Datenschutzerklärung
ClubForm — Football Club Management · Stand: 4. September 2026 · English version below
Der Schutz Ihrer persönlichen Daten ist uns ein besonderes Anliegen. Wir verarbeiten Ihre Daten ausschließlich auf Grundlage der gesetzlichen Bestimmungen (DSGVO, TKG 2021). In dieser Datenschutzerklärung informieren wir Sie über die wichtigsten Aspekte der Datenverarbeitung in der ClubForm-App und auf dieser Website.
1. Verantwortlicher / Betreiber
Die ClubForm-App und diese Website werden betrieben von:
Irfan Dogic (Einzelunternehmer)
Lange Gasse 13
8073 Feldkirchen bei Graz
Österreich
E-Mail: support@clubform.app
Ein Datenschutzbeauftragter ist nicht bestellt, da keine gesetzliche Verpflichtung dazu besteht.
2. Zwei Rollen: Ihr Verein und wir
ClubForm ist ein Werkzeug, mit dem Fußballvereine ihre Teams verwalten. Wer für Ihre Daten verantwortlich ist, hängt von der Art der Daten ab:
- Vereinsdaten — Spielerprofile, Spiel- und Trainingsdaten, Anwesenheiten, Statistiken, Bewertungen, Beiträge und Dokumente werden von Ihrem Verein eingegeben und verwaltet. Für diese Daten ist Ihr Verein Verantwortlicher im Sinne von Art. 4 Z 7 DSGVO; wir verarbeiten sie ausschließlich im Auftrag des Vereins als Auftragsverarbeiter (Art. 28 DSGVO) auf Grundlage eines Auftragsverarbeitungsvertrags, der Teil des Lizenzvertrags des Vereins ist.
- Konto- und Diagnosedaten — Ihr Anmeldekonto, Support-Kommunikation, Absturzberichte und Nutzungsstatistiken verarbeiten wir als Verantwortlicher.
Eine gemeinsame Verantwortlichkeit im Sinne von Art. 26 DSGVO besteht nicht — für jede Verarbeitung ist entweder Ihr Verein oder wir allein verantwortlich.
Bei Fragen dazu, wie Ihr Verein Ihre Daten verwendet (z. B. warum ein Spielerprofil existiert oder wer es sehen kann), wenden Sie sich bitte zuerst an Ihren Verein. Wir unterstützen die Vereine bei der Beantwortung solcher Anfragen.
3. Welche Daten verarbeitet werden
Betroffene Personen sind je nach Verarbeitung: Trainer/innen und Vereinsfunktionär/innen, Spieler/innen (auch Minderjährige), Eltern bzw. Erziehungsberechtigte, Fans, Besucher/innen dieser Website sowie Ansprechpersonen von Vereinen (Interessenten und Kunden).
a) Kontodaten (wir sind Verantwortlicher)
- E-Mail-Adresse, Anzeigename und Passwort (als sicherer Hash bei Firebase Authentication gespeichert — wir sehen Ihr Passwort nie).
- Persönliche App-Einstellungen: Sprache, Benachrichtigungseinstellungen, Teamfilter.
- Push-Token Ihrer Geräte (Firebase Cloud Messaging), damit die App Benachrichtigungen zustellen kann. Token werden beim Abmelden und bei Ungültigkeit entfernt.
- Support-Kommunikation: Wenn Sie uns per E-Mail kontaktieren, verarbeiten wir Ihre E-Mail-Adresse und den Inhalt Ihrer Nachricht, um Ihre Anfrage zu bearbeiten. Diese Korrespondenz wird nur so lange aufbewahrt, wie es für die Bearbeitung und Nachvollziehbarkeit der Anfrage erforderlich ist.
- Erforderlichkeit der Angaben: Die Angabe einer E-Mail-Adresse ist für die Erstellung eines Kontos erforderlich — ohne sie kann kein Konto angelegt und die App nicht genutzt werden. Ein Profilfoto und vergleichbare Zusatzangaben sind freiwillig.
b) Vereinsdaten (Ihr Verein ist Verantwortlicher)
- Spielerprofile: Name, Geburtsdatum, Position(en), Rückennummer und optionales Profilfoto.
