Draft v0.2, 15 September 2026. Last updated 10 October 2026 (Add people's team list and its call log added). Effective the day it is published.
0. Two words this policy uses precisely (added 20 Sep 2026)
Anonymised means the row stays and the person goes: name, date of birth, contacts, notes and consents are cleared, and the club's history (availability, selections, attendance, minutes, results) stays attached to an unnamed record. This is what happens to people.
Removed means the row is deleted outright. This applies only to operational records that are about a device or a session rather than a person's history: support conversations, product event rows, server logs, notification tokens, and coach register entries after a role ends. Principle 198's "nothing deletes" governs things a person made or a club needs; it does not oblige us to keep a 30-day-old server log for ever, and keeping one would breach data minimisation.
Where this policy says removed, delete. Where it says anonymised, anonymise. Nothing else is deleted.
1. Principles
We keep personal information only while it is needed for the purpose it was collected for, then archive, anonymise or delete it. "Nothing deletes data" inside the product means people cannot accidentally destroy records; it does not mean we keep information forever. Anonymisation removes the name, date of birth, contact details, notes and consents from a record and leaves the team's history (availability, minutes, results) attached to "Former player" so a club's records still add up.
2. Schedule
| Information | Kept while | Then |
|---|---|---|
| Adult account (name, email, phone) | The account is active | 24 months after last sign-in, or on request: anonymised |
| Child record (name, DOB) | An active membership exists | 18 months with no active membership: archived (hidden from clubs, restorable by the guardian); 6 further months: anonymised |
| Guardian-child links | The child's record exists | Ended with the record |
| Availability, selections, attendance, minutes, results | Indefinitely, attached to the (anonymised) record | Club history |
| Messages | Indefinitely within the thread | Retracted or hidden messages: hidden at once, body kept for safeguarding review, anonymised with the author's record |
| On-the-day note and emergency contact | While the child has an active membership and the consent stands | Removed on withdrawal of consent, on the child leaving, or on anonymisation, whichever first |
| Stand-down records | Until the until-date plus 12 months | Anonymised with the record; category and dates may remain in the club's safeguarding statistics without a name |
| Photo consent and other consents | While the child's record exists | With the record |
| Moments photos | While the child's record exists | Re-blurred, not removed, when any guardian withdraws consent (see the note under this table); removed with the child's record |
| Payments and receipts | 6 years from the end of the financial year (tax law) | Deleted; Stripe keeps its own records under its policy |
| Governing-body registration number, and who entered it | While the person has a Whole Team record | Deleted when the record is erased, or when the number is cleared (migration `20261112100000`) |
| Coach register (check references, qualification dates) | While the person holds a role | 12 months after the role ends, or as the governing body requires, then removed |
| Code of conduct acceptances | While the person is a member | 12 months after, then removed |
| Terms acceptances (which version of our terms a person or a club accepted, when, and on which surface) | 6 years after the account or the club closes | Deleted. Append-only while kept: a record of what somebody agreed to is worth nothing if a later version can rewrite it |
| Support conversations | 24 months | Deleted |
| Product events (analytics) | 13 months | Deleted or aggregated |
| Notification tokens | Until replaced or the device is removed | Removed |
| Server logs | 30 days | Deleted |
| A team's list of people to expect (a name, and an email, mobile or child's first name where the coach had one, from Add people) | 30 days after that person joins; 90 days if they never do | Deleted |
| What a file read by Claude cost (the club, the kind of file, the model, the tokens and the cost; never anything that was in the file) | 13 months | Deleted or aggregated |
| Job run records (which scheduled job ran, when, whether it succeeded, and counts; never a person) | 90 days | Deleted |
| Backups | 30 days rolling | Overwritten; anonymisation propagates at the next cycle |
Amended 20 September 2026 (David), principle 216: withdrawing photo consent re-blurs the child and keeps the photo. This row previously said the photo was removed. It was wrong, for two reasons.
First, a team photo carries other children whose guardians consented. Deleting it would take their memory away over someone else's decision, which is not a decision one guardian is entitled to make for another family.
Second, it is not what the guardian agreed to. The consent screen, which is what they actually read, says: "Off any time, blurred in every photo including old ones, within a minute. Other faces in the same photo may be blurred too, because we don't store who is who." A policy that promised deletion would contradict the screen the consent was given on.
So: on withdrawal, every photo of that child is re-rendered with their face blurred, everywhere, within a minute (proven at 986 ms), including photos added before the withdrawal and any board the child joins later. The blurring is not reversible from the stored image: the derived image is replaced, and the original was never uploaded. The child is no longer identifiable in it, which is what withdrawal is for.
A photo is still removed with the child's record, when it is anonymised or erased, exactly as this table says. An uploader may also hide their own photo at any time, and a coach may hide any photo on their team's board.
Principles 161, 170, 178 and now 216 say the same thing, and the code does it.
3. Erasure requests
- A guardian requests erasure of a child in the app or by email. A 30-day grace period starts.
- Every linked guardian is notified. If any objects, or the club's safeguarding officer objects, the
request pauses and the club's decision on membership governs; the data then follows that decision.
- If no objection, the record is anonymised on day 31.
- Adults may request erasure of their own account; it is anonymised within one month, except payment
records kept under tax law and any record needed for a safeguarding matter in progress.
- Requests are logged with dates in the rights-requests register.
4. Season rollover
Rolling a season forward copies memberships and ends the old rows; it never deletes. Past seasons stay readable to the club and the family behind a "Past seasons" link.
5. Review
This schedule is reviewed every 12 months and whenever a new category of information is introduced. Owner: David Godfrey.