Privacy policy

Last updated: 4 July 2026

1. Who we are

JudoHQ is a free, open-source club management platform for voluntary judo clubs in the United Kingdom, operated from the UK.

For the purposes of UK GDPR, each club (through the individual who registers and administers it) is the data controller for member data entered into the platform, and JudoHQ acts as a data processor on the club's behalf. For platform-level account data — your login credentials and the service emails we send to operate the platform — JudoHQ is the data controller. The platform operator can be contacted for all data protection matters at privacy@judohq.co.uk (see section 13).

2. Data we collect

We collect and process the following categories of personal data:

  • Club administrator data: name, email address, and password provided during club registration.
  • Member data: name, email, date of birth, grade/belt level, BJA membership number, address, emergency contact information, and attendance records — added by club administrators or provided by members during sign-up.
  • Medical data (special category): optional medical notes (e.g. allergies, conditions, medication) that you, a parent/guardian, or a club administrator may record so coaches can keep members safe during training. This is special-category data under UK GDPR and is only collected with explicit consent (see section 4).
  • Account data: login credentials, session tokens, and activity logs.
  • Payment and billing data: transaction amounts, payment status, Stripe payment identifiers (we never store card numbers), refund request reasons, and membership billing history. Processed to fulfil your club membership and event fees.
  • Safeguarding data: incident (injury) reports and behaviour/welfare reports recorded by club staff, which may include the names of those involved, descriptions of what happened, and any treatment or follow-up.
  • Club email data:when someone emails a club's address (e.g. yourclub@judohq.co.uk) we record message metadata — sender, recipient, subject, and delivery outcome — so the club can audit its mail routing. Message bodies are forwarded to the club's configured mailbox and are not stored by JudoHQ (see sections 5 and 7).
  • Feedback you submit: messages sent through the in-app feedback button or the Judo Helper (AI) thumbs-up/thumbs-down controls — the topic you pick, an optional rating, your message, the page you were on, and your browser type. This goes to the JudoHQ platform developer (not your club) to improve the service.
  • Technical and security data: IP addresses and request information used for rate limiting and security monitoring. Rate-limiting counters are short-lived and expire automatically. We do not collect analytics or tracking data.

3. How we use your data

We use personal data to:

  • Provide and operate the JudoHQ club management platform
  • Manage club memberships, gradings, competitions, and attendance
  • Keep members safe — recording injuries, welfare concerns and (with explicit consent) medical information so clubs can meet their safeguarding and duty-of-care obligations
  • Process payments and refunds for memberships, gradings, competitions, and shop purchases
  • Send notifications that club administrators or members have opted into
  • Maintain platform security and prevent fraud
  • Comply with legal obligations

5. Data sharing

We do not sell or rent personal data to third parties. We may share data with:

  • Hosting (OVH): the platform and its database are self-hosted on our own virtual private server provided by OVH, located in the UK/EU. Your data is not stored on third-party cloud application platforms, other than the payment and email providers described below.
  • Stripe (payment processing) for membership, grading, competition, and shop payments. We do not store card numbers — payments are completed on Stripe-hosted checkout pages. See section 6 for Stripe Connect and international transfers.
  • Resend (email delivery) to send transactional emails (account verification, membership and payment confirmations, renewal reminders sent 14 and 3 days before a membership expires, and notifications). We share only the recipient email address and the message content. Resend also receives email sent to club addresses (e.g. yourclub@judohq.co.uk), which we forward to the club's configured mailbox — JudoHQ keeps message metadata only, never the message body. Resend is a US-based provider, so email data passes outside the UK — see the international transfers note in section 7.
  • No AI provider: we do not share any data with third-party AI companies. The optional Judo Helper (AI) runs entirely on our own self-hosted infrastructure — see section 11.
  • Club administrators: member data is visible to the administrators of the club the member belongs to, including refund requests and reasons you submit.
  • National governing body (British Judo Association): your club may share member details — name, date of birth, BJA licence number and expiry, grade, and (for juniors) a guardian's contact details — with the British Judo Association or its affiliated bodies for licensing, insurance, and grading purposes. This is part of running an affiliated judo club, so the club relies on its legitimate interests and the necessity of performing your membership. It is an ordinary administrative disclosure only — no health or medical data is shared this way — and each export is logged by the club.
  • Legal authorities: if required by law, regulation, or legal process.

6. Payments and Stripe Connect

JudoHQ uses Stripe to process payments. Your club may receive payouts in two ways:

  • Stripe Connect (recommended):your club connects a bank account via Stripe Express onboarding in Dashboard → Settings → Payments. Members pay your club directly; Stripe handles identity verification, card processing, and payouts to your club's bank account. JudoHQ stores only a Stripe account identifier and payment status flags — not bank details.
  • Legacy platform billing: until Connect is complete, some clubs may process payments via the JudoHQ platform Stripe account. Payout arrangements for legacy clubs are managed by the platform operator.