- Spiel- und Trainingsdaten: Termine, Kader, Aufstellungen, Live-Ereignisse, Ergebnisse, Anwesenheiten und Zu-/Absagen.
- Optionale Begründungen zu Abwesenheiten und Absagen (Freitext, vom Verein bzw. von Erziehungsberechtigten eingegeben). Solche Begründungen können im Einzelfall Gesundheitsbezug haben (z. B. „krank“); die dafür erforderliche Rechtsgrundlage stellt Ihr Verein sicher (siehe Punkt 4). Absage-Begründungen aus Zu-/Absagen werden den zuständigen Trainer/innen und Admins auch per Push-Benachrichtigung angezeigt.
- Daraus abgeleitete Statistiken (z. B. Tore, Vorlagen, Karten, Einsatzminuten) und Trainer/innen-Bewertungen.
- Interne Notizen der Trainer/innen zu Spieler/innen (Gesprächsnotizen zu Elterngesprächen, Spieler-Kommentare, Freitexte in Bewertungen) — sichtbar nur für Vereins-Funktionsrollen, nicht für Eltern- oder Fan-Zugänge.
- Beiträge und Dokumente innerhalb des Vereins.
- Herkunft der Daten: Diese Daten werden nicht von uns bei Ihnen erhoben, sondern von Ihrem Verein (z. B. Trainer/innen oder Funktionär/innen) in die App eingegeben.
c) Diagnose- und Nutzungsdaten (wir sind Verantwortlicher)
- Absturzberichte (Firebase Crashlytics): technische Fehlerprotokolle, Gerätemodell, Betriebssystemversion und Ihre Firebase-Nutzer-ID — zur Fehlersuche und -behebung.
- Nutzungsstatistiken (Google Analytics for Firebase): Ereigniszähler zu App-Funktionen (z. B. „Training erstellt“), Geräte- und App-Versionsinformationen, verknüpft mit Ihrer Firebase-Nutzer-ID. Wir nutzen dies ausschließlich, um zu verstehen, welche Funktionen genutzt werden, und um die App zu verbessern.
- App-Integritätsprüfung (Firebase App Check): Geräte-Attestierungstoken zur Missbrauchs-Prävention. In der Web-App (app.clubform.app) erfolgt die Prüfung über Google reCAPTCHA Enterprise: Dabei wird ein Skript von Google geladen, das Browser- und Interaktionsmerkmale zur Bot-Erkennung auswertet und ein technisch erforderliches Integritätstoken im Browser speichert.
- Website: Beim Aufruf dieser Seiten verarbeitet Firebase Hosting Ihre IP-Adresse und übliche Zugriffs-Logs zu Auslieferungs- und Sicherheitszwecken.
d) Kundendaten und Anfragen (B2B — wir sind Verantwortlicher)
- Demo- und Vertriebsanfragen: Wenn Sie uns als Vereinsvertreter/in über demo@clubform.app kontaktieren, verarbeiten wir Ihre E-Mail-Adresse, Ihren Namen und den Inhalt Ihrer Anfrage zur Anbahnung eines Vertrags.
- Freischaltung: Zur Autorisierung der Vereinserstellung speichern wir die E-Mail-Adresse der berechtigten Ansprechperson (Freischaltliste).
- Vertrags- und Abrechnungsdaten von Vereinen und deren Ansprechpersonen im Rahmen der Geschäftsbeziehung.
- Empfänger: E-Mails an unsere Adressen werden über unsere E-Mail-Infrastruktur zugestellt (Weiterleitung durch Cloudflare, Postfach bei Microsoft).
e) Cookies und lokale Speicherung
Diese Website verwendet keine Cookies und keine Tracking- oder Analyse-Dienste (§ 165 TKG 2021). Die App – als mobile App und als Web-App unter app.clubform.app – speichert auf Ihrem Gerät bzw. in Ihrem Browser nur technisch erforderliche Daten (Anmeldesitzung, Einstellungs- und Daten-Cache), ohne die die App nicht funktionieren kann; eine Einwilligung ist dafür nicht erforderlich. Die Web-App nutzt zur Missbrauchs-Prävention Google reCAPTCHA Enterprise (siehe 3c); das dafür im Browser gespeicherte Integritätstoken (Cookie bzw. Local Storage „_GRECAPTCHA“) ist technisch erforderlich. Die Web-App verwendet keine Analyse-Dienste; Schriftarten und Programmdateien werden von unserem eigenen Hosting geladen, nicht von Google Fonts.
