BackTrim Athboy Anglers

Privacy Notice

1. Who We Are

Trim Athboy & District Angling Association ("the Club", "we", "us") is the Data Controller for the personal data described in this policy. We are a voluntary angling association and we process your data to manage club membership and activities.

If you have any questions about how we handle your data, contact us at trimathboyanglers@gmail.com.


2. What Information We Collect

Members

When you become a member, we collect:

  • Full name
  • Email address
  • Phone number
  • Date of birth
  • Postal address
  • Emergency contact details
  • Membership photo (for identification on membership card)

We also collect device information (browser type, operating system) when you access your digital membership card, for troubleshooting purposes only.

Applicants

When you apply for membership, we collect the information you provide on the application form, including your name, contact details, and any referee information if required.

Day Permit Purchasers

When you purchase a day permit, we collect your name, email address, phone number, and payment information (processed securely by our payment provider — we do not store card details).

Website Visitors

Our website uses essential cookies required for the site to function. We do not use tracking or analytics cookies.


3. Why We Collect Your Data (Legal Basis)

Under GDPR Article 6, we process your personal data on the following legal bases:

PurposeLegal Basis
Managing your membershipContract — necessary to fulfil our membership agreement with you
Collecting membership feesContract — necessary to process your membership payment
Sending renewal remindersLegitimate Interest — keeping members informed about their membership status
Membership photo on cardConsent — you provide your photo voluntarily during onboarding
Emergency contact informationVital Interests — for your safety during club activities
Financial record keepingLegal Obligation — tax law requires retention of financial records for 7 years

4. Who We Share Your Data With

We share your data only with service providers who help us run the club. Each provider processes data under a Data Processing Agreement (DPA) or equivalent safeguards.

  • Supabase (EU — Ireland) — database hosting and authentication
  • Vercel (Global, with EU processing) — website hosting
  • Cloudflare (Global) — website security and email routing
  • Stripe (EU) — payment processing. We never store your card details; Stripe handles all payment data under PCI DSS compliance
  • Brevo (EU — France) — email delivery for membership communications
  • Twilio (US, with EU processing) — SMS message delivery
  • Google — Google Wallet pass hosting (name, membership tier, expiry date)
  • Apple — Apple Wallet pass generation (name, membership tier, expiry date)

We also use Sentry for error tracking, which may capture technical error data but is configured to exclude personal information.

We do not sell your data to any third party, and we do not use your data for marketing purposes beyond club communications.


5. Digital Wallet Passes

If you choose to add your membership card to Apple Wallet or Google Wallet, the following information is stored on the pass:

  • Your name
  • Membership tier
  • Membership expiry date
  • Club name and logo

Wallet passes are updated automatically when your membership is renewed. You can remove a wallet pass at any time by deleting it from your device's wallet app. Deleting the pass removes all associated data from the wallet provider.


6. How Long We Keep Your Data

We retain different types of data for different periods, based on legal requirements and legitimate purposes:

Data TypeRetention PeriodLegal Basis
Financial records7 yearsTax law (Taxes Consolidation Act 1997)
Membership records (active)Duration of membershipContract
Membership records (lapsed)2 years after lapseLegitimate interest
Photos (adults)1 year after membership lapseConsent
Photos (juniors)Delete immediately on lapseConsent + Child protection
Rejected applications1 yearLegal protection
Communications log3 yearsDispute resolution
Booking history3 yearsService records

When data reaches the end of its retention period, it is securely deleted or anonymised.


7. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Article 15 — Right of Access: Show me all data you have on me. Time limit: 30 days.
  • Article 16 — Right to Rectification: Fix incorrect data. Time limit: Without undue delay.
  • Article 17 — Right to Erasure: Delete all my data. Time limit: 30 days.
  • Article 20 — Right to Data Portability: Give me my data to take elsewhere. Time limit: 30 days.
  • Article 21 — Right to Object: Stop contacting me. Time limit: Without undue delay.

To exercise any of these rights, contact us at trimathboyanglers@gmail.com. We will respond within 30 days.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Data Protection Commission (DPC), Ireland's supervisory authority:


8. Children's Data

We have junior members who are under 18 years of age. For these members, we apply enhanced protections:

  • Parental consent is required before we process any data for junior members
  • Photos of junior members are deleted immediately when their membership lapses, rather than the standard retention period
  • Junior member data is only accessible to authorised club administrators
  • We collect the minimum data necessary for junior membership

Parents or guardians can exercise data rights on behalf of junior members at any time.


9. Communications

We may contact you through the following channels:

  • Email — membership renewals, receipts, club announcements
  • SMS — urgent notices and time-sensitive communications
  • Push Notifications — sent to your device if you have installed our web app and opted in. You can disable these in your device settings at any time

You can update your communication preferences at any time through your member dashboard, or by contacting the club directly.


10. Our Data Processor

Our membership platform is provided by Tadpole (Tadpole Club Ltd), who acts as a Data Processor on our behalf. Tadpole processes your data only as instructed by the club, under a Data Processing Agreement that ensures GDPR compliance.

Tadpole's role is strictly limited to providing the technical platform — the club remains the Data Controller and makes all decisions about how your data is used.


11. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. The date of the last update is shown at the top of this page.

For significant changes, we will notify members through our usual communication channels.