1. Introduction
This Privacy Policy explains how Activora ("we", "us", "our") collects, uses, stores and protects personal information when you use our booking and management platform.
Activora helps activity providers, clubs, holiday camps, wraparound care settings, sports organisations and similar providers manage bookings, attendance, payments and communications with parents and guardians.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) and applicable standards relating to children's data.
Please read this policy carefully. By creating an account, completing onboarding or making a booking through Activora, you acknowledge that you have read and understood how we handle personal information.
2. Who we are
Activora operates the Activora booking platform. For the purposes of UK data protection law, Activora is the data controller responsible for personal information processed through the platform, except where a club or provider acts as an independent controller for their own customer relationships.
When you book an activity with a provider through Activora, that provider may also process your data as a separate controller for operational, safeguarding and attendance purposes. Providers are responsible for their own privacy notices where required.
- Platform
- Activora
- Contact email
- adminactivora@gmail.com
- Registered address
- 61 Frances Street, SE18 5AD
- Country
- United Kingdom
3. Information we collect
The tables below summarise the main categories of personal information processed through Activora. We collect only what is needed for bookings, safeguarding, payments and platform operation.
Parent and guardian data
| Data field | Purpose | Required |
|---|---|---|
| Full name | Account identification, bookings and communications | Yes |
| Email address | Login, booking confirmations and service messages | Yes |
| Phone number | Urgent booking or safeguarding contact | Often |
| Emergency contact details | Contact in an emergency during an activity | Often |
| Relationship to child | Verify parental responsibility and safeguarding | Often |
| Account credentials | Secure authentication | Yes |
| Booking and payment history | Manage reservations, refunds and receipts | Generated |
| Communication preferences | Respect marketing and notification choices | Optional |
| Reviews and feedback | Improve services and display public ratings where enabled | Optional |
Child data
| Data field | Purpose | Required |
|---|---|---|
| Full name | Identify the child on registers and bookings | Yes |
| Date of birth / age | Age-appropriate sessions and safeguarding | Yes |
| Medical conditions | Safe participation where disclosed | Optional |
| Allergies | Health and safety during activities | Optional |
| SEN / accessibility needs | Reasonable adjustments and inclusion | Optional |
| Emergency contacts | Contact if parent unavailable during session | Often |
| Attendance records | Registers, safeguarding and billing | Generated |
| Photos or media | Only where explicitly consented by parent/guardian | Optional |
| Safeguarding notes | Welfare concerns raised by providers where necessary | As needed |
Provider, club and organisation data
| Data field | Purpose | Required |
|---|---|---|
| Owner and staff names | Account management and support | Yes |
| Business email and phone | Verification, support and operational contact | Yes |
| Club or organisation name | Public listings and customer-facing pages | Yes |
| Business type and categories | Onboarding, search and compliance | Yes |
| Venue addresses | Session location and parent directions | Often |
| Profile, branding and media | Marketing pages and customer experience | Optional |
| Payout and billing details | Processed via payment partners (e.g. Stripe Connect) | For paid activities |
| Subscription plan | Platform access and billing | Yes |
| Session and activity data | Booking, registers and reporting | Generated |
| Customer and register records | Operational management by the provider | Generated |
Technical and usage data
| Data field | Purpose | Required |
|---|---|---|
| IP address | Security, fraud prevention and approximate location | Automatic |
| Device and browser type | Compatibility, diagnostics and security | Automatic |
| Session and authentication cookies | Keep you signed in and secure sessions | Automatic |
| Server and application logs | Troubleshooting, audit and security monitoring | Automatic |
| Analytics identifiers | Understand usage and improve the platform | Where enabled |
| Error and performance reports | Fix bugs and maintain reliability | Automatic |
| Referrer and page views | Navigation analytics and product improvement | Where enabled |
4. Special category data
Some information you or a provider enter may relate to health, disability or safeguarding. Under UK GDPR this can be special category data.
