Legal

Privacy Policy

Last updated: 30 July 2026

1. Who we are

Gaffer App ("Gaffer", "we", "us", "our") operates the website mygaffer.co.uk and the Gaffer progressive web application. We can be reached at info@mygaffer.co.uk.

This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data we collect

Account information

When you create an account we collect your first and last name, email address, phone number, and a hashed password. We do not store your password in plain text. Your phone number is used to contact you about your own sessions and for account recovery — we never share it with other organisers, sell it, or use it for marketing.

We also ask how you heard about MyGaffer, and optionally your city. We use these only to understand where the service is growing; neither is shown to anyone else.

If you sign in with Apple or Google instead, we receive your name and email address from them. Where you choose Apple's Hide My Email, we only ever receive the private relay address Apple generates, never your real one.

Session and squad data

As an organiser you enter information about your football sessions (name, location, date, format) and your squad (player first names, position hints, and skill ratings you assign). This data is stored on your behalf and is controlled by you.

Player RSVP data

When players respond to an RSVP link you share, we record their name (as entered by the organiser) and their attendance status (confirmed, declined, or no-show). Players do not need an account to RSVP.

Payment information

Match fee payments (organisers charging their own players for a session) are processed by Stripe. We never see or store your full card number, expiry date, or CVC. Stripe handles all payment data under their own privacy policy.

Push notification tokens

We treat device push notification tokens as personal data under UK GDPR. Today, if you grant notification permission in your browser, it generates a Web Push subscription token, which we store solely to deliver match alerts, fixture updates, and Player of the Match notifications — never for advertising or tracking. Once native iOS and Android apps are available, the same purpose-limited handling applies to their device tokens (APNs on iOS, Firebase Cloud Messaging on Android). You can revoke permission at any time in your browser or device settings, which stops us receiving any further tokens.

Usage and technical data

We may collect technical information such as your IP address, browser type, and pages visited to help us diagnose errors and improve the service. This data is not linked to your account unless needed to investigate a specific support request.

3. Legal basis for processing

We rely on the following legal bases under UK GDPR:

  • Contract — to provide the service you signed up for, including managing sessions and processing match fee payments.
  • Legitimate interests — to keep the service secure, fix bugs, and send you important service updates.
  • Consent — to send push notifications (you can withdraw consent at any time).
  • Legal obligation — to retain certain financial records as required by law.

4. How we use your data

  • Provide and operate the Gaffer service
  • Process match fee payments via Stripe
  • Send session and RSVP notifications you have opted into
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your personal data. We do not use it for advertising.

5. Third-party processors

We share data only with the following trusted processors, each bound by GDPR-compatible data processing agreements:

ProcessorPurposeLocation
SupabaseDatabase, authentication, and file storageEU / US (SCCs in place)
VercelFrontend hosting and edge infrastructureEU / US (SCCs in place)
StripePayment processing for organiser match feesUS (SCCs in place)
ResendDelivery of transactional email — session invites, verification and password resetsEU / US (SCCs in place)
AppleSign in with Apple authentication, and relaying our emails to Hide My Email addressesEU / US (SCCs in place)
Google / Firebase Cloud MessagingGoogle sign-in, and delivery of native push notificationsUS (SCCs in place)
RailwayHosts our self-hosted WhatsApp connector, which processes group communication metadata for organiser broadcastsEU (SCCs in place)

SCCs = Standard Contractual Clauses, approved by the UK ICO for international data transfers. Firebase Cloud Messaging is used for native app push delivery once the iOS/Android apps are available — Web Push (via Supabase-backed subscriptions) is what powers browser notifications today, with no separate third-party processor involved.

6. Data retention

We retain your data for as long as your account is active. If you delete your account:

  • Your account and squad data are deleted within 30 days.
  • Payment records are retained for 7 years to meet HMRC requirements.
  • Anonymised, aggregated usage statistics may be retained indefinitely.

7. Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data ("right to be forgotten"), subject to legal retention requirements.
  • Portability — receive your data in a machine-readable format.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — for processing based on consent (e.g. push notifications) at any time.

To exercise any of these rights, email info@mygaffer.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).

8. Cookies

We use only essential cookies and local storage required for authentication and session state. We do not use advertising or tracking cookies. No cookie consent banner is required for essential cookies under the UK Privacy and Electronic Communications Regulations (PECR).

9. Security

All data is transmitted over HTTPS. Passwords are hashed using industry-standard algorithms via Supabase Auth. We use row-level security (RLS) so each organiser can only access their own session data.

10. Age requirement & children's data

You must be at least 13 years old to create a Gaffer account. Gaffer is not directed at children, and we do not knowingly collect personal data directly from anyone under 13.

Session organisers sometimes enter details of younger players who play in their squad (e.g. a first name, for RSVP purposes). Where that happens, we follow the UK ICO's Children's Code: we collect the minimum data necessary (typically just a first name and a rating an organiser assigns), we do not track or profile any user, and we never use children's data for advertising. If you believe a child's personal data has reached us other than as described here, contact us and we will delete it promptly.

11. Changes to this policy

We may update this policy from time to time. We will notify you by email or in-app notice if we make material changes. Continued use of Gaffer after changes take effect constitutes acceptance of the updated policy.

12. Contact

For any privacy questions or to exercise your rights, contact us at info@mygaffer.co.uk.