Club Kickoff
Club Kickoff is a mobile application for organising grassroots and amateur sports club activities (events, RSVPs, team messaging and member management).
The data controller for personal data processed in the Club Kickoff app is transparently.tech. The app is published and distributed under transparently.tech’s Google Play and Apple App Store accounts.
| Field | Value |
|---|---|
| Controller (trading name) | transparently.tech |
| Registered legal name | transparently.tech Limited |
| Registered address | International House, 38 Thistle Street, Edinburgh, EH2 1EN |
| ICO registration number | ZB339779 |
| Contact for data protection / privacy requests | privacy@transparently.tech |
Relationship with clubs. Clubs and their administrators/coaches are users of the Club Kickoff platform. transparently.tech is the controller for the personal data held inside the app. A club that keeps its own separate records offline (for example, paper registration forms or its own spreadsheets) may be an independent controller for those records — that is outside the scope of this notice.
We collect and process the following categories of personal data.
Children’s data is always entered and managed by a parent or guardian through their own account. Children do not hold their own accounts and cannot consent on their own behalf. See section 6.
We do not intentionally collect special-category data (e.g. health, religion). Please do not enter such data into free-text fields (e.g. messages or notes).
For all core club-management processing, our lawful basis is Legitimate Interests under UK GDPR Article 6(1)(f). Our legitimate interests are: operating a functioning club-organisation service, enabling clubs to coordinate events and communicate with their members, and keeping members informed about activities they have chosen to take part in.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and maintain your account | To let you sign in and use the app | Legitimate interests / performance of the service you requested |
| Show clubs your membership, role and contact name | So clubs can organise and manage their members | Legitimate interests |
| Record RSVPs and poll responses (incl. for children) | So events can be planned with accurate numbers | Legitimate interests |
| Assign members/children to event groups | So coaches know who is in their group | Legitimate interests |
| Deliver club chat, event-thread and broadcast messages | So clubs can communicate about activities | Legitimate interests |
| Send push and email notifications about events/messages | To keep you informed of activity you opted into | Legitimate interests (you can disable in settings) |
| Send club/event invitations by email | To let you join clubs you have been invited to | Legitimate interests |
| Estimate travel/departure time to an event | Convenience feature you actively request | Legitimate interests (processed only on request) |
| Collect crash and diagnostic data | To keep the app stable and diagnose faults | Legitimate interests (app stability/security) |
| Handle safety reports and moderate messages (review reports, remove messages, act on safeguarding concerns) | To keep members, and especially children, safe | Legitimate interests (the safety of our users and the public interest in protecting children) |
| Optional future features: photo sharing, marketing | — | Explicit consent (UK GDPR Art 6(1)(a)) — not yet active |
Consent is reserved for optional, non-core features. Core processing does not rely on consent and therefore cannot be “withdrawn” in a way that would stop the service functioning — but you retain the right to object (see section 8).
Your data is visible to other people within the clubs you belong to, as required for the service to work:
We use the following sub-processors (third parties who process data on our behalf, under a data-processing contract):
| Sub-processor | Purpose | Location & safeguards |
|---|---|---|
| Google Firebase / Google Cloud Platform (Google Cloud EMEA Limited / Google LLC) | Database (Firestore), authentication, cloud functions, file storage, push messaging |
Your member records (profiles, children’s profiles, club and event data, RSVPs,
messages and uploaded files) are stored in the United Kingdom (Google
Cloud London region, europe-west2). Firebase Authentication credentials
(e.g. your sign-in email) are processed on Google’s global infrastructure and are
not pinned to a single region. All processing is under Google’s Cloud Data
Processing Addendum, which incorporates the EU Standard Contractual Clauses and the UK
International Data Transfer Addendum. See section 7.
|
| Google Maps Platform (Distance Matrix API) | Travel/departure-time estimates (only when you request them) | Google Cloud, under Google’s Cloud Data Processing Addendum (SCCs + UK Addendum). See section 7. |
| Google Firebase Crashlytics (Google LLC) | Crash and diagnostic reporting, to keep the app stable | Crash reports and diagnostic data, with your Firebase user ID attached, are processed by Google on its global infrastructure and are not pinned to a single region (the same posture as Firebase Authentication). All processing is under Google’s Cloud Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. See section 7. |
| Resend (Plus Five Five, Inc., San Francisco, USA) | Transactional email delivery (invitations, notifications, and safety-report alerts) | Email content (recipient address, message) is processed in the United States under Resend’s Data Processing Addendum, which applies the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and the EU–US / UK Data Privacy Framework. |
When you report a safety concern, the report is sent to the other admins of your club (never to the person you are reporting) and always to us, the operator (transparently.tech), as an independent safety backstop — so a concern can be acted on even if the problem is a club admin. We send these alerts by email as well as in the app. The email tells the recipient that a report has been made, its category, who made it (and, if it was made on behalf of a child, that child’s name), a short extract of the reported message, and a link to view the full report in the app. Because we use an email provider (Resend, see above) to deliver these alerts, that limited report information passes through that provider. For a concern that a child may be at risk, we may share the report with the police or the relevant child-safeguarding authority.
We do not sell your personal data. We do not share it with advertisers.
We keep personal data only as long as needed for the purposes above.
| Data | Retention |
|---|---|
| Event message threads | 12 months after the event |
| RSVPs / attendance records | 12 months after the event |
| Club chat messages | 24 months |
| Kit orders (planned feature — no data stored yet) | 12 months |
| Inactive accounts | Reviewed for deletion after 24 months of inactivity |
| Consent records (future opt-in features) | Lifetime of account + 7 years |
| Safety reports and the evidence attached to them | 12 months (longer where a safeguarding concern is being dealt with) |
| Records of messages removed by coaches or admins (moderation log) | 24 months |
| Safety/moderation records about a child (not a safeguarding concern) | 6 months |
When you delete your account, your profile and child profiles are deleted or anonymised, subject to any retention we are legally required to keep.
Club Kickoff is built for clubs whose members include children. We take the stricter obligations for children’s data seriously:
Because children do not access or use Club Kickoff themselves — only adult parents, guardians, coaches and administrators do — the service is not an “information society service likely to be accessed by children” under the ICO’s Age Appropriate Design Code (Children’s Code). We nonetheless apply the heightened-care commitments above to all children’s data we hold on a guardian’s behalf.
If you report a concern that a child may be at risk, we treat it as a safeguarding matter: we keep the report for as long as we need to act on it and to pass it to the right safeguarding authority, and we keep other safety records about a child for a shorter time than ordinary records.
If you are a parent/guardian and want a child’s data removed, use the contact details in section 1 or section 8.
Our primary infrastructure (Google Firebase / Google Cloud) stores your member data —
your profile, children’s profiles, club and event records, RSVPs and messages
(Firestore) and any uploaded files (Storage) — in the
United Kingdom (Google Cloud’s London region,
europe-west2). Because this data stays in the UK, storing it does not involve a
restricted transfer of your data out of the UK.
A small number of transfers outside the UK still apply, each protected by appropriate safeguards — the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum (and, for Resend, the EU–US / UK Data Privacy Framework) — as set out in each provider’s data-processing terms:
You can ask us for more detail about the safeguards for any specific transfer using the contact details in section 1.
Under UK GDPR you have the right to:
To exercise any right, contact privacy@transparently.tech. We aim to respond within one month.
You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
To request deletion of your account and personal data, see our data deletion page.
We may update this notice. The current version and date are shown at the top of this page. Material changes will be notified in-app.