ClubOS legal

Privacy Policy

Last updated 13 August 2026

1. Who we are

ClubOS is operated by Bytecode Consulting Ltd. We provide a multi-tenant sports club management platform for club administrators, members, volunteers, and public visitors.

2. Data we process

ClubOS may process account details, club contact details, member records, payments metadata, onboarding submissions, support tickets, audit logs, uploaded media, and operational telemetry needed to run and secure the service. Payment card details are handled by Stripe or the relevant payment provider and are not stored by ClubOS.

3. How we use data

We use data to provide tenant-specific club services, authenticate users, enforce access control, process support requests, deliver transactional email, monitor reliability, prevent abuse, investigate platform issues, and improve ClubOS. Platform operator actions are audited so sensitive tenant, billing, support, and domain changes can be traced.

4. Sharing and subprocessors

We use trusted providers for hosting, authentication, email, storage, monitoring, payments, and related operations, including AWS, Cognito, Stripe, Resend, and Google where sign-in or integrations are enabled. Data is shared only where needed to provide or secure the service, comply with law, or support a club's configured integrations.

If you book a demo or walkthrough with us, that appointment is handled by Cal.com, Inc. (a scheduling provider in the United States). Cal.com receives the details you enter to make the booking — typically your name, email address, time zone, any notes you add, and technical data such as your IP address — and processes them on our behalf so we can hold the meeting. Transfers outside the UK rely on the provider's standard data protection terms. You can email us instead of using the scheduler if you would prefer not to use it.

5. Retention and security

ClubOS keeps tenant data for as long as needed to provide the service, meet legal or accounting duties, maintain audit trails, and resolve support issues. We use tenant-aware access controls, audit logging, encryption-capable AWS services, and operational monitoring to protect the platform.

6. AI assistant and voice

When an authorised user uses the ClubOS AI assistant, their prompt, relevant club data, and the assistant response may be processed by an AI service provider so ClubOS can answer the request or carry out an authorised workflow. For realtime voice, microphone audio and relevant authorised ClubOS data are streamed to OpenAI for the live session. Voice is optional: the interface asks the user to agree before the microphone starts, clearly shows when it is active, and keeps typed chat available when voice is declined.

ClubOS applies the signed-in user's existing club and role permissions before returning member data or executing a tool. AI providers do not receive direct access to the ClubOS database or payment-card details. We use contractual and technical safeguards appropriate to OpenAI and do not permit provider training on ClubOS customer data where the service terms offer that control.

7. Cookies

ClubOS uses essential cookies for sign-in, session security, onboarding invite gates, and request protection. We do not use advertising cookies in the platform app. See the Cookie Policy for more detail.

8. Contact

Privacy requests can be sent to admin@cluboss.co.uk.