← Back to Troop

Privacy Policy

Last updated: 28 September 2026

1. Who is responsible for your data

Your activity club ("the Club" — e.g. a swim school) is the data controller for information about you and your child: it decides what to collect and why, and is who you should contact first about a specific booking, medical note, or family record.

Troop, provided by My Task Master Ltd, company number 16878946, Flat 93 March Court, Warwick Drive, London SW15 6LD, is the data processor— we hold and process data only on the Club's instructions, via this software. For a narrow set of things Troop decides itself (account security, billing records, this website), Troop is also a controller in its own right.

2. What data we hold

In line with our data-minimalism principle, Troop deliberately holds less than most platforms in this space. Specifically:

  • About a child: first name, date of birth, and one optional free-text "essential information" field (e.g. allergies). No surname — our database physically refuses to store one for a child.
  • About an adult member (clubs running adult teams): first name, surname, email address, and the same optional "essential information" field. Adult members hold their own account, so unlike a child they are identified in full.
  • Photos: where a Club uses class photos, images are stored only with a guardian's explicit, per-child consent, which can be withdrawn at any time. A child with no consent on file is never included. Adult members manage their own consent.
  • Health and incident information: no medical-records module and no safeguarding case-notes module. Where a Club records an accident or incident, that report is visible only to the Club's staff and to the guardians of the children named in it.
  • About a guardian: name, email address, phone number (optional), and your relationship to the child (primary guardian, carer, or pickup-only).
  • Attendance and booking data: which classes/camps a child is enrolled in, session attendance, reported absences, waitlist and catch-up-credit status.
  • Coaching data: qualifications and DBS/first-aid compliance records for coaches (not guardians or children), and incident reports where a Club records one.
  • Payment data: invoice records (amount, description, status) and a Stripe payment reference. Troop never stores card numbers — these are handled directly by Stripe.
  • Account data: login email, and system logs needed to operate the Service securely.

3. Why we process this data (lawful basis)

  • Performance of a contract — running bookings, attendance, and payments is how we deliver the Service the Club (and, for direct public bookings, you) has asked for.
  • Legitimate interests — of the Club, in running classes safely and communicating with families; balanced against your rights, and never used for a child's data where a more protective basis applies.
  • Legal obligation — retaining financial records (see §5) for UK tax purposes, and safeguarding compliance records.
  • Consent — for anything not necessary to deliver the Service, e.g. non-essential cookies (see our Cookie Policy). No analytics or advertising cookies are in use today.

Essential-information fields about a child (e.g. allergies) are special category data under UK GDPR. We process this only where necessary to protect the child's vital interests or for substantial public interest reasons (running the activity safely), and access is restricted to the Club's own staff for that child's classes.

4. Who we share data with

We use a small number of specialist processors, each bound by a data processing agreement:

  • Stripe — payment processing. Card details go directly to Stripe; we never see or store them. Payments use Stripe Connect direct charges, so the Club is the merchant of record for its own transactions.
  • Supabase — our database and authentication provider, hosting all the data described in §2.
  • Amazon Web Services (SES) — sends transactional emails (booking confirmations, absence notifications, etc.).
  • Vercel — hosts the application and its request logs.
  • Expo — delivers push notifications to the mobile app, where your family uses it.
  • Anthropic— an AI model that helps a Club set up. Two things are sent to it, and nothing else: the one-sentence description of the Club an organiser types when signing up (to draft a starting timetable), and, when a Club imports a family spreadsheet with a column Troop doesn't recognise, the spreadsheet's column headings only (to suggest which column is which). No row of the spreadsheet is ever sent, so no child's or family's details reach Anthropic. Under Anthropic's commercial terms it may not use this data to train its models. Anthropic processes data in the United States (see §8).

PostHog (product analytics) is built into the Service but switched off: no analytics data is collected or sent to PostHog today. If we ever switch it on, we will update this policy first, and ask for your consent wherever cookies or similar technologies are involved.

The full list, with regions and our sub-processor change process, is in the Data Processing Agreement. We run no analytics or advertising service, so no analytics provider receives your data.

We do not sell personal data, and do not share child data with any third party for marketing purposes.

5. How long we keep data

  • Active family/child records — for as long as the family is enrolled at the Club, plus a reasonable period after (set by the Club) in case of re-enrolment.
  • Financial records (invoices) — retained for 6 years after the tax year they relate to, as required by UK law, even after a family's other data has been deleted. See §7 — an account-deletion request anonymizes the family/child records attached to an invoice rather than deleting the invoice itself.
  • Safeguarding/compliance records (coach DBS, incident reports) — retained per the Club's own safeguarding policy, typically the duration recommended by UK safeguarding guidance.
  • Account security logs — a rolling, limited period sufficient to detect and investigate abuse.

6. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you or your child (right of access);
  • Have inaccurate data corrected (rectification) — most fields can be edited directly in your account;
  • Request deletion of your data (erasure), subject to the financial/safeguarding retention described in §5;
  • Object to, or ask us to restrict, certain processing;
  • Receive your data in a portable format (portability).

You can exercise access and erasure rights yourself, immediately, from Account → My Data. For any other request, or if you're acting on behalf of a family and don't have your own login, contact hello@mbo9.com or your Club administrator directly.

If you're unhappy with how we've handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or 0303 123 1113.

7. Deletion and financial records

Deleting your account removes your login, and your family's guardian, child, booking and communication records. Where a child has a paid-invoice history, the invoice itself is kept, not deleted — UK tax law requires clubs to retain financial records for 6 years — but the child and family records it references are anonymized (names removed) rather than left identifiable. This is the minimum retention the law requires, not a way of holding on to more than necessary.

8. International transfers

All primary processing takes place in the United Kingdom — our database and file storage (Supabase) in London, our hosting (Vercel) in London, and our email delivery (AWS SES) in London.

Stripe and Expo operate globally, and Anthropic processes data in the United States, so some payment, push-notification and set-up data is processed outside the UK. Those transfers are covered by the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, or by an adequacy decision.

8a. If something goes wrong

If a personal data breach affects your club's data, we notify the club within 72 hours of becoming aware of it, with what we know about what happened, who is affected, and what we are doing about it. Your club, as controller, decides whether the ICO and affected families must be told; we give them what they need to make that call. The full commitment is in the Data Processing Agreement.

9. Children's data specifically

A child does not hold their own Troop account — all data about a child is entered and managed by their guardian or the Club. We collect the minimum needed to run a safe class (see §2) and never use a child's data for marketing or profiling.

9a. The Troop mobile app

The Troop app for iPhone and Android is distributed through Apple's App Store and Google Play. Downloading it is covered by Apple's or Google's own terms and privacy policy; once installed, the app works on the same account and data as the website, under this policy.

The app asks for only these device permissions, and only when you use the feature that needs them:

  • Camera — when a coach takes a class photo to share with families.
  • Photos — when a coach picks class photos from the library to share, or when you save a shared photo to your device.
  • Notifications — to tell you about bookings, offers and messages. Push notifications are delivered through Expo and Apple or Google; you can turn them off in your device settings at any time.

The app does not use your microphone or your location, and has no advertising or tracking. It reads your device's language to show the app in it. Payments made in the app go directly to Stripe, as on the website. You can delete your account from inside the app, in My Data.

10. Contact

Data protection queries: hello@mbo9.com.