Privacy Policy
Last updated: 28 July 2026
This Privacy Policy explains how Ballr Club Limited (company number NI736442), trading as “Ballr” (“Ballr”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you use our websites and apps, including ballr.club, the Ballr iOS and Android mobile apps, and related features such as the Club Website API (together, the “Services”).
1) Who we are, and who is responsible for what
Ballr Club Limited (company number NI736442), trading as “Ballr”, operates the Services. Data protection contact: support@ballr.club
Responsibility for personal data on Ballr is split, and which part applies depends on the data:
1.1 Where Ballr is the controller
We decide how and why the following data is processed, and we are the controller for it:
- your Ballr user account (name, email, password, phone, sign-in and security data)
- billing and subscription data for Ballr Plus and other Fees you pay us
- website and app usage, device, log and security data
- cookies and similar technologies on our websites
- messages you send to our support team
1.2 Where the club is the controller and Ballr is the processor
Clubs use Ballr as a tool to run their own club. For the data a club puts into Ballr, the club is the controller and Ballr acts as its processor — we process that data on the club’s documented instructions and for no independent purpose of our own. This includes:
- player profiles created by the club (including any name, contact details, date of birth, gender, position and notes the club chooses to enter)
- squads, teams, availability responses, selections, lineups, match records and player statistics
- club feed posts, comments, photos and other content published within the club
- club membership records and the club’s own donation records
- data the club retrieves through the Club Website API
This means the club — not Ballr — is responsible for having a lawful basis for that data, for collecting any permissions or consents needed (including from parents or guardians where players are children), for keeping it accurate, for deciding how long to keep it, and for responding to requests from the people it relates to. Our processor obligations to clubs, including security, sub-processors, assistance with data subject requests and deletion or return of data, are set out in the Data Processing Terms in our Terms and Conditions.
If you are a player, parent or guardian and want data corrected or removed, contact your club first, as they control it. You can also contact us at support@ballr.club and we will help, and will pass the request to the club where we act only as processor.
2) What this policy covers
This policy applies to:
- visitors to ballr.club and related Ballr websites
- users of the Ballr mobile apps (iOS and Android)
- users who create an account
- clubs using Ballr to manage club pages, player profiles, posts, memberships, donations, and (where enabled) the Club Website API
- anyone who contacts support@ballr.club
This policy covers how Ballr processes personal data. If a club retrieves data via the Club Website API and displays it on the club’s own website, that club is responsible for its own website privacy practices and for any further processing it carries out.
3) Personal data we collect
We collect personal data you provide directly, data generated by your use of the Services, and data we receive from third parties.
3.1 Data you provide
- Account data: name, email address, password (stored in hashed form), phone number (if provided), role, status, approvals, and account settings.
- Sign-in with Google or Apple (where available): we receive basic account identifiers such as name and email address from the provider to create or sign in to your Ballr account. We do not receive your Google or Apple password.
- Club admin and club page data: club name, branding (logo/colours), descriptions, contact/social links you choose to publish, and other club profile information.
- Player profiles created by clubs: player name (or nickname), shirt number, position, date of birth and gender (if provided), availability/status, and other profile details that a club chooses to store. Player profiles are not user accounts unless and until an individual creates their own Ballr account and links a profile.
- Purchases, memberships, donations, and support: billing details handled by Stripe (we do not store full card numbers), order or donation details (such as name, email, amount, and optional messages), and messages you send to support (including attachments).
- Content: posts, comments, images, videos, match reports, and other content you upload or publish where features are available.
- Photos from your device (with permission): for example club logos, opponent badges, profile images, and feed images.
