1. Who we are and what this policy covers
ClubStreak is a product of EarlyDot Tech Private Limited (“ClubStreak”, “we”, “us”). ClubStreak is the name the product is sold and supported under, and EarlyDot Tech Private Limited is the company behind it: the company you contract with, the company that bills you, and the company responsible for the personal data described in this policy. Its registered office is at No 9, 2nd Floor, 27th Main, 100 Feet Ring Road, BTM 1st Stage, Bengaluru, Karnataka 560068, India.
ClubStreak is a platform that helps sports and skill academies run their day to day, and gives the students who train at those academies an app of their own for schedules, attendance, fees, events, announcements and their training records.
This policy applies to:
- Academy users: owners, coaches and staff of the academies that use ClubStreak (“Academies”).
- Members: adult students who train at an Academy, and the parents or guardians who hold an account and manage a student’s profile (“Guardians”).
- Visitors: people who browse our website, view a public academy page, send an enquiry to an academy, or register for a public event.
A ClubStreak account is held by an adult. You must be 18 or over to create or use a ClubStreak account, and the Service is not directed to children. Where a student is under 18, their parent or guardian holds the account and manages the student’s profile. Section 7 explains how we handle information about a student under 18.
It covers the ClubStreak mobile application, the ClubStreak web application and our website (together, the “Service”). ClubStreak is offered in India, the European Union and United Kingdom, and the United States including California. Sections 12 to 14 set out the rights that apply in each. Where local law gives you stronger rights than this policy describes, local law wins.
2. The three relationships
Who is responsible for your data depends on which relationship it sits in. There are three, and the distinction matters because it decides who you ask for what.
(a) You and ClubStreak
For your account, for operating and securing the platform, for the public academy directory and enquiries, for platform-level payment processing and the legal obligations that come with it, and for reviews, ClubStreak decides how and why data is processed. Here we are a data controller (GDPR), data fiduciary (India’s DPDP Act) or business (California’s CCPA).
(b) You and your Academy
When an Academy manages its students on ClubStreak (rosters, attendance, the fees it sets, coach notes, answers to enrollment questions it configures, the training records it maintains, announcements it publishes), the Academy decides how and why that data is processed. The Academy is the controller or data fiduciary, and ClubStreak processes it on the Academy’s behalf as a processor or service provider. Our contract with every Academy, the Academy Data Processing Addendum, restricts what we may do with it.
(c) The student and their own record
A student’s training record belongs to the student. Who can see it is controlled by the student, or by their Guardian where the student is under 18, and we keep a record of every change to those settings. We process it on their instructions.
If you have a question about data an Academy holds about you, you can go to the Academy directly, or come to us and we will pass the request on and help.
3. Personal data we collect
We collect what the Service needs to work, and not more.
3.1 Account data
- Mobile phone number, which is how you sign in.
- First and last name.
- Profile photo, if you add one.
- Sign-in records: one-time codes stored only as hashes and only briefly, verification status, last sign-in time and session records.
3.2 Student profile data
Provided by a Guardian, by an adult student about themselves, or by the Academy:
- Name, date of birth, gender.
- Contact email and address, where provided.
- School attended, where provided.
- Emergency contact name, phone number and relationship, where provided.
- Profile and cover photos, where provided.
- Answers to enrollment questions configured by the Academy. Academies decide what to ask; our terms require that anything mandatory is limited to what enrollment genuinely needs.
The Service has no health field. There is no medical or allergy field anywhere in it, and an Academy cannot add one: enrollment and event questions that ask for health details are refused. Academies that need medical information about a student keep it in their own records, outside the Service.
We ask Academies and Guardians not to put health details into free-text fields either, such as the note attached to a “cannot attend” message. Anything written there is treated as ordinary free text: it is shown only to the Academy it was sent to, is not used for anything else, and is deleted with the record it belongs to.
3.3 Guardian relationships
Which accounts are linked as Guardians of which student profiles, including where a second Guardian is linked to the same student.
3.4 Attendance and scheduling
Class schedules and sessions, attendance marks including self check-in by scanning a code at class, absence notices a Member sends, and holiday or closure records.
3.5 Training records
Records an Academy’s coaches maintain about a student’s training: assessments of skill and progress, coaching notes, achievements and participation history. Students and Guardians can see this record, control who else can see it, and share it through a private link that can be revoked or set to expire. We keep an append-only log of visibility and consent changes, so there is always an answer to who allowed something, and when.
3.6 Class feedback
Members may rate a class and leave a short comment. Ratings and comments are shown to the Academy without the student’s name attached. We store the link to the account so the Member can manage their own data; we do not show it to the Academy.
3.7 Payments
- For Members: fees due and paid, amounts, dates, payment method, billing period, receipts and receipt numbers, refunds and payment reminders.
- Online payments are handled by regulated payment providers (Section 8.3). We never receive or store card numbers, UPI PINs or banking credentials of Members. We receive confirmation that a payment succeeded, and a reference.
- Where an Academy records a cash or offline payment, we store the record it enters, which may include a receipt image.
3.8 Academy business and settlement data
For Academy owners who enable online payments:
- Business details: legal name, address, contact email, GSTIN.
- Settlement details: account holder name, bank account number and IFSC, and PAN. Bank account numbers and PAN are stored encrypted, and only masked values are ever shown in the app.
- Verification (KYC) status and results from our payout partner, and the time and version of the consent given when these details were submitted.
This can relate to an identifiable person, for example a sole proprietor, and is treated as personal data when it does.
3.9 Content you create
Posts, announcements, event descriptions, comments, photos and videos you upload, and reviews you write about an Academy. Reviews carry your name and are public on that Academy’s page.
3.10 Enquiries
If you send an enquiry to an Academy from its public page: your name, phone number, an optional message, and optionally the age of the student you are enquiring for. Section 8.2 explains what happens to it.
3.11 Technical data
- Push notification token, device platform, device identifier and app version, used only to deliver the notifications you turned on.
- Server logs including IP address, timestamps and which endpoint was called, used for security, debugging and preventing abuse.
- Notification delivery records and your notification preferences, including quiet hours.
3.12 What we do not collect
- No location. The app never asks for location permission. When a coach types a venue address, the device’s own map service turns that text into coordinates.
- No contact list, no photo library scanning (you pick individual photos yourself), no microphone.
- No advertising identifiers, and no cross-app or cross-site tracking. We do not follow you around other companies’ apps or websites, and there is no third-party advertising software in ours. Section 4.1 explains how advertising inside ClubStreak works.
- No biometric data, and no passwords, because we sign you in with a code sent to your phone.
4. Purposes and legal bases
| Purpose | Data used | GDPR legal basis | DPDP basis |
|---|---|---|---|
| Creating and securing your account, signing you in | 3.1, 3.11 | Contract (Art. 6(1)(b)); legitimate interests for security (6(1)(f)) | Consent; legitimate use for security |
| Running the Academy relationship: rosters, schedules, attendance, fees, announcements, events | 3.2 to 3.7 | Processor acting on the Academy's instructions | Processing on behalf of the Academy |
| Maintaining the training record and its sharing controls | 3.5 | Contract; consent for sharing beyond the default audience | Consent |
| Processing payments; tax and accounting duties | 3.7, 3.8 | Contract; legal obligation (6(1)(c)) | Legitimate use (compliance with law) |
| Verifying an Academy's identity for settlement | 3.8 | Legal obligation; contract | Legitimate use (compliance with law) |
| Delivering notifications you turned on | 3.11 | Contract; consent for optional categories | Consent |
| Public academy pages, enquiries and reviews | 3.9, 3.10 | Consent; legitimate interests in a trustworthy directory | Consent |
| Security, fraud prevention, service integrity | 3.11, audit logs | Legitimate interests | Legitimate use |
| Complying with law and lawful requests | As required | Legal obligation | Legitimate use |
4.1 Advertising
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. No advertising network, data broker, social media platform or other third party receives personal data from us for advertising, and there are no third-party advertising tags or pixels in the Service.
We may show advertising inside ClubStreak, and some of it may be matched to your interests. Where we do, it works like this.
- We build and serve it ourselves. Campaigns run through our own campaign system. Deciding which advertisement to show happens on our servers, using data we already hold as controller. Nothing is delegated to an advertising network.
- The advertiser never receives you. An advertiser describes the audience it wants to reach and we do the matching. It receives aggregate results, for example how many people saw or responded to a campaign. It does not receive your identity, your contact details, your data, or any list or segment from which you could be identified.
- We use a limited set of signals, being your account details, the disciplines, academies and events you look at or follow on ClubStreak, and your city.
Four things are never used to target advertising, in any circumstances:
- Anything about a student under 18. Section 9(3) of India’s DPDP Act prohibits targeted advertising directed at children, and we apply that everywhere we operate rather than only in India.
- Anything that would count as special category or sensitive personal information. The Service has no health field (Section 3.2), and nothing in this category is used for advertising.
- The records an Academy keeps about its students, meaning attendance, fees, coach notes and training records. We hold those on the Academy’s behalf as its processor, and a processor may not repurpose a controller’s data for its own ends. See Section 2(b) and the Academy Data Processing Addendum.