Wir zeigen keine Werbung, verkaufen keine Daten, verfolgen Sie nicht über andere Apps oder Websites hinweg, führen kein Profiling durch und treffen keine automatisierten Entscheidungen im Sinne von Art. 22 DSGVO.
4. Rechtsgrundlagen
- Kontodaten und Bereitstellung des Dienstes: Vertragserfüllung, Art. 6 Abs. 1 lit. b DSGVO.
- Absturzberichte, Nutzungsstatistiken, Sicherheit und Missbrauchs-Prävention: berechtigtes Interesse an einem stabilen und sicheren Dienst, Art. 6 Abs. 1 lit. f DSGVO.
- Vereinsdaten: Die Rechtsgrundlage stellt Ihr Verein als Verantwortlicher her (in der Regel Mitgliedschaftsvertrag oder Einwilligung — bei Minderjährigen die Einwilligung der Erziehungsberechtigten, siehe Punkt 6).
- Kundendaten und Anfragen (B2B): Vertragsanbahnung und -erfüllung, Art. 6 Abs. 1 lit. b DSGVO; Aufbewahrung von Buchhaltungsunterlagen zur Erfüllung rechtlicher Pflichten, Art. 6 Abs. 1 lit. c DSGVO.
5. Empfänger und Drittlandübermittlung
Wir nutzen Google Firebase (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Irland, sowie Google LLC, USA) als technische Plattform: Authentication, Cloud Firestore (Datenbank), Cloud Storage (Bilder und Dokumente), Cloud Functions, Cloud Messaging (Push), Hosting, Crashlytics, Analytics und App Check – in der Web-App zusätzlich reCAPTCHA Enterprise. Google ist unser Sub-Auftragsverarbeiter. Daten können auf Servern in der EU und in den USA verarbeitet werden; Übermittlungen in die USA sind durch das EU-US Data Privacy Framework und/oder EU-Standardvertragsklauseln abgesichert.
Für den Versand von Transaktions-E-Mails (z. B. Vereinseinladungen) nutzen wir Brevo (Brevo SAS, 106 boulevard Haussmann, 75008 Paris, Frankreich) als Sub-Auftragsverarbeiter. Brevo verarbeitet die E-Mail-Adresse des Empfängers und den E-Mail-Inhalt auf Servern innerhalb der Europäischen Union. Die E-Mail-Adresse der eingeladenen Person erhalten wir dabei nicht von dieser selbst, sondern vom einladenden Verein.
