infacta

Legal

Privacy Policy

Last updated 16 September 2026

This policy has not yet been reviewed by a data-protection lawyer. It describes how the service actually works today, and we will post a reviewed version here when one is ready.

This Privacy Policy explains how Infacta Account, operated by Groupmail Ltd. trading as Infacta (registered in Ireland, company no. 284930, registered office Unit 15, SocoLab, Strandhill, Co. Sligo, F91 E426, Ireland) (“Infacta”, “we”, “us”), handles personal data. Infacta Account is the central sign-in and club-management service for Infacta products, hosted in the European Union (Frankfurt, Germany). It covers everyone who holds an Infacta account and anyone who requests an invitation for their club at id.infacta.com.

Controller and processor roles

For your Infacta account itself — your name, email address and sign-in credentials — and for invitation requests submitted at id.infacta.com, we are the data controller.

A Club decides who belongs to it: its admins invite people, assign roles and grant access to products. We hold and process that membership data to operate the shared account service on the Club’s behalf.

Information we collect

How we use personal data

We use personal data to:

We do not sell personal data and we do not use it for advertising.

Sharing with Infacta products

The account service exists to be shared: when you sign in to an Infacta product (such as ClubCards or FloorTime), we pass it the account and membership data it needs — your name, your email address, your phone number and profile photo if you have added them, the club you are acting in, your roles there, and the club’s identity (name, crest and colours). Requests between the account service and the products are cryptographically signed.

Your profile photo is served at a web address that is hard to guess but can be viewed by anyone who has it, and replacing or removing the photo retires that address.

Each product’s own privacy policy covers what it does with data from there, and with the data you enter in the product itself.

Cookies

We use a single essential session cookie to keep you logged in. It is required for the service to function and is not used for advertising or cross-site tracking.

Service providers and sub-processors

We use a small number of trusted providers to run the service — cloud hosting and database (in the EU) and transactional email delivery. They process data on our instructions under their own data-protection terms.

Data retention

We keep account data for as long as your account is active. After an account is closed we delete or anonymise account data within 30 days, except for routine backups and anything we must keep to meet a legal obligation. Backups are taken daily, and operational logs are kept for a variable period — typically around 30 days.

Invitation requests are kept for up to 12 months; if we haven’t been able to set your club up in that time, we delete them.

Membership requests are kept for 90 days after they’re decided (approved, declined or left unanswered), then deleted.

A club’s audit records are part of that club’s account and are kept for as long as the club’s account is active.

Security

We take reasonable measures to protect personal data: passwords are stored only as secure hashes, sign-in and reset links are single-use, data is transmitted over encrypted connections, requests between the account service and Infacta products are cryptographically signed, and each club’s data is logically isolated so one club cannot access another’s.

Personal data breaches

If a personal data breach affects data a Club has entrusted to us, we will notify the Club without undue delay and give them the information they need to meet their own obligations. For data we control, we will comply with our own notification duties under applicable law.

Where we process data and international transfers

The account service hosts its application and database in the European Union (Frankfurt, Germany), so personal data is processed in the EU by default.

Our transactional-email provider may process limited data outside the EEA/UK. Where that happens, we rely on the European Commission’s 2021 Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or port your personal data, or to object to its processing. To exercise them, contact us below. If your data was entered by your club, we may direct the request to the club and support them in responding.

Children

Infacta accounts are for adults (18+) — the people who run and use a club’s account. The service does not hold data about the children who attend a club’s activities.

Changes to this policy

We may update this policy from time to time. We will post the new version on this page and update the “last updated” date above.

Contact

Questions or privacy requests? Email us at hello@infacta.com. Clubs acting as controllers can also read our Data Processing Agreement.