3.2 Payments and subscriptions (Stripe)
We use Stripe to process payments and subscriptions and, where applicable, to enable payouts to clubs (for example via Stripe Connect). This may include Ballr Plus club subscriptions, club memberships, and donations. We do not store full card details on our servers. We may store:
- payment/subscription status, timestamps, amounts, and currency
- Stripe customer IDs, subscription IDs, invoice/payment references, and payout references
- for clubs receiving payouts: Stripe account IDs and onboarding/status metadata needed to operate payouts
3.3 Messaging (Twilio / WhatsApp) and email delivery (Mailgun)
- Twilio (where enabled by a club): phone number and message metadata (such as time sent and delivery status) to deliver WhatsApp and related notifications (for example availability requests and reminders).
- Mailgun: email address, email content we send, and delivery metadata (such as delivery status and timestamps) to deliver transactional messages (for example verification emails, receipts, and service notifications).
3.4 Push notifications
If you enable push notifications, we store the token or subscription needed to deliver them:
- on mobile devices, a device push token (via Expo / Apple Push Notification service / Firebase Cloud Messaging as applicable)
- in web browsers, a Web Push subscription (endpoint and encryption keys issued by your browser vendor’s push service), used with the VAPID standard
You can control notification preferences in Account settings and revoke permission in your browser or device settings at any time.
3.5 Technical, usage, and device data
- IP address, device type, operating system, browser type/version, language and time zone settings
- approximate location derived from IP (city/region-level)
- log data (pages viewed, feature usage, timestamps, errors, and security events)
- referrer information and campaign attribution data (for example UTM parameters) on our websites
The Ballr mobile apps do not use the device advertising identifier (IDFA) for cross-app tracking, and we do not use third-party advertising SDKs inside the native apps.
3.6 Cookies, analytics, and advertising tags (“pixels”) — websites
On our websites (not in the native mobile apps), we use cookies and similar technologies for:
- strictly necessary operation (for example security, session management, load balancing, and remembering your cookie choice). These are always active — they do not require consent because the Services cannot work without them.
- analytics (Google Analytics, loaded through Google Tag Manager) to understand how people use Ballr. Only with your consent.
- marketing and measurement tags (“pixels”), which may include Meta, TikTok, Google Ads, LinkedIn, and X. Only with your consent.
Analytics and marketing technologies are not loaded at all until you consent. Our tag container is not present on the page beforehand, and consent signals default to “denied”, so no analytics or advertising cookies are set and no data is sent to those providers unless and until you opt in. Choosing “Necessary only”, or simply ignoring the banner, means none of them ever load.
4) How we use personal data
We use personal data to:
- create and administer accounts (including approvals, permissions, and two-factor authentication where enabled)
- operate club pages, player profiles, posts, availability, fixtures, and other platform features
- where a club enables the Club Website API, make selected club-related data available to that club (via authenticated API requests) so the club can display it on its own website
- process memberships, donations, subscriptions, refunds, disputes, fraud checks, and chargeback handling
- send service communications via email, push notification, and (where enabled) WhatsApp
- monitor and protect the security of the Services and users
- analyse usage to improve features, reliability, and user experience
- on our websites, measure marketing performance where you allow marketing tags
- comply with legal obligations and respond to lawful requests
5) Lawful bases
We process personal data under one or more of the following lawful bases:
- contract: where processing is needed to provide the Services you request (accounts, payments, subscriptions, and club features including the Club Website API where enabled by the club)
- legitimate interests: to operate, secure, and improve Ballr (balanced against your rights), including providing clubs with tools to publish selected club-related information they manage
- legal obligation: where we must comply with UK law
- consent: for non-essential cookies/tags and certain marketing-related processing where required
6) Who we share personal data with
We share personal data only as needed to run Ballr, provide the Services, and comply with law. This may include:
- Stripe (payments, subscriptions, donations, fraud checks, disputes, and payouts)
- Twilio (WhatsApp / messaging features, if enabled)
- Mailgun (email delivery)
- Google and Apple (only as needed for Sign in with Google / Sign in with Apple)
- Expo / Apple / Google push infrastructure (to deliver push notifications you enable)
- cloud hosting and file storage providers (for example to store uploaded images)
- Google (Google Analytics) and advertising/social platforms (for example Meta, TikTok, Google Ads, LinkedIn, X) on our websites where enabled by your cookie preferences
- hosting, infrastructure, monitoring, logging, and security service providers
- professional advisers (such as accountants and lawyers) where necessary
- regulators, law enforcement, or courts where we are legally required to disclose information
- a club (and systems acting for that club, such as the club’s website hosting or caching infrastructure) when the club enables and uses the Club Website API — see section 6.1
- club administrators and staff for clubs you join, follow, donate to, or otherwise interact with, so they can manage players, availability, memberships, and related club operations
6.1 Club Website API (sharing with a club’s own website)
Eligible clubs may generate an API key and use Ballr’s Club Website API to retrieve selected data from Ballr for use on the club’s own website. When a valid API key for a club is presented, Ballr discloses available API data to that club (or to servers/systems using the key on the club’s behalf).
