clubr

Privacy Policy

Last updated: June 2026

Clubr (“we”, “us”, or “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use the Clubr platform, including our website at clubrapp.com and our mobile applications for iOS and Android (together, the “Service”). It has been written in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who this policy is for

Clubr is used by two types of people:

If you have any questions about this policy, contact us at support@clubrapp.com.

1. What Data We Collect

We collect personal data that you provide directly to us, as well as data generated through your use of the Service.

Account and identity information:

Member data added to the platform:

Payment information:

Communications and notifications:

Usage and technical data:

We do not collect your precise location, contacts, photos, or device advertising identifiers, and we do not use your data for third-party advertising or tracking.

2. How We Use Your Data

We use your personal data to:

Our lawful bases for processing under UK GDPR are: (a) performance of a contract with you; (b) our legitimate interests in operating a secure and effective platform; and (c) your consent where we ask for it (e.g. enabling push notifications).

3. Who We Share Your Data With

We do not sell your personal data. We share data only with the following trusted service providers, each of which is bound by appropriate data processing agreements and provides protection consistent with this policy:

Where you are a member, your business can also see the member data described above, as the controller of that data. We may also disclose data where required by law, a court order, or a regulatory authority, or where necessary to protect the rights, property or safety of Clubr or others.

4. Data Retention

We retain account data for as long as your account is active. If a business cancels its subscription, we retain its data for up to 90 days to allow for reactivation, after which it is securely deleted. Backup copies may be retained for up to a further 30 days for disaster recovery. We may retain anonymised or aggregated data (which can no longer identify you) indefinitely for analytics.

5. Account Deletion

You can delete your account and associated personal data at any time:

Deletion is permanent and cannot be undone. Some information may persist briefly in encrypted backups before being overwritten, as described in section 4.

6. Children and Young People

The Clubr app is not directed at children, and member accounts are intended to be created and managed by adults. Many businesses serve members under 18 (for example, children's martial-arts or dance classes). In those cases the business is responsible, as data controller, for obtaining any necessary parental or guardian consent and for the lawful basis of processing a child's data. We process children's data only on the business's instructions and apply the same security and retention protections described in this policy. If you believe a child's data has been provided without appropriate consent, contact us at support@clubrapp.com and we will work with the relevant business to address it.

7. Your Rights Under UK GDPR

As a data subject under UK GDPR, you have the following rights:

To exercise any of these rights, email us at support@clubrapp.com. We will respond within 30 days. If you are a member, you can also contact your business directly. You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

We use essential session cookies to keep you logged in. These are strictly necessary for the Service to function and do not require consent under UK GDPR. We do not use advertising or tracking cookies. You can control or delete cookies through your browser settings, but disabling essential cookies will prevent you from logging in.

9. Data Security

We use industry-standard security measures including TLS encryption in transit, encrypted databases at rest, hashed passwords, and access controls. Despite these measures, no system is completely secure. We will notify you and the ICO of any data breach that is likely to result in a risk to your rights and freedoms, as required by UK GDPR.

10. International Transfers

Some of our service providers may process data outside the UK or EEA. Where this occurs, we ensure appropriate safeguards are in place (e.g. UK adequacy regulations, Standard Contractual Clauses, or equivalent mechanisms).

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice in the app or on our platform before the changes take effect. The “Last updated” date at the top of this page reflects when it was last revised.

12. Contact Us

For any questions, requests, or complaints about your privacy or this policy:

Also read our Terms of Service.