We only collect medical, allergy, SEN or accessibility information where it is necessary for safe participation, reasonable adjustments, safeguarding or legal obligations. Providers should collect the minimum information required for their activity.
Where consent is the appropriate lawful basis for special category data, we rely on the parent or guardian providing that information knowingly as part of a booking or profile. You may withdraw consent for optional health data by updating your profile or contacting us, subject to legal and safeguarding limits.
5. How we use information
We use personal information for the following purposes, depending on your role and how you interact with Activora:
Account and platform services
- Creating and managing user accounts for parents, providers and staff.
- Authenticating users and maintaining secure sessions.
- Enabling club onboarding, profile setup and dashboard access.
Bookings and attendance
- Processing activity bookings, waitlists and session registers.
- Sharing booking details with the relevant provider.
- Recording attendance for safeguarding, billing and operational needs.
Payments and refunds
- Facilitating card and direct debit payments through payment partners.
- Issuing receipts, invoices and refund processing.
- Managing provider payouts and platform subscription fees.
Communications
- Sending booking confirmations, reminders and service notifications.
- Delivering provider messages about sessions or schedule changes.
- Responding to support requests and callback enquiries.
Safeguarding and fraud prevention
- Investigating suspicious activity and protecting accounts.
- Supporting providers with welfare concerns where appropriate.
- Maintaining audit logs for security and compliance.
Analytics and improvement
- Understanding how features are used to improve Activora.
- Measuring performance and fixing errors.
- Developing new tools for providers and parents.
Legal and regulatory
- Complying with tax, accounting and record-keeping obligations.
- Responding to lawful requests from regulators or courts.
- Enforcing our terms and protecting our legal rights.
6. Legal basis
Under UK GDPR we must identify a lawful basis for processing personal data. The table below summarises the main bases we rely on:
| Purpose | Lawful basis | Explanation |
|---|---|---|
| Creating and managing your account | Contract | Processing is necessary to provide the Activora service you sign up for. |
| Processing bookings and attendance | Contract | Required to deliver the booking and register features you use. |
| Payment processing and refunds | Contract | Necessary to take payment for activities and manage financial transactions. |
| Optional marketing emails or newsletters | Consent | We only send marketing where you opt in. You can unsubscribe at any time. |
| Medical, allergy or accessibility information | Consent / Legitimate interests | Collected where necessary for safety and inclusion, often with explicit parent input. |
| Platform security and fraud prevention | Legitimate interests | Protecting users, providers and the platform from misuse and unauthorised access. |
| Analytics to improve Activora | Legitimate interests | Understanding aggregated usage to improve reliability and user experience. |
| Tax, accounting and legal record keeping | Legal obligation | Retaining financial and booking records as required by UK law. |
| Safeguarding and welfare concerns | Legitimate interests / Legal obligation | Protecting children and meeting safeguarding duties where applicable. |
7. Payments
Activora uses trusted payment partners to process transactions securely. Card payments are handled through Stripe, including Stripe Connect for provider payouts. Direct debit collections may be processed through GoCardless where enabled.
We do not store full payment card numbers on Activora servers. Payment partners tokenise card details and process transactions on our behalf under their own privacy policies and PCI-DSS standards.
We may retain transaction references, amounts, dates, refund status and limited billing metadata for accounting, dispute resolution and legal compliance.
8. Communications
We send transactional messages that are necessary for the service, including account verification, booking confirmations, payment receipts, schedule changes and security alerts. These are not marketing messages and cannot always be opted out of while you use the platform.
Providers may send operational messages to customers about their sessions through Activora. Providers are responsible for ensuring those messages are appropriate and lawful.
Marketing communications about Activora products or features are sent only with your consent. You can withdraw marketing consent through account settings where available, unsubscribe links in emails, or by contacting us.
9. Data sharing
We do not sell personal information. We share data only as described below:
Activity providers and clubs
- Booking, child and contact details needed to deliver the activity you booked.