Übersicht — welche Daten an welchen Dienst gehen:
| Dienst | Daten | Zweck | Ort |
|---|---|---|---|
| Firebase Authentication | E-Mail-Adresse, Passwort-Hash, Anzeigename | Anmeldung und Kontoverwaltung | EU/USA* |
| Cloud Firestore | Vereinsdaten (Spielerprofile, Spiel- und Trainingsdaten, Statistiken, Bewertungen, Beiträge), App-Einstellungen | Datenbank der App | EU/USA* |
| Cloud Storage | Profilfotos, Bilder und Dokumente | Dateispeicher | EU/USA* |
| Cloud Functions | Vereins- und Kontodaten (serverseitige Verarbeitung) | Serverlogik (z. B. Einladungen, Benachrichtigungen) | EU/USA* |
| Cloud Messaging | Push-Token, Benachrichtigungsinhalte | Push-Benachrichtigungen | EU/USA* |
| Apple APNs | Push-Token, Benachrichtigungsinhalte | Zustellung von Push-Benachrichtigungen an iOS-Geräte | EU/USA* |
| Firebase Hosting | IP-Adresse, Zugriffs-Logs | Auslieferung dieser Website | EU/USA* |
| Crashlytics | Fehlerprotokolle, Gerätemodell, OS-Version, Firebase-Nutzer-ID | Fehlersuche und -behebung | EU/USA* |
| Google Analytics for Firebase | Ereigniszähler, Geräte- und App-Versionsinfos, Firebase-Nutzer-ID | Verbesserung der App | EU/USA* |
| Firebase App Check | Geräte-Attestierungstoken | Missbrauchs-Prävention | EU/USA* |
| Google reCAPTCHA Enterprise (nur Web-App) | IP-Adresse, Browser- und Interaktionsmerkmale, Integritätstoken | Bot-/Missbrauchs-Prävention (App Check) | EU/USA* |
| Brevo | E-Mail-Adresse des Empfängers, E-Mail-Inhalt | Transaktions-E-Mails (z. B. Vereinseinladungen) | EU |
| Cloudflare, Inc. | eingehende E-Mails an unsere Support-/Vertriebsadressen (Inhalt und Metadaten) | E-Mail-Weiterleitung (Email Routing) | EU/USA* |
| Microsoft Corporation | E-Mail-Inhalt und -Metadaten unserer Support-/Vertriebspostfächer | Postfach-Hosting | EU/USA* |
* Übermittlungen in die USA sind durch das EU-US Data Privacy Framework und/oder EU-Standardvertragsklauseln abgesichert (siehe oben).
Darüber hinaus geben wir Daten nur weiter, wenn wir gesetzlich dazu verpflichtet sind. Eine Weitergabe zu Werbezwecken findet nicht statt.
6. Kinder und jugendliche Spieler/innen
ClubForm wird von Vereinen zur Verwaltung von Jugendmannschaften genutzt; Spielerprofile betreffen daher häufig Minderjährige. Diese Profile werden vom Verein angelegt und verantwortet. Die Einholung der Einwilligung der Erziehungsberechtigten ist Aufgabe des Vereins und eine vertragliche Pflicht jedes Vereins, der ClubForm nutzt. Eltern können jederzeit beim Verein Auskunft, Berichtigung oder Löschung der Daten ihres Kindes verlangen; der Verein kann dies direkt in der App umsetzen. Spielerprofile sind nicht öffentlich — sie sind nur für angemeldete Mitglieder desselben Vereins sichtbar, entsprechend den Rollen- und Sichtbarkeitseinstellungen des Vereins.
7. Speicherdauer
- Kontodaten: bis zur Löschung Ihres Kontos. Die Löschung ist direkt in der App möglich und wirkt sofort — siehe Konto löschen.
- Vereinsdaten: solange der Verein sie verwaltet. In der App „gelöschte“ Inhalte wandern zunächst in einen Papierkorb und können vom Verein endgültig entfernt werden; endet der Vertrag eines Vereins, werden dessen Daten innerhalb von 30 Tagen nach Vertragsende gelöscht; verschlüsselte Backups sind spätestens 14 Tage danach überschrieben.
- System-Backups: verschlüsselte Sicherungen werden bis zu 14 Tage aufbewahrt; danach sind gelöschte Daten auch aus Backups verschwunden.
- Absturzberichte: 90 Tage (Firebase-Crashlytics-Standard).
- Nutzungsstatistiken: bis zu 14 Monate (Firebase-Analytics-Aufbewahrung).
- Kundendaten (B2B): für die Dauer der Geschäftsbeziehung; Buchhaltungsunterlagen darüber hinaus für die gesetzliche Aufbewahrungsfrist von 7 Jahren (§ 132 BAO).
- Website-Hosting-Logs: werden von Firebase Hosting laut Google-Dokumentation für einige Monate aufbewahrt.
