Privacy Policy
How we collect, use and protect personal data, and how clubs and families stay in control of theirs.
Last updated: 25 August 2026
1. Who we are
Sweeper (“we”, “us”) provides software that grassroots football clubs use to run their club. The legal entity responsible is [Company legal name], [address], registered with the UK Information Commissioner’s Office under [ICO registration number]. Contact us at [email protected].
2. Controller and processor
When a club uses Sweeper, the club is the data controller for its members’ data and Sweeper is the data processor, handling that data on the club’s instructions. For our own website and account data (for example a person who signs up for a club), Sweeper is the controller. Clubs sign a Data Processing Agreement covering the processor relationship.
3. What data we process
- Account & contact, names, email addresses, phone numbers, roles.
- Membership, player and guardian details, team assignments, availability.
- Children’s data, where clubs manage under-18 players: name, date of birth, and any medical or consent notes the club records.
- Payments, subscription and fee records; card details are handled by our payment providers, not stored by us.
- Usage & technical, device, log and (with consent) analytics data.
4. Children’s data
Youth football necessarily involves children’s data. We apply heightened care: strong isolation between clubs, role-based access so only appropriate people can see sensitive fields, and data-minimisation by default. Clubs are responsible for obtaining any parental consent required and for their own safeguarding policies. See our Children’s data & safeguarding statement.
5. Why we process it (legal bases)
We rely on: performance of a contract (to provide the service), legitimate interests (to run and secure the platform), consent (for optional analytics and marketing), and legal obligation (for example financial and safeguarding records that must be retained).
6. Sharing and sub-processors
We share data only with service providers who help us run Sweeper, for example hosting, email delivery, and payment processing (Stripe, GoCardless). Each is bound by contract to protect the data. Payments are paid directly into the club’s own provider account; we do not take custody of club funds. A current list of sub-processors is available on request.
7. Retention
We keep personal data only as long as needed to provide the service and to meet legal requirements. When a club or account is closed, data is deleted or anonymised, except where we are legally required to retain it (for example certain financial or safeguarding records).
8. Your rights
Under UK GDPR you can request access, correction, deletion, restriction, portability, and can object to certain processing. For club-held data, contact the club; for data we control as a controller, contact us. You can also complain to the ICO (ico.org.uk).
9. Security & international transfers
We use encryption in transit, access controls and tenant isolation to protect data. Where data is processed outside the UK/EEA, we use appropriate safeguards such as the UK International Data Transfer Agreement.
10. Cookies
See our Cookie Policy for how we use cookies and how to change your choices.
11. Changes & contact
We’ll post any material changes here and update the date above. Questions? Email [email protected].