- Attendance and register information for sessions you attend.
Schools and partner organisations
- Where a school or organisation uses Activora for wraparound care or clubs, limited data may be shared as configured by that organisation.
Payment providers
- Stripe and GoCardless receive data necessary to process payments, verify accounts and prevent fraud.
Analytics and infrastructure providers
- Cloud hosting, monitoring and analytics services that help us run Activora securely.
- These providers act as processors under contractual safeguards.
Professional advisers and authorities
- Lawyers, accountants or insurers where reasonably necessary.
- Regulators, courts or law enforcement when required by law.
10. International transfers
Activora is based in the United Kingdom. Some service providers we use may process data outside the UK, including in the European Economic Area, United States or other countries.
Where personal data is transferred internationally, we implement appropriate safeguards such as UK International Data Transfer Agreements, Standard Contractual Clauses or transfers to countries with adequacy decisions, as applicable.
You may contact us for more information about the safeguards applied to specific transfers.
11. Data retention
We keep personal information only for as long as necessary for the purposes described in this policy:
| Data type | Retention period | Notes |
|---|---|---|
| Bookings and attendance records | 7 years | For accounting, disputes and regulatory requirements. |
| Payment and transaction records | 7 years | As required for tax and financial reporting. |
| Account profiles | Until deletion | Retained while your account is active. Deleted or anonymised after a verified deletion request, subject to legal retention limits. |
| Support enquiries | 24 months | To resolve issues and improve support quality. |
| Analytics data | 26 months | Aggregated usage metrics; identifiers removed or shortened where possible. |
12. Children's privacy
Activora is designed for use by parents, guardians and activity providers. Children should not create accounts or provide personal data directly without parental involvement.
Parents and guardians are responsible for the accuracy of child information they enter, for consenting to bookings on a child's behalf, and for reviewing provider requirements before booking.
If you believe a child has provided personal information to us without appropriate consent, please contact us and we will take steps to delete it where required.
13. Security
We take appropriate technical and organisational measures to protect personal information against unauthorised access, loss or misuse.
- Encryption of data in transit using TLS and encryption at rest for sensitive fields.
- Role-based permissions so staff and providers access only what they need.
- Access controls, session management and authentication safeguards.
- Regular backups and infrastructure monitoring.
- Audit logs for administrative and security-sensitive actions.
Learn more on our Security page.
14. Your rights
Under UK GDPR you have rights in relation to your personal data. These rights are not absolute and may be limited in some circumstances, for example where we must retain records by law.
- Right of access
- Request a copy of the personal data we hold about you.
- Right to rectification
- Ask us to correct inaccurate or incomplete information.
- Right to erasure
- Request deletion of your data where there is no compelling reason to continue processing.
- Right to data portability
- Receive your data in a structured, commonly used format where processing is based on consent or contract.
- Right to restrict processing
- Ask us to limit how we use your data in certain cases.
- Right to object
- Object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent
- Withdraw consent at any time where processing is based on consent.
- Right to complain
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you are unhappy with how we handle your data.
16. Data requests
To exercise your privacy rights, contact us using the form below or email adminactivora@gmail.com. We aim to respond within one month, as required by UK GDPR.
Submit a data request
Use this form to email our team about access, correction, deletion or other privacy requests. We may need to verify your identity before responding.
17. Contact details
For privacy questions, data requests or concerns about this policy, contact:
Activora61 Frances Street, SE18 5AD
United Kingdom
adminactivora@gmail.com
18. Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in law, our services or how we process data.
When we make material changes, we will update the effective date and version number at the top of this page and, where appropriate, notify you by email or in-app notice.
Continued use of Activora after changes take effect constitutes acceptance of the updated policy, except where further consent is required by law.
Version history
Current version: 1.0.0
- v1.0.0
Initial publication of the Activora Privacy Policy covering parents, children, providers, payments, cookies and UK GDPR rights.
