Privacy Policy
Version 2026-07-20 · Effective 20 July 2026
This policy explains what personal data Podium collects, why, on what lawful basis, who we share it with, how long we keep it, and the rights you have under the UK GDPR and the Data Protection Act 2018.
Draft, not yet reviewed by a solicitor
This document was prepared by Podium's engineering team so that the product has a good-faith, substantive policy in place during development. It has not been reviewed or approved by a qualified legal practitioner. It must be reviewed and signed off by a solicitor qualified in England and Wales, with particular attention to the provisions on minors, consumer rights, and data protection, before Podium accepts a single live user. Do not rely on it as legal advice.
1. Who is responsible for your data
Podium (legal entity name to be confirmed before launch) is the controller of the personal data described in this policy. We are based in the United Kingdom.
Data protection enquiries and rights requests: privacy@podium.com. Our registration with the Information Commissioner's Office (ICO), and the identity of our data protection contact, will be confirmed here before launch.
Where a brand and an athlete conclude a deal, each party remains a controller of the personal data they hold about the other for their own purposes. We are not responsible for what a counterparty does with data you choose to share with them.
2. What personal data we collect
Account data (all users). Email address, hashed password (held by our authentication provider, so we never see your password), account role, email verification state, the version and timestamp of the Terms and Privacy Policy you accepted, your cookie preferences, and account lifecycle timestamps including deactivation and deletion requests.
Athlete profile data. Display name, full legal name, date of birth and the derived flag recording whether you are under 18, height and weight, telephone number, profile and action photographs and highlight videos, sport, position, competitive level, university, academy or national programme, years active, achievements, performance statistics, social media account handles and audience figures, home city and country, travel radius, availability, and the deal categories you are seeking.
Guardian data (athletes under 18). Where the athlete is under 18 we collect the guardian's name, relationship to the athlete, email address, telephone number and the timestamp at which the guardian gave consent.
Team and agent profile data. Team or agency name, sports, competition level, venue, attendance and fan-reach figures, social accounts, sponsorship targets and brief documents, plus named contacts (commercial manager and primary controller name, role, email and telephone) and, for agents, specialisms, regions, services and verification status. Team accounts may also list additional administrators by name and email address.
Brand data. Company and trading name, industry, description, website and LinkedIn, logo and imagery, headquarters location, company registration and VAT numbers, and approval status.
Marketplace activity. Listings, connection requests and the message that accompanies them, matches, shortlists, blocks, reports you file or that are filed about you, and the contents of messages you send, including attachments and their file metadata.
Deal, contract and payment data. Proposals and their terms, concluded contracts and the associated e-signature evidence (signing timestamp, signer IP address and device description, e-signature provider and envelope reference), payment records including amount, currency, status, fees, receipt links and Stripe payment identifiers, saved card metadata (brand, last four digits and expiry, never the full card number), payout preferences including bank name, account holder and the last four digits of the account and sort code, and brand subscription records.
Security and device data. Login history (success or failure, IP address, user agent, coarse location), active sessions (session identifier, IP address, user agent, device label, last activity), and two-factor authentication state where enabled.
Notification and settings data. Your notification matrix and quiet hours, email digest and marketing preferences, visibility and discoverability settings, location precision, currency, and a log of the notifications we have generated for you.
Administrative records. Audit log entries recording significant actions taken on the platform, including by our staff, together with the IP address from which they were taken.
Special category data. We do not ask for health, racial or ethnic origin, religious, political or sexual-life data. Please do not put such information in free-text fields. Note that a photograph or a stated sport may indirectly reveal such characteristics; we do not use it for that purpose.
3. Why we use it, and our lawful basis
- To provide the platform: creating your account, publishing your profile, running discovery and matching, carrying messages, generating proposals and contracts, and taking payment. Basis: performance of a contract (Art. 6(1)(b)).
- To take payment and administer subscriptions. Basis: performance of a contract, and legal obligation for the accounting records we must keep (Art. 6(1)(c)).
- To keep the platform safe, covering fraud prevention, moderation, reports, blocking, login history, session management and audit logging. Basis: legitimate interests in protecting users and the service (Art. 6(1)(f)), and legal obligation where we must act.
- Safeguarding minors: recording guardian consent, flagging under-18 accounts, and acting on underage concerns. Basis: legitimate interests in child protection, and legal obligation.
- Service and transactional messages: verification emails, security alerts, deal and payment notifications. Basis: performance of a contract and legitimate interests. You cannot opt out of essential security and transactional messages while you hold an account.
- Marketing emails and optional analytics. Basis: your consent (Art. 6(1)(a)), which you may withdraw at any time in your settings or via the cookie preferences control in the footer. Withdrawal does not affect processing carried out before you withdrew.
- Retaining contracts and financial records after account closure. Basis: legal obligation and legitimate interests in establishing, exercising or defending legal claims.
