Sub-processors
clubrooms uses these services to run the product. Each one processes club data on our behalf and under our instructions — they are not free to use it for anything else, and none of it is sold.
This is the complete list. If a service is not here, it does not receive club data.
| Service | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Stores the database and runs sign-in | Everything clubrooms holds: accounts, players, fixtures, availability | Australia (ap-southeast-2) |
| Vercel | Runs the website and the scheduled jobs | Data in transit as pages are served; server logs | Australia (syd1) for requests; United States for builds |
| Resend | Sends email — reminders, invitations | Email addresses, player and club names, fixture details | United States |
| Sentry | Records errors so we can fix them | Error details, the page it happened on, an account identifier; session replays with all text masked | United States |
| PostHog | Counts how features are used | Pseudonymous usage events | United States |
| Browser push services (Google, Apple, Mozilla) | Delivers notifications to a device that has opted in | The encrypted message and the device’s push address. The contents cannot be read by them; that a message was sent, and when, can. | Determined by the browser vendor, typically the United States |
Some of those process data in the United States, which means club data — including children's names — leaves Australia.
When this changes
Adding a service to clubrooms means adding it here, and a change that alters who receives club data is recorded in the privacy policy changelog. If you have agreed to this list as part of an arrangement with your club, that changelog is where to look for what moved.
Questions about anything on this page: privacy@clubrooms.team.
Last updated 2026-08-03. Part of our privacy policy.