8. Ihre Rechte
Nach der DSGVO haben Sie das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) sowie Widerspruch gegen Verarbeitungen auf Basis berechtigter Interessen (Art. 21). Beruht eine Verarbeitung auf einer Einwilligung, haben Sie zudem das Recht, diese jederzeit zu widerrufen (Art. 7 Abs. 3 DSGVO); die Rechtmäßigkeit der bis zum Widerruf erfolgten Verarbeitung bleibt davon unberührt. Einwilligungen gegenüber Ihrem Verein (z. B. für Spielerprofile) widerrufen Sie direkt beim Verein. Für Konto- und Diagnosedaten wenden Sie sich an support@clubform.app; für Vereinsdaten an Ihren Verein — wir unterstützen den Verein bei der Erfüllung Ihrer Anfrage.
Außerdem haben Sie das Recht auf Beschwerde bei einer Aufsichtsbehörde. In Österreich ist dies die Datenschutzbehörde (DSB), Barichgasse 40–42, 1030 Wien, www.dsb.gv.at.
9. Sicherheit
Alle Daten werden verschlüsselt übertragen (TLS). Der Zugriff auf Vereinsdaten ist durch serverseitige Sicherheitsregeln entsprechend Ihrer Rolle im Verein beschränkt; der API-Zugriff kann zusätzlich durch Geräte-Attestierung (App Check) geschützt werden. Eine Ausnahme ist das optionale Kalender-Abo: Aktiviert eine berechtigte Person des Vereins den Termin-Feed eines Teams, sind dessen Termindaten (Termine, Gegner, Ort, Ergebnisse — keine Spielernamen und keine Anwesenheiten) über einen nicht erratbaren Abo-Link ohne Anmeldung abrufbar; der Verein kann den Link jederzeit in der App widerrufen. Bilder liegen in zugriffsgeschütztem Cloud-Speicher.
10. Änderungen dieser Erklärung
Wir aktualisieren diese Erklärung, wenn sich die Datenverarbeitung der App ändert. Die jeweils aktuelle Fassung ist unter dieser Adresse abrufbar; das Datum oben zeigt den Stand der letzten Überarbeitung.
Privacy Policy
ClubForm — Football Club Management · Last updated: 4 September 2026
Protecting your personal data is important to us. We process your data exclusively on the basis of the applicable legal provisions (GDPR, Austrian Telecommunications Act — TKG 2021). This privacy policy explains the most important aspects of data processing in the ClubForm app and on this website.
1. Who we are
The ClubForm app and this website are operated by:
Irfan Dogic (sole proprietor)
Lange Gasse 13
8073 Feldkirchen bei Graz
Austria
Email: support@clubform.app
We have not appointed a data protection officer, as there is no legal obligation to do so.
2. Two roles: your club and us
ClubForm is a tool that football clubs use to manage their teams. Who is responsible for your data depends on the kind of data:
- Club data — player profiles, match and training records, attendance, statistics, evaluations, posts and documents are entered and managed by your club. For this data, your club is the data controller within the meaning of Art. 4(7) GDPR, and we process it strictly on the club's behalf as a processor (Art. 28 GDPR) under a data processing agreement that is part of the club's license contract.
- Account and diagnostic data — your sign-in account, support communication, crash reports and app-usage statistics are processed by us as the controller.
There is no joint controllership within the meaning of Art. 26 GDPR — for every processing activity, either your club or we alone are responsible.
For questions about how your club uses your data (for example why a player profile exists or who can see it), please contact your club first. We support clubs in answering such requests.
3. What data is processed
Depending on the processing, the data subjects are: coaches and club officials, players (including minors), parents and legal guardians, fans, visitors of this website, and contact persons of clubs (prospects and customers).
a) Account data (we are controller)
- Email address, display name and password (stored as a secure hash by Firebase Authentication — we never see your password).
- Personal app preferences: language, notification settings, team filters.
- Push notification tokens for your devices (Firebase Cloud Messaging), so the app can deliver notifications your club or the app sends you. Tokens are removed on logout and when they become invalid.
- Support communication: if you contact us by email, we process your email address and the content of your message to handle your request. This correspondence is kept only as long as needed to handle and document the request.
- Required information: an email address is required to create an account — without it, no account can be created and the app cannot be used. A profile photo and similar additional details are optional.
b) Club data (your club is controller, we process on its behalf)
- Player profiles: name, date of birth, position(s), jersey number and an optional profile photo.
