Adelaide Falcons Cricket Club

Privacy Policy

Effective date: 1 April 2026 — Version 1.2 (updated 30 May 2026)

Adelaide Falcons Cricket Club (“we”, “us”, “our”) is committed to protecting the privacy of our members and affiliated individuals. This policy explains how we collect, use, store, disclose, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Information we collect

We collect personal information you provide when you:

  • Accept a membership invitation and create an account;
  • Complete your member profile.

This information may include:

  • Full name and email address;
  • Mobile phone number;
  • Emergency contact name and phone number;
  • Photo consent preference.

2. How we use your information

We use your personal information solely to:

  • Manage your club membership and season registration;
  • Contact you about club matters (fees, fixtures, announcements);
  • Contact your nominated emergency contact in an on-field emergency;
  • Publish photographs on club channels (Facebook, website) only where you have given explicit consent.

We do not use your information for commercial marketing, and we do not sell or share it with third parties except as described in section 4.

3. Sensitive information

The club does not collect sensitive information (such as health, medical, or Working With Children Check details) through this platform.

4. Disclosure to third parties

We may disclose your information to:

  • Clerk — authentication and identity management (stores your email, password hash, and session data in accordance with their privacy policy);
  • Supabase — hosted database provider (stores your profile data on servers in Australia or Singapore);
  • Cricket Australia / SACA — for registration and compliance purposes, as required by the applicable governing body rules.

All third-party providers are contractually bound to process your data only as instructed by us and to maintain appropriate security measures.

5. Data storage and security

Your data is stored in a Supabase-hosted PostgreSQL database. Row-level security policies ensure that:

  • Members can only read and update their own profile;
  • Emergency contacts are visible to committee members only;
  • No member can read another member’s data without an appropriate committee-level role.

We implement technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access. These include TLS in transit, encrypted storage at rest, and role-based access controls.

6. Data retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law, and then destroy or de-identify it (Australian Privacy Principle 11.2). Specific retention periods are:

  • Member profile (name, email, mobile, emergency contact) — kept while you are a member. If you leave the club, your profile is de-identified (personal details removed) 24 months after your membership ends. We keep a de-identified record only where it is still linked to financial records we are legally required to retain.
  • Correspondence to club mailboxes (emails you send to a club role address, and any attachments) — deleted 24 months after receipt.
  • Notification and communication records — the per-recipient detail of who received a given message is removed 24 months after it was sent; only aggregate delivery counts are retained.
  • Financial records (fee payments, ledger entries, payment receipts) — retained for 7 years from the date of the transaction, in accordance with ATO record-keeping requirements under the Income Tax Assessment Act 1936 (Cth) §262A, then destroyed.
  • Account and role history (account creation, role changes, profile updates) and operational activity logs — kept readily accessible for 24 months, then moved to restricted cold storage accessible only to the club Administrator, and destroyed after 7 years in total.
  • Email dispatch records — retained indefinitely in our internal database; provider-side logs (Resend) are retained for 30 days per their default policy.
  • Error and application logs — retained for up to 90 days in our error monitoring system (Sentry) and up to 30 days in our hosting platform (Vercel).

Automated daily jobs enforce these windows: one moves account and operational history past its active window into cold archive storage, and another destroys or de-identifies records once they pass the periods above. Payment receipts stored in Supabase Storage are subject to the same 7-year window as financial records.

If you wish to request deletion of your personal information, please contact us at the address in section 10 below. Note that records subject to a legal retention obligation (e.g. financial records) cannot be deleted until the mandatory period has elapsed.

7. Access and correction

Under APP 12 and APP 13, you have the right to access the personal information we hold about you and to request correction of inaccurate data. You may update most information directly from your profile page. For other requests, contact us at the address below.

8. Complaints

If you believe we have breached the APPs, please contact us in the first instance. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

9. Changes to this policy

We may update this policy from time to time. Material changes will be notified to members by email. Continued use of the platform after notification constitutes acceptance of the revised policy.

10. Contact

Adelaide Falcons Cricket Club
Email: committee@adelaidefalcons.com.au