Legal · GDPR

Privacy Policy

Transparency is the foundation of our partnership. This document outlines how Venue-Booker processes personal data on behalf of the clubs and organisations that use our platform.

Last updated
June 2026
01

Who we are

Venue-Booker ("we", "us", "our") provides a software platform that enables sports clubs and organisations to manage facility bookings, registrations, and related administrative activities.

For the purposes of GDPR:

  • The sports club or organisation using Venue-Booker is the Data Controller
  • Venue-Booker acts as a Data Processor, processing personal data strictly on behalf of the club in accordance with its instructions
  • We do not determine the purposes or means of processing personal data entered into the Service
02

Our role under GDPR

When an organisation uses Venue-Booker:

The organisation decides

  • · What facilities can be booked
  • · Booking rules, pricing, cancellation policies
  • · Membership structures and permissions

Venue-Booker provides

  • · The technical architecture to store and transmit booking data
  • · Processing only on documented instructions from the organisation
  • · No use of personal data for our own purposes

All processing is governed by a Data Processing Agreement (DPA) between Venue-Booker and the organisation.

03

Personal data processed

We process personal data only as required to provide the Service. This may include:

NameEmail addressPhone numberTeam / group affiliationRole and permissionsCommunication logsLogin and audit activity

Venue-Booker does not independently collect or determine the purpose of this data.

3.1 Payments

Where enabled by the club:

  • Name of payer
  • Email address
  • Payment reference IDs (Stripe)
  • Transaction amount and status
  • Refund status

Full card details are never stored by Venue-Booker and are processed directly by Stripe.

04

Sub-processors

Public Register

We use trusted third-party service providers to operate the platform.

EntityPurpose
SupabaseDatabase, authentication, storage
StripePayment processing
ResendTransactional email delivery
GoogleCloud hosting / authentication
Google Gemini FlashSmart Booking Assistant

All sub-processors are subject to appropriate GDPR transfer safeguards, including Standard Contractual Clauses (SCCs) where required.

05

International transfers

While every effort is made to ensure data is processed within the EEA, some (sub) processors may transfer data outside the EEA.

Where this occurs, appropriate safeguards are used, including:

  • European Commission Standard Contractual Clauses (SCCs)
  • EU–US Data Privacy Framework (where applicable)
06

Data retention

Data is retained only as long as required to provide the Service or as instructed by the Data Controller.

  • Booking records: as determined by the club
  • User accounts: until deleted by the club or user request via the club
  • Payment records: retained per Stripe and controller requirements
  • Logs: typically 30 days
  • Camp/event data: as determined by the club (or until deletion request via controller)

Venue-Booker does not independently set retention periods for customer data unless required for security or legal compliance.

07

Data subject rights

Under GDPR, individuals have rights including:

AccessRectificationErasureRestrictionData portabilityObjection

Because Venue-Booker is a data processor, we will:

  • Forward any data subject requests to the relevant sports club (Data Controller)
  • Assist the club in fulfilling their obligations where required

Compliance inquiries

alan@venue-booker.com

Complaints may be made to the Irish Data Protection Commission: dataprotection.ie

08

Security

We implement appropriate technical and organisational measures, including:

Encryption in transit (TLS)
Encryption at rest
Role-based access controls
Audit logs for administrative actions
Secure authentication via trusted providers
Webhook and API signature verification
Least-privilege access controls

Payment data is processed entirely by Stripe. Venue-Booker does not store full card details.

09

Cookies & local storage

We use only essential functionality:

  • Authentication session storage
  • Basic user session and form persistence
  • Administrative session flags

We do not use advertising cookies or behavioural tracking.

10

What we do not do

  • We do not sell personal data
  • We do not use personal data for advertising or profiling
  • We do not send marketing communications using customer data
  • We do not determine how clubs use personal data within their organisation
11

Changes to this policy

We may update this policy from time to time.

Material changes will be communicated to account holders or system administrators in advance where appropriate.

© 2026 Venue-Booker. This document is maintained by Venue-Booker.

Back to home