Privacy notice
Last updated 17 July 2026
Clobelo provides club management software to private clubs in the United Kingdom. This notice explains what personal data we handle, why, and what rights you have. We have written it in plain English because a privacy notice nobody can read protects nobody.
1. Who we are
Clobelo, United Kingdom. Contact: [email protected]. If you have a question about your data, that address reaches a person, not a queue.
2. Website visitors
| What | Why | Lawful basis | Kept for |
|---|---|---|---|
| Enquiry form: club name, your name, email, approximate member count, any note you write | To reply to you and to understand which clubs are interested | Legitimate interests (responding to a business enquiry you initiated) | 24 months from last contact |
| Aggregate analytics: page views, country, referrer | To understand whether the site is useful | Legitimate interests | Retained in aggregate only |
We do not use tracking cookies. Our analytics are cookieless and do not build a profile of you or follow you across other websites, which is why you are not being asked to dismiss a cookie banner. We do not sell data, we do not share it with advertisers, and we do not add enquirers to a marketing list.
3. Club staff using Clobelo
When a club's staff use the platform we hold their name, email address, role and sign-in records, so that we can provide the service and keep an audit trail of who did what. Lawful basis: performance of our contract with the club.
4. Club members' data
Clubs store their members' details in Clobelo — names, contact details, membership category, subscription charges, payments and statements. That data belongs to the club. We process it only to run the service, and only on the club's instructions.
If you are a member of a club that uses Clobelo and you want to see, correct or delete your data, please contact your club first — they control it. If you contact us, we will help them help you.
We never sell club or member data, and we do not use it to train anything.
5. Payments
Card payments are processed by Stripe, which is regulated for this purpose. Card numbers are entered directly into Stripe's own secure fields — they never reach the club's systems or ours. We store a payment reference and the amount so that the member's statement is correct.
6. Where data is held, and who else touches it
| Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application and database hosting | Germany (EU) |
| Cloudflare | Website delivery and security | Global edge network |
| Stripe | Card payment processing | EU / US under approved safeguards |
| Resend | Sending transactional email | EU / US under approved safeguards |
| Zoho Corporation | Our own business email | European Union |
Where a processor transfers data outside the UK/EEA, that transfer relies on an adequacy decision or on standard contractual clauses.
7. Security
In plain terms: each club's data is isolated at the database level, so one club's records cannot be read by another even if our application code has a bug. Financial records are append-only — entries cannot be quietly edited or deleted, only corrected by a visible reversal. Access is restricted by role and every privileged action is logged. Data is encrypted in transit.
8. Your rights
Under UK GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable format. Email [email protected] and we will respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk), though we would rather you gave us the chance to put it right first.
9. Changes
If we change this notice materially we will say so here, with a new date, and tell any club we work with directly.