Governance & Legal Centre

Data Retention Policy

Last Reviewed: 7 July 2026Version: 1.04 min read

Document Information

Document
Data Retention Policy
Document ID
CLB-DRET-001
Category
Privacy
Version
1.0
Status
Approved
Effective Date
7 July 2026
Last Reviewed
7 July 2026
Next Review
7 July 2027
Review Cycle
Annual
Owner
Cluboom

This policy sets out how long Cluboom keeps the personal information held in the platform on behalf of grassroots sports clubs, and what happens to that information when it is no longer needed. It should be read alongside the Privacy Policy, the Data Processing Agreement (UK GDPR) and the Data Subject Rights Policy. It is not legal advice.

1. Purpose

Grassroots clubs need information to run: who is in the squad, who is available on Saturday, who turned up to training, and who to contact if a child is hurt. That information is genuinely useful, and in many cases a club needs it across several seasons rather than a few weeks.

Keeping information for longer than it is needed is a different matter. It increases the harm caused if something goes wrong, makes it harder to keep records accurate, and is contrary to the storage limitation principle of the UK GDPR. This policy sets deliberate, documented retention periods so that Cluboom keeps what clubs genuinely need — and no more.

2. Retention principles

Cluboom applies the following principles to every category of data:

  • information is retained only for as long as it is necessary for the purpose it was collected for;
  • retained information is reviewed periodically, and at least at each annual policy review, to confirm the period remains appropriate;
  • information that is no longer required is deleted, or anonymised where a club still benefits from aggregate figures such as season participation totals;
  • some information is kept for longer where the law requires it (for example accounting records), where a safeguarding responsibility applies, or where there is a clear and proportionate business purpose such as defending a legal claim or investigating a security incident.

Where a longer period is applied, it is applied to the narrowest set of records that achieves the purpose, rather than to the account as a whole.

3. Data retention schedule

The table below sets out the typical retention period for each category of information held in Cluboom. Periods run from the trigger described in the table — usually the closure of an account, the end of a role, or the date the record was created.

  • Club accounts

    Typical retention period

    Life of the club’s subscription, then 12 months

    Reason

    Keeps the club’s season history usable while it is active, and allows a short window to reinstate a club that leaves and returns before the record is deleted.

  • Club administrator accounts

    Typical retention period

    While the role is held, then 12 months

    Reason

    Administrators make consequential changes (roles, teams, deletions), so a short tail is kept for accountability and handover to the next committee.

  • Team administrator accounts

    Typical retention period

    While the role is held, then 12 months

    Reason

    Supports continuity between seasons and evidences who managed a team if a question is raised later.

  • Coach accounts

    Typical retention period

    While the role is held, then 12 months

    Reason

    Coaches are linked to attendance, availability and injury records; a short retention period keeps those records meaningful.

  • Parent accounts

    Typical retention period

    While linked to an active player, then 12 months

    Reason

    Parents need access across seasons and between siblings, and consent and contact history must stay traceable for a reasonable period.

  • Player accounts (including PIN profiles)

    Typical retention period

    While registered with the club, then 12 months

    Reason

    Allows a player to rejoin, or a club to correct a mistaken removal, without losing their squad history.

  • User profiles (name, contact details, preferences)

    Typical retention period

    Deleted with the associated account

    Reason

    Profile information has no purpose once the underlying account has been removed.

  • Invitations (email and code invites)

    Typical retention period

    90 days after expiry or acceptance

    Reason

    Short-lived credentials should not linger. A brief window supports troubleshooting failed invites.

  • Authentication logs (sign-in, PIN attempts, rate limiting)

    Typical retention period

    90 days

    Reason

    Needed to detect brute-force attempts and investigate account access issues, and of little value after that.

  • Audit logs (role changes, deletions, administrative actions)

    Typical retention period

    24 months

    Reason

    Committees change annually. Two years allows a club to understand who changed what across at least one full handover.

  • Attendance records

    Typical retention period

    Life of the club account, then deleted or anonymised

    Reason

    Clubs use attendance across seasons for selection, participation reporting and funding evidence.

  • Availability responses

    Typical retention period

    24 months

    Reason

    Operational scheduling data with limited long-term value once the fixture has passed.

  • Training records (sessions, drills, cancellations)

    Typical retention period

    Life of the club account

    Reason

    Forms the club’s planning history and supports coach development and session review.

  • Match statistics and results

    Typical retention period

    Life of the club account; may be retained longer as club history

    Reason

    Sporting records are part of a club’s identity. Clubs may choose to preserve results indefinitely as a historical record.

