ClubFlow only sets the cookies it needs: sign-in, language, this choice. With your OK we also count page visits, without cookies, to see which parts of the product get used. No advertising, ever.
How ClubFlow collects, uses and looks after personal data, written to match what the product actually does, not a generic template.
ClubFlow is a tool football clubs use to run themselves, managing teams, players, fixtures, development plans and scouting. To do that we hold the information the club enters about the people inside it. This notice explains exactly what we hold, why, who else sees it, and what you can ask us to do with it.
Only club staff (owners, administrators, managers, coaches and scouts) have ClubFlow accounts. Players and their parents do not sign in to the platform; their data is recorded and managed by the club staff that works with them. The one exception is wellness check-ins: where a club has enabled them, players submit their own short check-ins through a link the club shares, identifying themselves with their name and a personal PIN, still without an account. ClubFlow’s own staff see a club’s data only when the club grants them time-limited support access.
ClubFlow AB, org. no. 559602-2540, a limited company registered in Sweden, builds and operates the ClubFlow platform. In this notice, “ClubFlow”, “we” and “us” mean ClubFlow AB. There are two layers of responsibility:
For privacy questions or to exercise your rights under GDPR, write to privacy@theclubflow.com.
Everything below is data we either capture when you use the platform or that club staff type into the product. We do not import personal data about players from any external source today. Optional fields are marked accordingly.
| Category | Fields | Source |
|---|---|---|
| Account | Email, first name, last name, the language you chose when you joined | Provided when you accept an invitation |
| Club membership | Clubs you belong to, your role within each club, the teams you are assigned to. Before you join: the email, role and teams on your invitation | Set by the club admin who invited you |
| Player profile | First name, last name, date of birth, gender, nationality, preferred foot, position and shirt number, height and weight over time, contract end date, player category and transfer availability | Entered by club staff |
| Parent height (optional) | Self-reported mother and father height in centimetres | Entered by club staff when used; only consumed by the player’s maturation-forecast feature |
| Match data | Lineups, positions, minutes played, goals, assists, cards, substitutions, a coach’s performance rating, and the referee’s name | Entered by coaches |
| Other appearances | National team, loan and guest appearances: organisation, date, minutes, position, notes | Entered by club staff |
| Development notes | Coach notes, skill and ability ratings, individual development plan goals, reviews, the player’s own vision, career goals and reflections, and squad plans for future seasons | Entered by coaches and technical staff |
| Injury & absence | Availability status (for example injured or ill), dates, expected return, a short free-text reason. Injury and illness records are health data. | Entered by club staff, or created by a coach from a player’s wellness check-in |
| Wellness check-ins (where enabled) | Short self-reports on a fixed scale: sleep quality, fatigue, muscle soreness, stress, mood, session effort, where it is sore and how much on a body map, plus an optional free-text note, optionally tied to a match or session. To identify themselves, players give their name and date of birth and choose a PIN, which we store only as a salted hash. This is health and wellbeing data. | Submitted by the player through the club’s check-in link, only after the club has enabled wellness check-ins and affirmed the consent described under lawful basis. The club chooses which check-ins are asked, of which teams, and how often; nothing is collected until it does |
| Scouting records | For tracked candidates: name, date of birth, gender, nationality, position, current club, contract end date, ability and potential ratings, a link to an external profile, priority and assigned scout, scout reports with a recommendation, dated match notes | Entered by scouts within the club |
| Transfer negotiation records | Transfer cases linking a player or candidate to a deal: counterpart club, deal type, fee and bid amounts, clause terms, contract offers (salary, contract dates, terms), a contact log of calls and meetings, and uploaded deal documents | Entered by club staff handling the transfer |
| Public application form | First name, last name, email, date of birth, gender, language, and the answers to any questions the club adds. The sender’s IP address is kept for up to 7 days to stop abuse | Submitted by the candidate (or their guardian) using a club’s public application link |
| Waitlist | Club name, email, optional phone number, your role, language | Submitted by you on our website. ClubFlow is the controller |
| Feedback & bug reports | Your message, the page you were on, your browser, your account and club | Submitted by you from inside the platform |
| Support access | Which ClubFlow staff member was granted access, why, and for how long | Granted by the club |
| Authentication & usage | IP address and timestamps (Supabase Auth logs), session tokens | Captured automatically when you sign in |
| Audit log | Who changed what and when, with IP address. Entries can name the player concerned | Recorded when club staff change data |
| Usage & page-speed measurement | Page path with ids removed, referrer, country, device type, browser, and page load timings. Visitors are told apart by a hash that resets every day; no cookie, no raw IP address and no name is stored | Page-speed timings are captured automatically on every page except the check-in, application-form and invite pages. Page views are counted on the same pages, only after you accept it on the cookie banner |
| Consent records and confirmations | Which version of this notice and the terms you were shown and when, with IP address and browser; and, for club admins, which consent obligations you confirmed on the club’s behalf and when | Recorded when you join, and when you confirm an obligation in the club’s settings |
A club can connect optional integrations that let ClubFlow read data from an external system. We never push data the other way.
We use the data above only to run the parts of the product the club is using:
ClubFlow shows club staff short signals about players, for example that a player has had no playing time despite being available, that a development plan is due for follow-up, or that a contract is about to expire. Signals are profiling under GDPR Art. 4(4), so this is how they work:
We do not use any of this data for advertising. We do not train machine-learning models on personal data.
Under Article 6 of the GDPR, our lawful bases are:
We keep data for as long as it is needed to run the club, then we erase or anonymise it on a published schedule. The same retention schedule applies to every club on the platform.
Under GDPR, the people whose data we hold have the right to:
Because players and their parents do not have ClubFlow accounts, rights requests about a player’s data are usually fastest if you first contact the club itself. The club is the data controller for the data it entered about its players. If the club cannot help, or your request concerns account data ClubFlow controls, email privacy@theclubflow.com. We respond within the time GDPR Art. 12(3) requires: one month, typically much sooner.
A large share of the data inside ClubFlow concerns players who are under 18. The club, as controller, informs guardians or gathers guardian consent where required. Inside the platform we apply the same rules as for any other player, with some practical guarantees:
Personal data is encrypted in transit and at rest using the industry-standard encryption provided by our database and authentication subprocessor. Each club’s data is separated by row-level security in the database. Access to production systems is restricted to the small number of people who need it to run the service. ClubFlow staff can see a club’s data in the product only when the club grants them support access, for at most 30 days; the club can see and revoke that access at any time.
If a personal-data breach affects a club’s data, we notify the club without undue delay, and where possible within 24 hours of becoming aware of it. The club, as data controller, notifies IMY within the 72 hours Article 33 requires, and we help it investigate and inform the people affected. For a breach of the account data we control ourselves, we notify IMY directly.
For material changes that affect how we process personal data, we email every account holder at least 30 days before the effective date. Continuing to use ClubFlow after that date counts as accepting the new version; we do not ask you to accept it again when you sign in. Minor wording fixes do not trigger an email.