Privacy Policy

Last updated: 20 July 2026

This notice explains how Spike, operated by Bielov Software Limited ("we", "us"), collects and uses personal information when you use our website at www.volleyspike.app and the Spike mobile apps (together, the "Service"). We are the data controller for the personal data described here. Contact us at [email protected].

The short version

We collect what we need to run a volleyball community app — profiles, club and event participation, messages and posts, and payment records. We don't sell your data and we don't use it for advertising.

Children use Spike

Spike is built for community sport, including juniors. Under-13s can only be on Spike through a profile created and managed by a parent or guardian; 13–17s have additional protections. See section 2.

Who sees what

Your profile and participation are visible to the communities you join (your clubs, teams, groups and events) — that is what the app is for. See section 4.

Your choices

You can access and correct your data, control notifications, withdraw consents, and delete your account (30-day grace period, then deletion/anonymisation). See sections 7 and 9.

Contents

1. What Information We Collect

Information you give us

  • Account details: name, email address, password (stored as a secure hash), date of birth and country. Date of birth and country are required so we can apply the right age rules (section 2).
  • Profile information: what you choose to add — profile photo, playing positions, skill and preference details, and similar.
  • Family (household) information: if you use family features, the link between guardian and child profiles, the child's details a guardian provides, and the permissions and consents the guardian sets.
  • Content you create: posts, comments, polls, reactions, messages, photos, videos and documents you upload, and drills or training plans you create.
  • Invitations: if you invite someone who isn't on Spike yet, the name/email you provide for them (used only to deliver and manage the invitation).

Information created by using the Service

  • Participation records: your club, team and group memberships and roles, event registrations, responses, attendance and waitlist history.
  • Coaching records: evaluations and feedback a coach records about a player (shared with the player when the coach chooses to share them).
  • Payment records: when you pay for an event or a club subscription, we keep transaction records (what was paid, for what, when, and its status). Card details are collected and held by our payment processor Stripe — they never touch our servers. If you receive payments as an organizer, we hold your Stripe connected-account status and payout/balance information.
  • Technical data: IP address, device and app version information, and logs generated by normal operation (including security and audit logs).
  • Crash and diagnostic data: error reports and performance telemetry via Sentry, including limited session replay on the website (section 10).
  • Location: only if you use the map feature when creating an event — a one-off foreground location lookup to place the venue on the map. We do not track your location in the background.
  • Notification tokens: device push tokens so we can deliver notifications you have enabled.

We collect most information directly from you. Children's information may be provided by their guardian (section 2), roster and invitation details may be provided by your club, and Stripe provides us with transaction outcomes and connected-account data.

We do not intentionally collect special-category data (such as health, ethnicity or beliefs), and we ask you not to post it on the Service. We do not collect data for advertising, and we do not buy data about you from anyone.

2. Children's Data and Guardian Consent

Spike supports junior volleyball, so we process children's data — carefully, and with guardians in control:

  • Under 13: children under 13 cannot register themselves. They can only be on Spike as a guardian-managed profile: a parent or guardian creates the profile, provides the child's information, and gives the consents that control what the profile can be used for (for example event participation, messaging, photos, payments). A managed profile has no login of its own.
  • 13 to 17: young people aged 13 or over can register themselves (or a guardian can grant login access to a managed profile at 13+). In countries where the digital age of consent is higher than 13 (up to 16 in parts of the EU), we require guardian consent up to that age, based on the country you register in.
  • Guardian oversight: guardians can see and manage their linked children's activity through family features, according to the permissions they hold.
  • Turning 18: when a managed user turns 18, guardian management ends and consents given on their behalf expire; they continue with their own account and their own choices.

Extra protections for children on Spike:

  • no advertising or marketing use of any data — for anyone, and especially not children;
  • consent-gated features for managed children (a guardian must enable messaging, photo storage or sharing, payments and similar before they apply to the child);
  • community standards that specifically protect children, including rules about images of children and adult–minor contact, with reporting and takedown routes (see the Terms of Service);
  • guardians can ask us to remove content identifying their child and can request deletion of a managed profile.

If you believe a child is using Spike outside these rules, or that we hold a child's data without proper consent, contact us and we will investigate and fix it.

3. How and Why We Use Your Information

We use personal data to:

  • create and secure your account, and operate the Service's features (clubs, events, messaging, posts, coaching tools);
  • apply age rules and guardian controls;
  • process payments and subscriptions through Stripe, and keep required financial records;
  • send service communications (verification, security, payments, account lifecycle) and the notifications you have enabled;
  • keep the Service safe: prevent fraud and abuse, moderate reported content, protect children, and secure our systems;
  • fix problems and improve reliability using diagnostics and crash reports; and
  • comply with our legal obligations.

Our legal bases (UK GDPR)

  • Contract: most processing is necessary to provide the Service you signed up for.
  • Consent: feature-specific consents (especially those a guardian gives for a child), optional features like the venue-map location lookup, and anything else we ask you for specifically. You can withdraw consent at any time.
  • Legitimate interests: service security, abuse prevention, diagnostics and improvement — balanced against your rights, with extra weight given to children's interests.
  • Legal obligation: financial record-keeping, responding to lawful requests, and safeguarding disclosures.