- Match and training data: schedules, squads, lineups, live match events, results, attendance and RSVP responses.
- Optional reasons for absences and declines (free text, entered by your club or by parents/legal guardians). Such reasons can in individual cases relate to health (e.g. "sick"); your club is responsible for the required legal basis (see section 4). Decline reasons from RSVP responses are also shown to the responsible coaches and admins in push notifications.
- Statistics derived from the above (e.g. goals, assists, cards, minutes played) and coach evaluations.
- Internal coach notes about players (notes on parent conversations, player comments, free-text parts of evaluations) — visible only to club staff roles, not to parent or fan accounts.
- Posts (announcements) and documents shared inside the club.
- Origin of the data: this data is not collected from you by us — it is entered into the app by your club (e.g. coaches or club officials).
c) Diagnostic and usage data (we are controller)
- Crash reports (Firebase Crashlytics): technical crash traces, device model, operating system version and your Firebase user ID, so we can find and fix errors.
- Usage statistics (Google Analytics for Firebase): anonymous-by-design event counters for app features (for example "training created", "attendance marked"), device and app-version information, associated with your Firebase user ID. We use this only to understand which features are used and to improve the app.
- App integrity checks (Firebase App Check): device attestation tokens that verify requests come from the genuine app — used for abuse prevention and security. In the web app (app.clubform.app) this check uses Google reCAPTCHA Enterprise: a script from Google evaluates browser and interaction signals for bot detection and stores a technically required integrity token in the browser.
- Website: when you open these web pages, Firebase Hosting processes your IP address and standard request logs for delivery and security purposes.
d) Customer data and inquiries (B2B — we are controller)
- Demo and sales inquiries: if you contact us as a club representative via demo@clubform.app, we process your email address, name and the content of your inquiry in order to prepare a contract.
- Authorization: to authorize club creation we store the email address of the entitled contact person (allowlist).
- Contract and billing data of clubs and their contact persons in the course of the business relationship.
- Recipients: email sent to our addresses is delivered through our email infrastructure (forwarding by Cloudflare, mailbox hosted by Microsoft).
e) Cookies and local storage
This website uses no cookies and no tracking or analytics services (Section 165 TKG 2021). The app — as a mobile app and as a web app at app.clubform.app — stores only technically required data on your device or in your browser (login session, settings and data cache), without which the app cannot function; no consent is required for this. For abuse prevention the web app uses Google reCAPTCHA Enterprise (see 3c); the integrity token it stores in the browser (cookie or local storage "_GRECAPTCHA") is technically required. The web app uses no analytics services; fonts and program files are served from our own hosting, not from Google Fonts.
We do not show advertising, we do not sell data, we do not track you across other apps or websites, we do not carry out profiling, and we make no automated decisions within the meaning of Art. 22 GDPR.
4. Legal bases
- Account data and service provision: performance of the contract, Art. 6(1)(b) GDPR.
- Crash reports, usage statistics, security and abuse prevention: our legitimate interest in a stable, secure and improving service, Art. 6(1)(f) GDPR.
- Club data: the legal basis is established by your club as the controller (typically membership contract or consent — including parental consent for minors, see section 6).
- Customer data and inquiries (B2B): preparation and performance of the contract, Art. 6(1)(b) GDPR; retention of accounting records to comply with legal obligations, Art. 6(1)(c) GDPR.
5. Recipients and international transfers
We use Google Firebase (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA) as our technical platform: Authentication, Cloud Firestore (database), Cloud Storage (images and documents), Cloud Functions, Cloud Messaging (push), Hosting, Crashlytics, Analytics and App Check — in the web app additionally reCAPTCHA Enterprise. Google acts as our sub-processor. Data may be processed on servers in the European Union and the United States; transfers to the USA are safeguarded by the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses.
For sending transactional emails (e.g. club invitations) we use Brevo (Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France) as a sub-processor. Brevo processes the recipient's email address and the email content on servers within the European Union. We receive the invited person's email address not from that person, but from the inviting club.
