Who This Policy Covers
This policy applies to people who register with Liverpool Lions RLFC, including players, parents and guardians, coaches, volunteers, staff, committee members and users of the club management platform.
Liverpool Lions RLFC is the data controller for club records. Data controller contact: Club Secretary / Data Protection Lead, contact details to be confirmed by the committee.
Information We Collect
- Names, contact details, addresses and account login details.
- Player details such as date of birth, school, team, registration numbers, attendance, availability, scores and match participation.
- Parent or guardian contact details and emergency contact information.
- Health, medication, allergy, injury, first aid, safeguarding and consent information where needed to protect players and run activities safely.
- Photos, documents, incident reports, payment records and club communication records.
Why We Use Information
- To manage membership, teams, events, matches, training and club administration.
- To contact members, parents, guardians, staff and volunteers about club matters.
- To protect children, young people and adults at risk through safeguarding, medical and incident processes.
- To record permissions, attendance, payments, documents and operational decisions.
- To meet legal, insurance, league, safeguarding and governing-body responsibilities where they apply.
Legal Reasons For Use
The club may rely on different lawful bases depending on the situation, including consent, legitimate interests, contract or membership administration, legal obligations, vital interests and safeguarding-related reasons. Health, medical and safeguarding information is treated as more sensitive and should only be accessed by people who need it for their role.
Who Can Access Information
Access is role based and enforced by the app. Parents and guardians can see linked child records only. Coaches and team managers can access practical team, attendance and match information. Finance users can access payment records. Safeguarding officers can access restricted safeguarding records and audit history.
The club does not sell personal information.
Sharing Information
Information may be shared where needed with parents or guardians, coaches, club officers, leagues, governing bodies, insurers, medical or emergency services, safeguarding authorities, technology providers or legal/regulatory bodies. Safeguarding information may be shared when necessary to protect a child, young person or adult at risk.
The app may use third-party processors for hosting, email delivery, backups and file storage. The club should keep processor details under review.
How We Protect Information
- Accounts are password protected and access is limited by role.
- Sensitive dashboard areas are restricted to authorised users.
- Only information needed for club purposes should be collected and kept.
- Old, incorrect or test data should be corrected or archived when identified.
- Devices, backups and exported files should be kept secure by club officers.
Public Website Analytics
Public analytics is disabled by default. If the club enables the internal, first-party option, it records only aggregate page views, registration starts and contact starts on approved public paths.
It does not record names, child or player identifiers, contact details, IP addresses, user agents, query strings, medical or safeguarding information, payment references or form contents. The club can disable collection immediately with the analytics kill switch.
How Long We Keep Information
Information should only be kept for as long as needed for club administration, safeguarding, legal, insurance, finance or governing-body reasons. The app can archive inactive players after 24 months, remove expired sessions after 7 days, and archive stale pending registrations after 90 days unless the club configures different retention periods.
Safeguarding, incident, audit and finance records may need to be kept longer and are not automatically hard-deleted by the app.
Your Rights
You can ask to see, export, correct, restrict or delete personal information where the law allows. Parent and guardian exports are limited to linked child data and exclude safeguarding investigation notes, internal coach notes and unrelated third-party information. Some records cannot always be deleted immediately if the club must keep them for safeguarding, legal, finance or insurance reasons.
Questions Or Requests
Contact a club admin or committee member if you want to ask about privacy, update incorrect information, request access to your data, request a data export, or raise a concern about how information is handled. Correction requests should be reviewed by an admin and approved changes should be recorded with old and new values in the audit log.
If you are unhappy with how a concern is handled, you can contact the UK Information Commissioner's Office.