Privacy Policy
1. Introduction
BoatSched ("we", "our", "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our boat booking management platform, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
2. Data Controller
BoatSched is the data controller responsible for your personal data. If you have any questions about this policy or our data practices, please contact us using the details in the Contact section below.
3. Information We Collect
We may collect and process the following personal data:
- Identity Data: Name, username, date of birth.
- Contact Data: Email address.
- Profile Data: Weight, stroke side preference, sculling proficiency ratings, role within your rowing club.
- Usage Data: Booking history, boat usage records, damage reports, login timestamps.
- Technical Data: IP address, browser type and version, time zone, operating system, and device information.
- Communications Data: Any correspondence you send to us via our contact form or email.
4. Lawful Basis for Processing
Under the UK GDPR, we rely on the following lawful bases:
- Contract: Processing is necessary for the performance of our service agreement with you and your rowing club (Article 6(1)(b)).
- Legitimate Interests: Processing is necessary for our legitimate interests, such as improving our services and ensuring platform security, provided these do not override your rights (Article 6(1)(f)).
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose, such as marketing communications (Article 6(1)(a)).
- Legal Obligation: Processing is necessary to comply with a legal obligation (Article 6(1)(c)).
5. How We Use Your Data
- To provide and maintain the BoatSched platform and its features.
- To manage your account, bookings, and club membership.
- To communicate with you about your account, bookings, and service updates.
- To improve our platform and develop new features.
- To ensure the security and integrity of our platform.
- To comply with legal obligations.
6. Data Sharing
We may share your personal data with:
- Your Rowing Club: Club administrators and coaches may view member profiles, booking data, and damage reports as necessary for club management.
- Service Providers: Third-party providers who assist us in operating our platform (e.g., hosting, email delivery), bound by contractual obligations to protect your data.
- Legal Requirements: Where required by law, regulation, or legal process.
We do not sell your personal data to third parties.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. When your data is no longer required, it will be securely deleted or anonymised.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
9. Your Rights
Under the UK GDPR, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data in certain circumstances.
- Right to Restrict Processing: Request limitation of processing in certain circumstances.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us using the details below. We will respond within one month of receiving your request.
10. Cookies
BoatSched uses essential cookies required for the platform to function (e.g., session authentication). We do not use advertising or tracking cookies. By using our platform, you consent to the use of essential cookies in accordance with PECR.
11. International Transfers
Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the Information Commissioner's Office (ICO), to ensure an adequate level of protection for your data.
12. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection. You can contact the ICO at ico.org.uk or by telephone on 0303 123 1113.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us or email us at privacy@boatsched.com.