Privacy policy

Version of 2026-10-04

Sport CRM is a service for sports clubs and schools: schedule, attendance, subscriptions, payments and a portal for parents. This policy explains what personal data is processed, why, who sees it and what your rights are. We follow the EU General Data Protection Regulation (GDPR) and apply the same rules to users from every country.

1. Who is responsible

The service is provided by Stanislav Mashyn (an individual, Spain) — “we”. Contact for personal data: privacy@sportcrm.app.

Data about players, parents, staff, leads and payments is entered and used by the sports club. For this data the club is the controller and we are a processor that stores and processes it on the club's behalf (Art. 28 GDPR). For questions about this data (for example, to erase a child's data) please contact the club first; we help the club fulfil your request.

For user accounts (email, password, settings), notifications, the change log and backups, we are the controller.

2. What data is processed

  • Account: email address, password (only as a protected hash), language, date format, consents to the documents.
  • Club staff: name, role, phone and messengers, extra fields the club defines, who marked attendance or took a payment.
  • Parents and other contacts: name, phone, messengers, email, relation to the child, the club's notes.
  • Players (mostly children): name, date of birth, contacts, team, attendance and reasons for absence, subscriptions and payments, height and weight, medical certificate and insurance dates, competition results, the club's notes and extra fields.
  • Athlete development (if the club turned it on): physical test results, personal records, belts and gradings, tournament entries (team roster, shirt number).
  • Online payments (if the club turned them on): the amount, who it is for, the payer's email, the payment status. Card details are entered on Stripe's page and never reach us.
  • Leads from the form on the club's website: the parent's surname, first name and phone, the child's name and birth year, a comment, and the history of the club's work on the lead (who changed its status or details, and when).
  • Calendar links (if you subscribed to the schedule in your calendar): the link holds a secret key, and the schedule (including children's names) goes to the calendar service you chose. You can revoke the link in the settings.
  • Messages from the form on sportcrm.app: name, email, club and text — only to reply; they reach us by email and stay in the mailbox as long as the conversation needs.
  • Technical data: cookies for signing in and for settings (see the cookie policy), server logs (IP address, request time) — kept up to 7 days.

Health data (medical certificate, insurance, height and weight, reasons for absence, fields such as “allergies”) is a special category. The club processes it only with the parents' explicit consent, which parents give to the club and confirm in the parent portal.

3. Why, and on what basis

  • Providing the service to the club and its users — performance of a contract (the terms of use), Art. 6(1)(b) GDPR.
  • Players' and parents' data in the club — on the club's own basis: its agreement with parents about the training, its legitimate interest, or the parents' consent.
  • Health data — the parents' explicit consent, Art. 9(2)(a) GDPR.
  • Signs that a player may drop out (several absences in a row, a debt older than a week, a sharp fall in attendance) — the club's legitimate interest in keeping the player, Art. 6(1)(f) GDPR. This is an automated assessment, that is profiling, but it decides nothing by itself: a club manager only gets a task to contact the family. You can object to it by contacting the club.
  • Security, abuse prevention, backups — our legitimate interest, Art. 6(1)(f) GDPR.
  • Legal obligations (for example, answering a lawful request of an authority) — Art. 6(1)(c) GDPR.

We do not sell data, show ads, use visitor analytics, or share data with third parties for their own purposes. The only profiling is the risk signs above; the system makes no automated decisions with legal or similarly significant effects on a person (Art. 22 GDPR).

4. Children

Children do not have their own accounts: their data is entered by the club and the parents. Only adults may sign up. Parents see their child's data in the parent portal, can correct the name and date of birth, and can ask the club to erase or anonymise the data.

5. Who sees the data

  • Club staff — according to their role (owner, support, manager, coach). A club can limit coaches to the players of their own teams.
  • Parents — only their own children's data.
  • The platform administrator — only for support and troubleshooting; their changes are recorded in the change log.
  • Processors that help us run the service (below).

6. Processors and transfers outside the EU

  • Supabase — database and sign-in; data is stored in the EU (Ireland).
  • Cloudflare — application servers and protection; processing runs in the EU region, Cloudflare's network is global.
  • GitHub (Microsoft) — encrypted database backups kept up to 30 days; USA.
  • Telegram — only if a parent connects the reminder bot: the child's first name, session time, debt, certificate date.
  • Email provider — for password reset and confirmation emails.
  • Cloudflare Turnstile — checks that a person, not a bot, fills in the form on sportcrm.app; not used for ads or tracking.
  • Stripe — only if the club turned on online payments: the payment goes to the club's Stripe account; Stripe receives the amount, the payer's email and the card details (we neither see nor store the card). For the payment itself Stripe acts as an independent controller under its own privacy policy; data may be transferred to the USA.

Transfers to the USA rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses. We notify clubs in advance about changes of processors.

7. How long we keep data

  • Account — until you delete it.
  • Club data — until the club deletes it or the club itself is deleted.
  • Archived players — the club is offered to anonymise them after 3 years.
  • Closed leads — 12 months.
  • Read notifications, used and expired invitations — 90 days.
  • Change log — 30 days; backups — 30 days; server logs — up to 7 days.
  • Consent records — as long as needed to prove the consent was given.

8. Your rights

You have the right to access your data and get a copy, to rectify it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time (without affecting earlier lawful processing).

  • You can download your data and delete your account yourself in the settings.
  • For data held by a club (including a child's data), contact the club or us: privacy@sportcrm.app.
  • We answer within one month.

You may also complain to a supervisory authority: in Spain the Agencia Española de Protección de Datos (aepd.es), or the authority of your own country.

9. Security

Connections are encrypted (HTTPS), the database is encrypted at rest, each club's data is separated by rules enforced in the database, backups are encrypted and changes are logged. If a breach puts your rights at risk, we inform the club without undue delay and the supervisory authority within 72 hours.

10. Cookies

We use only necessary cookies: to keep you signed in and for your settings (language, date format, theme). There are no analytics or advertising cookies, so no separate consent or banner is needed. The list of cookies with their lifetimes is in the cookie policy.

11. Changes

If we change this policy materially, you will see the new version and confirm it the next time you sign in. The version date is shown at the top.