Privacy
Last updated [effective date]. This policy explains what Annuaro holds about people, why, who else handles it, how long it is kept, and what you can do about it. Annuaro is run by [legal entity] ("Annuaro", "we", "us").
1. Who this policy is for
Annuaro is club membership software. The people whose details pass through it fall into three groups, and the group you are in decides who is responsible for your data.
A club's officers. A treasurer, membership manager, or other officer who holds a sign-in to the club's account. Annuaro is the club's supplier and decides how officers' account details are handled; this policy is the full account of that.
A club's members. A person on a club's roster. The club decides what it records about its members, why, and for how long; Annuaro holds and processes those records on the club's behalf and under its instructions, as the club's service provider. If you are a member and want to see, correct, or delete what your club holds about you, ask your club. Section 8 explains how we help.
Visitors and correspondents. Anyone who reads annuaro.com or writes to hello@annuaro.com. Annuaro is responsible for what it holds about you.
Annuaro is offered to clubs in the United States, and the service runs in the United States.
2. What we hold
About a club's officers
- The officer's email address and a password, which is stored only in a hashed form by our sign-in service and is never readable by us.
- Which club or clubs the officer belongs to, when the officer was added, and which officer added them.
- The time the officer last signed in, kept by the sign-in service.
About a club's members
Recorded by the club's officers, imported from the club's previous system, entered by the member on the club's join form, or changed by the member after signing in:
- Name, email address, phone number, and an emergency contact.
- Membership status, renewal date, and paid-through date.
- Notes the club's officers write about the member's standing.
- Archived columns carried over from the club's previous system, kept read-only exactly as they were imported.
- Whether the member has agreed to receive the club's mail, when that changed, and why.
- The dues ledger: what the member owed and paid, the date, the method, such as card, check, cash, or a waiver, and any voided line with its reason.
- When a member signs in, the sign-in service holds the member's email address as a login record.
- For a card payment made through the club's payment page: the outcome and the payment provider's reference numbers for the charge and any refund. We never receive or store a card number.
About mail sent on a club's behalf
For each mail the service sends to a member for the club, a log line: the address it went to, the kind of mail, such as a renewal reminder or a cutover notice, when it was sent, and whether it was delivered, bounced, or reported as spam. Each reminder carries a link, unique to that member, that stops the club's mail.
About the club itself
The club's name, its plan, its paid-through date, any renewal instructions its officers wrote, the domain the club sends mail from and the state of its mail records, and the identifier and status of the club's own Stripe account. We never hold the club's Stripe credentials or its bank details.
About people who use a club's public pages
A club's join form asks for a name, an email address, and a phone number, which go onto the club's roster as a member record. To stop repeated submissions, the join form and the club's payment page record a scrambled form of the visitor's network address for 24 hours and then delete it. The scrambled form cannot be turned back into the address.
About visitors to annuaro.com
Our hosting provider keeps standard server logs of each request: the network address, the page requested, the time, and the browser type. We do not run analytics, advertising, or tracking scripts on any page.
The service sets three cookies: one that keeps a signed-in officer or member signed in, which scripts cannot read; one that remembers a light or dark display choice; and a short-lived one that carries a one-line notice after an officer changes the payment account. None carries tracking, and no third party sets cookies through the service.
About people who write to us
The mail you send to hello@annuaro.com and our replies.
3. Where it comes from
Officers enter and import the club's records. Members add or change their own details on the join form and after signing in. The club's payment provider reports the outcome of card payments. Our mail service reports whether each mail was delivered. Nothing about a club or its members comes from data brokers, social networks, or other outside sources.
4. What we use it for
We use the data above only to:
- run the service for the club: keep the roster, the ledger, and the mail log, and show each officer and member what they are entitled to see;
- send mail the club has asked us to send to its members, such as renewal reminders and cutover notices, under the club's own name;
- send our own operational mail: sign-in links for members and officers, password resets, renewal invoices, and notices about the club's account;
- answer support requests;
- keep the service safe, for example by limiting repeated submissions to a public form; and
- meet a legal obligation or respond to lawful process.
We do not sell personal information, share it for advertising, use it to profile anyone, or share one club's data with another club.
5. Who else handles it
Annuaro runs on services provided by other companies. Each one receives only what its job needs, under a contract that limits it to that job.
- Supabase provides the database that holds every record above and the sign-in service that holds officer and member email addresses and officer password hashes. Hosted in [region].
- Netlify hosts the service and keeps the server logs described in section 2.
- Resend delivers mail. For each mail it receives the address, the subject, and the body, and it reports delivery, bounces, and spam complaints back to us.
