Privacy Policy

Last Updated: August 1, 2026

This policy explains what personal data ClubMeister collects, why we process it, the third-party providers (sub-processors) we rely on to run the service, and the rights you have under the EU General Data Protection Regulation (GDPR) and comparable laws such as the UK GDPR. We collect only what we need to run a team-management app — no advertising, no selling of your data, ever.

1. Who We Are (Data Controller)

ClubMeister is a team- and club-management app operated by Jasper Boskma ("ClubMeister", "we", "us"). For any privacy matter — including exercising your rights below — you are the data subject and we are the controller of your personal data.

Our full legal notice is in the Legal Notice.

Where your club or team is the entity that decides how your data is used within the app (for example, which members to invite, which events to create, or whether to enable payments), that club acts as a controller in its own right and ClubMeister acts as its processor. This policy covers ClubMeister's own processing.

2. Information We Collect

We collect the following categories of personal data:

Account & profile data

Team & activity data

Payment data (only if your club enables payments)

Card and bank details are collected and processed directly by our payment provider, Stripe (see the sub-processor table). ClubMeister never stores your full card number.

Contact form

When you write to us through the form at /support, we receive your name, your email address and the message itself. We use them to answer you and for nothing else — no marketing, no profiling. Your IP address is not stored: we keep only a salted, irreversible hash of it, purely to stop the form being used to send us hundreds of messages an hour. Enquiries are deleted once the matter is resolved and no longer needed as a record, and at the latest in line with Section 11.

Technical & usage data

3. Legal Bases for Processing (GDPR Art. 6)

We rely on the following legal bases:

4. How We Use Your Data

We do not use your data for advertising, we do not sell it, and we do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.

5. Analytics

We use Mixpanel to understand how ClubMeister is used, configured for EU data residency (data is sent to Mixpanel's EU endpoint). In the app, analytics events are tied to a pseudonymous identifier and record which features are used, not the content of your messages or personal details. Our marketing website uses Mixpanel in a cookieless mode: no cookies, no persistent identifiers, IP-based geolocation disabled, and the browser's "Do Not Track" signal is respected. We do not build advertising profiles.

6. Sub-Processors and Third-Party Services

To run ClubMeister we share the minimum necessary personal data with the vetted service providers ("sub-processors") listed below. Each processes data only on our instructions and under a data-processing agreement. Some are located outside the EU/EEA — see Section 7 on international transfers.

ProviderPurposeData processedLocation / transfer
Supabase Inc.
Privacy
Core backend: database, authentication, file storage, and server-side functions. This is where your account, profile, team, event, chat, and content data live. All account, profile, team, content, and activity data USA (hosted on AWS, region us-west-1). SCCs.
Amazon Web Services, Inc.
Privacy
Underlying cloud infrastructure on which our Supabase backend runs. All hosted data (as processor to Supabase) USA. SCCs / EU-US Data Privacy Framework.
Stripe, Inc. / Stripe Payments Europe, Ltd.
Privacy
Payment processing, club subscriptions, and Stripe Connect payouts (only if your club enables payments). Name, email, transaction and payment details; payout/identity details for club accounts EU & USA. SCCs / DPF.
Twilio Inc.
Privacy
Delivery of SMS event reminders and RSVP messages (only if you provide a phone number and opt in). Phone number, message content USA. SCCs.
OneSignal, Inc.
Privacy
Delivery of push notifications to your device. Push token, device/app info, notification content USA. SCCs.
Mixpanel, Inc.
Privacy
Product and website usage analytics (pseudonymous, EU data residency). Pseudonymous usage events, coarse region, device/app info EU data residency (api-eu.mixpanel.com).
Google (Google Ireland Ltd / Google LLC)
Privacy
"Sign in with Google" authentication; Google Maps/Places for venue search; Google Fonts on our website. Email & account identifier (sign-in); IP and search query (maps/fonts) EU & USA. SCCs / DPF.
Apple Inc.
Privacy
"Sign in with Apple" authentication. Email (or Apple relay address) and account identifier USA. SCCs.
Mapbox, Inc.
Privacy
Venue/location search and maps when adding event locations. Search text, approximate location USA. SCCs.
Giphy, Inc.
Privacy
GIF search when you add a GIF to a chat message. Search text, IP address USA. SCCs.
Vercel Inc.
Privacy
Hosting of our marketing website and these legal pages. IP address and request metadata (website only) USA. SCCs / DPF.

We keep this list current. If we add or replace a sub-processor, we will update this page and, where required, notify you.

7. AI Connections (Claude & ChatGPT)

A team admin can connect ClubMeister to an AI assistant such as Claude (Anthropic) or ChatGPT (OpenAI) using our MCP connector. This is off by default and only takes effect when an admin explicitly connects an assistant and chooses a single team to connect. If nobody in your club does that, nothing in this section applies to you.

What the assistant can access

Once connected, the assistant can request the following data for the one connected team only, and only within what the connecting admin's own role already permits:

The connector cannot read or send chat messages of any kind (team chat, group chats or direct messages), and cannot access payment, fee or Stripe data. It cannot delete anything, and it cannot invite, remove or change the role of a member.

