ClubRise
Back to home Get started

App & platform privacy

How we handle your data in ClubRise.

This policy covers the ClubRise platform — the web app at your club's address on clubrise.app and the Club Rise mobile app for Android and iOS. The marketing site at www.clubrise.app is covered by the site privacy policy.

Who is responsible for your data

Two different answers, depending on which data you mean.

  • Your account — the email address and password you sign in with, and the profile you manage yourself. The controller is Creative Code Lab PR, a sole proprietorship registered in the Republic of Serbia at Đurićeva 20, 11000 Belgrade, tax ID (PIB) 114041189.
  • What your club records about you — your membership, bookings, competition entries, results, attendance and payments. Here your club is the controller and Creative Code Lab acts as a processor, handling that data on the club's instructions. If you want that data changed or removed, your club decides; we act on their instruction, and we will help you reach them.

You can reach us at [email protected] or by phone at +381 65 528 9164.

What the app collects

Everything below is data you or your club enter. The app has no background collection: it gathers nothing while you are not using it.

  • Account — email address, password (stored only as a salted hash, never in readable form), display name, and an optional phone number.
  • Player profile — first and last name, and any optional details you choose to fill in: date of birth, hometown, height, the year you started playing, dominant hand, backhand style, preferred surface, favourite shot, and racket.
  • Photos — images you upload for a profile, club, competition, or club branding.
  • Club activity — court bookings, competition and league entries, match results and rankings, session attendance, and membership tier.
  • Payments — the amount, currency, status, and the reference number the bank returns for a transaction. See Card payments below.
  • Crash diagnostics — if the app crashes, a technical report. See Crash reports below.
  • A push notification token — if you allow notifications, the identifier your phone's operating system issues so we can send them. See Push notifications below.

What the app does not collect

  • No location. The app never requests or records your position, precise or approximate.
  • No contacts, calendar, microphone, or health data.
  • No advertising identifiers, and no tracking. We do not build an advertising profile, we do not run third-party analytics or advertising SDKs in the app, and we never link your activity to data from other companies' apps or websites.
  • No selling of data, to anyone, for any purpose.

Permissions the app asks for

On Android the app declares internet and network-state access, which need no prompt, and permission to post notifications, which Android 13 and later ask you about once. On iOS it asks for notifications, and for the photo library or the camera only at the moment you choose to attach an image. Every one of these prompts can be declined and the app keeps working: decline photos and you cannot attach one, decline notifications and you read the same messages inside the app instead. Neither platform build asks for location, contacts, or any other sensitive permission.

Card payments

When your club uses online payments, the payment itself happens on the bank's own hosted page. Your card number, expiry date, and security code are entered there and go directly to the payment provider — they are never sent to, processed by, or stored on ClubRise servers. What we store is the amount, the currency, whether the payment succeeded, and the reference number the provider returns, so your club can reconcile it against your booking.

Crash reports

The mobile app sends crash and error reports to Sentry, hosted in Sentry's European Union region, so these reports do not leave the EU. A report contains the technical failure — the type of error, where in the code it happened, the app version, and the device model and operating-system version.

It is configured not to attach personal information: sign-in tokens, session cookies, and authorisation headers are removed on the device before the report is sent, and the option that would otherwise include user identifiers is switched off.

Push notifications

If you allow notifications, your phone's operating system issues a device token for the app and we store it against your account, together with the platform (Android or iOS) and the app version, so support can tell which build a device is running. The token is not stored against a club: one phone receives notifications from every club you belong to, and each message carries the club it came from so the app can switch before it opens the screen.

Sending a notification means handing it to the operating system's own delivery service — Firebase Cloud Messaging for Android and the Apple Push Notification service for iOS. There is no other way for an app to make a phone show a notification. What travels through that service is the notification's title and text, the club it belongs to, the screen a tap should open, and its identifier and timestamp. Because the title and text are the message itself, they can name the thing the notification is about: a booking, a match, a payment. If that matters to you, keep notifications switched off and read the same messages inside the app.

The token is deleted, not flagged, as soon as it stops being valid: when you sign out, when Apple or Google reports the token unregistered because you deleted the app or turned notifications off, or after 90 days in which the device has not checked in. You can withdraw permission at any time in your phone's system settings, and per-notification-type choices stay in your ClubRise notification settings.