- Stripe runs the club's own payment account and the page a member pays on. When a member pays, Stripe receives the member's email address and a reference to the member's record from us so the payment can be matched to the member, and Stripe collects the card details itself. Stripe's own privacy policy governs what Stripe holds. Stripe also runs the hosted invoice page a club's officer pays the club's subscription on.
- [Backup location] holds an encrypted weekly copy of the database and the second copy of each migration snapshot, for recovery only.
We may also share data with our professional advisers under a duty of confidence, with a successor that takes over the service and this policy, or when the law requires it. When the law allows, we tell the affected club before we hand over its data in response to legal process.
6. How long we keep it
While a club is active. The club's records stay as long as the club's account is open. A club can export all of them at any time, and its officers can correct or delete member records themselves. A ledger line is never deleted while the club stands; a mistaken line is voided and stays visible with its void, because the ledger is the club's financial record.
When a Club plan subscription lapses. From the day after the club's paid-through date the account is read-only for 60 days and closed from day 61. Twelve months after the lapse date we delete the club's account and every record in it, or sooner if the club asks in writing. A club on the Free plan never lapses; its records stay until the club asks us to close the account.
When a club leaves. A club that closes its account gets its export first, and we then delete its records, including the mail log and the archived columns.
Migration snapshots. Everything extracted from a club's previous system during a migration is kept as one frozen snapshot for 60 days after cutover, or after a stopped migration. In that window we do not delete it and we do not change it, and the club can ask for a copy. At the end of the 60 days we delete it from both storage locations.
Short-lived records. The scrambled network address the join form and payment page record is deleted after 24 hours. Server logs are kept for our hosting provider's standard period. Backup copies roll off within [number] weeks.
Officers and correspondence. An officer's sign-in is removed from the club when the club asks us, and we delete the login itself on request or when the club's account is deleted. Mail to hello@annuaro.com is kept for as long as it is needed to deal with the request and for our own records.
7. How we protect it
- Every connection to the service is encrypted in transit.
- Each club's records are kept apart from every other club's, and that separation is tested as part of the service so that no officer or member can reach another club's data.
- Officers sign in with a password; members sign in with a one-time link sent to the address on their record, so no member password exists to be lost.
- Card numbers never pass through the service. Stripe collects them on its own page.
- Passwords are stored only as hashes by the sign-in service.
- Our own access to production data is limited to what running the service and answering support needs.
If we learn of a breach that affects a club's data, we tell the club's officers without undue delay and give them what they need to tell their members and meet their own obligations.
8. Your choices and rights
If you are a club member. Sign in with the link the club's sign-in page sends to the email address on your record. You can then read your own record and dues history and change your contact details. Every reminder the club sends you through the service carries a link that stops the club's mail. For anything else, including a request to correct or delete your record, ask your club. Clubs can do all of this themselves, and we help a club answer a member's request within 30 days when it asks us to.
If you are a club officer. Another officer can remove your sign-in from the club's account. To change your sign-in address or to have your sign-in deleted, write to us.
If you wrote to us or visited the site. Write to hello@annuaro.com to ask what we hold about you, to correct it, or to have it deleted. We answer within 30 days and may ask you to confirm your identity first.
We never treat anyone differently for exercising these rights.
9. Children
Annuaro is not directed to children, and we do not knowingly collect personal information from a child under 13 through annuaro.com or a club's public pages. A club that keeps records of members under 13, for example a family or youth club, does so as the club's own record, entered by its officers, and is responsible for having a parent's or guardian's consent. If you believe a child has entered their own details on a join form, tell the club or write to us and the record will be deleted.
10. Notice for residents of California and other states
Some states give their residents rights over personal information, including the right to know what a business holds, to have it deleted, to correct it, and to opt out of its sale or sharing. Annuaro does not sell or share personal information for advertising, and does not use it to make automated decisions about anyone. Because nothing is sold or shared, an opt-out preference signal such as Global Privacy Control has nothing to switch off; every visitor is already treated as opted out.
For a club's member records, Annuaro acts as the club's service provider and processes the records only on the club's instructions; a request about those records goes to the club. For officer accounts, correspondence, and site visits, Annuaro is responsible, and section 8 says how to make a request. We do not discriminate against anyone for making one.
The categories of personal information we hold, the sources, the purposes, and the recipients are set out in sections 2 to 5 of this policy.
11. Changes to this policy
We may change this policy. For a change that reduces what we promise here, we email every club's officers at least 30 days before it takes effect. The date at the top of this page shows the current version.
12. Contact
Questions about privacy go to hello@annuaro.com.
[Legal entity] [Mailing address]