  • Fitness test results

    Typical retention period

    Life of the player’s registration, then 12 months

    Reason

    Physical measurements are more sensitive than routine sporting data and are not kept as long-term history by default.

  • Awards and achievements

    Typical retention period

    Life of the club account; may be retained longer as club history

    Reason

    Player of the match and similar honours form part of the club’s permanent record where the club chooses to keep them.

  • Push notification history

    Typical retention period

    6 months

    Reason

    Supports delivery troubleshooting and complaint handling, then serves no further purpose.

  • Uploaded images (club badges, player photos, media)

    Typical retention period

    Deleted with the associated record or account

    Reason

    Images of children in particular should not outlive the record they belong to.

  • Support enquiries and correspondence

    Typical retention period

    24 months from closure

    Reason

    Allows recurring issues to be understood and disputes about advice given to be resolved fairly.

  • Billing and transaction records

    Typical retention period

    7 years

    Reason

    Required by UK tax and company law for accounting records; retained regardless of account closure.

  • Security logs (infrastructure, access, incident data)

    Typical retention period

    12 months; longer where an incident is under investigation

    Reason

    Supports detection, forensic review and any regulatory reporting obligations following an incident.

  • Website analytics data

    Typical retention period

    14 months, in aggregated form

    Reason

    Enables year-on-year comparison of website performance without keeping identifiable visitor records.

Sporting records are treated differently to administrative records. Match statistics, results, awards and achievements form part of a club’s history, and many clubs wish to keep them well beyond the involvement of any individual season. Where a club chooses to preserve these records, Cluboom retains them for the life of the club account, reducing them to the minimum identifying detail needed for the record to make sense. A player or parent can still ask for that information to be reviewed under the Data Subject Rights Policy.

Retention periods are maximums, not targets. Where a shorter period is practical — for example expired invitations or delivered notifications — the information is removed sooner.

4. Club responsibilities

For most information stored in Cluboom, the club is the data controller and Cluboom acts as its processor. The club decides which players, parents, coaches and volunteers are added, what is recorded about them, and when a person should be removed.

Clubs are therefore responsible for:

  • removing players, staff and parents who are no longer involved;
  • deciding whether to preserve historical sporting records, and telling members that they do so;
  • applying any retention requirements imposed by their league, county association or national governing body;
  • responding to requests from their members, with Cluboom’s support where needed.

Where a club’s own retention requirement is shorter than the period in the schedule above, the club should tell us and we will apply the shorter period to that club’s data.

5. Data subject requests

Anyone can ask for a copy of their information, ask for it to be corrected, or ask for it to be deleted. How to make that request, and how identity is verified, is set out in the Data Subject Rights Policy.

Deletion requests are considered alongside legal, safeguarding and operational obligations. Information cannot always be erased immediately — for example billing records required by tax law, audit entries evidencing an administrative action, or records connected to an open safeguarding concern. Where a request cannot be met in full, we explain which information is retained, why, and for how long, and we restrict its use to that purpose.

6. Secure disposal

When a retention period expires, information is securely deleted from the production database and associated file storage, or irreversibly anonymised so that it can no longer be linked to an individual.

Encrypted backups are retained on a rolling schedule for disaster recovery. Deleted records may persist in those backups until the backup itself expires; they are not restored into production except as part of a full recovery, and deletions are reapplied where a restore takes place. Disposal is carried out using the same access controls, encryption and logging that protect live data.

7. Policy review

This policy is reviewed at least annually. Retention periods may be shortened or extended before that review following:

  • changes in legislation or regulatory guidance;
  • operational improvements to how Cluboom stores and archives data;
  • security requirements arising from an incident or risk assessment;
  • safeguarding requirements, including guidance from national governing bodies.

The version, effective date and review date shown at the top of this document always reflect the current published position.

8. Feedback

Questions regarding this policy can be sent to support@cluboom.co.uk.

Cluboom welcomes responsible feedback that helps improve our governance, security and compliance documentation.

Cluboom maintains a single governance register. Every document in the register is published and publicly available. Browse the full library in the Governance Centre.

Questions about this document? Contact us at support@cluboom.co.uk.

Cluboom is a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079), 24 Brynaeron, Dunvant, Swansea, United Kingdom, SA2 7UX.

  • Built in the UK
  • Designed with privacy in mind
  • Secure cloud infrastructure
  • Designed for grassroots sport