← Back to Gaffer HQ

Privacy Policy

Gaffer HQ Ltd · Last updated: 20th May 2026

This Privacy Policy for Gaffer HQ Ltd (Company Number: 17189389), trading as GAFFER HQ ('we', 'us', 'our'), describes how and why we collect, store, use, and share your personal information when you use our Services, including when you:

  • Visit our website at https://app.gafferhq.uk
  • Use the GAFFER HQ platform and its features
  • Engage with us in other related ways

GAFFER HQ (operated by Gaffer HQ Ltd) is an online platform designed to support youth and adult football clubs' team managers and referees across England. The platform enables managers to post team availability and arrange friendly fixtures, find and contact qualified referees, and discover local pitch facilities. GAFFER HQ is accessed via our website at app.gafferhq.uk.

Questions or concerns? Contact us at [email protected] or by post at: Gaffer HQ Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.

1. What personal information do we collect?

Information you provide directly

We collect personal information you voluntarily provide when you register, create a profile, or use our Services. This includes:

  • Name, email address and mobile phone number (all users)
  • Roles — manager or referee
  • Club name, team age group, team gender (predominantly boys or girls), county, league standard, and kit colour (managers)
  • Preferred locations (town/city), county, age groups covered, and availability dates (referees)
  • Club name, description, and contact links (club administrators)

Information collected automatically

When you use our Services, we automatically collect certain aggregate information through Plausible Analytics, our privacy-first analytics provider. This includes:

  • Pages visited and features used
  • Approximate country-level location (derived from IP address — not stored at individual level)
  • Device type and browser
  • Referral source (how you found the site)

Payment data

We do not currently collect payment data. If subscription features are introduced in future, payment processing will be handled by a regulated third-party payment provider. We will update this Privacy Policy at that time.

2. How do we use your personal information?

We process your personal information for the following purposes:

  • To create and manage your account and verify your identity
  • To provide the Services — including displaying your team's availability on the regional calendar, connecting you with other managers and referees
  • To send transactional notifications — match requests, booking confirmations, cancellations, and account-related communications
  • To send you marketing or product updates, where you have given explicit consent to receive them
  • To send you updates to the Privacy Policy or terms and conditions
  • To improve and develop the platform using anonymised, aggregate analytics data
  • To comply with our legal obligations, including UK GDPR and ICO requirements
  • To prevent fraud and protect the security of the platform and its users

3. Legal bases for processing

Under UK GDPR, we rely on the following legal bases:

  • Contract — processing your account details and profile data is necessary to provide the Services you have registered for
  • Legitimate interests — processing location data (county for managers, county/town/city for referees) is necessary to provide the regional matching that is the core purpose of the platform.
  • Legitimate Interests / Soft opt-in — where we communicate with existing users about similar services, product updates, or platform news, we may rely on legitimate interests under PECR (Privacy and Electronic Communications Regulations), where you have an existing customer relationship with us. This means we may use an opt-out rather than opt-in model for certain communications. Where we rely on this basis you will always be given a clear and easy way to opt out. For other marketing communications, we rely on your explicit consent. You can manage all preferences in your Account Settings
  • Legal obligation — where we are required to process data to comply with applicable law

4. Do we process sensitive or children's data?

No. GAFFER HQ is designed for use by adults aged 18 and over, including referees. We do not permit users under 18 to create accounts.

However, in the future, the platform may hold personal data relating to players who are under the age of 18 (name-only as part of a squad list), entered by an authorised adult manager or club administrator using a team management capability (not yet in production). At such time, the Privacy Policy will be updated in accordance with under 18's data and child safeguarding regulations.

5. Do we use artificial intelligence?

As part of our Services, we plan to offer AI-assisted features, including personalised match suggestions, referee recommendations, and platform improvements. These features are designed to improve your experience and may be powered by AI tools.

Where AI features are used to process your personal data, we ensure this is done transparently, on a clear legal basis, and in accordance with UK GDPR. We do not use fully automated decision-making that produces legally significant effects without human oversight.

Your personal data is not used to train external AI models. Any AI processing of data relating to players under the age of 18 in the future will be subject to additional safeguards.

You can opt out of personalised AI-assisted features by updating your preferences in Account Settings.

6. Do we use cookies?

GAFFER HQ does not use cookies for tracking, advertising, or analytics purposes.

We use one strictly necessary session cookie to keep you securely logged in to your account. This cookie is essential to the operation of the service. It does not track your behaviour across other websites and does not share any data with third parties.