- Payment, settlement and identity verification details (Sections 3.7 and 3.8).
Your control
- You can turn interest-based advertising off at any time in your settings. You may still see advertising, but it will not be matched to your interests.
- In the EEA and the UK, we ask for your consent before using your data to personalise advertising, and you can withdraw it at any time. You also have an absolute right under Article 21(2) of the GDPR to object to direct marketing, including any profiling connected with it, and we act on such an objection immediately.
- In India, we rely on your consent, which you may withdraw as easily as you gave it.
- In California, because no third party is involved, this is neither a sale nor a share, so there is nothing to opt out of on that basis. You can still switch personalisation off, and we honour Global Privacy Control signals as described in Section 14.
If we change how advertising works, in particular if a third party were ever to be involved in delivering it, we will update this policy and tell you before that happens, and we will ask for your consent where the law requires it.
5. Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects. Reminders, summaries and trends shown to an Academy are informational. Decisions, for example about enrollment or fees, are made by people at the Academy.
6. How long we keep data
| Category | Retention |
|---|---|
| Account data | Until you delete your account, plus the 30-day grace period below |
| One-time sign-in codes | Stored hashed, valid for minutes, deleted automatically after use or expiry |
| Student profile, attendance and training records | While the profile exists; see deletion below |
| Payment and settlement records | Kept after account deletion where tax, accounting and payment law require, for up to 8 years |
| Enquiries | Until resolved or deleted on request; the Academy keeps its own copy (Section 8.2) |
| Server logs | 90 days |
| Push notification tokens | Until you sign out, remove the app, or the token stops working |
| Encrypted backups | Residual copies expire within 35 days |
Deletion
You can delete your account, a student profile you manage, or an Academy you own, from inside the app. Deletion takes effect after a 30-day grace period during which it can be cancelled, and your session is ended immediately when you request it. After the grace period, personal identifiers are removed or irreversibly scrambled, and files such as photos are deleted from storage.
Records we are legally required to keep, such as payment records, are retained in a form that no longer identifies you wherever the law allows. Content you posted into shared spaces may remain visible without your name attached.
7. Students under 18
Nobody under 18 uses ClubStreak. The Service is not directed to children, and a person under 18 may not create an account, sign in, post or otherwise use it. If we learn that an account has been created by someone under 18, we close it and delete the data associated with it.
We do hold information about students who may be under 18, because that is who academies teach. That information reaches us in one of two ways, and an adult is responsible for it either way:
- a parent or guardian enters it on the student’s profile from their own account; or
- the Academy the student is enrolled with enters it, under its own responsibilities.
Because that information concerns a minor, we apply extra protections:
- Consent comes from the parent or guardian. Before information about a student under 18 is processed, we require the consent of the parent or guardian responsible for that student, in the way applicable law requires, including Section 9 of India’s DPDP Act. Academies are contractually required to hold that consent for information they enter.
- No tracking, no advertising, no profiling. We do not monitor a student’s behaviour for any purpose beyond providing the Service itself. Section 9(3) of India’s DPDP Act prohibits behavioural monitoring and targeted advertising directed at children, and we treat that as a hard line: whatever we do in future, advertising will never involve students under 18.
- No health field. The Service does not ask for medical or allergy details about a student, and an Academy cannot add a question that does. An Academy that needs those details keeps them in its own records.
- Nothing about a student is shared by default. Making a training record visible beyond the student, their Guardians and their Academy takes a deliberate choice, which can be reversed, and every such change is logged.
- The guardian stays in control. A parent or guardian can see, correct, export or delete everything on a student’s profile, and can withdraw consent at any time.
If you believe information about a student has reached us without the right consent, or that someone under 18 has created an account, write to legal@clubstreak.com and we will act promptly.
9. International transfers
Our infrastructure runs in the United States and Europe, and hosting locations may change as the Service evolves. Some of the providers in Section 8.3 also process data in other countries. Where data of EEA or UK users leaves the EEA or UK, we rely on an adequacy decision or on Standard Contractual Clauses with supplementary measures. Data of Indian users is transferred only to countries not restricted by the Central Government under Section 16 of the DPDP Act.
10. Security
- All data is encrypted in transit and at rest.
- Sensitive financial information is protected with an additional layer of encryption, and only masked values are displayed.
- Sign-in codes are stored only as hashes, expire quickly, and are rate limited.
- Access inside an Academy is permission based: staff see only what their role allows, and permission changes are written to an audit log.
- Private share links are stored hashed, can be revoked, and can be set to expire.
