Dit document is beschikbaar in de oorspronkelijke taal.
Privacy policy
Version of 2026-10-08
Sport CRM is a service for sports clubs and schools: schedule, attendance, subscriptions, payments and a portal for parents. This policy explains what personal data is processed, why, who sees it and what your rights are. We follow the EU General Data Protection Regulation (GDPR) and apply the same rules to users from every country.
1. Who is responsible
The service is provided by Stanislav Mashyn (an individual, Spain) — “we”. Contact for personal data: privacy@sportcrm.app.
Data about players, parents, staff, leads and payments is entered and used by the sports club. For this data the club is the controller and we are a processor that stores and processes it on the club's behalf (Art. 28 GDPR). For questions about this data (for example, to erase a child's data) please contact the club first; we help the club fulfil your request.
For user accounts (email, password, settings), notifications, the change log and backups, we are the controller.
2. What data is processed
- Account: email address, password (only as a protected hash), language, date format, consents to the documents.
- Club staff: name, role, phone and messengers, extra fields the club defines, who marked attendance or took a payment; if the club records them — coach pay rates and payouts, and the expiry date of the criminal record certificate required for work with children (only the date, not the certificate).
- Parents and other contacts: name, phone, messengers, email, relation to the child, the club's notes.
- Players (mostly children): name, date of birth, contacts (phone, email, address), team, attendance and reasons for absence, game call-ups, subscriptions, payments and one-off charges, height and weight, medical certificate and insurance dates, federation licence number and expiry, competition results, workouts, club shop orders and equipment lent, the club's notes and extra fields.
- Athlete development (if the club turned it on): physical test results, personal records, belts and gradings, tournament entries (team roster, shirt number).
- Online payments (if the club turned them on): the amount, who it is for, the payer's email, the payment status. Card details are entered on Stripe's page and never reach us.
- Leads from the form on the club's website: the surname, first name, phone, messengers and email of the parent (or of the adult signing up themselves), the child's name and birth year, a comment, and the history of the club's work on the lead (who changed its status or details, and when). If the club turned on messages after a trial session and the lead left an email, they are sent to it.
- Calendar links (if you subscribed to the schedule in your calendar): the link holds a secret key, and the schedule (including children's names) goes to the calendar service you chose. You can revoke the link in the settings.
- Messages from the form on sportcrm.app: name, email, club and text, plus the sender's IP address and country (against spam) — only to reply; they reach us by email and stay in the mailbox as long as the conversation needs.
- Sign-in with Google or Apple (if you choose it): the email and name from that account, kept with your account.
- Club billing details (for a paid plan): the club's legal name, tax ID, address and billing email, and the plan payments.
- Technical data: cookies for signing in and for settings (see the cookie policy), server logs (IP address, request time) — kept up to 7 days; sign-in sessions (IP address and browser) — while you stay signed in.
Health data (medical certificate, insurance, height and weight, reasons for absence, fields such as “allergies”) is a special category. The club processes it only with the parents' explicit consent, which parents give to the club and confirm in the parent portal.
3. Why, and on what basis
- Providing the service to the club and its users — performance of a contract (the terms of use), Art. 6(1)(b) GDPR.
- Players' and parents' data in the club — on the club's own basis: its agreement with parents about the training, its legitimate interest, or the parents' consent.
- Health data — the parents' explicit consent, Art. 9(2)(a) GDPR.
- Signs that a player may drop out (several absences in a row, a debt older than a week, a sharp fall in attendance) — the club's legitimate interest in keeping the player, Art. 6(1)(f) GDPR. This is an automated assessment, that is profiling, but it decides nothing by itself: a club manager only gets a task to contact the family. You can object to it by contacting the club.
- Security, abuse prevention, backups — our legitimate interest, Art. 6(1)(f) GDPR.
- Legal obligations (for example, answering a lawful request of an authority) — Art. 6(1)(c) GDPR.
