This Privacy Policy explains how Iniesta Academy Dubai ("we", "us") collects, uses, stores, and protects personal data of players, parents, coaches, and website visitors. By using our website or registering a player, you agree to this policy.
1. Data we collect
- Player details: full name, date of birth, gender, nationality, school, kit sizes, medical notes, emergency contact, preferred venue.
- Parent / guardian details: full name, email, mobile number, alternative phone, home address, consent signature.
- Account data: email, hashed password, sign-in metadata.
- Payment data: amount, currency, payment status, Stripe customer/subscription identifiers. We do not store card numbers — Stripe processes all card data directly.
- Uploaded documents: passport copy, Emirates ID, photos, medical letters when provided.
- Communications: contact form messages and WhatsApp/email correspondence.
- Technical data: IP address, browser type, referring URL, and standard server logs.
2. How we use your data
- Operating registrations, memberships, attendance, evaluations, and training.
- Processing payments, refunds, renewal reminders, and receipts.
- Sending operational emails and WhatsApp updates (consent-gated).
- Safeguarding, medical response, and emergency contact.
- Improving the service and meeting legal/accounting obligations.
3. Legal basis
We process data under contract (membership), legitimate interest (academy operations and safeguarding), consent (marketing/WhatsApp), and legal obligation (tax/accounting).
4. Sharing
We share data only with service providers required to operate the academy: Stripe (payments), Supabase / Lovable Cloud (hosting and database), Resend (transactional email), and Meta WhatsApp Cloud API (messaging, where opted in). Each provider is bound by their own data-protection terms.
5. Storage and retention
Data is stored on Lovable Cloud infrastructure with row-level security and encrypted at rest. We retain active member data for the lifetime of the membership and for up to 7 years thereafter for accounting/legal purposes. Uploaded registration documents are stored privately and accessible only by the parent and authorised academy staff.
6. Your rights
- Access, correction, or deletion of your data.
- Withdraw consent for marketing or WhatsApp messages.
- Request a data export.
- Lodge a complaint with the UAE Data Office.
7. Children
All player accounts are created and managed by a parent or legal guardian. We do not knowingly collect data from minors directly.
8. Cookies
We use only essential cookies (authentication session, CSRF) and no third-party advertising trackers.
9. Contact
For privacy questions or data requests, email info@iniestaacademydubai.com.