Payment-related data we process includes transaction amounts, payment status, Stripe payment identifiers, refund request reasons, and membership billing history. We retain payment audit records for as long as needed to operate the service, resolve disputes, and meet legal obligations.

Stripe is an independent data controller for payment processing. Payment data may be transferred outside the UK/EEA (including to the United States) under Stripe's safeguards. See Stripe's Privacy Policy for details. Club administrators who enable Connect also accept Stripe's Connected Account Agreement during onboarding.

7. Data storage, security and retention

Data is stored on our own self-hosted infrastructure — a virtual private server provided by OVH and located in the United Kingdom and European Economic Area. We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, row-level access controls that isolate each club's data, and regular security reviews.

International transfers. Your data is stored in the UK/EU and we do not transfer it outside the UK, with two limited exceptions: Stripe (payments — see section 6) and Resend(email delivery), both of which are US-based and may process data in the United States. These restricted transfers are safeguarded by appropriate measures under Articles 44–46 UK GDPR — the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as set out in each provider's data processing terms.

Retention. We keep personal data only for as long as necessary for the purposes described in this policy:

  • Account, profile and membership data: retained while your account is active. When an account is deleted or an erasure request is completed, we delete or irreversibly anonymise your personal data. Where an account simply lapses, we retain it for up to 24 months after your last membership ends (so returning members can rejoin easily), then delete or anonymise it.
  • Members deleted by a club administrator:when a club administrator deletes a member, that member's access to the club ends immediately and their personal data is permanently deleted 7 dayslater. During those 7 days the club can reverse the deletion — this short window exists so that a deletion made in error (for example, the wrong person picked from a list of similar names) does not destroy a member's records. Nothing is disclosed to anyone new during the window, and the data is still covered by every right described in section 8: a subject access request made in that period still returns the data, because we still hold it. This window does not apply where you ask us to erase your data — a request you make yourself (through your account settings or as an erasure request) is actioned without this delay, and a club administrator actioning your request on your behalf can also erase your data immediately.
  • Club records deleted by a club administrator: when a club administrator deletes something the club manages — a training session, an announcement, a shop item, a syllabus technique, a draft event — that record is removed from the app straight away and held, unreadable to everyone, for 7 days so the club can undo a mistake. Where such a record has your personal data attached (most often the attendance register of a deleted session, or a technique sign-off), that data is held for the same 7 days and then permanently deleted. The purpose is protective: before this, deleting a session in error destroyed its whole register with no way back. During the window nothing is disclosed to anyone new, a subject access request still returns the data because we still hold it, and an erasure — yours or one made on your behalf — removes you from these held records immediately and is verified to have done so.
  • Payment and accounting records: retained for 6 years to meet UK tax and accounting obligations (HMRC). This retention is processing under a legal obligation — Article 6(1)(c) UK GDPR — so the right to erasure does not extend to deleting these records (Article 17(3)(b)). Where you exercise erasure, they are instead retained in anonymised form: your name and email address are removed from retained invoices and credit notes, and other personal identifiers are stripped from payment records, while the financial details (amounts, dates and document numbers) are kept for the remainder of that period.
  • Incident and safeguarding reports:retained in line with UK safeguarding guidance and are not deleted when an account is erased. Reports involving a child are kept at least until that person's 25th birthday; reports involving adults are kept for at least 7 years from the date of the report, then reviewed for deletion.
  • Signed club agreements (risk acknowledgment): when you (or a parent/guardian on a child's behalf) e-sign a club's risk-acknowledgment and club-agreement document, we keep the signed record — the document version and its content fingerprint, the typed name, who signed and in what capacity, the date and time, and technical signing details (IP address and browser) — as evidence for the establishment, exercise or defence of legal claims (Article 6(1)(f) UK GDPR). Because claims can lawfully be brought years later (Limitation Act 1980), these records are kept for at least 7 years after your membership ends, and where the record concerns someone who signed (or was signed for) as a child, at least until that person's 21st birthday, then reviewed for deletion. The right to erasure does not extend to deleting these records (Article 17(3)(e)); on erasure the record is unlinked from your account but the signed record itself is kept for the remainder of the period.
  • Judo Helper (AI) audit metadata: retained for up to 90 days for safeguarding review, then automatically deleted. Chat message bodies are never stored (see section 11).
  • Club email metadata: the routing record for each message sent to a club address (sender, recipient, subject, delivery outcome — never the message body) is retained for up to 12 months, then deleted.
  • Data-request records: the log of your export and erasure requests (who asked, when, and the outcome) is retained for 6 years as evidence of our UK GDPR compliance.
  • Verification and password-reset tokens: stored only as a cryptographic hash and short-lived — email verification tokens expire after 24 hours and password-reset tokens after 1 hour; they are deleted once used or expired.
  • Backups: the database server that holds your personal data is backed up automatically by our hosting provider (OVH, UK/EU) on a short rolling daily cycle — each backup covers the previous 24 hours and is replaced as the cycle rotates. The application server, which holds very little personal data (short-lived security counters and operational logs), is backed up daily to a backup server on our own private infrastructure and those backups are rotated on a fixed schedule. Backups exist only for disaster recovery and are never used for any other purpose. When you exercise your right to erasure we delete your data from live systems straight away; copies in backups expire as the backup cycles above rotate, and if a backup ever had to be restored we would re-apply completed erasure requests.
  • Security counters: rate-limiting and session counters are held in memory only and expire automatically within hours.

