ClubManager Member Software
Get Started

ClubManager — Sub-processors and Third Party Services

1. What this page is

To deliver ClubManager we use a small number of suppliers who process personal data on our behalf. These are our sub-processors. We publish them here so that our customers can meet their own transparency obligations as data controllers.

This page forms part of the Data Processing Agreement at Schedule 3 of our Terms of Service.

2. What this page is not

It does not cover services you choose to connect to your account — see section 5. Nor does it cover any third party to whom you grant access through the ClubManager API; that access is controlled by you.


3. Our sub-processors

We do not use analytics or advertising providers.

Availability monitoring. We use an independent third-party service to monitor whether our servers are reachable. It checks unauthenticated status endpoints that return only whether the service is up. It processes no personal data and holds no access to our systems, so it is not a sub-processor.

A note on messaging. Delivering SMS and WhatsApp messages necessarily involves mobile network operators in the recipient's country. Those carriers are not our sub-processors and are not within our control; our providers' own agreements govern that part of the chain.

3.1 India

For customers in India, all data is hosted on infrastructure located within India. Payments are processed on pages hosted by the payment provider, so card information is not handled by us.

Some processing takes place outside India, and we state this plainly rather than describing the arrangement as entirely in-country:

  • our support team in the United Kingdom accesses the Indian infrastructure to provide support and onboarding;
  • messages are delivered through Twilio, Bird and Meta;
  • support correspondence is held in Zendesk.

Our position under India's Digital Personal Data Protection Act 2023. We apply the same standards to Indian customers as we do under UK GDPR. The club is the Data Fiduciary and we are the Data Processor, acting on its instructions. Section 16 of the Act permits transfer to any country other than those restricted by the Central Government, so the processing described above is permitted. We do not track members and we do not advertise to members, including children.


4. Changes to this list

We give at least 30 days' notice before adding or replacing a sub-processor. An Account Holder may object within that period on reasonable data protection grounds — see paragraph 4.4 of our Data Processing Agreement.

This page carries a "last verified" date at the top. We review it at least annually, and whenever a supplier changes.


5. Payment providers, and how card data is handled

We do not store card details.

Payment providers are chosen by you and connected to your account. They process payment data under their own terms and their own privacy policies.

For most providers, the payment page is hosted by the provider. Card details are entered directly with the provider, which is certified to PCI DSS Level 1, and we never hold them.

Where card information is submitted through a server operated by us, it is passed directly to the payment provider and discarded immediately. It is not retained and is not written to logs.

GoCardless states that it acts as a data controller in its own right for payer and merchant personal data, rather than as a processor. Its own privacy policy applies to that processing.


6. Contact

Questions about this list: [email protected]