Last updated: 31 August 2026
This policy explains how DutyGO collects, uses, and protects personal data belonging to the club, club administrators, club members, and visitors to our website and portal.
(“You”, “club”, “customer”) refers to Customer.
DutyGO is a product of Firebound Interactive (“we”, “us”, “our”). Firebound Interactive is the data controller; DutyGO is the name of the service.
We are registered with the Information Commissioner’s Office under registration number ZC202413.
For questions about this policy or how your data is handled, contact us at [email protected]. We are the data controller for the purposes described in Section 2, and this is our contact point for all data protection matters.
Which role we play depends on the data:
If you are a club member and want to know why your club holds particular information about you, ask your club. If you want to know how we handle it on their behalf, this policy and the Addendum explain that.
| What we do | Lawful basis (UK GDPR Article 6) |
|---|---|
| Create and manage your account and club membership | Performance of a contract |
| Operate roster, duty swap, check-in, document and announcement features on behalf of your club | Performance of a contract (with your club); we act as its processor |
| Send account emails - welcome, password reset, removal notices, and club announcements | Performance of a contract, and legitimate interests in running the service |
| Take payment and manage subscriptions | Performance of a contract, and legal obligation for financial records |
| Respond to quote requests and provide support | Legitimate interests in responding to enquiries |
| Apply rate limits, prevent abuse, and keep the service secure | Legitimate interests in protecting the service and its users |
| Marketing communications, where you have opted in | Consent - withdrawable at any time |
Where we rely on consent, you can withdraw it at any time by contacting us. Withdrawing consent does not affect processing carried out before you withdrew it. Where we rely on legitimate interests, you have the right to object - see Section 8.
DutyGO is not designed to hold special category data as defined by Article 9 of the UK GDPR - that is, data revealing health, racial or ethnic origin, religious beliefs, sex life or sexual orientation, political opinions, trade union membership, or genetic or biometric data - nor criminal offence data under Article 10.
Clubs must not record medical information, safeguarding records, DBS results, or other criminal offence data in DutyGO - including in qualification names, administrator notes, or documents linked from the portal. This restriction is a term of our Terms & Conditions.
Qualification records are competency records: they show that someone holds a certificate, such as a first aid or powerboat qualification. They are not records about that person’s own health.
We do not sell personal data. We share it only with:
| Provider | What it does | Where data is processed |
|---|---|---|
| Google (Firebase Authentication, Cloud Firestore) | Account authentication and the main database | Belgium (European Union) |
| Cloudflare | Application hosting (Workers), file storage (R2) for club logos, and outbound email delivery | Global edge network, including outside the UK |
| Stripe Payments UK, Ltd. | Subscription billing and card processing. Stripe is a separate controller for payment data and applies its own privacy policy. | UK, EU and US |
We do not use third-party advertising or analytics providers.
Your club's data is stored in Belgium, within the European Union. Transfers from the United Kingdom to the EU are covered by the UK Government's adequacy regulations for the EEA, which means no additional safeguard is required for that transfer.
Two of our providers operate more widely. Cloudflare delivers the application and email from a global edge network, and Stripe processes payment data in the UK, EU and US. Where those transfers reach a country without UK adequacy, they are protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.
You can request details of the safeguard applied to a specific transfer by contacting us.
| Data | Retention period |
|---|---|
| Club and member records for an active subscription | For as long as the subscription is active |
| All club data after a subscription is cancelled | 30 days from the end of the final billing period, then permanently deleted |
| A member removed from a club | Their club record for that club, and any administrator notes about them, are deleted immediately. |
| A sign-in account after leaving the last club | Kept for 24 months, then automatically deleted. If you rejoin a club in that time, your account carries on as before. You can ask us to delete it sooner at any time. |
| Check-in and check-out records | 24 months from the date of the check-in, then automatically deleted |
| Quote request enquiries | No longer than 24 months |
| Billing and financial records | 6 years, as required by UK tax law |
| Security and rate-limiting logs | No longer than 30 days |
If you belong to more than one club, removal from one club does not affect your membership of another, and your sign-in account continues to work for the clubs you remain part of.
Access to club data is restricted by account-level permissions enforced on our servers, not only in the browser, so members can only reach data belonging to their own club. Passwords are never stored in plain text; they are handled entirely by Firebase Authentication. Data is encrypted in transit. We apply rate limits to sensitive operations, and we review the service’s security regularly.
Club administrators can see the contact details and duty records of members of their own club. Members of the same club can see each other’s names and duty assignments on the roster. Email addresses are hidden from the roster by default on new accounts; a member can choose to show theirs so others can contact them about duties. Members of the same club can look up each other’s contact details within the club.
You have the right to:
To exercise any of these, contact us using the details in Section 1, or ask your club administrator to remove your account. We will respond within one month.
The 24-month period in Section 8 is a convenience, not a condition: it exists so you can rejoin without losing your account. It does not delay your right to erasure. If you ask us to delete your account, we do it - we do not wait for the 24 months to run.
If we act as a processor for your club, we will pass your request to them and assist them in answering it.
If you are unhappy with how we have handled your personal data, please contact us first so we can try to put it right.
You also have the right to complain to the Information Commissioner’s Office, the UK’s supervisory authority for data protection:
You do not have to contact us before complaining to the ICO.
Clubs may add members under 18 to a roster. Many clubs run junior sections, and a duty system that excluded them would not reflect how those clubs actually work.
Your club decides who is added and is responsible for having a lawful basis for it, including any parental consent its own arrangements require. We hold that data on the club’s behalf.
Because the service can be used by under-18s, we apply the same protections to everyone rather than asking anyone to prove their age:
If you are a parent or guardian and want to know what we hold about your child, or want it deleted, contact us at [email protected] or speak to the club. The rights in Section 10 apply to children in the same way.
Our website and portal use only the technical storage required to keep you signed in and remember your club selection. See our Cookie Policy for full details.
We may update this policy from time to time. Material changes will be notified to account holders by email and reflected by updating the “Last updated” date at the top of this page.