Skip to main content

Legal · Privacy · Data Processing

Privacy & Data Processing Policy

How we collect, use, share, and protect your data across the SHOT Clubhouse mobile application (iOS and Android) and the website shotclubhouse.com.

Effective
12 December 2025
Last updated
April 2026
Version
1.1

Who we are

SHOT Clubhouse (“we”, “our”, or “us”) operates the SHOT Clubhouse mobile application (available on iOS and Android) and the website shotclubhouse.com. We are committed to protecting your privacy and ensuring you have control over your data.

By using SHOT Clubhouse, you agree to the collection and use of information in accordance with this policy.

Data Controller: SHOT Clubhouse Limited, a company registered in England and Wales (company number 16350767), with its registered office at 86-90 Paul Street, London, England, EC2A 4NE.

1. Information we collect

To provide the SHOT Clubhouse experience (performance tracking, club linking, and evaluations), we collect the following types of data.

A. Identity & contact data (the “SHOT ID”)

  • Personal identifiers: full name, date of birth (to verify age and squad eligibility).
  • Contact details: email address and telephone number (required for account verification and club communication).
  • Profile data: username, profile picture (avatar), and team or club affiliation.

B. Performance & evaluation data (the “Matrix”)

  • Evaluations: subjective and objective data entered by coaches, or self-reported by athletes, regarding technical, personal, physical, social, and psychological performance.
  • Health & fitness data: height, weight, injury status (if logged), and physical test results (e.g. beep test scores).
  • Activity data: training logs, match statistics, and timeline posts.

C. Club & team data

  • Linking: information connecting your profile to specific clubs, academies, or teams.
  • Role: designation as athlete, coach, parent, or admin.

D. Device & usage data

  • IP address, device type, operating system (iOS or Android), and crash logs to ensure app stability.

E. Website-specific data

  • The shotclubhouse.com website is served by our hosting provider. The provider records standard request metadata (IP address, user agent, timestamps) in its server logs and retains that data under its own privacy policy.
  • When you use the AI-powered support chat at shotclubhouse.com/support, the messages you send are transmitted to Google's Gemini API to generate a response. Messages are not stored by SHOT Clubhouse beyond the duration of your session.
  • The website embeds an RSS news carousel from rss.app and social media links (Instagram, TikTok, X/Twitter). These third parties may set cookies when their widgets load or when you follow their links.

2. How we use your data

We use your data to:

  • Create your SHOT ID: a unique identity to track your development journey.
  • Facilitate club linking: allowing verified coaches and clubs to view your profile and add you to team rosters.
  • Generate evaluations: storing and processing coach feedback to visualise progress (the Matrix).
  • Social timeline: displaying your updates, achievements, and content to your connected network.
  • Communication: using your telephone number or email for critical updates, team notifications, and password resets.
  • Service quality: diagnosing crashes, improving usability, and measuring feature performance (see also Sections 10 and 11).

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we rely on the following legal bases:

  • Contract: processing necessary to provide the SHOT Clubhouse services you have signed up for (account creation, club linking, evaluations, communications).
  • Consent: for optional analytics, session replay, marketing communications, and for all processing of data relating to users under the age of 13 (obtained from a verified parent or guardian). Consent can be withdrawn at any time.
  • Legitimate interests: for service improvement, fraud prevention, and product security, balanced against your rights and freedoms.
  • Legal obligation: where we must retain or disclose data to comply with UK law.

4. Data sharing & disclosure

We do not sell your personal data. We share data only in these specific scenarios:

  • With your linked club or coach: if you join a club on the app, authorised coaches and admins of that club can view your name, telephone number, and performance evaluations.
  • With parents: for users under the age of 13, connected parent accounts can view full activity and evaluation history.
  • Service providers: we use third-party providers for hosting, authentication, analytics, and error tracking. See Section 10 for a complete list of our third-party processors.
  • Legal requirements: if required by law enforcement, or to protect the safety of a user.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, data may be transferred to the successor organisation, subject to equivalent data protection commitments.

5. Minors and children

SHOT Clubhouse is designed for youth sports development.

  • Under 13: we adhere to COPPA (USA) and UK GDPR children's provisions (GDPR-K). Users under 13 cannot create an account without verified parental consent.
  • Parental linking: parents must link to their child's account to authorise data collection and view interactions.
  • Safety: we restrict direct messaging features for minors to ensure safeguarding compliance.
  • Age verification: age is determined from the date of birth provided during registration.

6. Data security

We implement industry-standard security measures (encryption in transit and at rest) to protect your performance database and contact information. Access to production data is restricted to authorised personnel on a need-to-know basis. However, no method of transmission over the internet is 100% secure.

7. Data retention

  • Account data: retained while your account is active. When you delete your account, personal data is removed within 30 days (see Section 14).
  • Performance & evaluation data: retained for the lifetime of your SHOT ID and deleted alongside the account, unless you have requested earlier deletion of specific records.
  • Crash logs & diagnostic data: retained for up to 90 days for debugging purposes.
  • Legal & financial records: retained for up to 7 years where required by UK tax, accounting, or regulatory obligations.
  • Aggregated and anonymised data (with no identifiers) may be retained indefinitely for statistical purposes.

8. Your rights (UK GDPR / CCPA)

You have the right to:

  • Access: request a copy of your evaluations and personal data.
  • Correction: fix incorrect data (for example, wrong phone number or date of birth).
  • Deletion: request the deletion of your SHOT ID and all associated data (“the right to be forgotten”).
  • Restriction: ask us to pause processing of your data in specific circumstances.
  • Portability: receive a copy of your data in a common, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: at any time, where processing is based on consent.
  • Unlink: remove your association with a specific club (this stops the club from seeing future data).