We do not use Google Analytics, Google Maps, or any other Google services. Our analytics provider, Plausible, is cookieless and collects no personal identifiers.

No cookie consent banner is required on GAFFER HQ under UK GDPR guidelines, as we use no non-essential cookies.

7. Do we share your personal information?

We do not sell your personal data. We do not share your personal data with advertisers.

We may share your information in the following limited circumstances:

  • With other users of the platform — your team name, age group, county, league standard, and availability are displayed to other managers in your region. Your personal contact details are not displayed publicly.
  • With service providers — we use Supabase (database and authentication), Railway (hosting), Resend (email), Mapbox (mapping), and Plausible (analytics) to operate the platform. These providers process data only as necessary to provide their services and are bound by appropriate data processing agreements.
  • In connection with a business transfer — if Gaffer HQ Ltd is acquired or merged, your data may be transferred as part of that transaction. You will be notified in advance.
  • Where required by law — we may disclose information where required to do so by law, regulation, or legal process.

8. Do we transfer data internationally?

Gaffer HQ Ltd is a UK-registered company. Your data is stored on Supabase infrastructure in the EU West (London) region, keeping it physically within the United Kingdom.

Some of our service providers (including Railway and Plausible) may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, including standard contractual clauses or adequacy decisions recognised under UK GDPR.

9. How long do we keep your data?

We keep your personal data for as long as your account is active or as necessary to provide the Services. When you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, regulatory, or fraud-prevention purposes.

10. How do we keep your data safe?

We implement appropriate technical and organisational security measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Row-level security controls so that each user can only access their own data and the data of their specific team
  • Access controls limiting admin access to authorised personnel only
  • Regular security reviews before and after major platform updates

No electronic transmission over the internet can be guaranteed to be 100% secure. While we take every reasonable precaution, we cannot guarantee the absolute security of your data.

11. UK Online Safety Act 2023

We are committed to maintaining a safe, respectful, and trustworthy platform experience. In line with the UK Online Safety Act 2023, we implement proportionate measures designed to support user safety, reduce harmful activity, and provide clear ways for users to report concerns or manage their experience. Examples of supported Platform capabilities:

FeatureDescription
Report / Flag ButtonAvailable within message chats, tournament listings, and availability posts. Submissions generate an alert within the admin moderation dashboard for review.
PDF Approval QueuePDF content uploads are held in a pending review queue and require manual approval before publication.
Account SuspensionAdmin dashboard controls allow administrators to suspend or permanently ban user accounts immediately where required.
Profanity FilterBasic profanity and inappropriate language filtering applied across free-text inputs, including messages, usernames, and descriptions.
Appeals ProcessSuspended users may submit an appeal request through a dedicated form, which is delivered to the admin review inbox.
Safety Onboarding ScreenPost-signup onboarding screen presenting some core community and safety guidelines, requiring user acknowledgement before continuing.
Rate Limiting on MessagesMessage activity limited to a maximum number of messages per hour within each fixture thread to help reduce spam and harassment.
User BlockingUsers may block another manager account, preventing direct messages and match-related requests between the accounts.

12. Your privacy rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your data ('right to be forgotten')
  • Right to restrict processing — request that we limit how we use your data
  • Right to data portability — request your data in a portable format
  • Right to object — object to processing based on legitimate interests
  • Rights relating to automated decision-making — not to be subject to solely automated decisions that significantly affect you

The easiest way to exercise your rights is through your Account Settings at https://app.gafferhq.uk/account, where you can update your preferences, request a data export, or submit an account deletion request. You can also contact us directly at [email protected].

We will respond to all data rights requests within 30 days in accordance with UK GDPR.

If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. Our ICO registration number is ZC139011.

13. Marketing communications

We will only send you marketing or promotional communications where you have given explicit consent by ticking the optional marketing opt-in box at registration. We will not send marketing emails based on implied consent or pre-ticked boxes.

You can withdraw your consent and unsubscribe from marketing communications at any time by: (a) clicking the unsubscribe link in any marketing email, or (b) updating your preferences in Account Settings.

Withdrawing marketing consent will not affect your receipt of transactional service emails, which are necessary to operate your account.

14. Do-Not-Track signals

We do not currently respond to Do-Not-Track browser signals, as no uniform industry standard has been established. Given that GAFFER HQ does not use tracking cookies, this has limited practical effect on your privacy when using our Services.

15. Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. If we make material changes, we will notify you by email with at least 30 days' notice before the changes take effect. The updated date at the top of this policy will reflect the date of the most recent revision.

16. Contact us

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

  • Email: [email protected]
  • Post: Gaffer HQ Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom