanup process.
9.4 Extended Retention
- Required by law (for example, financial records)
- Necessary for legitimate business purposes (for example, fraud prevention)
- Subject to ongoing disputes or legal proceedings
9.5 Backup Retention
Backups may retain data for a limited period after deletion from the primary system.
10. Your Rights
Under applicable data protection laws, you may have the following rights:
10.1 Right of Access
Request a copy of the personal data we hold about you.
10.2 Right to Rectification
Request correction of inaccurate or incomplete personal data.
10.3 Right to Erasure
Request deletion of your personal data, subject to legal retention requirements. You can exercise this right directly by using the "Delete My Account" feature in the app. See Section 9.3 for details and pre-conditions.
10.4 Right to Restriction
Request that we limit processing of your data in certain circumstances.
10.5 Right to Data Portability
Request your data in a portable format for transfer to another service.
10.6 Right to Object
Object to processing based on legitimate interests in certain circumstances.
10.7 Data Export
Data export is available upon request. To request an export of your data, please contact us at support@clubnizer.com. We will respond within a reasonable timeframe.
10.8 How to Exercise Your Rights
To delete your account: Use the "Delete My Account" option in your Profile settings within the app. This performs an immediate, permanent deletion of your account data. See Section 9.3.
For Club data: Contact your Club administrator, who as Data Controller can assist with requests relating to Club membership data.
For account data or other requests: Contact us directly at privacy@clubnizer.com. We aim to respond to requests within 30 days.
11. Cookies and Tracking
11.1 Essential Cookies
We use essential cookies necessary for the Service to function, including:
- Authentication and session management
- Security features
11.2 Analytics
We may collect anonymized usage data to improve the Service. This does not include personal identifiers.
12. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction.
Our security measures include:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of data at rest
- Access controls and authentication
- Regular security reviews
However, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk.
12a. Device Permissions
Clubnizer may request the following device permissions. The specific permission identifiers differ by platform but serve the same purpose.
| Permission | Android | iOS | Purpose | Required |
|---|---|---|---|---|
| Camera | android.permission.CAMERA | NSCameraUsageDescription | Allows you to take a photo when uploading a profile picture, club logo, or group image | Optional |
| Photo Library | android.permission.READ_EXTERNAL_STORAGE | NSPhotoLibraryUsageDescription | Allows you to select an existing image from your device photo library when uploading | Optional |
| Push Notifications | android.permission.POST_NOTIFICATIONS | Prompted at runtime by iOS | Allows the app to send you notifications about events and club activities | Optional |
All permissions are requested at the moment you choose to use the relevant feature, or (for notifications) when you first enable them in the app. You may decline any permission — this will prevent the specific feature from working but will not affect other app functionality. You can manage or revoke permissions at any time through your device settings.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- The "Last Updated" date will be revised
- Material changes will be communicated via the Platform or email
- Continued use of the Service after changes constitutes acceptance
We encourage you to review this policy periodically.
14. Contact Us
For questions about this Privacy Policy or our data practices:
- Privacy Inquiries: privacy@clubnizer.com
- General Support: support@clubnizer.com
We aim to respond to all inquiries within 30 days.
15. Additional Information for Specific Jurisdictions
15.1 European Economic Area (EEA) Users
If you are located in the EEA, you have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.
15.2 California Users
California residents may have additional rights under the California Consumer Privacy Act (CCPA). We do not sell personal information as defined under CCPA.
By using Clubnizer, you acknowledge that you have read and understood this Privacy Policy.