Depending on the endpoints used and the data the club has entered on Ballr, this may include:
- club profile information (for example name, branding, venue, public contact/social links, and about text)
- fixtures and results (for example match dates/times, opponents, venues, scores, and related public match/report links)
- player statistics associated with player profiles (for example player name and aggregate match stats such as appearances, goals, assists, and cards)
- club feed posts the club has published (for example titles, body text, images, and video links)
The Club Website API is not intended to expose private player contact details (such as personal email addresses or phone numbers), membership or payment information, availability responses, or other admin-only team management data. Clubs control whether to enable the API, who may manage API keys, and what retrieved data they choose to display outside Ballr.
If a club republishes personal data on its own website, the club is responsible for that processing (including having an appropriate lawful basis and any permissions/consents required, especially where children are involved). Visitors to a club’s own website should consult that club’s privacy information for how the club handles data on its site. Ballr remains responsible for personal data processed within the Ballr Services as described in this policy.
7) International transfers
We may host and process data in more than one region (including the UK, the EEA, and other countries) because our infrastructure and vendors are based in multiple locations. Where personal data is transferred internationally, we use appropriate safeguards required under UK data protection law (for example approved contractual clauses) where applicable.
8) Cookies and your choices
We ask for your consent before any non-essential cookie is set or any analytics or advertising technology is loaded. Until you give it, those technologies are not loaded at all.
You can change your mind at any time. Signed-in users can update cookie choices in Account Centre → Preferences;
everyone can clear the cookie_consent cookie in their browser to be asked again. Withdrawing consent
stops further analytics and marketing processing and reloads the page to clear anything already loaded in that
session. You can also block or delete cookies through your browser settings. If you block strictly necessary
cookies, parts of the Services may not function.
In the mobile apps, you can manage notification preferences in Account settings and revoke photo or notification permissions in your device settings.
9) Children and young players
Grassroots football involves children, so this section matters. Please read it in full if you run a youth team or if your child plays for a club on Ballr.
9.1 Ballr accounts
Ballr accounts are intended for people aged 13 and over. If we believe an account holder is under 13, we may suspend or delete the account and associated content. If you are under 18, you may only use Ballr with the permission of a parent or guardian.
9.2 Player profiles are controlled by the club
A player profile is a record a club creates to run its squad. It is not a user account. Where a club stores data about a child — name, date of birth, gender, contact details, photographs, availability, statistics — the club is the controller of that data (see section 1.2). The club is responsible for having a lawful basis, for obtaining parental or guardian consent where that is the basis it relies on, and for making sure any content it publishes about children is appropriate.
Clubs must not enter or publish sensitive details about children such as home address, school, medical information or precise location.
9.3 What can be seen publicly, and how to change it
Some club information on Ballr is public by design, because clubs want fixtures, results and squads visible to supporters. Depending on the club’s settings, the following may be visible to anyone on the internet and may be indexed by search engines:
- the club’s public profile, fixtures and results
- a club statistics page listing player names alongside appearances, goals, assists, cards and awards
- an individual public player profile page showing name, position, season statistics and recent matches
- match graphics (for example starting XI images) that a club generates and shares
Individual player profile pages can be turned off. A player (or the club) can set a profile to private in Ballr, which removes that individual page from public view and from our sitemap.
