Draft — not legal advice
Draft Privacy Policy
Last updated: July 2026
This is a working draft for ClubElfi's private pilot. It is provided for transparency and planning — not as legal advice. Your club should review it with counsel before relying on it for compliance decisions.
Overview
ClubElfi is software used by clubs to manage membership and operations. Clubs enter and control most information in the system. ClubElfi hosts and processes that information to provide the service.
Information clubs store in ClubElfi
Depending on how a club uses ClubElfi, the system may include:
- Member and household contact information (names, addresses, email, phone)
- Household and profile details (membership type, status, notes)
- Vehicles, children/dependents, and tools-to-loan listings
- Profile and vehicle photos uploaded by authorized users
- Activity schedules, attendance, and participation records
- Renewal, dues, and payment records entered by club officers
- Communications sent through ClubElfi, including optional file attachments
- Records of when a tracked communication download link was accessed
Authentication
ClubElfi uses passwordless sign-in. When you request access, we send a magic link to your email address via our email provider. We store a hashed token to complete sign-in and maintain a session cookie while you are signed in.
How information is used
- Operate the ClubElfi application for your club
- Send authentication, renewal, and club communication emails you or your officers initiate
- Store and serve uploaded photos and communication files
- Maintain audit logs of significant administrative actions
- Improve reliability, security, and support during the pilot
ClubElfi does not sell personal information.
Who can access information
Access within ClubElfi is limited by club role (for example, members, officers, and administrators see different areas). Club officers are responsible for entering accurate data and using communications features appropriately. ClubElfi operators can access hosted systems as needed to run, secure, and support the service.
Service providers
ClubElfi relies on third-party infrastructure to host the service, including:
- Vercel — application hosting
- Neon — PostgreSQL database
- Resend — transactional and club email delivery
- Vercel Blob — storage for member photos and communication file attachments
These providers process data on our behalf under their own terms and security practices. ClubElfi does not claim third-party certifications on their behalf.
Data retention
Clubs control most membership records. Audit and communication logs are kept to support club administration and troubleshooting. Retention practices may evolve during the pilot; clubs should export records they need for their own archives.
Security
We use industry-standard practices appropriate for a volunteer-club application: encrypted connections, signed sessions, role-based access, and private storage for sensitive files where supported. No system is perfectly secure; clubs should avoid uploading highly sensitive materials through communication features.
Contact
For privacy questions during the pilot, contact your club administrator or ClubElfi support at privacy@clubelfi.com (placeholder).