To exercise these rights, contact us at info@shotclubhouse.com. We respond within one month.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the UK's supervisory authority: the Information Commissioner's Office (ico.org.uk).

9. App Tracking Transparency (iOS)

On iOS devices, SHOT Clubhouse requests permission to track your activity across other companies' apps and websites using Apple's App Tracking Transparency (ATT) framework.

  • What this means: if you allow tracking, we may use identifiers to personalise your experience and measure app performance through our analytics providers.
  • If you deny: analytics services (PostHog, Microsoft Clarity) will be completely disabled. Sentry session replays will be disabled, but crash reporting remains active to help us fix app issues.
  • Your choice: you can change your tracking preference at any time in your iPhone's Settings → Privacy & Security → Tracking.

Note: this prompt only appears on iOS 14.5 and later. Web users and Android users are not affected by ATT requirements.

10. Third-party data processors

We work with the following third-party service providers who process data on our behalf. Each is contractually obligated (under a Data Processing Agreement) to protect your data and process it only according to our instructions.

A. Infrastructure & database

  • Supabase Inc. (supabase.com) — database hosting, authentication, and real-time features. Data is stored in EU and US regions.
  • Hosting provider — static & edge hosting for the shotclubhouse.com website. Full list of sub-processors available on request.

B. Analytics & performance

  • PostHog Inc. (posthog.com) — product analytics to understand how users interact with the app. Used to improve features and user experience.
  • Microsoft Clarity (clarity.microsoft.com) — session replay and heatmaps to understand user behaviour and improve usability.
  • Google Firebase (firebase.google.com) — analytics, crash reporting, and push notifications for mobile apps.

C. Error monitoring

  • Sentry (sentry.io) — error tracking and crash reporting to identify and fix bugs. Session replay is used for debugging complex issues.

D. Payments

  • Stripe Inc. (stripe.com) — payment processing for subscriptions and in-app purchases. Stripe handles payment card data according to PCI-DSS standards.
  • RevenueCat (revenuecat.com) — subscription management for in-app purchases on mobile platforms.

E. Website-only

  • Google LLC — Google Fonts (font delivery) and Gemini API (used by the AI support chat at /support).
  • rss.app (rss.app) — RSS news carousel embedded on the public website.
  • Cloudflare, Inc. — content delivery network for the Tailwind CSS and GSAP libraries used by the website.

11. Analytics for minors

To protect the privacy of young athletes, we apply additional restrictions for users under 18 years of age:

  • No personal analytics tracking: for users identified as minors, we do not use personalised analytics. PostHog user identification, Microsoft Clarity session recording, and Sentry session replays are completely disabled.
  • Limited data collection: only essential app functionality data is collected, such as crash reports (without user identification) to maintain app stability.
  • No behavioural profiling: we do not create behavioural profiles or use data for advertising targeting for minor users.
  • Parental visibility: parents linked to minor accounts can request information about any data collected related to their child.

Age is determined from the date of birth provided during registration. If you believe a minor's data has been collected inappropriately, please contact us immediately at info@shotclubhouse.com.

12. Cookies & similar technologies

The SHOT Clubhouse website uses a minimal set of cookies and browser storage. The mobile apps do not set cookies in the same way, but they store local data on your device for authentication and offline use.

  • Strictly necessary: session tokens and authentication state required to keep you signed in. Cannot be disabled.
  • Functional: stores your preferences (such as consent choices, UI theme, and last-used filters).
  • Analytics (consented only): PostHog and Microsoft Clarity within the app, subject to your consent and the minor-protection rules in Section 11.
  • Third-party embeds: the rss.app news carousel and embedded social links on the public website may set their own cookies when loaded or followed.

In the SHOT Clubhouse app, you can manage your preferences from Settings → Privacy. On the website, you can clear cookies at any time through your browser settings.

13. International data transfers

SHOT Clubhouse is operated from the United Kingdom, but several of our processors (Supabase, PostHog, Firebase, Sentry, Stripe, Microsoft, Google) operate globally. Where personal data is transferred outside the UK or European Economic Area, we rely on the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or equivalent safeguards approved by the UK Information Commissioner's Office to ensure a comparable level of protection.

14. Account deletion

You may delete your SHOT Clubhouse account at any time:

  • In-app: go to Settings → Account → Delete My Account. You will be asked to confirm by typing “DELETE”.
  • By email: send a deletion request from the email address associated with your account to info@shotclubhouse.com.

Account deletion will:

  • Cancel any active subscriptions.
  • Remove your profile and all associated data.
  • Unlink you from all clubs and teams.
  • Delete your evaluation history and performance data.

This action is irreversible. Historical aggregated data (without personal identifiers) may be retained for statistical purposes. Financial records required by UK law are retained for the periods described in Section 7.

15. Changes to this policy

We may update this Privacy & Data Processing Policy from time to time to reflect changes in our practices, services, or legal obligations. The “Last updated” date at the top of this page will always reflect the most recent revision. Material changes will be communicated in-app or by email before they take effect.

16. Contact us

If you have questions about this policy, or wish to exercise any of your rights, please contact our Data Protection Officer:

  • Email: info@shotclubhouse.com
  • Registered address: SHOT Clubhouse Limited, 86-90 Paul Street, London, England, EC2A 4NE
  • Company number: 16350767 (England and Wales)

You may also raise a complaint with the UK Information Commissioner's Office at ico.org.uk.

Questions about your data?

Our Data Protection Officer responds within one month. Reach out any time via info@shotclubhouse.com.

Email us