Legal
Privacy Policy
Last updated: 4 September 2026
1. Who We Are
Clubhouse ("we", "us", "our") is a digital operations platform operated by Clubhouse Software Pty Ltd. Our platform is available at dashboard.clubhouseapp.com.au and through our mobile applications.
2. Information We Collect
We collect the following types of information:
- Account information: Name, email address, phone number, and role within the club (parent, player, coach, or administrator).
- Player information: Name, date of birth, squad membership, and playing history as required for club administration and competition compliance.
- Attendance and performance data: Training attendance, match participation, game time, and individual development plan records.
- Expression-of-interest submissions: If you submit an expression of interest to a club through its public form, we collect the details you provide (such as name, contact details, playing or coaching background, and any links you include) so the club can consider and respond to your submission.
- Calendar data: When you connect a third-party calendar (Google Calendar, Microsoft Outlook, or Apple Calendar), we create calendar events for training sessions, matches, and club events. We do not read or access your existing calendar events.
- Device information: Basic device and browser information collected automatically for security and to improve the platform experience.
- Push notification tokens: When you enable push notifications on our iOS or Android app, we collect a device token to deliver notifications about schedule changes, fixture updates, and club communications.
- Wearable health data (optional): If your club has enabled the wearable recovery module and you expressly opt in, we collect the health data described in section 6 from Apple Health (iOS) or Health Connect (Android).
Where this information comes from. Most information is provided by you, your club, or your parent/guardian. In addition:
- Competition data: We receive fixtures, results, ladders and match records — including team sheets and playing records of registered players, some of whom are juniors — from the competition management systems used by the club's governing federation (for NSW clubs, the Football NSW competition system operated on the Dribl platform). This information is created as part of normal competition administration that players and parents consent to at registration, and is used inside the platform for club administration only.
- Registration data: Clubs may import their own player and family registration details from registration reports they download from Football Australia's PlayFootball system.
3. How We Use Your Information
We use your information to:
- Operate and maintain the Clubhouse platform for club administration
- Manage squad rosters, training schedules, and match fixtures
- Track attendance, game time, and player development as required by the club's compliance frameworks (such as FNSW Club Standards)
- Keep club fixtures, results and playing records accurate by matching them against competition data
- Help club staff review expressions of interest, including checking a submission against playing records the club already holds
- Send notifications about schedule changes, fixture updates, and club communications
- Sync training and match schedules to your connected calendar
- Generate reports for coaching staff and club compliance
4. Third-Party Calendar Integration
When you connect your calendar, we request permission to create and manage events in a dedicated calendar for your club within your account. Specifically:
- Google Calendar: We request the
calendarandcalendar.eventsscopes to create a dedicated calendar and add/update/remove events for your child's schedule. - Microsoft Outlook: We request the
Calendars.ReadWritescope for the same purpose. - Apple Calendar (iCal): We provide a subscription URL that your device fetches periodically. No OAuth access is required.
We do not read, modify, or delete your personal calendar events. We only write to the dedicated club calendar we create. You can disconnect your calendar at any time from the Add to Calendar page in your profile menu.
5. AI Assistant Connections (Optional)
You can connect an AI assistant (such as Anthropic's Claude) to your Clubhouse account so you can ask it about your club schedule. This is entirely optional, and a connection only exists if you create it yourself: you add Clubhouse inside the assistant, then approve the connection on a Clubhouse consent screen that names the assistant, your club, and exactly what it will be able to view.
- Read-only, and scoped to your own role: A connected assistant can view what your own role at the club is already entitled to see, and nothing beyond it. Everyone with a connection can ask about fixtures and results, training sessions, club key dates, club information such as grounds and programmes, and published league tables. Club staff roles can additionally view the information their role covers — squad lists with player names shortened to first name and last initial, fees and payments, next season's sign-up numbers, compliance scores, fitness testing averages by age group, the recruitment pipeline, and coach feedback from club surveys. Each of these is authorised individually against your role, so a treasurer is answered about fees and a coach is not. Assistants cannot change anything in Clubhouse.
- Never shared with assistants: Contact details, dates of birth, guardian information, medical information, payment details and wearable health data are never included in a response to an assistant, whatever your role. Nor is what a parent wrote in a survey: an assistant can be told a coach's score and which themes came up most often, but the comments themselves stay in Clubhouse.
- Information involving children by name: Where a response would name a child, we assess it before making it available to an assistant rather than after. Some information your role can see inside Clubhouse is therefore not yet answerable through an assistant.
- Checked on every request: Each request an assistant makes is authorised against your role at that moment and recorded in an audit log, along with how many records it returned. If your role at the club changes or is removed, the assistant's access narrows with it on its very next request — a connection you approved cannot outlast the role you approved it for.
- Additional verification for staff: Club administrators and technical directors must confirm new connections with an SMS code sent to the number on their staff record.