Overview — which data goes to which service:
| Service | Data | Purpose | Location |
|---|---|---|---|
| Firebase Authentication | Email address, password hash, display name | Sign-in and account management | EU/USA* |
| Cloud Firestore | Club data (player profiles, match and training data, statistics, evaluations, posts), app preferences | The app's database | EU/USA* |
| Cloud Storage | Profile photos, images and documents | File storage | EU/USA* |
| Cloud Functions | Club and account data (server-side processing) | Server logic (e.g. invitations, notifications) | EU/USA* |
| Cloud Messaging | Push tokens, notification content | Push notifications | EU/USA* |
| Apple APNs | Push tokens, notification content | Delivery of push notifications to iOS devices | EU/USA* |
| Firebase Hosting | IP address, request logs | Serving this website | EU/USA* |
| Crashlytics | Crash traces, device model, OS version, Firebase user ID | Finding and fixing errors | EU/USA* |
| Google Analytics for Firebase | Event counters, device and app-version info, Firebase user ID | Improving the app | EU/USA* |
| Firebase App Check | Device attestation tokens | Abuse prevention | EU/USA* |
| Google reCAPTCHA Enterprise (web app only) | IP address, browser and interaction signals, integrity token | Bot/abuse prevention (App Check) | EU/USA* |
| Brevo | Recipient's email address, email content | Transactional emails (e.g. club invitations) | EU |
| Cloudflare, Inc. | Incoming email to our support/sales addresses (content and metadata) | Email forwarding (Email Routing) | EU/USA* |
| Microsoft Corporation | Email content and metadata of our support/sales mailboxes | Mailbox hosting | EU/USA* |
* Transfers to the USA are safeguarded by the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (see above).
Beyond this, data is only disclosed if we are legally obliged to do so. There is no disclosure for advertising purposes.
6. Children and young players
ClubForm is used by clubs to manage youth teams, so player profiles frequently relate to minors. These profiles are created and controlled by the club. Obtaining the consent of parents or legal guardians is the club's responsibility and is a contractual obligation of every club using ClubForm. Parents can request access, correction or deletion of their child's data from the club at any time; the club can fulfil such requests directly in the app. Player profiles are not publicly visible — they are only accessible to signed-in members of the same club, according to the club's role and visibility settings.
7. How long data is kept
- Account data: until you delete your account. Deletion is available directly in the app and takes effect immediately — see how to delete your account.
- Club data: for as long as the club manages it. Content the club "deletes" in the app is first moved to a trash state and can be permanently removed by the club; when a club's contract ends, its data is deleted within 30 days; encrypted backups are overwritten at most 14 days later.
- System backups: encrypted backups are retained for up to 14 days, after which deleted data disappears from backups as well.
- Crash reports: 90 days (Firebase Crashlytics default).
- Usage statistics: up to 14 months (Firebase Analytics retention).
- Customer data (B2B): for the duration of the business relationship; accounting records beyond that for the statutory retention period of 7 years (Section 132 of the Austrian Federal Fiscal Code, BAO).
- Website hosting logs: retained by Firebase Hosting for a few months according to Google's documentation.
8. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you also have the right to withdraw that consent at any time (Art. 7(3) GDPR); the lawfulness of processing carried out before the withdrawal remains unaffected. Consent given to your club (e.g. for player profiles) is withdrawn directly with the club. For account and diagnostic data, contact us at support@clubform.app. For club data, contact your club — we assist the club in fulfilling your request.
You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde (DSB), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
9. Security
All data is transmitted encrypted (TLS). Access to club data is restricted by server-side security rules based on your role in the club, and API access can additionally be protected by device attestation (App Check). One exception is the optional calendar subscription: if an authorized person of the club activates a team's schedule feed, that team's schedule data (events, opponents, locations, results — no player names and no attendance data) can be retrieved without signing in via an unguessable subscription link; the club can revoke the link in the app at any time. Images are stored in access-controlled cloud storage.
10. Changes to this policy
We will update this policy when the app's data processing changes. The current version is always available at this address; the date at the top shows when it was last revised.