4. Who Can See Your Information on Spike

Spike is a community platform, and sharing within your communities is its purpose. In general:

  • your profile is visible to members of the clubs, teams, groups and events you belong to;
  • your event responses and attendance are visible to the event's participants and organizers;
  • content you post is visible to the audience of the space you post it in (a group, a team, an event chat, and so on);
  • organizers and club admins can see the member information they need to run their activities (for example rosters and payment status for their events);
  • guardians can see their linked children's activity according to their permissions; and
  • coaching evaluations are visible to the coach (and club staff with access) and to the player once shared by the coach.

Organizers must only use member information for running their club or event (it's in the Terms of Service). What clubs do with information outside Spike (for example their own spreadsheets) is their responsibility as the collector of it.

5. Service Providers and Other Sharing

We share personal data with the providers who run parts of the Service for us:

  • Stripe — payment processing and organizer payout accounts (Stripe's privacy policy);
  • Amazon Web Services — cloud storage for uploaded media, content delivery, and sending our transactional emails;
  • Expo — delivering push notifications to your device (via Apple and Google push services);
  • Sentry — crash reporting, diagnostics and session replay, hosted in the EU (section 10);
  • Cloudflare — networking, security and content delivery in front of our services;
  • Google Maps — showing venue maps and converting locations to addresses when you use map features.

We may also share personal data:

  • with law enforcement, safeguarding authorities or regulators where the law requires it or where we believe someone — particularly a child — is at risk;
  • in connection with a sale, merger or reorganization of the Service, in which case this notice continues to apply to your data and we will tell you about any change of controller.

We do not sell personal data, and we do not share it with advertisers or data brokers.

6. International Transfers

We are UK-based and host the Service's data in the UK and EU. Some of our providers (for example Stripe, Expo, Cloudflare and parts of AWS) may process data in other countries, including the United States. Where that happens, we rely on appropriate safeguards recognised under UK data-protection law — such as UK adequacy regulations and the UK Addendum to the EU Standard Contractual Clauses — so your data keeps equivalent protection.

7. How Long We Keep Your Information

  • While your account is active: we keep your data so the Service works for you and your communities.
  • When you delete your account: there is a 30-day grace period during which you can change your mind. After it, we delete or anonymise your personal data across the Service. Anonymisation means records of past activity (for example that an event had a participant, or that a message was sent) may remain, but no longer identify you. Full propagation across all systems can take a short additional period after the 30 days.
  • Financial and payment records: kept for up to 7 years after the transaction, as required for tax and financial compliance (in pseudonymised form after account deletion).
  • Security and audit logs: kept for 3 years (7 years where payment-related).
  • Backups: deleted data may persist in backups for a limited period before being overwritten.

Guardians can request deletion of a managed child's profile at any time from family settings; the same process applies.

8. How We Keep Your Information Safe

We protect your data with technical and organisational measures including encryption in transit and at rest, token-based authentication, per-service access controls, security logging, and media access controls (uploads are private to their audience by default). Access to production data is restricted to what is needed to operate the Service.

No internet service can be guaranteed 100% secure, so please use a strong, unique password and contact us immediately if you suspect any problem with your account.

9. Your Rights

Under UK data-protection law (and the GDPR where it applies to you), you have the right to:

access a copy of your personal data
correct inaccurate data
have your data erased
restrict or object to processing
data portability
withdraw any consent at any time

You can exercise most of these directly: edit your profile in settings, manage consents and notifications in the app, and delete your account from account settings (web or app). For anything else — including access requests — email us and we will respond within the legal timescale (normally one month).

Guardians can exercise these rights on behalf of a managed child. Young people with their own accounts can exercise their own rights.

We do not make automated decisions about you that have legal or similarly significant effects.

10. Cookies, Crash Reporting and Session Replay

The website uses cookies and similar storage that are essential for signing you in, keeping your session secure, and remembering your preferences. We do not use advertising or cross-site tracking cookies.

For reliability, we use Sentry (EU-hosted) to collect crash reports and performance diagnostics from the website and apps. On the website this includes session replay — a reconstruction of a small sample of sessions (and sessions where an error occurred) that helps us fix bugs. Replay is configured to mask text you type and sensitive content. Diagnostic data is used only for fixing and improving the Service.

Because there is no settled standard for Do-Not-Track browser signals, we do not respond to them — but as described above, we do not track you across other websites in the first place.

11. Changes to This Notice

We update this notice when our practices or the law change; the "Last updated" date at the top always reflects the current version. For material changes — especially any affecting children's data — we will notify you by email and/or a notice in the Service before they take effect.

12. How to Contact Us and Complain

For any privacy question, request, or concern:

Controller: Bielov Software Limited

Registered in England and Wales: company no. 17407224

Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

ICO registration: ZC226188

Email: [email protected]

If you are unhappy with how we handle your data or your request, you have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or, if you live in the EU, to your local supervisory authority. We'd appreciate the chance to resolve it directly first.