- Improving the product using aggregated and anonymised usage information. Basis: legitimate interests.
Where we rely on legitimate interests we have carried out a balancing assessment; you may ask us for a summary of it and you have the right to object (see section 8).
5. International transfers
We aim to host data in the UK or the European Economic Area. Some of our processors, including Stripe and Vercel, operate globally, so personal data may be processed outside the UK, including in the United States.
Where that happens we rely on one of: an adequacy decision (or UK adequacy regulations) covering the destination; the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum; supported by a transfer risk assessment and, where appropriate, additional technical measures such as encryption in transit and at rest. You may request details of the safeguards applying to a particular transfer.
6. How long we keep it
- Active accounts: for as long as your account is open.
- After you request deletion: we hold the request for a 14-day grace period, during which you can cancel it simply by signing back in and cancelling. After that a scheduled job erases your data as described in section 7.
- Concluded contracts: retained until seven years after the contract was finalised (recorded on each contract as its retention date), to meet accounting and limitation-period requirements. After erasure of your account the retained contract record is stripped of personal identifiers.
- Payment and subscription records: retained for at least six full financial years, as required by tax and accounting law, in anonymised form once your account is erased.
- Login history and active sessions: deleted with your account; in normal operation, login history is kept for a limited security window.
- Data export files: download links expire 72 hours after the export is ready, and the file is purged.
- Moderation reports and audit logs: retained after account erasure, because they are the record of safety decisions and cannot be reconstructed. The free-text description and any internal notes are deleted once the report is closed, and IP addresses recorded against your actions are cleared.
- Backups: deleted data persists in encrypted backups for a short rolling window before those backups expire.
7. What happens when you delete your account
You can request erasure from your settings. We record the request and schedule the erasure 14 days later. Signing back in and cancelling the request during that window stops it.
When the erasure runs, an automated job:
- permanently deletes your profile (including photographs, videos, date of birth, guardian details, contact details and social accounts), your settings, your shortlists, blocks and connection requests, your matches, your message content and attachments, your notification history, your sessions and login history, your saved payment method metadata, your payout details, and your two-factor and data-export records;
- anonymises, rather than deletes, contracts, proposals, payments and subscriptions. Names, email addresses, addresses, IP addresses and device descriptions are removed or replaced; amounts, dates and record identifiers are kept, because we are legally required to retain the financial and contractual record; and
- replaces your user record with a tombstone: your email address is replaced with a non-routable placeholder and the account is permanently disabled. The empty record remains only so that the retained financial records stay internally consistent; it contains no information that identifies you.
We write an audit entry recording that an erasure took place, the date, and which categories were deleted or anonymised. That entry does not contain your personal data beyond the internal account identifier.
Content you sent to another user may remain visible to them where it forms part of a concluded deal record they are entitled to keep.
8. Your rights
Under the UK GDPR you have the right to:
- Access a copy of your personal data. You can generate a machine-readable export from your settings.
- Rectify inaccurate or incomplete data. Most of which you can correct directly in your profile.
- Erase your data (“right to be forgotten”), subject to the retention obligations in section 6.
- Restrict processing while a dispute about accuracy or legitimate interests is resolved.
- Object to processing based on legitimate interests, and to object to direct marketing at any time. absolutely and free of charge.
- Data portability: receive data you gave us in a structured, commonly used, machine-readable format.
- Withdraw consent at any time where we rely on it, without affecting prior processing.
- Not be subject to a solely automated decision with legal or similarly significant effects. Our match scoring is a ranking aid only; it does not decide anything about you on its own, and a human is always in the loop on account suspension and brand approval decisions.
To exercise a right, use your settings or email privacy@podium.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
You can complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113). We would appreciate the chance to resolve it with you first.
9. Children's data
Podium is not for anyone under 16. Athletes aged 16 and 17 may use Podium only with the involvement of a parent or guardian, whose name and contact details we hold for that purpose.
We take extra care with minors' data: an under-18 flag is derived automatically from the date of birth; guardian consent is recorded with a timestamp; and reports raising an underage or safeguarding concern are prioritised. We do not use a minor's data for marketing or behavioural profiling, and we do not run marketing cookies against accounts flagged as under 18.
A guardian may ask to see, correct or erase the data we hold about a minor athlete in their care by emailing privacy@podium.com. If we learn we hold data about someone under 16, we delete it.
10. Security
We use encryption in transit and at rest, row-level authorisation rules in the database so users can only read their own records, hashed passwords held by our authentication provider, optional two-factor authentication, session management with the ability to revoke a device, and audit logging of significant actions. No system is perfectly secure; if a breach is likely to result in a risk to your rights we will notify the ICO within 72 hours and tell you where the risk is high.
12. Changes to this policy
This is version 2026-07-20. We will post any update here with a new version date, and where the change is significant we will notify you and, where required, ask for your consent again.