8. Your rights

Under UK GDPR, you have the right to:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate or incomplete data
  • Erasure:request deletion of your personal data (“right to be forgotten”). Records we are legally required to keep — invoices, credit notes and other accounting records (Article 6(1)(c) UK GDPR / HMRC rules) and safeguarding reports — are not deleted but are anonymised or retained under those legal bases, as described in section 7
  • Restriction: limit how we process your data
  • Portability: receive your data in a structured, machine-readable format
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: withdraw consent at any time where processing is based on consent

You can exercise the most common rights directly from your account: Dashboard → Profile lets you download a machine-readable copy of your data (portability) and request account deletion (erasure). Requests are logged and actioned by your club administrator through a data-request queue, subject to the retention obligations in section 7 (for example, anonymised accounting records).

To exercise any other right, or if you cannot access your account, contact your club administrator or email us at the address below. Exercising your rights is free of charge, and we (or your club, as controller) will respond within one calendar month of receiving your request.

If you are unhappy with how your data has been handled, you have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; helpline 0303 123 1113; ico.org.uk/make-a-complaint. We would appreciate the chance to resolve your concern first, but you can go to the ICO at any time.

9. Cookies

We use essential cookies only — to keep you logged in and remember your preferences. We do not use analytics, advertising, or any third-party tracking cookies. See our Cookie policy for full details.

10. Children's data

JudoHQ is used by clubs with junior members. Anyone under 18 cannot create their own account— the sign-up flow blocks this and directs them to a parent or guardian. A junior's record is created and managed by a parent/guardian (from Dashboard → My children) or by a club administrator, and the junior does not have their own login.

Parental or guardian consent is required before a junior's data is processed, and separately before a junior may use the Judo Helper (AI). We design the platform in line with the ICO's Age Appropriate Design Code: we collect only the minimum data needed to run the club, settings default to the highest level of privacy, and we nevershow advertising, profile children, use their data for marketing, track their location, or use nudge techniques to encourage them to share more data. Children's data is processed in accordance with the UK GDPR and the Data Protection Act 2018.

If you are under 18 — the short version

Your parent or guardian (or your club) looks after your judo record — things like your name, belt and which sessions you came to. We only use it to run your club. We never sell it, never show you adverts, and never share it with anyone who doesn't need it. If something worries you about your information, tell your parent, guardian, or your club's welfare officer, and they can ask us to help.

11. Judo Helper (AI)

The optional Judo Helper is an AI assistant that answers questions about official British Judo rules and club services. It is off by default until your club administrator enables it. Members (and parents/guardians for juniors) must give separate consent before use.

  • What we send: your question, your grade band only (not your name or contact details), and excerpts from official public documents. Before processing, we automatically remove common personal identifiers from your question — email addresses, phone numbers, dates (including dates of birth), BJA licence numbers and postcodes. This automatic filter cannot reliably detect free-text details such as names or street addresses, so please avoid typing them into the helper; anything you do type is still processed only on our own local server and is never stored or sent to any third party.
  • Processing: answers are generated by a language model running on our own self-hosted infrastructure. Your questions are not sent to any third-party AI provider.
  • What we do not store: chat message bodies are not persisted. We keep minimal audit metadata (intent, tools used, retrieved document IDs) for up to 90 days for safeguarding review.
  • Safeguarding: messages indicating abuse or self-harm are not sent to the AI — you receive a static response with welfare contacts.
  • Your rights: you can withdraw AI consent at any time in your profile settings, or ask your club to disable the feature.

12. Changes to this policy

We may update this policy from time to time to reflect changes to the platform or the law. We will notify registered club administrators by email of any material changes before they take effect, and the “last updated” date at the top of this page will always show the current version.

13. Contact us

If you have questions about this privacy policy or wish to exercise your data rights, please contact your club administrator or email us at privacy@judohq.co.uk.