Skip to main content

Privacy Policy

Version 2 · effective 7/14/2026

This platform is operated by ClubHelix ("we", "us", "our"). This Privacy Policy explains how we handle personal information across the ClubHelix platform — the platform website, every organisation (club or governing-body) site we host, and the admin tools. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Our two roles

We handle personal information in two distinct capacities:

  • As the platform operator, we collect and hold information about account holders — your account details, subscription and billing records, support requests and platform usage. For this information, we decide how and why it is processed.
  • On behalf of organisations. When a club or governing body records its members' details, publishes content, sells products or runs events on its ClubHelix site, that organisation collects the information and decides why — the organisation is responsible for its members' personal information, including collecting it lawfully and handling enquiries about it. We process it on the organisation's behalf to provide the platform. If you have questions about how a particular club uses your information, contact that club first.

2. What we collect

  • Account information — name, email address, password (stored as a salted hash, never in plain text), optional multi-factor authentication enrolment, and sign-in records. If you sign in with Google, we receive your Google email and basic profile.
  • Member and roster information entered by organisations — such as names, contact details, dates of birth, emergency contacts, membership status and payment status of their members. The organisation controls what is recorded.
  • Billing information — plan, invoices and payment history. Card details are collected and stored by our payment processor (Stripe); we never see or store full card numbers.
  • Transactions on organisation sites — registrations, event tickets and shop orders you place with an organisation, processed through the organisation's connected payment provider.
  • Content and communications — content you or your organisation publish, emails sent through the platform, support correspondence, and consent records (which document accepts what, when, and from which IP address).
  • Technical and usage data — IP address, browser and device information, request logs, error reports and page analytics, used for security, debugging and capacity planning.
  • Push subscriptions — if you opt in to notifications, the endpoint your browser issues for delivering them.

3. How we use personal information

We use personal information to: provide and operate the platform; authenticate you and secure accounts; process subscriptions and payments; send service messages (receipts, sign-in and security notices, and notifications you have opted into); deliver email broadcasts on an organisation's behalf; provide support; monitor, debug and improve the platform; enforce our Terms and protect against fraud, abuse and security threats; and meet our legal obligations.

We do not sell personal information, and we do not use member data to advertise to members.

4. Who we share it with

  • Service providers (sub-processors). We use a small set of providers for hosting, database and storage, payments, email delivery, security and observability. The current list, what each does and what data it handles is published at our Sub-processors page.
  • Your organisation(s). Administrators of an organisation can see the information held in that organisation's roster and records, including activity connected to it (such as orders and registrations with that organisation). Where an organisation belongs to a governing body, limited information may be visible to the parent body according to the platform's access rules.
  • Payment providers. Payments are processed by Stripe (and, where an organisation has connected it, Square) under their own privacy policies.
  • Legal requirements. We may disclose information where required or authorised by law, to enforce our Terms, or to protect the safety of users or the public.
  • Business changes. If our business is restructured or sold, personal information may be transferred as part of that transaction, subject to this policy.

5. Overseas disclosure

We are based in Australia and our primary database is hosted in Australia. Some of our service providers (listed on the Sub-processors page) store or process data in other countries, including the United States. Where personal information is disclosed overseas, we take reasonable steps — including contractual data-processing terms — to ensure it is handled consistently with the APPs.

6. Cookies

We use cookies that are necessary to run the platform — chiefly to keep you signed in and to protect against request forgery. We do not use third-party advertising or cross-site tracking cookies. Blocking essential cookies will prevent sign-in from working.

7. Email and notifications

Service emails (such as receipts and security notices) are sent as needed to operate your account. Broadcast emails sent by organisations through the platform include a one-click unsubscribe link, and your unsubscribe choice is enforced by the platform. Push notifications are entirely opt-in and can be disabled from your account or your browser at any time.

8. Security

We take security seriously: every organisation's data is isolated by database-level access controls (row-level security), traffic is encrypted in transit, passwords are hashed, multi-factor authentication is available and is required for administrative access, payment card data never touches our servers, and we keep audit logs and routine encrypted backups. No system is perfectly secure; if we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.

9. Retention and deletion

We keep personal information for as long as needed to provide the platform and meet legal obligations (for example, financial records must be retained for several years). When an organisation leaves the platform, its data is made available for export and is then deleted or anonymised in line with our retention schedule. You can ask us, or the relevant organisation, to delete information that is no longer required; some records (such as consent and payment records) may need to be retained or anonymised rather than erased.

10. Children

Organisations may record details of members who are minors (for example, junior players). The organisation is responsible for having a parent or guardian's consent to record that information. Platform accounts for people under 18 require parental or organisational consent, as set out in our Terms.

11. Access, correction and complaints

You may ask for access to, or correction of, the personal information we hold about you — email security@clubhelix.au and we will respond within a reasonable time (normally 30 days). Where the information is held in an organisation's roster, we may refer you to, or work with, that organisation. Most details can also be viewed and corrected directly from your account settings.

If you have a privacy complaint, contact us first and we will investigate and respond. If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au.

12. Changes to this policy

We may update this policy as the platform evolves. Material changes will be notified — for example by email or an on-screen notice asking you to re-accept. The current version, with its effective date, is always published at /legal/privacy.

13. Contact

Privacy questions, access or correction requests, and complaints: security@clubhelix.au. General support: support@clubhelix.au.