A club noticeboard covered in decades of handwritten league results

Who Owns Your Club's Data?

Most clubs never ask who owns their data. They ask once, and always too late: when the committee changes and nobody has the login, when a platform doubles its price, or when a member sends an email asking for everything the club holds about them.

By then the answer is whatever the platform decided years ago, and you agreed to it without reading.

Here is the thing worth internalising. A club's data is not really data. It is the club's memory. Twenty years of ladders, the night someone finally beat the club champion, who paid subs in 2019, which junior came through the Thursday group and now runs it. Losing it is not an IT inconvenience. It is amnesia.

So it is worth a few minutes of scepticism before you hand it over. There are four questions, and they get progressively harder for a vendor to answer.

Question one: can you get everything out, today, without asking?

Not "we offer data export on request". Not "contact support and we will prepare a file". Those are promises about someone's future goodwill, and goodwill is exactly the thing that evaporates when a company is being acquired or wound up.

The test is simpler than it sounds. Log in right now and try to download the lot. If you can, in one action, without a support ticket, you have real portability. If you cannot, you have a hostage situation with good manners.

Then look at what actually comes out. A database dump nobody can read is not an export, it is a receipt for an export. The useful version is ordinary CSV and JSON with a plain English description of what every field means, so that a spreadsheet opens it today and a different system can ingest it in ten years. On ServeLeague this is the club data pack: one button, everything, with a README, a format guide and a JSON Schema in the file.

Ask the vendor for a sample export before you sign. The answer tells you a lot, quickly.

Question two: is ownership written down, or just said warmly?

Every platform says you own your data. It costs nothing to say. What matters is whether it appears in the contract, because only the contract survives a change of management.

Read the terms and look for two specific things. First, an explicit statement that customer data belongs to the customer, not a vague "you retain rights". Second, and far more revealing, what happens at the end. Most terms are silent about the end, which is precisely the moment you care about.

Our Terms of Service commit to 90 days' notice before the service closes, to keeping clubs on their existing plan for the whole notice period, and to export being the last thing switched off rather than the first. That last point is the one to steal when you evaluate anyone else. Plenty of services disable exports the moment billing lapses, which is the software equivalent of changing the locks while your possessions are still inside.

Question three: what gets deleted, and when?

This is where warm words meet reality, because "we delete your data" is meaningless without a schedule. Deletion is not one thing. Different categories have genuinely different lifespans, and a vendor who has thought about it will tell you the numbers.

For reference, ours are published in the Privacy Policy:

Data Retention
Account and club data Deleted or anonymised within 90 days of account closure
Backups Purged within 30 days
Operational logs (notifications, webhooks, automations, audit events) Purged after 90 days
Analytics data 14 months
Legal registers (audit trails, data access logs, deletion requests) 7 years, as required by law

Notice that last row, because it is the honest part. A platform that promises to delete absolutely everything on request is either not doing it or is breaking the law in doing it. Some records must be kept: proof that you honoured a deletion request is itself a record you have to keep. If a vendor tells you every trace vanishes instantly, they have not read their own obligations.

Backups are the other place claims quietly fall apart. Deleting a row from the live database does nothing to the copy sitting in last night's backup. Ask how long backups live, and whether deletion propagates to them.

Question four: who is actually responsible for member data?

This one catches committees off guard, and it is the most important for anyone running a club in the UK, EU, New Zealand or Australia.

When a club uses a platform to manage its members, the club is usually the data controller and the platform is the processor. In plain terms: the club decides what member data is collected and why, and the platform handles it on the club's instructions. That is not a technicality to push onto your vendor. It means that when a member exercises their right of access or erasure, the obligation lands on the club first.

So the practical question is whether your platform makes that possible. Can you find everything held about one member? Can you export it in a machine-readable format and hand it over? Can you delete a member properly, rather than hiding them from a list while the records sit underneath?

If the answer is no, the club is carrying a legal duty it has no tools to discharge. That is a bad position to discover during a complaint.

A short version you can take to your committee

Ask any platform, including this one:

  1. Show me a full export, downloaded today, without a support request.
  2. Show me the sentence in the contract that says we own it, and the clause that says what happens if you shut down.
  3. Show me the retention schedule, in numbers, including backups.
  4. Show me how I answer a member's access or deletion request.

Four answers, and you will know more about a vendor's character than any sales call will tell you. A company that has thought about its own ending is a company that will be straight with you about everything before it.

If you want to see how we answer them, the specifics are in Data ownership, the Privacy Policy and the Terms of Service. We would rather you read them now than need them later.