- Revocation: You can disconnect an assistant at any time from the AI assistants page in your settings. Revocation takes effect immediately, including for requests already in flight.
Once information is delivered to an assistant in response to your question, it is handled by the assistant's provider (for example Anthropic or OpenAI) under that provider's own terms and privacy policy, and it may be processed on servers outside Australia. Those terms are the provider's, not ours, and they can change without reference to us — which is the main reason a connection is something you opt into rather than something we switch on. We recommend reviewing your assistant's data settings, particularly around conversation history and model training, before connecting an account that can see other people's children. Clubhouse does not send your data to any AI provider except in direct response to requests you make through a connection you have approved.
What you accept by connecting. Assistants such as Claude and ChatGPT are consumer services, and we hold no agreement with either provider that governs how they handle information you ask for. So when you approve a connection, you consent to your club's information being disclosed to a recipient outside Australia on that basis. Australian Privacy Principle 8.1 will not apply to that disclosure, which means two things plainly: Clubhouse is not accountable for what the provider does with the information once it reaches them, and you may have no remedy under the Privacy Act against the provider if they mishandle it. Australian Privacy Principle 8.2(b) permits the disclosure on that footing, and only if you have been told this before you consent, so we say it here and again on the consent screen itself. If that is not a trade you want to make, do not connect an assistant. Everything in Clubhouse remains available to you in the app either way, and nothing else about your account changes.
6. Wearable Health Data (Optional)
Clubs on the wearable recovery module can offer adult players optional monitoring of training recovery through the player's own wearable device. If you opt in, we read the following data types from Apple Health (iOS) or Health Connect (Android): sleep sessions, heart rate variability, resting heart rate, respiratory rate, daily steps, active energy burned, and workout sessions. Access is read-only — we never write to Apple Health or Health Connect.
This is sensitive information under the Privacy Act 1988 (Cth), and we handle it in accordance with Australian Privacy Principles 3 and 6:
- Express opt-in consent: Collection only begins after you complete an in-app consent screen that itemises every metric and names who can see it, followed by your device's own health permission prompt. Consent is never a condition of using Clubhouse.
- Purpose: Your recovery data (compared against your own baseline) is used solely to help your club manage your training load and reduce injury risk, alongside the club's existing GPS and wellness monitoring. It is never used for advertising or marketing, never sold, and never shared with data brokers or any other third party.
- Who can see it: You, and your club's authorised coaching, strength & conditioning and medical staff. No one else.
- Withdrawal: You can withdraw consent at any time in the app. Withdrawal stops syncing immediately, and you can choose to delete your synced health data history at the same time.
- Retention: Wearable health data is kept only while your consent is active, and is deleted on request or when your account is deleted.
7. Data Storage and Security
Your data is stored securely in Australia using Supabase (hosted on AWS ap-southeast-2, Sydney). We use row-level security policies to ensure users can only access data they are authorised to view. All data is transmitted over HTTPS.
OAuth tokens for calendar integrations are stored encrypted and are only used to sync schedule events on your behalf.
8. Data Sharing
We do not sell your personal information. We share data only:
- With authorised club staff (coaches, technical directors, administrators) who need it to perform their roles
- With parents/guardians of registered players, limited to their own children's information
- With the club itself, whose staff may use platform records to prepare the compliance and competition submissions the club is required to make to its federation (such as FNSW)
- With third-party services that help us operate the platform (Supabase for database hosting, Brevo for email, Twilio for SMS notifications, Firebase Cloud Messaging for push notifications)
Personal information held in the platform is not published publicly or made searchable by the general public.
9. Your Rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Object to, or request suppression of, records about you or your child that were received from competition data
- Withdraw wearable health data consent at any time, and request deletion of the synced history
- Disconnect third-party calendar integrations at any time
- Opt out of non-essential notifications
10. Data Retention
We retain your data for as long as your account is active and as required for club administration and competition compliance. Historical playing records and development plans are retained across seasons for player pathway tracking. If you request account deletion, we will remove your personal data within 30 days, except where retention is required for compliance purposes.
11. Children's Privacy
Player accounts for minors are managed by their registered parent or guardian. Parents can view and manage their children's data through the parent portal. We do not knowingly collect information directly from children without parental consent.
Some information about junior players — such as squad membership, team sheets and match participation — reaches the platform indirectly through the competition data described in section 2, as part of normal competition administration. This information is only visible to authorised club staff and to the player's own parent or guardian. If you are a parent or guardian and would like a record about your child corrected, suppressed or deleted, contact us using the details below and we will action the request.
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify registered users of any material changes via email or in-app notification.
13. Contact Us
If you have questions about this privacy policy or your data, or wish to exercise any of the rights above, contact Clubhouse Software Pty Ltd at help@clubhouseapp.com.au. You can also raise any request through your club, and it will reach us.