Who we are
Venue-Booker ("we", "us", "our") provides a software platform that enables sports clubs and organisations to manage facility bookings, registrations, and related administrative activities.
For the purposes of GDPR:
- The sports club or organisation using Venue-Booker is the Data Controller
- Venue-Booker acts as a Data Processor, processing personal data strictly on behalf of the club in accordance with its instructions
- We do not determine the purposes or means of processing personal data entered into the Service
Our role under GDPR
When an organisation uses Venue-Booker:
The organisation decides
- · What facilities can be booked
- · Booking rules, pricing, cancellation policies
- · Membership structures and permissions
Venue-Booker provides
- · The technical architecture to store and transmit booking data
- · Processing only on documented instructions from the organisation
- · No use of personal data for our own purposes
All processing is governed by a Data Processing Agreement (DPA) between Venue-Booker and the organisation.
Personal data processed
We process personal data only as required to provide the Service. This may include:
Venue-Booker does not independently collect or determine the purpose of this data.
3.1 Payments
Where enabled by the club:
- Name of payer
- Email address
- Payment reference IDs (Stripe)
- Transaction amount and status
- Refund status
Full card details are never stored by Venue-Booker and are processed directly by Stripe.
Sub-processors
We use trusted third-party service providers to operate the platform.
| Entity | Purpose |
|---|---|
| Supabase | Database, authentication, storage |
| Stripe | Payment processing |
| Resend | Transactional email delivery |
| Cloud hosting / authentication | |
| Google Gemini Flash | Smart Booking Assistant |
All sub-processors are subject to appropriate GDPR transfer safeguards, including Standard Contractual Clauses (SCCs) where required.
International transfers
While every effort is made to ensure data is processed within the EEA, some (sub) processors may transfer data outside the EEA.
Where this occurs, appropriate safeguards are used, including:
- European Commission Standard Contractual Clauses (SCCs)
- EU–US Data Privacy Framework (where applicable)
Data retention
Data is retained only as long as required to provide the Service or as instructed by the Data Controller.
- Booking records: as determined by the club
- User accounts: until deleted by the club or user request via the club
- Payment records: retained per Stripe and controller requirements
- Logs: typically 30 days
- Camp/event data: as determined by the club (or until deletion request via controller)
Venue-Booker does not independently set retention periods for customer data unless required for security or legal compliance.
Data subject rights
Under GDPR, individuals have rights including:
Because Venue-Booker is a data processor, we will:
- Forward any data subject requests to the relevant sports club (Data Controller)
- Assist the club in fulfilling their obligations where required
Compliance inquiries
alan@venue-booker.comComplaints may be made to the Irish Data Protection Commission: dataprotection.ie
Security
We implement appropriate technical and organisational measures, including:
Payment data is processed entirely by Stripe. Venue-Booker does not store full card details.
What we do not do
- We do not sell personal data
- We do not use personal data for advertising or profiling
- We do not send marketing communications using customer data
- We do not determine how clubs use personal data within their organisation
Changes to this policy
We may update this policy from time to time.
Material changes will be communicated to account holders or system administrators in advance where appropriate.
© 2026 Venue-Booker. This document is maintained by Venue-Booker.
Back to home