Document Information
- Document
- Data Retention Policy
- Document ID
- CLB-DRET-001
- Category
- Privacy
- Version
- 1.0
- Status
- Approved
- Effective Date
- 7 July 2026
- Last Reviewed
- 7 July 2026
- Next Review
- 7 July 2027
- Review Cycle
- Annual
- Owner
- Cluboom
- Contact
- support@cluboom.co.uk
This policy sets out how long Cluboom keeps the personal information held in the platform on behalf of grassroots sports clubs, and what happens to that information when it is no longer needed. It should be read alongside the Privacy Policy, the Data Processing Agreement (UK GDPR) and the Data Subject Rights Policy. It is not legal advice.
1. Purpose
Grassroots clubs need information to run: who is in the squad, who is available on Saturday, who turned up to training, and who to contact if a child is hurt. That information is genuinely useful, and in many cases a club needs it across several seasons rather than a few weeks.
Keeping information for longer than it is needed is a different matter. It increases the harm caused if something goes wrong, makes it harder to keep records accurate, and is contrary to the storage limitation principle of the UK GDPR. This policy sets deliberate, documented retention periods so that Cluboom keeps what clubs genuinely need — and no more.
2. Retention principles
Cluboom applies the following principles to every category of data:
- information is retained only for as long as it is necessary for the purpose it was collected for;
- retained information is reviewed periodically, and at least at each annual policy review, to confirm the period remains appropriate;
- information that is no longer required is deleted, or anonymised where a club still benefits from aggregate figures such as season participation totals;
- some information is kept for longer where the law requires it (for example accounting records), where a safeguarding responsibility applies, or where there is a clear and proportionate business purpose such as defending a legal claim or investigating a security incident.
Where a longer period is applied, it is applied to the narrowest set of records that achieves the purpose, rather than to the account as a whole.
3. Data retention schedule
The table below sets out the typical retention period for each category of information held in Cluboom. Periods run from the trigger described in the table — usually the closure of an account, the end of a role, or the date the record was created.
| Data Category | Typical Retention Period | Reason |
|---|---|---|
| Club accounts | Life of the club’s subscription, then 12 months | Keeps the club’s season history usable while it is active, and allows a short window to reinstate a club that leaves and returns before the record is deleted. |
| Club administrator accounts | While the role is held, then 12 months | Administrators make consequential changes (roles, teams, deletions), so a short tail is kept for accountability and handover to the next committee. |
| Team administrator accounts | While the role is held, then 12 months | Supports continuity between seasons and evidences who managed a team if a question is raised later. |
| Coach accounts | While the role is held, then 12 months | Coaches are linked to attendance, availability and injury records; a short retention period keeps those records meaningful. |
| Parent accounts | While linked to an active player, then 12 months | Parents need access across seasons and between siblings, and consent and contact history must stay traceable for a reasonable period. |
| Player accounts (including PIN profiles) | While registered with the club, then 12 months | Allows a player to rejoin, or a club to correct a mistaken removal, without losing their squad history. |
| User profiles (name, contact details, preferences) | Deleted with the associated account | Profile information has no purpose once the underlying account has been removed. |
| Invitations (email and code invites) | 90 days after expiry or acceptance | Short-lived credentials should not linger. A brief window supports troubleshooting failed invites. |
| Authentication logs (sign-in, PIN attempts, rate limiting) | 90 days | Needed to detect brute-force attempts and investigate account access issues, and of little value after that. |
| Audit logs (role changes, deletions, administrative actions) | 24 months | Committees change annually. Two years allows a club to understand who changed what across at least one full handover. |
| Attendance records | Life of the club account, then deleted or anonymised | Clubs use attendance across seasons for selection, participation reporting and funding evidence. |
| Availability responses | 24 months | Operational scheduling data with limited long-term value once the fixture has passed. |
| Training records (sessions, drills, cancellations) | Life of the club account | Forms the club’s planning history and supports coach development and session review. |
| Match statistics and results | Life of the club account; may be retained longer as club history | Sporting records are part of a club’s identity. Clubs may choose to preserve results indefinitely as a historical record. |
| Fitness test results | Life of the player’s registration, then 12 months | Physical measurements are more sensitive than routine sporting data and are not kept as long-term history by default. |
| Awards and achievements | Life of the club account; may be retained longer as club history | Player of the match and similar honours form part of the club’s permanent record where the club chooses to keep them. |
| Push notification history | 6 months | Supports delivery troubleshooting and complaint handling, then serves no further purpose. |
| Uploaded images (club badges, player photos, media) | Deleted with the associated record or account | Images of children in particular should not outlive the record they belong to. |
| Support enquiries and correspondence | 24 months from closure | Allows recurring issues to be understood and disputes about advice given to be resolved fairly. |
| Billing and transaction records | 7 years | Required by UK tax and company law for accounting records; retained regardless of account closure. |
| Security logs (infrastructure, access, incident data) | 12 months; longer where an incident is under investigation | Supports detection, forensic review and any regulatory reporting obligations following an incident. |
| Website analytics data | 14 months, in aggregated form | Enables year-on-year comparison of website performance without keeping identifiable visitor records. |
Club accounts
Typical retention period
Life of the club’s subscription, then 12 months
Reason
Keeps the club’s season history usable while it is active, and allows a short window to reinstate a club that leaves and returns before the record is deleted.