A club can also remove itself from public discovery entirely in club settings, which takes its club and player pages out of Explore and out of our sitemap.
If you are a parent or guardian and you do not want your child’s name or statistics shown publicly, contact your club, which controls these settings. If you cannot reach the club, contact support@ballr.club and we will act on it.
9.4 Messaging young players
Where a club enables it, Ballr sends availability requests and reminders to the contact details the club has entered for a player, by email, WhatsApp or push notification. For children, clubs should use a parent or guardian’s contact details rather than the child’s own, and are responsible for ensuring it is appropriate to contact that person.
9.5 Squad chats
When a club publishes a squad, Ballr opens a chat for that match. Everyone selected for the squad can read it, and confirmed players can post. The club controls this content (see section 1.2).
A squad chat closes 48 hours after kick-off, at which point the players in it can no longer open it. It is not deleted at that point: the club keeps a readable record of it for a further 90 days, and the club’s owners, admins and managers can read and download that record during those 90 days. This is deliberate — a safeguarding concern raised after a match needs the conversation still to exist. After 90 days the chat and its messages are permanently deleted.
Page managers and financial admins at the club cannot read squad chats at any point. Neither can anyone at another club, and neither can Ballr staff except where necessary to investigate a reported concern or to maintain the service.
Messages in a squad chat are encrypted at rest, and photos shared in one are stored privately and served only to people entitled to open that chat. Squad chats are not end-to-end encrypted: the club’s owners, admins and managers can read the chat and download it as a record, which is the point of the 90 days described above. See section 12 for what our security measures do and do not cover.
9.6 Reporting a concern
To report content or a safeguarding concern involving a child, contact support@ballr.club with as much detail as you can (links, screenshots, club name and dates). We will review it promptly and can remove content or suspend accounts. If a child is at immediate risk, contact the police.
10) How long we keep data
We keep personal data only as long as necessary for the purposes described in this policy, including:
- while your account is active and for a reasonable period after closure
- to provide support and resolve disputes
- to meet legal, tax, accounting, and audit requirements
- to maintain security and investigate abuse (for limited periods)
- squad chats: readable by the squad until 48 hours after kick-off, then kept as a club record readable by the club’s owners, admins and managers for a further 90 days, then permanently deleted (see section 9.5)
11) Your rights and account deletion
Depending on your circumstances, you may have rights to access, correct, delete, restrict or object to certain processing of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).
You can delete your Ballr account in the mobile app (Account → Delete account) or on the website via Account Centre → Personal details. When you do, we anonymise the account: your name is replaced, your email address is replaced with a non-identifying value, your phone number is removed, your password is reset to an unusable value, and your two-factor settings, push subscriptions and notification preferences are deleted. The underlying record is retained in anonymised form so that club records that reference it (such as posts and comments) remain intact, and we may keep limited information where we must for legal, security or accounting reasons.
Deleting your user account does not automatically delete player profiles or club content that a club controls. Those are the club’s records (see section 1.2) — ask your club to remove them, or contact us and we will pass the request on.
To exercise your rights, contact: support@ballr.club
12) Security
We use appropriate technical and organisational measures designed to protect personal data, such as access controls, encryption in transit where available (HTTPS), and monitoring for suspicious activity. No system is completely secure, and we cannot guarantee absolute security.
Squad chat messages are additionally encrypted at rest, so they are stored as ciphertext rather than as readable text in our database. Photos shared in a squad chat are stored privately and are only served to people who are entitled to open that chat at the time they ask for it. To be clear about what this does and does not mean: squad chats are not end-to-end encrypted, and cannot be, because a club’s owners, admins and managers can read and download the chat as a safeguarding record (see section 9.5). Assume that anything you post in a squad chat can be read by the people who run the club.
13) Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will post an updated version on our website and update the “Last updated” date.
14) Contact
Questions about privacy should be sent to: support@ballr.club