Privacy Policy
Last updated: 31 May 2026
1. Who we are
Clubhouse HQ is operated by Leighton Moore ("we", "us", "our"), a sole trader based in the United Kingdom. Clubhouse HQ is software for running amateur golf societies. For any privacy questions you can reach us via the Contact page.
2. Our role (controller)
For personal data you provide directly to Clubhouse HQ (your account details, the data you enter about your society and members), Leighton Moore is the data controller. Our payment provider, Paddle, acts as an independent controller and Merchant of Record for purchases — see "Payments" below.
3. Information we collect
- Account data: name, email address, password hash, optional avatar.
- Society data you enter: members, fixtures, results, scores, notes.
- Support messages: emails or in-app messages you send us.
- Technical data: IP address, device/browser type, usage and error logs.
- Cookies: essential session cookies; optional analytics cookies where you consent.
4. How we use your information and legal bases
- Contract (Art. 6(1)(b) UK GDPR): creating your account, providing the service, processing your subscription.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing fraud, improving the product, responding to support requests.
- Legal obligation (Art. 6(1)(c)): tax, accounting, and responding to lawful requests.
- Consent (Art. 6(1)(a)): optional analytics cookies and any marketing emails.
5. Payments and the Merchant of Record
Our order process is conducted by our online reseller Paddle.com. Paddle is the Merchant of Record for all our orders and is an independent controller of the data you submit at checkout (billing name, email, address, payment details, tax info). Paddle handles payments, billing, tax compliance, invoicing, refunds and related customer enquiries. We receive a limited record of the transaction (e.g. plan, status, last 4 digits, country) to provision your subscription. See Paddle's privacy notice at paddle.com/legal/privacy.
6. Who we share data with
- Hosting and database providers that run the Clubhouse HQ infrastructure, under data-processing agreements.
- Paddle, our Merchant of Record, for payments, subscription management, tax, and invoicing.
- Email delivery providers for transactional emails (verification, password reset, receipts).
- Professional advisers (accountants, legal) where necessary.
- Authorities where required by law.
7. International transfers
Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses, or transfers to countries covered by an adequacy decision.
8. Retention
We keep account and society data for as long as your account is active. If you delete your account, we delete or anonymise personal data within 90 days, except where we must retain records for legal reasons (typically up to 7 years for billing and tax records held by us or Paddle). Backups are rotated and overwritten on a rolling 30-day cycle.
9. Security
We use industry-standard technical and organisational measures, including TLS encryption in transit, encryption at rest, hashed passwords, role-based access control, audit logging, and least-privilege access for staff. No system is perfectly secure, but we work hard to protect your data and will notify you of any qualifying breach as required by law.
10. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability and to withdraw consent. You can exercise most rights from your Settings page, or by contacting us. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
11. Cookies
We use essential cookies to keep you signed in. We may use optional analytics cookies only where you have consented via our cookie banner; you can change your choice at any time.
12. Changes
We may update this policy. Material changes will be communicated via email or in-app notice.