Club administrator accounts
Typical retention period
While the role is held, then 12 months
Reason
Administrators make consequential changes (roles, teams, deletions), so a short tail is kept for accountability and handover to the next committee.
Team administrator accounts
Typical retention period
While the role is held, then 12 months
Reason
Supports continuity between seasons and evidences who managed a team if a question is raised later.
Coach accounts
Typical retention period
While the role is held, then 12 months
Reason
Coaches are linked to attendance, availability and injury records; a short retention period keeps those records meaningful.
Parent accounts
Typical retention period
While linked to an active player, then 12 months
Reason
Parents need access across seasons and between siblings, and consent and contact history must stay traceable for a reasonable period.
Player accounts (including PIN profiles)
Typical retention period
While registered with the club, then 12 months
Reason
Allows a player to rejoin, or a club to correct a mistaken removal, without losing their squad history.
User profiles (name, contact details, preferences)
Typical retention period
Deleted with the associated account
Reason
Profile information has no purpose once the underlying account has been removed.
Invitations (email and code invites)
Typical retention period
90 days after expiry or acceptance
Reason
Short-lived credentials should not linger. A brief window supports troubleshooting failed invites.
Authentication logs (sign-in, PIN attempts, rate limiting)
Typical retention period
90 days
Reason
Needed to detect brute-force attempts and investigate account access issues, and of little value after that.
Audit logs (role changes, deletions, administrative actions)
Typical retention period
24 months
Reason
Committees change annually. Two years allows a club to understand who changed what across at least one full handover.
Attendance records
Typical retention period
Life of the club account, then deleted or anonymised
Reason
Clubs use attendance across seasons for selection, participation reporting and funding evidence.
Availability responses
Typical retention period
24 months
Reason
Operational scheduling data with limited long-term value once the fixture has passed.
Training records (sessions, drills, cancellations)
Typical retention period
Life of the club account
Reason
Forms the club’s planning history and supports coach development and session review.
Match statistics and results
Typical retention period
Life of the club account; may be retained longer as club history
Reason
Sporting records are part of a club’s identity. Clubs may choose to preserve results indefinitely as a historical record.
Fitness test results
Typical retention period
Life of the player’s registration, then 12 months
Reason
Physical measurements are more sensitive than routine sporting data and are not kept as long-term history by default.
Awards and achievements
Typical retention period
Life of the club account; may be retained longer as club history
Reason
Player of the match and similar honours form part of the club’s permanent record where the club chooses to keep them.
Push notification history
Typical retention period
6 months
Reason
Supports delivery troubleshooting and complaint handling, then serves no further purpose.
Uploaded images (club badges, player photos, media)
Typical retention period
Deleted with the associated record or account
Reason
Images of children in particular should not outlive the record they belong to.
Support enquiries and correspondence
Typical retention period
24 months from closure
Reason
Allows recurring issues to be understood and disputes about advice given to be resolved fairly.