No system is perfectly secure. If a breach affects you we will notify you and the relevant authority as the law requires, including the Data Protection Board of India and supervisory authorities under the GDPR.
11. Your rights
Wherever you are, you can:
- Access the data we hold about you and get a copy.
- Correct anything inaccurate or incomplete. Most profile data is editable directly in the app.
- Delete your account, a student profile you manage, or an Academy you own, from inside the app, subject to records the law makes us keep.
- Withdraw consent for anything based on it, such as optional notifications or sharing a training record beyond its default audience. Withdrawing is as easy as giving it, and takes effect going forward.
- Object to or restrict processing we base on legitimate interests.
- Take your data with you, in a structured, machine-readable format.
Use the controls in the app, or write to legal@clubstreak.com. We verify the request, normally by confirming control of the account’s phone number, and reply within the time the law allows: one month under the GDPR, 45 days under the CCPA, and the period set by the DPDP rules. We will never treat you differently for exercising a right. A Guardian may exercise these rights for a student under 18, and an authorised agent may act for you where local law permits.
12. Additional information for India (DPDP Act, 2023)
- ClubStreak is the data fiduciary for the processing in Section 2(a), and a data processor for Academies as described in Section 2(b).
- Grievance Officer: legal@clubstreak.com. We acknowledge and resolve grievances within the timelines the Act and its rules prescribe.
- You have the rights to access, correction, completion, updating and erasure, to grievance redressal, and to nominate another person to exercise your rights if you die or are incapacitated.
- If our answer does not satisfy you, you may complain to the Data Protection Board of India.
- Consent requests are written in clear, plain language.
- No one under 18 may hold an account. Where we process information about a student under 18, we do so on the consent of their parent or guardian, and never for tracking, behavioural monitoring or targeted advertising, as Section 9(3) requires. That limit is absolute and is not contingent on anything we do later.
13. Additional information for the EEA and UK (GDPR)
- Controller: EarlyDot Tech Private Limited, the company behind ClubStreak, No 9, 2nd Floor, 27th Main, 100 Feet Ring Road, BTM 1st Stage, Bengaluru, Karnataka 560068, India.
- Legal bases are in Section 4. Where we rely on legitimate interests you may object at any time.
- You may complain to your local supervisory authority, though we would rather have the chance to put things right first.
14. Additional information for California (CCPA/CPRA)
Notice at collection
In the last 12 months we collected the categories in Section 3, which map to the CCPA categories as follows: identifiers (3.1, 3.2, 3.10, 3.11); customer records (3.2, 3.7, 3.8); protected classifications (age and gender, where provided); commercial information (3.7); internet or network activity (3.11, limited to our own service logs); audio and visual information (photos and videos you upload); and sensitive personal information (account log-in together with its security code, and government identifiers submitted by Academy owners for settlement verification). Sources, purposes and retention are in Sections 3, 4 and 6.
- We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16. Advertising we show inside ClubStreak is first-party: we select and serve it ourselves and disclose no personal information to the advertiser, so it is neither a sale nor a share as the CCPA defines those terms. Section 4.1 sets this out in full.
- The Service is not directed to children and is not intended for use by anyone under 18, so we do not knowingly collect personal information from a child. Where we hold information about a student under 18, an adult provided it, as described in Section 7.
- Sensitive personal information is used only for purposes the CCPA regulations permit without a right to limit, namely providing the Service, security and verification. It is never used to infer characteristics about you and never used to target advertising (Section 4.1). If that ever changes we will update this notice and offer the right to limit.
- You have the rights to know, delete and correct, to opt out of sale or sharing (we do neither, so there is nothing to opt out of on that basis; you can still turn off interest-based advertising in your settings), and to non-discrimination. Submit requests in the app or at legal@clubstreak.com.
- We honour Global Privacy Control signals. Because we neither sell nor share personal information, such a signal confirms the position the Service is already in; we additionally treat it as a request to turn off interest-based advertising, and act on it accordingly.
- Categories disclosed for a business purpose in the last 12 months are those in Sections 8.1 to 8.3, to the recipients named there. None were sold or shared.
15. Changes to this policy
We will post changes on this page and update the date at the top. If a change materially affects how we handle your data we will tell you in the app or by the contact details on your account before it takes effect, and where the change needs fresh consent we will ask for it.
16. Contact
EarlyDot Tech Private Limited
No 9, 2nd Floor, 27th Main, 100 Feet Ring Road, BTM 1st Stage, Bengaluru, Karnataka 560068
Privacy questions and requests: legal@clubstreak.com
India Grievance Officer: legal@clubstreak.com.