Last updated: 25 June 2026
ClubEasy ("we", "us", "our") provides gym management software at clubeasy.app. ClubEasy is operated by Joel Nathan Shapcott (ABN 39 683 259 554), trading as ClubEasy App, based in Queensland, Australia. We are committed to protecting personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle the personal data of individuals in the European Union or United Kingdom, we also aim to comply with the EU/UK General Data Protection Regulation (GDPR).
ClubEasy is used by martial arts gyms ("Gyms") to manage their members. When a Gym uses ClubEasy, the Gym decides what member information to collect and why — in data-protection terms the Gym is the "controller" and we act as the "processor" on the Gym's behalf. If you are a gym member, your gym is the primary holder of your information — contact them first with questions about how your information is used. This policy also covers information we collect as a controller in our own right, such as gym-owner accounts and visitors to our website.
On our public website we use a small number of cookies and similar technologies. Strictly necessary cookies (for example, to keep you signed in and to remember your cookie choice) are always active. With your consent, we also use analytics and advertising cookies:
We use Google Consent Mode with region-specific defaults. For visitors in the EU, UK, EEA and Switzerland, analytics and advertising cookies are denied by default and are only enabled after you accept them via our cookie banner. For visitors in other regions (such as Australia), these cookies may be enabled by default; you can decline them via the cookie banner at any time. Wherever you are, you can also change or withdraw your choice by clearing the cookie/site data in your browser, or by using your browser's cookie controls. These cookies are not used on our staging or development environments.
We do not sell personal information, and we do not use member portal data for advertising.
Where the GDPR applies, we rely on: performance of a contract (to provide the service you or your gym have signed up for); consent (for analytics/advertising cookies and optional communications, which you may withdraw at any time); legitimate interests (to secure, maintain, and improve the service, balanced against your rights); and legal obligation (to meet record-keeping and compliance requirements). For member data we process on a Gym's instructions, the Gym is responsible for establishing the lawful basis.
Member data is stored on servers located in Australia. Credentials and payment-provider keys are encrypted at rest, access is restricted by role-based permissions, and connections are encrypted in transit (TLS). Some of the service providers listed below process limited data overseas (including in the United States). Where we transfer personal data of EU/UK individuals overseas, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an equivalent mechanism.
For gyms: our Data Processing Agreement sets out how we process member data on your behalf, including the full sub-processor list and change-notice process.
ClubEasy is offered to gyms and gym owners, not directly to children. Where a gym trains minors, a parent or guardian (together with the gym) creates and controls the child's record. We do not knowingly collect information directly from children. For EU/UK users, parental consent requirements under GDPR Article 8 are the responsibility of the Gym as controller. If you believe a child's information has been provided to us improperly, contact us and we will address it.
You can view and update most of your information in the member portal. Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, and (in the EU/UK) receive a copy of your data in a portable format. To exercise these rights, contact your gym, or email us at [email protected]. We will respond within the timeframe required by applicable law.
We keep personal information for as long as an account is active and as needed to provide the service. When a gym closes its account, its data is available for export on request for 30 days, after which it is deleted, unless we are required to retain it to meet a legal obligation.
We comply with the Notifiable Data Breaches (NDB) scheme. If a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC). Where the GDPR applies, we will also notify the relevant supervisory authority within the required timeframe.
If you have a privacy concern, contact us at [email protected] and we will respond within 30 days. If you are not satisfied with our response, you may complain to the OAIC at oaic.gov.au. If you are in the EU/UK, you may also lodge a complaint with your local data-protection supervisory authority.
Joel Nathan Shapcott, trading as ClubEasy App (ABN 39 683 259 554), Queensland, Australia. Email [email protected].
We may update this policy from time to time. Material changes will be notified via the app or email.