Billing and transaction records
Typical retention period
7 years
Reason
Required by UK tax and company law for accounting records; retained regardless of account closure.
Security logs (infrastructure, access, incident data)
Typical retention period
12 months; longer where an incident is under investigation
Reason
Supports detection, forensic review and any regulatory reporting obligations following an incident.
Website analytics data
Typical retention period
14 months, in aggregated form
Reason
Enables year-on-year comparison of website performance without keeping identifiable visitor records.
Sporting records are treated differently to administrative records. Match statistics, results, awards and achievements form part of a club’s history, and many clubs wish to keep them well beyond the involvement of any individual season. Where a club chooses to preserve these records, Cluboom retains them for the life of the club account, reducing them to the minimum identifying detail needed for the record to make sense. A player or parent can still ask for that information to be reviewed under the Data Subject Rights Policy.
Retention periods are maximums, not targets. Where a shorter period is practical — for example expired invitations or delivered notifications — the information is removed sooner.
4. Club responsibilities
For most information stored in Cluboom, the club is the data controller and Cluboom acts as its processor. The club decides which players, parents, coaches and volunteers are added, what is recorded about them, and when a person should be removed.
Clubs are therefore responsible for:
- removing players, staff and parents who are no longer involved;
- deciding whether to preserve historical sporting records, and telling members that they do so;
- applying any retention requirements imposed by their league, county association or national governing body;
- responding to requests from their members, with Cluboom’s support where needed.
Where a club’s own retention requirement is shorter than the period in the schedule above, the club should tell us and we will apply the shorter period to that club’s data.
5. Data subject requests
Anyone can ask for a copy of their information, ask for it to be corrected, or ask for it to be deleted. How to make that request, and how identity is verified, is set out in the Data Subject Rights Policy.
Deletion requests are considered alongside legal, safeguarding and operational obligations. Information cannot always be erased immediately — for example billing records required by tax law, audit entries evidencing an administrative action, or records connected to an open safeguarding concern. Where a request cannot be met in full, we explain which information is retained, why, and for how long, and we restrict its use to that purpose.
6. Secure disposal
When a retention period expires, information is securely deleted from the production database and associated file storage, or irreversibly anonymised so that it can no longer be linked to an individual.
Encrypted backups are retained on a rolling schedule for disaster recovery. Deleted records may persist in those backups until the backup itself expires; they are not restored into production except as part of a full recovery, and deletions are reapplied where a restore takes place. Disposal is carried out using the same access controls, encryption and logging that protect live data.
7. Policy review
This policy is reviewed at least annually. Retention periods may be shortened or extended before that review following:
- changes in legislation or regulatory guidance;
- operational improvements to how Cluboom stores and archives data;
- security requirements arising from an incident or risk assessment;
- safeguarding requirements, including guidance from national governing bodies.
The version, effective date and review date shown at the top of this document always reflect the current published position.
8. Feedback
Questions regarding this policy can be sent to support@cluboom.co.uk.
Cluboom welcomes responsible feedback that helps improve our governance, security and compliance documentation.
Related Governance Documents
Cluboom maintains a single governance register. Every document in the register is published and publicly available. Browse the full library in the Governance Centre.
- Privacy PolicyCLB-PRIV-001
- Data Processing Agreement (UK GDPR)CLB-DPA-001
- Data Subject Rights PolicyCLB-DSR-001
- Data Retention PolicyCLB-DRET-001This document
- Children’s Data & Parental Consent PolicyCLB-CHILD-001
- Data Protection Impact Assessment (Public Summary)CLB-DPIA-001
- Security PolicyCLB-SECU-001
- Personal Data Breach Response ProcedureCLB-BREACH-001
- Subprocessor RegisterCLB-SUB-001
- Acceptable Use PolicyCLB-AUP-001
- Terms & ConditionsCLB-TERM-001
- Cookie PolicyCLB-COOK-001
- Refund & Cancellation PolicyCLB-REF-001
- Safeguarding & Child Protection PolicyCLB-SAFE-001
Questions about this document? Contact us at support@cluboom.co.uk.
Cluboom is a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079), 24 Brynaeron, Dunvant, Swansea, United Kingdom, SA2 7UX.
