← Back to Troop

Privacy Policy

Last updated: 16 July 2026

1. Who is responsible for your data

Your activity club ("the Club" — e.g. a swim school) is the data controller for information about you and your child: it decides what to collect and why, and is who you should contact first about a specific booking, medical note, or family record.

Troop, provided by [Company legal name], company number [00000000], [registered address], is the data processor— we hold and process data only on the Club's instructions, via this software. For a narrow set of things Troop decides itself (account security, billing records, this website), Troop is also a controller in its own right.

2. What data we hold

In line with our data-minimalism principle, Troop deliberately holds less than most platforms in this space. Specifically:

  • About a child: first name, date of birth, and one optional free-text "essential information" field (e.g. allergies) — no surname, no separate medical-records table, no photos are stored by Troop.
  • About a guardian: name, email address, phone number (optional), and your relationship to the child (primary guardian, carer, or pickup-only).
  • Attendance and booking data: which classes/camps a child is enrolled in, session attendance, reported absences, waitlist and catch-up-credit status.
  • Coaching data: qualifications and DBS/first-aid compliance records for coaches (not guardians or children), and incident reports where a Club records one.
  • Payment data: invoice records (amount, description, status) and a Stripe payment reference. Troop never stores card numbers — these are handled directly by Stripe.
  • Account data: login email, and system logs needed to operate the Service securely.

3. Why we process this data (lawful basis)

  • Performance of a contract — running bookings, attendance, and payments is how we deliver the Service the Club (and, for direct public bookings, you) has asked for.
  • Legitimate interests — of the Club, in running classes safely and communicating with families; balanced against your rights, and never used for a child's data where a more protective basis applies.
  • Legal obligation — retaining financial records (see §5) for UK tax purposes, and safeguarding compliance records.
  • Consent — for anything not necessary to deliver the Service, e.g. non-essential cookies (see our Cookie Policy) once analytics are introduced.

Essential-information fields about a child (e.g. allergies) are special category data under UK GDPR. We process this only where necessary to protect the child's vital interests or for substantial public interest reasons (running the activity safely), and access is restricted to the Club's own staff for that child's classes.

4. Who we share data with

We use a small number of specialist processors, each bound by a data processing agreement:

  • Stripe — payment processing. Card details go directly to Stripe; we never see or store them. Payments use Stripe Connect direct charges, so the Club is the merchant of record for its own transactions.
  • Supabase — our database and authentication provider, hosting all the data described in §2.
  • Amazon Web Services (SES) — sends transactional emails (booking confirmations, absence notifications, etc.).

We do not sell personal data, and do not share child data with any third party for marketing purposes.

5. How long we keep data

  • Active family/child records — for as long as the family is enrolled at the Club, plus a reasonable period after (set by the Club) in case of re-enrolment.
  • Financial records (invoices) — retained for 6 years after the tax year they relate to, as required by UK law, even after a family's other data has been deleted. See §7 — an account-deletion request anonymizes the family/child records attached to an invoice rather than deleting the invoice itself.
  • Safeguarding/compliance records (coach DBS, incident reports) — retained per the Club's own safeguarding policy, typically the duration recommended by UK safeguarding guidance.
  • Account security logs — a rolling, limited period sufficient to detect and investigate abuse.

6. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you or your child (right of access);
  • Have inaccurate data corrected (rectification) — most fields can be edited directly in your account;
  • Request deletion of your data (erasure), subject to the financial/safeguarding retention described in §5;
  • Object to, or ask us to restrict, certain processing;
  • Receive your data in a portable format (portability).

You can exercise access and erasure rights yourself, immediately, from Account → My Data. For any other request, or if you're acting on behalf of a family and don't have your own login, contact hello@mbo9.com or your Club administrator directly.

If you're unhappy with how we've handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or 0303 123 1113.

7. Deletion and financial records

Deleting your account removes your login, and your family's guardian, child, booking and communication records. Where a child has a paid-invoice history, the invoice itself is kept, not deleted — UK tax law requires clubs to retain financial records for 6 years — but the child and family records it references are anonymized (names removed) rather than left identifiable. This is the minimum retention the law requires, not a way of holding on to more than necessary.

8. International transfers

Our processors (Stripe, Supabase, AWS) may process data outside the UK. Where they do, transfers are covered by the UK's International Data Transfer Addendum or an adequacy decision.

9. Children's data specifically

A child does not hold their own Troop account — all data about a child is entered and managed by their guardian or the Club. We collect the minimum needed to run a safe class (see §2) and never use a child's data for marketing or profiling.

10. Contact

Data protection queries: hello@mbo9.com.