Where your data is stored

ClubRise runs on servers operated by Hetzner Online GmbH inside the European Union. Your club's database and any photos you upload live on that same infrastructure — we do not use a third-party storage provider for them.

Four services support the platform:

  • Cloudflare — routes and protects traffic to clubrise.app;
  • Brevo (France) — delivers transactional email such as password resets, confirmations and invitations;
  • Sentry (EU region) — receives crash reports, as described above;
  • Firebase Cloud Messaging (Google, Android) and the Apple Push Notification service (iOS) — deliver push notifications to your phone, as described above.

Cloudflare, Brevo and Sentry act as processors under contract and may not use your data for their own purposes. Push delivery is different in kind: it is part of the phone's operating system rather than something we could choose a supplier for, it runs on Apple's and Google's own global infrastructure under their terms, and a notification on its way to you may therefore pass outside the European Union. Nothing else we hold about you is sent to either of them.

How long we keep it

Your account and club records are kept for as long as your club uses ClubRise and your membership is active. If your club leaves the platform, its data is deleted within 90 days of the account closing, apart from anything we are legally required to keep — payment records, for example, are retained for the period Serbian accounting law requires. Crash reports are kept for 90 days and then deleted automatically, and so is a push notification token that has gone that long without the device checking in.

Your rights

If you are in the European Union you have the rights set out in the GDPR: access a copy of what we hold about you, correct it, ask us to erase it, ask us to restrict processing, object to processing, and receive your data in a portable format. If you are in Serbia the same rights apply under the Zakon o zaštiti podataka o ličnosti.

Two of these you can exercise yourself, without asking anyone. Signed in to ClubRise, open your account settings and use:

  • Download your data — produces a file containing the personal data held on your account;
  • Delete your account — see Deleting your account below for exactly what this removes.

For anything else, or for data your club controls, email [email protected]. We respond within 30 days. You may also lodge a complaint with the Serbian supervisory authority (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti) or with the data protection authority where you live in the EU.

Deleting your account

You can delete your ClubRise account yourself, at any time, without asking us or your club. Signed in to ClubRise — in the mobile app, open account management from the menu, which opens your account pages in the browser — go to Personal data and choose Delete. You will be asked for your password to confirm. The deletion is immediate and cannot be undone.

If you cannot sign in — you have lost access to the email address, for example — write to [email protected] from any address you can prove is yours, and we will verify your identity and delete the account for you. We complete these requests within 30 days.

What deleting removes: your sign-in identity — email address, password, phone number, display name and account identifier — and the push notification token of every phone you had signed in to. Records you created inside a club (a booking you made, a result you entered) are not erased from the club's history; their authorship is reassigned to an internal System user, so the club's records stay complete without still naming you.

What it does not remove: the player profile and membership records your club holds about you — your name on a team sheet, past results, attendance. Your club is the controller of that data, as explained above, so the decision is theirs. Ask your club to remove it and they can; we will act on their instruction, and we will help you reach them if you are not sure who to contact.

If you want a copy of your data before deleting it, use Download your data on the same page first — deletion is not reversible, and we cannot restore an account afterwards.

Children

Clubs often have junior members, and a club may record a junior player's profile and results as part of running its programmes. Where a child is under 16, the club is responsible for obtaining the consent of a parent or guardian before entering that data, and for holding it under its own membership rules. ClubRise accounts are not intended to be created by children directly. If you believe a child's data has been entered without the proper consent, email us and we will work with the club to remove it.

Changes to this policy

If we change how the platform handles personal data, we will update this policy and the date below. Where a change is material — a new processor, a new category of data — we will also notify club administrators by email before it takes effect.

Last updated: 9 September 2026.

ClubRise

The operating system for your club.

Product

Modules Platform Partners Impressions Pricing FAQ

Company

[email protected] +381 65 528 9164 Privacy App privacy Terms

Get started

Get started Already a member? Find your club

© 2026 ClubRise. Built for clubs that take the game seriously.

Hosted in Europe

ClubRise is operated by Creative Code Lab PR · Đurićeva 20, 11000 Belgrade, Serbia · PIB 114041189.