This privacy policy explains how Bainisteoir ("we", "us", "our") collects, uses, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller
Bainisteoir is operated from Northern Ireland, United Kingdom. For any data protection queries, please contact us at: privacy@bainisteoir.app
What Data We Collect
We collect and process the following personal data:
- Email address — required for account creation and authentication
- Password — securely hashed, used for authentication
- Player names — to identify team members
- Player dates of birth — for age-appropriate team management
- Parent/guardian contact details — phone or email for communication
- Player notes — optional free-form information
- Event locations — training and match venues
- Attendance records — tracking player participation
- Match scoring data — individual performance records
- Team membership — linking coaches to teams
Legal Basis for Processing
We process your personal data on the following legal bases:
- Legitimate interest — for core team management features including scheduling, attendance tracking, match scoring, and lineup management (UK GDPR Article 6(1)(f))
- Consent — for non-essential cookies and analytics (UK GDPR Article 6(1)(a))
- Contract — to provide the service you have signed up for (UK GDPR Article 6(1)(b))
How We Use Your Data
Your data is used for:
- Team management — creating and managing sports teams
- Attendance tracking — recording and monitoring player attendance
- Match scoring — tracking live match scores and statistics
- Lineup management — building and managing team formations
- Session planning — creating training session plans
- Communication — sending account-related emails (e.g. email confirmation)
Data Retention
We retain your data as follows:
- Active accounts — data is retained while your account is active
- Deleted accounts — all data is permanently purged immediately upon account deletion
- Inactive players — players marked as inactive are permanently removed after 90 days
Third-Party Processors
We use the following third-party services to operate Bainisteoir:
- Supabase — database hosting, authentication, and storage. Supabase may process data outside the UK under Standard Contractual Clauses (SCCs) or adequacy decisions.
- Vercel — application hosting and deployment. Vercel may process data outside the UK under Standard Contractual Clauses (SCCs) or adequacy decisions.
International Data Transfers
Some of our third-party processors may transfer your data outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions recognised by the UK government.
Children's Data
Bainisteoir is used by coaches (adults) to manage their sports teams. The app collects children's data (date of birth and parent/guardian contact information) as entered by coaches. This data is processed under the legal basis of legitimate interest for sports team management. Coaches are responsible for ensuring they have appropriate consent from parents or guardians before entering children's information into the system.
Your Rights
Under UK GDPR, you have the following rights:
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate personal data
- Right to erasure — request deletion of your personal data
- Right to restriction — request limited processing of your data
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interest
How to Exercise Your Rights
You can exercise your rights in the following ways:
- In-app — use the Data & Privacy section in Settings to download your data or delete your account
- Email — contact us at privacy@bainisteoir.app
Right to Complain
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated. You can contact the ICO at ico.org.uk or by calling 0303 123 1113.
Cookies
Bainisteoir uses strictly necessary cookies for authentication and session management. These cookies are essential for the app to function and do not require consent under PECR. We do not currently use analytics or advertising cookies. If we introduce non-essential cookies in the future, we will obtain your consent before setting them.