Privacy Policy
Last updated: July 7, 2026
This Privacy Policy explains how ClubCore, operated by Poco Labs, handles personal information. ClubCore is a business-to-business platform used by private clubs; for a club's members, the club is the controller of member data and ClubCore acts as its processor.
1. Information we process
Account & profile: name, email, role, and club affiliation. Activity: bookings, check-ins, orders, and communications generated in the normal use of the platform. Payments: handled by our processor (Stripe) — we store payment identifiers and status, never full card numbers. Technical: logs and diagnostic data needed to operate and secure the service.
2. How we use it
To provide and operate the platform, authenticate users, process payments a club initiates, send transactional communications (confirmations, reminders), maintain security and prevent abuse, and improve reliability. We do not sell personal information, and we do not use member data for advertising.
3. Sub-processors
We rely on a small set of infrastructure providers to run the service:
- Supabase — database and authentication
- Stripe — payment processing (PCI-compliant; holds card data)
- Resend — transactional email delivery
- Vercel — application hosting
Each processes data only as needed to provide its function to ClubCore.
4. Tenant isolation
ClubCore is multi-tenant. Each club's data is scoped to that club and access is enforced at the authentication and authorization layer so that one club cannot access another club's data. This isolation is a core design invariant and is verified by an automated test suite.
5. Data retention
We retain personal information for as long as an account is active or as needed to provide the service. When a club ends its use of ClubCore, its data is available for export for a reasonable period and then deleted, subject to any legal retention obligations.
6. Security
Data is encrypted in transit and at rest by our infrastructure providers. Access is restricted by role, secrets are never committed to source control, and dependencies are monitored for vulnerabilities. No system is perfectly secure, but we treat protection of member data as a first-class requirement.
7. Your choices and rights
Members should direct requests to access, correct, or delete their data to their club, which controls that data. Clubs may contact us to exercise these rights on their members' behalf. We will assist clubs in responding to such requests as their processor.
8. Changes
We may update this policy as the platform evolves. Material changes affecting customers will be communicated with reasonable notice, and the “last updated” date above will change.
9. Contact
Privacy questions: stu@pocolabs.ai.