Where that data goes

When an assistant requests data, we transmit it to the AI provider the admin chose. That provider is not our sub-processor. We have no agreement with it, we do not select it, and we receive nothing back from it. The admin, acting for the club, directs the transfer to a service of their own choosing under their own relationship with that provider. What the provider then does with the data — including whether it is retained, reviewed by staff, or used to train models — is governed by that provider's terms and privacy policy, not by this one. Anthropic and OpenAI are both established in the United States, so connecting an assistant will normally involve a transfer outside the EU/EEA that the club, not ClubMeister, is responsible for.

Who is responsible for what

Connecting an assistant is a decision your club makes, not one we make for it. As set out in Section 1, where your club decides how member data is used within the app, the club is the controller and ClubMeister acts as its processor. Enabling a connection is a documented instruction from the club to us to transmit that team's data to the assistant it has chosen, and we act on it. The split is:

If you are a team admin, this is on you

The data an assistant can reach includes personal data about other members of your team, who are not party to your decision and may not know you have made it. Before you connect an assistant, and for as long as it stays connected, you are responsible for:

ClubMeister provides the connector, the admin-only gate, the per-team scoping and the audit log so that these decisions can be made and reviewed. We do not, and cannot, make them for you. Before a connection can be created, the admin must confirm on the consent screen that they are authorised to make it and will tell their members; we record when that confirmation was given. These obligations are set out as binding warranties in clause 5 of our Terms of Service.

What we store about the connection

Retention

Expired authorization codes and long-expired access tokens are deleted automatically each night. Refresh tokens are kept for the life of the connection so that a replayed token can be detected and the connection shut down. Connection records and audit entries are retained while the connection exists and for a limited period afterwards for security and troubleshooting, then deleted in line with Section 11.

Your control

An admin can see every assistant they have connected under AI connections in the app, and disconnect any of them at a tap. Access stops immediately: the assistant's tokens are revoked in the same moment. Permissions are also re-checked on every single request, so a role change or a deactivated membership takes effect at once rather than at the next sign-in. Data already sent to an AI provider before you disconnect is subject to that provider's retention — contact them to have it removed.

Legal basis

For the connection metadata we hold as controller, we rely on performing the service you asked us to provide (GDPR Art. 6(1)(b)) and, for the audit log and rate limiting, on our legitimate interest in keeping the connector secure and abuse-free (Art. 6(1)(f)). For the team data transmitted to the assistant we act on the club's instruction as its processor; establishing the lawful basis for that transfer, and any safeguard required for sending it outside the EU/EEA, is the club's responsibility as controller.

8. International Data Transfers

ClubMeister's primary database is hosted in the United States (AWS, region us-west-1), and several of the sub-processors above are located outside the EU/EEA. Where personal data of EU/EEA (or UK) users is transferred to a country without an EU adequacy decision, we rely on appropriate safeguards under GDPR Chapter V — principally the European Commission's Standard Contractual Clauses (SCCs), and, where a provider is certified, the EU-US Data Privacy Framework. You may request a copy of the relevant safeguards via privacy@clubmeister.app.

SMS Notifications

If you provide your phone number, we may send you SMS messages related to team events, including event reminders and RSVP confirmations. By replying YES to our opt-in message, you consent to receiving these messages.

SMS notifications are sent through our third-party messaging provider, Twilio, Inc. Twilio processes your phone number solely to deliver messages on our behalf. For more information, see Twilio's privacy policy.

9. Data Storage and Security

Your data is stored and managed using Supabase, hosted on Amazon Web Services in the United States. We apply technical and organisational measures to protect your personal information, including encryption in transit (HTTPS/TLS), hashed passwords, row-level access controls in the database so members can only see data they are entitled to, and restricted administrative access. No method of transmission or storage is completely secure, but we work to protect your data and to keep these measures under review.

10. Your Rights

Under the GDPR (and equivalent laws) you have the right to:

You can exercise many of these directly in the app (editing or removing your data, deleting content, or deleting your account). For any request, contact privacy@clubmeister.app; we will respond within the time limits set by law (generally one month). You also have the right to lodge a complaint with a data-protection supervisory authority — in the Member State of your habitual residence, your place of work, or the place of the alleged infringement (GDPR Art. 77). As we are established in North Rhine-Westphalia, the authority competent for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW); you are free to approach your own instead.

11. Data Retention and Deletion

We keep personal data only for as long as needed for the purposes described in this policy. In particular:

12. Children's Privacy

ClubMeister is used by sports clubs and teams, which may include minors. Where a member is under the age required for consent in their country, an account should be set up and managed with the involvement of a parent, guardian, or the club administrator responsible for that member. We do not knowingly collect data from children beyond what a club needs to manage participation. If you believe a child's data has been provided without proper authorisation, contact us and we will address it.

13. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will post the updated policy on this page and revise the "Last Updated" date above. For material changes we will provide a more prominent notice where appropriate.

14. Contact Us

If you have any questions about this privacy policy or our data practices, or to exercise your rights, please contact us at:

privacy@clubmeister.app