Privacy Policy
Last updated: August 9, 2026
At MembershipSoft, we prioritize the privacy and security of our users and their members. This Privacy Policy describes how we collect, process, and safeguard personal data in compliance with GDPR Art.13/14, CCPA/CPRA, and international privacy standards.
1. Information We Collect
We collect information provided directly by account operators and automatically during service usage:
- Account Details: Name, work email address, phone number, and billing details processed securely via Stripe.
- Member Data: Member rosters, attendance records, and booking data uploaded by operators to their tenant instance.
- Usage & Diagnostics: Technical telemetry, IP addresses, and browser signatures collected for security and performance optimization.
2. Legal Basis for Processing (GDPR Art. 6)
| Purpose of Processing | Legal Basis (GDPR Art. 6) |
|---|---|
| Account creation, multi-tenant CRM hosting, & billing | Contractual Necessity (Art. 6(1)(b)) |
| System security, fraud detection, & DDoS prevention | Legitimate Interest (Art. 6(1)(f)) |
| Product analytics & performance cookies | Consent (Art. 6(1)(a)) |
| Financial recordkeeping & tax compliance | Legal Obligation (Art. 6(1)(c)) |
3. Data Retention Schedule
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & Operator Data | Life of contract + 2 years | Contractual / Legal |
| Payment & Transaction Records | 7 years | HMRC / Tax Law |
| Audit Logs & Security Telemetry | 5 years | Legitimate Interest |
| Analytics (Consent-gated) | 13 months rolling | Consent |
| Deleted Member PII (DSAR) | Anonymized/Erased within 30 days | GDPR Art.17 Erasure |
4. Your Data Rights (GDPR & CCPA)
Under GDPR and CCPA/CPRA, you have rights to access, rectify, erase (Art. 17), restrict processing, request portability (Art. 20), and opt out of data sharing. To exercise these rights, submit a request to privacy@membershipsoft.com.
5. Cookies & Tracking Technologies
We use essential cookies for session management and optional analytics cookies (gated via consent banner). For detailed category breakdowns and management, review our Cookie Policy.
6. International Transfers & Subprocessors
Personal data may be processed outside the UK/EEA under standard contractual clauses (EU SCCs Module 2). Subprocessors include Cloudflare, Stripe, Resend, Telnyx, PostHog, and Plausible. Review our Data Processing Agreement for full subprocessor listings.
7. Data Protection Contact
For questions or privacy concerns, contact our Data Protection lead at privacy@membershipsoft.com or lodge a complaint with the UK ICO (ico.org.uk).