Data & security

Start with less data. Prove value before asking for more.

The first Audit should use the minimum information needed. Persistent integrations come only after permissions, responsibility and value are clear.

Minimisation

We prefer anonymised IDs instead of full names. We do not ask for passwords, card data, identity documents or private-message content.

Club isolation

Each club's data and outputs should remain separated. Cross-club search of private customer data is not part of the pilot.

Booking connectors

A connector is enabled only when the club has authority and the provider exposes the technical access required. We do not bypass APIs, contracts or access controls. Two-way sync and reservation locking are used only when supported and tested.

Federation networks

A federation layer can aggregate public availability/discovery, but should not expose one club's customer list to another. Aggregated reporting should preserve tenant separation.

Analytics

Website events measure pages, source/UTM, CTA, demo, simulator and forms. Form-field contents, passwords and payment data are not included in analytics events.

Retention, export and deletion

Before a persistent integration, commercial scope should define retention, export, deletion and processing roles.