1. Who we are and the scope of this Policy
Varoom Ltd operates ClubPayee at clubpayee.com and app.clubpayee.com. You can contact us atsupport@clubpayee.com.
This Policy covers the ClubPayee website, application, Help Centre, account administration, service operation, support, security and our commercial relationship with Clubs. It should be read with any privacy information supplied by the Club that entered or manages your details.
Clubs and ClubPayee have different responsibilities
For Member, Payer and ordinary Club operational information, the Club generally decides why the information is collected, who is included, how Fees and relationships are configured, who may access it and how it is used. In that context, the Club will generally be the data controller and Varoom Ltd will generally process the information on the Club's behalf to provide ClubPayee.
Varoom Ltd also processes some information for its own purposes, including establishing and administering accounts, approving or locking Clubs, securing and operating the service, preventing misuse, providing support, managing the commercial relationship, improving reliability and meeting legal obligations. The precise legal role can depend on the information and circumstances; this Policy does not override responsibilities assigned by data-protection law.
2. Information processed through ClubPayee
The service may process the following categories.
Club and account information
- Club name, lifecycle and approval information and Club settings;
- Club User and Platform Administrator names, email addresses, account status, roles or relationships and login history;
- password hashes, email-verification and authentication challenge records, failed-attempt counts and server-side session records; and
- support correspondence and information a person chooses to provide when asking for help.
Member and Payer information supplied by Clubs
- names, email addresses, phone numbers, gender and date of birth where entered and relevant;
- adult or underage Member type and active/inactive status;
- Club, Team, Season, membership and Payer-responsibility relationships;
- Payer account, readiness, communication and login information; and
- import mapping preferences and the data accepted from a Club's CSV or Excel import.
Import files are interpreted in the browser and approved rows are sent to ClubPayee for creation. Clubs should review the preview and avoid including columns or information that ClubPayee does not need.
Club and financial records
- Seasons, Teams, Fees, Fee rules, Team assignments and Member Ledger entries;
- manual and online Payments, amounts, dates, methods, references, notes, allocations and balances;
- Refunds and adjustments, including reasons, status and the Club User who recorded or requested them;
- ClubPayee credit-ledger and Member/Season usage records; and
- optional Payment Plan details, instalment schedules, consent records, statuses, attempts, cancellation and action-required history.
Notifications
ClubPayee may store notification type, intended recipient, email and name snapshots, scheduled and event dates, content data needed to render the message, delivery status, attempts, provider reference and failure category. This supports delivery, retries, duplicate protection and the Club's Delivery History.
Technical and security information
When the application is used, servers and service providers necessarily handle network and request information such as IP address, request path, timestamps, browser or device headers and operational logs. ClubPayee records selected security and rate-limit events. For relevant Payer authentication and payment controls, email addresses, source IPs and session identifiers may be stored as keyed hashes rather than in raw form. Security records may include a category, Club or Payer reference, counts, time windows, temporary-lock information and provider-transaction references.
3. Information about children and minors
Sports and community Clubs may use ClubPayee to manage Members who are children. Their records may include a name, date of birth, gender, Team, Season, Fees and a relationship to the responsible Payer.
The Club is responsible for identifying an appropriate lawful basis, providing required information to parents, guardians and Members, and ensuring that its records and Payer relationships are accurate. ClubPayee does not ask children to create ordinary Club administration accounts and does not implement a separate parental-consent workflow.
Clubs should collect only information needed for ClubPayee's registration and financial purposes. They should not use ClubPayee notes, imports or free-text fields to store unnecessary medical, safeguarding, disciplinary or other sensitive information about a child.
4. Why information is used and the lawful bases
Depending on the information and context, we process data to:
- provide, host and support ClubPayee and carry out our agreement with a Club;
- create and administer accounts, authenticate users and maintain sessions;
- maintain Member relationships, Fees, balances, Payments, Refunds, reports and optional Payment Plans on the Club's instructions;
- deliver access messages and Club-configured financial communications;
- approve, lock and support Clubs and manage credits and the commercial relationship;
- secure the service, limit abuse, investigate incidents, reconcile provider outcomes and maintain reliable financial history; and
- comply with legal obligations and establish or defend legal claims.
Lawful bases may include performance of a contract, compliance with a legal obligation and our legitimate interests in providing, securing, supporting and administering ClubPayee. Where we act for a Club, the Club is responsible for identifying its lawful basis for Member and Payer processing. Consent may be relevant to a Club in some circumstances, but ClubPayee does not assume that consent is the basis for every record.
5. Payments and Stripe
Clubs may connect their own Stripe account. Stripe processes card and payment details under its own terms and privacy information. ClubPayee does not store full card numbers or CVCs.
ClubPayee stores the identifiers and records needed to operate and reconcile online Payments and Refunds. These can include a connected Stripe account identifier, Checkout Session, Payment Intent, Charge, balance-transaction and Refund identifiers, transaction status, amount, currency, processing fee, net amount and failure information.
Where optional Payment Plans are enabled, ClubPayee may also store Stripe customer and payment-method identifiers, the payment method's brand, last four digits and expiry details, consent and instalment information, and provider-attempt history. Stripe retains the full payment credentials and uses the authorised payment method for future automatic instalments.
Clubs may also record cash, bank transfer and other manual Payments. Those records are supplied by the Club and do not involve Stripe.
6. Service providers and recipients
We use service providers only where needed to operate ClubPayee. Current material providers include:
- Railway — application hosting, networking and managed infrastructure;
- PostgreSQL — the application database hosted in our Railway environment;
- Stripe — connected-account services and card-payment, Refund and optional automatic-instalment processing;
- SendGrid — delivery of authentication, access and configured notification emails;
- Cloudflare Turnstile — bot and abuse checks on the Payer code-request journey;
- Google Ads — consent-controlled measurement of successful registrations resulting from advertising; and
- Google Fonts — delivery of fonts used by the public marketing site, which may involve a request from the visitor's browser to Google's font services.
We may also disclose information to professional advisers, authorities or other recipients where reasonably necessary to meet legal obligations, protect rights and security, handle a corporate transaction or respond to a lawful request. We do not sell personal data or use it for third-party advertising.
7. International transfers
Some providers operate internationally or may process support, infrastructure, security or payment information outside Ireland or the European Economic Area. Where data-protection law requires safeguards for an international transfer, we seek to rely on an adequacy decision, approved contractual protections or another lawful transfer mechanism. Provider locations and mechanisms can change, so contact us if you need current information about a particular transfer.
8. How long information is kept
We retain information for as long as reasonably needed to provide and secure ClubPayee, follow the Club's valid instructions, maintain accurate financial and provider history, meet legal and accounting requirements, resolve disputes and enforce agreements. Different records require different treatment.
- Active account, Club, Member and Payer information is generally retained while the relevant relationship and service use continue.
- Disabling a Club User or Payer, making a Member inactive, locking a Club or cancelling a Payment Plan does not by itself erase associated historical records.
- Financial ledger entries, Payments, Refunds, adjustments, provider outcomes, credit usage and related audit records may need to be retained after an account or Club stops using the service so that financial history remains accurate and legal obligations can be met.
- Notification and delivery records are retained for operational history, support, duplicate protection and financial audit context. The user interface may show a shorter period than the underlying record is kept.
- Selected security-event records are assigned a 30-day retention deadline. Other server and provider logs follow operational and provider retention arrangements.
- Deleted information may remain temporarily in restricted backups until the relevant backup cycle expires.
ClubPayee does not currently promise one universal deletion period. When data is no longer required, it should be deleted or anonymised, subject to technical backup cycles and records that must be preserved. Contact us or the relevant Club for a request concerning a particular record.
9. Security, authentication and cookies
ClubPayee uses measures intended to protect the service and separate Club data, including account authentication, email verification codes, role- and relationship-based access, server-side sessions, tenant-scoped access controls, rate limits, bot checks, password and token hashing, security event records and restricted handling of payment-provider credentials. Some sensitive Stripe connection credentials are stored in encrypted form where that connection method is used.
No system can guarantee absolute security. Clubs and users must protect their credentials and devices, grant access carefully and report suspected compromise promptly.
Cookies and similar storage
The application uses strictly necessary HTTP-only session cookies to keep Platform Administrators, Club Users and Payers signed in securely. These cookies use secure settings in Production and are not used for advertising. The application may also use limited browser storage for functional user preferences, such as a remembered dashboard selection.
Cloudflare Turnstile and other essential infrastructure may use technical storage or request information needed to provide security and prevent abuse.
Google Ads conversion measurement
With your permission, ClubPayee uses Google Ads conversion measurement to understand whether advertising results in a successful ClubPayee registration. This helps us assess whether our advertising is effective.
Advertising measurement is non-essential and is disabled by default. You can allow or decline it using the consent choice shown on the website. We remember that choice in a cookie shared by the ClubPayee website and application. If you decline, the Google advertising tag is not loaded.
ClubPayee does not send a registrant's name, email address or phone number in the conversion event, and does not currently use Google Enhanced Conversions.
10. Your data-protection rights
Depending on the circumstances and applicable law, you may have rights to request access to personal data, correction, deletion, restriction, objection and data portability, and to withdraw consent where processing is based on consent. These rights can be subject to legal conditions and exceptions, including requirements to preserve financial records or the rights of other people.
For Member or Payer information entered and controlled by a Club, contact that Club first where practical. The Club is best placed to verify your relationship, correct its records and decide how its data should be used. We will assist Clubs with valid requests where we process the information on their behalf. You may also contact us directly, particularly for ClubPayee account, security, support or commercial information for which Varoom Ltd is responsible.
ClubPayee provides on-screen records and Club reports, including printable reports and Payment Activity CSV export. These operational capabilities do not replace a formal data-subject request where one is applicable.
11. Contact, complaints and Policy changes
Privacy questions and requests can be sent tosupport@clubpayee.com. Please provide enough information for us to identify the relevant account or Club without sending passwords, verification codes or full payment-card data. We may need to verify your identity and authority before acting.
You may also complain to the Irish Data Protection Commission. Information about making a complaint is available atdataprotection.ie. You may have the right to contact another competent supervisory authority depending on where you live or work.
We may update this Policy to reflect changes in the service, providers or law. We will publish the current version here and update the date above. Where a change is material, we will provide additional notice where appropriate.
For the contractual terms governing Clubs' use of ClubPayee, see ourTerms of Service.
