MustAIM Privacy Policy
Effective date: 3 August 2026
1. Who we are
MustAIM ("we", "us") is the data controller for the personal data described in this policy. We're operated as a sole trader. Our contact for anything data-related is dpo@mustaim.com.
2. What we collect
If you're a Player:
- Account: email address, full name, date of birth (collected before your first booking — Venues use this to check you in).
- Preferences: preferred city/region/sport, marketing consent choices.
- Booking data: which Games you've booked, spots, amount paid, booking reference, cancellation/attendance history.
- Payment data: we don't see or store your card details — Stripe (see §4) handles that directly and gives us only a payment status.
If you're a Venue Owner (in addition to the above):
- Verification data: business type, the name and date of birth confirmed by our identity-verification provider, Companies House lookup results (for limited companies/LLPs), copies of ownership evidence you upload (e.g. an HMRC letter or business bank statement for sole traders/partnerships, or a letter of authority if you're representing the owner).
- Insurance data: your insurer's name, your policy number, and your policy's expiry date, plus a copy of the certificate itself. We do not collect or record the amount or scope of your cover — see /how-we-verify for why.
- Payment data for the verification fee (handled by Stripe, same as booking payments — see §4).
- Signature record: the version of the Venue Owner Agreement you accepted, a typed name, timestamp, and the IP address you accepted it from.
Everyone:
- Technical data: IP address, browser/device information, pages visited — collected via cookies/analytics, only once you've consented where consent is required (see our cookie banner).
- Error and performance data, collected automatically if something goes wrong on the Platform (see §4, Sentry).
3. Why we process it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating and running your account | Performance of a contract with you |
| Processing bookings and payments | Performance of a contract with you |
| Verifying a Venue Owner's identity and business | Performance of a contract with you / legal obligation (fraud prevention) |
| Sending transactional emails (confirmations, reminders, refunds) | Performance of a contract with you |
| Sending marketing emails (offers, recommendations) | Your consent, given separately and withdrawable any time |
| Fraud prevention and Platform security | Our legitimate interest in running a safe service |
| Site analytics | Your consent (cookie banner) |
| Responding to legal requests, keeping records for tax/dispute purposes | Legal obligation |
4. Who we share it with
We use the following processors. Each only receives what it needs to do its job:
- Supabase — hosts our database and handles sign-in. Holds essentially all the data described above.
- Stripe — processes every payment (bookings, verification fees) and payouts to Venues. Stripe holds your payment details directly; we never see or store your card number.
- Stripe Identity — a Stripe product we use to verify a Venue Owner claimant's identity. The identity document itself (passport/driving licence image) is held by Stripe, never by us — we only receive the verified name, date of birth, and a pass/fail result.
- Companies House — the UK's public register of companies. For limited company/LLP Venues, we look up the public director/PSC listing to cross-check against the verified identity above. This is a public register, not a data-sharing arrangement — we're querying data Companies House already publishes.
- Resend — sends our transactional emails (booking confirmations, reminders, verification-related emails).
- Sentry — error tracking, so we can find and fix bugs. May incidentally capture technical data (browser, request details) at the moment of an error.
- Upstash — rate-limiting infrastructure that protects login and booking endpoints from abuse. Processes IP addresses only, very briefly, to count requests.
- Google Analytics 4 — site analytics, only active once you've consented via our cookie banner.
- Vercel — hosts the Platform itself.
We do not sell personal data, and we do not share it with anyone for their own marketing purposes.
5. International transfers
Some of the processors above (notably Stripe, Sentry, and Google) may process data outside the UK. Where they do, transfers are made under appropriate safeguards — Standard Contractual Clauses issued or recognised by the UK, or an equivalent adequacy mechanism.
6. How long we keep it
- Player account and booking data: for as long as your account is active, plus 7 years afterwards for anything with a financial- transaction dimension, consistent with UK tax record-keeping norms.
- Venue verification documents and insurance certificates: while the Venue is active on the Platform, plus a short grace period after closure (currently 30 days for verification records, 90 days for a superseded insurance certificate after it's replaced) to cover any in-flight dispute. After that, documents are permanently deleted — see §9 for the full closure/erasure process. Identity-verification documents are never held by us at all; Stripe Identity's own retention applies, and we request deletion of the underlying verification session when a Venue closes.
- Marketing consent records: until you withdraw consent, then kept as a minimal record (that consent was withdrawn and when) so we don't accidentally re-contact you.
7. Your rights
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct anything inaccurate (rectification);
- delete your data, subject to the retention needs described above (erasure);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, for anything we process on that basis.
To exercise any of these, email dpo@mustaim.com. We'll respond within one month. If you're not satisfied with our response, you can complain to the UK Information Commissioner's Office (ico.org.uk).
8. Cookies
We use essential cookies to keep you signed in and to remember your cookie preferences. Google Analytics is only loaded, and its cookies only set, once you've actively consented via the cookie banner.
9. Venue closure and data erasure
If a Venue Owner closes their venue, or asks us to delete their data:
- Any future games on that venue are automatically cancelled and every affected Player is refunded.
- After a short grace period (to cover any chargeback or dispute that might still be raised), we permanently delete the insurance certificate and any ownership-evidence documents we hold — both the file and its record.
- We ask Stripe to delete the underlying identity-verification session.
- We keep a minimal audit trail (that a verification happened, when, and when it was deleted) with the personal-data fields stripped out, so we retain no way to re-identify who it related to beyond what's needed to prove the deletion occurred.
- You'll get an email confirming what was deleted.
10. Security
We restrict access to personal data on a need-to-know basis, store sensitive documents (insurance certificates, ownership evidence) in a private storage location that's never publicly accessible, and log every time someone on our side accesses one of those documents.
11. Children
The Platform is not directed at children. Account creation and bookings are subject to the age requirements in our Terms of Service (clause 4), which depend on the specific Venue's own age policy and any applicable law.
12. Changes to this policy
We'll update the effective date at the top of this page when we make a change, and flag material changes the next time you sign in.
13. Contact us
Questions about this policy or your data: dpo@mustaim.com. To complain: ico.org.uk, or dpo@mustaim.com first if you'd like us to try to resolve it directly.