UClub Store Privacy Disclosure Notes

Effective reference date: June 23, 2026

These notes are not public legal copy. Use them when completing App Store Connect App Privacy and Google Play Data safety forms so the store answers stay consistent with the Privacy Policy.

Likely Data Categories Collected

  • Contact info: name, email address, phone number, advisor email, payer contact details.

  • Identifiers: Supabase user ID, push token, Stripe customer IDs, Stripe connected account IDs, RevenueCat app user/customer identifiers, payment IDs.

  • User content: profile photos, club media, event images, chat messages, chat media, form responses, feedback, announcements.

  • Purchases and financial info: dues payment records, payment status, billing period, refund status, connected payout status, subscription/entitlement status. Full card and bank credentials are handled by payment providers.

  • Usage data: taps, saves, joins, RSVPs, boost events, analytics counters, notification activity, event registrations, app feature activity.

  • Diagnostics: app version, platform, device name when included in feedback, logs and errors needed to support the app.

  • Other data: university, account type, major, expected graduation term/year, interests, memberships, officer roles, permissions, dues status, event attendance, check-in status.

Likely Purposes

  • App functionality.

  • Account management and authentication.

  • User communication and notifications.

  • Payments, dues, subscriptions, refunds, and payout administration.

  • Safety, security, fraud prevention, moderation, reports, and abuse prevention.

  • Analytics for club leaders and product improvement.

  • Customer support and feedback.

  • Legal compliance.

Sharing / Third Parties To Consider

  • Supabase: authentication, database, storage, Edge Functions.

  • Stripe: dues payments, payment records, connected club payouts, fraud and compliance.

  • RevenueCat: premium subscriptions and entitlement management, when configured.

  • Expo and platform notification services: push notifications.

  • Brevo: transactional and support email delivery.

  • Apple and Google: app distribution, app-store services, notifications, and device permissions.

  • Other UClub users, club officers, organizers, and campus admins according to app roles and visibility.

Tracking / Advertising

Current policy position: UClub does not sell personal information and does not use personal information for third-party advertising or cross-app tracking. Keep this answer aligned with any future analytics, attribution, ad, or marketing SDK changes.

Sensitive Permissions To Explain

  • Notifications: announcements, event updates, chat alerts, role invites, dues reminders.

  • Photos/media library and camera: avatars, club media, event images, chat media.

  • Microphone/audio permission: only if required by the platform or enabled media features.

Before Submission

  • Host the Privacy Policy at an active public web URL, not a PDF, and link it in the app and store listings.

  • Make the Terms and Conditions available from the website and preferably from the app settings legal section.

  • Make sure App Store Connect App Privacy and Google Play Data safety answers match the actual SDKs and backend behavior in the submitted build.

  • Update these notes if new SDKs, ads, analytics, tracking, location, contacts, biometric, health, or sensitive-data features are added.

Create a free website with Framer, the website builder loved by startups, designers and agencies.