We do not sell data, show ads, use visitor analytics, or share data with third parties for their own purposes. The only profiling is the risk signs above; the system makes no automated decisions with legal or similarly significant effects on a person (Art. 22 GDPR).
4. Children
Children do not have their own accounts: their data is entered by the club and the parents. Only adults may sign up. Parents see their child's data in the parent portal, can correct the name and date of birth, and can ask the club to erase or anonymise the data.
5. Who sees the data
- Club staff — according to their role (owner, support, manager, coach). A club can limit coaches to the players of their own teams.
- Parents — only their own children's data.
- The platform administrator — only for support and troubleshooting; their changes are recorded in the change log.
- Processors that help us run the service (below).
6. Processors and transfers outside the EU
- Supabase — database and sign-in; data is stored in the EU (Ireland).
- Cloudflare — application servers and protection; processing runs in the EU region, Cloudflare's network is global.
- GitHub (Microsoft) — encrypted database backups kept up to 30 days; USA.
- Telegram — only if a parent connects the reminder bot: the child's first name, club, session time and place, coach, debt, certificate and insurance dates, subscription end, game call-ups, birthday greetings and visit milestones, club announcements.
- Resend — sends emails: password reset and email confirmation, messages after a trial session on the club's behalf (if the club turned them on and the lead left an email) and plan reminders to club owners; receives the email address and the message; sent from the EU (Ireland), the company is in the USA; no open or click tracking.
- Google and Apple — only if you sign in with them: they confirm who you are and give us your email and name; for the sign-in itself they act as independent controllers under their own privacy policies; USA.
- Google (Gmail) — the mailbox where messages to support@ and privacy@sportcrm.app and from the form on sportcrm.app arrive; USA.
- Sentry (Functional Software) — application error reports: what broke, the page address, version and browser; no IP addresses, cookies or entered data. Stored in the EU (Germany), up to 30 days.
- Cloudflare Turnstile — checks that a person, not a bot, fills in the form on sportcrm.app; not used for ads or tracking.
- Stripe — only if the club turned on online payments: the payment goes to the club's Stripe account; Stripe receives the amount, what it is for (the child's name and the club), the payer's email and the card details (we neither see nor store the card); when a club connects its account — the owner's email and the club name. For the payment itself Stripe acts as an independent controller under its own privacy policy; data may be transferred to the USA.
Transfers to the USA rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses. We notify clubs in advance about changes of processors.
7. How long we keep data
- Account — until you delete it.
- Club data — until the club deletes it or the club itself is deleted.
- Archived players — the club is offered to anonymise them after 3 years.
- Closed leads — 12 months.
- Read notifications, used and expired invitations — 90 days.
- Replies “coming / not coming” and reminder marks — 90 days; club announcements and who read them — 180 days.
- Change log — 30 days; backups — 30 days; server logs — up to 7 days.
- Consent records — as long as needed to prove the consent was given.
8. Your rights
You have the right to access your data and get a copy, to rectify it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time (without affecting earlier lawful processing).
- You can download your data and delete your account yourself in the settings (how to delete an account).
- For data held by a club (including a child's data), contact the club or us: privacy@sportcrm.app.
- We answer within one month.
You may also complain to a supervisory authority: in Spain the Agencia Española de Protección de Datos (aepd.es), or the authority of your own country.
9. Security
Connections are encrypted (HTTPS), the database is encrypted at rest, each club's data is separated by rules enforced in the database, backups are encrypted and changes are logged. If a breach puts your rights at risk, we inform the club without undue delay and the supervisory authority within 72 hours.
10. Cookies
We use only necessary cookies: to keep you signed in and for your settings (language, date format, theme). There are no analytics or advertising cookies, so no separate consent or banner is needed. The list of cookies with their lifetimes is in the cookie policy.
11. Changes
If we change this policy materially, you will see the new version and confirm it the next time you sign in. The version date is shown at the top.