1. Who is responsible
Clutchhall is operated by legal entity namerequired before launch of registered business addressrequired before launch. For privacy questions, write to privacy contact addressrequired before launch.
Clutchhall is a single-operator service. There is no data protection officer and no privacy team; the operator answers these requests directly.
2. What is collected, and why
This is the whole inventory, not a summary of it. Retention values marked as a working default are the current intended policy and have not yet been confirmed with qualified counsel.
| Data | Purpose | Working minimisation and retention |
|---|---|---|
| Account email, authentication ID, recovery and security events | Sign-in, support, security | Account life, plus a defined closure and security period |
| Display name and community membership | Shared community identity and authorisation | Active community; pseudonymised or deleted under the member request process where feasible |
| Community name and identity | Providing the community its own space | Community life, plus the read-only export period |
| Selections, receipts, scores, standings, corrections | Operating the competition and keeping a trustworthy history | Community life. Visible inside the community, and permanent after the applicable lock |
| Stripe customer, subscription, and invoice references | Entitlement, support, accounting | As long as legal and accounting need requires. No card data is held in Clutchhall |
| IP address, device, and security logs | Abuse prevention, reliability, incident evidence | Working default: 30 days for raw access logs; longer only for documented security evidence |
| Audit and correction records | Integrity and dispute resolution | Working default: 1 year after the competition, then minimised or pseudonymised as obligations allow |
| Support messages | Resolving your request and improving the service | Working default: 1 year after closure, unless evidence or an obligation requires longer |
3. Who processes it
Clutchhall uses a small number of processors, each for one job. Vendor contracts and data-processing terms with all of them are processor agreementsrequired before launch.
- Cloudflare
- Domain, edge delivery, and application hosting. Sees request metadata, including IP address.
- Supabase
- Managed Postgres and authentication. Holds accounts, communities, selections, receipts, scores, and correction records.
- Stripe
- Subscription billing. Handles card details directly; Clutchhall holds only customer, subscription, and invoice references.
- Email delivery
- Sign-in links, invitations, receipts, renewal notices, and correction notices. Sees the recipient address and message content.
- Sports schedule and results provider
- Supplies authoritative kickoff times and official results. Receives no personal data about members.
The processing regions for each of these, and the transfer mechanism where data leaves its region, are processing regions and transfer basisrequired before launch.
4. What Clutchhall never collects
For this launch, Clutchhall does not collect card numbers, contacts or address books, precise location, government identity documents, full dates of birth, private messages, or health and demographic attributes. It has no chat, no direct messages, and no user-uploaded media.
5. What other members can see
Inside a community, other members see your display name, your membership, and — after the applicable lock — your selections, your scores, and your position in the standings. That is the point of the product, and it is not adjustable per member.
Before a lock, nobody sees your selection. Not other members, not commissioners, and not Clutchhall staff through the interface, an API, an export, or a log. Your account email is not shown to other members.
6. Your rights, and the route to them
You can ask us to:
- Access — tell you what we hold about you;
- Export — send you a copy of your data in a portable form;
- Correct — fix something inaccurate, such as a display name;
- Delete — remove your account and identifying data, subject to section 7; and
- Appeal — have a refusal reconsidered, with a reason given in writing.
The route is your account: privacy and your data. We may need to confirm that a request comes from the account holder before acting on it, and we will do that through the account email rather than by asking for a document. Response ownership sits with the operator, and the target response time is rights response timerequired before launch.
7. Deletion against a finished record
A community’s finished results are the shared history of a group of people, not one person’s record, and a competition that silently loses a participant stops being trustworthy for everyone else in it.
So a deletion request removes your identity while leaving the non-identifying result in place. Your account, email, and display name are removed or pseudonymised. The selections, scores, and standings that belong to a finished competition remain, attributed to a former participant rather than to you. Where a competition has not yet locked, the entry itself can be removed.
We will tell you exactly what was removed and what remained, and why, rather than reporting a deletion that was only partial.
8. Backups and deletion propagation
Backups exist so a community’s history survives a failure, which means a deletion cannot be instant everywhere. Deletions are recorded in a deletion ledger, and that ledger is reapplied after any restore, so a restore cannot silently resurrect data you already asked us to remove. Backup ages and the exact propagation window are backup retention schedulerequired before launch.
9. After paid access ends
When a community’s entitlement ends, the community becomes read-only for a working 90-day window so its owner can export its history. See refunds and cancellation for what happens at the end of that window.
10. Analytics and advertising
Clutchhall uses no advertising pixels, no cross-site behavioural profiling, no data sale, and no sensitive-data inference. Analytics are first-party and minimal, kept to what is needed to know whether the product works. Cookies are used to keep you signed in, and to remember choices you make in the interface; there is no advertising cookie.
11. Security
Access to community data is enforced in the database with row-level security, so a request that is not entitled to a row does not receive it. Elevated access is limited to server routines that have already established who is asking and what they may do, and staff break-glass access is rare and attributable.
No system is perfectly secure, and we do not claim otherwise. We will not describe Clutchhall as guaranteed secure.
12. If something goes wrong
If we become aware of a breach of personal data, we will assess it, preserve evidence, escalate to the affected processor, decide on notification under the law that applies, and tell affected customers what happened and what to do. The specific notification thresholds and timelines that apply are breach notification obligationsrequired before launch.
13. Children
Clutchhall is for adults and is not directed to children. We do not knowingly collect data from anyone under 18. If you believe a minor holds an account, write to privacy contact addressrequired before launch and we will restrict the account, keep only what is necessary as evidence, and resolve the data under the approved process.
14. Changes to this notice
We will update this notice as the product and its processors change, and record the date of each change. Where a change materially affects what we collect or how long we keep it, we will give notice before it takes effect.
This draft carries no effective date because Clutchhall holds no production data yet. The version that takes effect will carry one.