← Ubouk

Privacy Policy

How Ubouk collects, uses, and protects personal information.

Effective: September 13, 2026 · Last updated: September 13, 2026

1. About this policy and our two roles

Ubouk (“we”, “us”) operates a multi-tenant platform that lets sports organizations run branded registration portals, take payments, communicate with families, and manage participants and staff. Our role under privacy law depends on the information:

  • Information we control. For the accounts people create on Ubouk (organization owners, staff, and family account holders), our billing records, and our usage analytics, Ubouk is the organization responsible for that personal information. This policy describes how we handle it.
  • Information we process for an organization. When you register with a sports organization through Ubouk, that organization decides what to collect and why, and is responsible for it. Ubouk acts only as its service provider (processor), handling that data on the organization’s instructions. For questions about how a specific organization uses your information, contact that organization — see its own privacy page.

2. Who we are and how to reach our Privacy Officer

The person responsible for the protection of personal information is Luciano Votano, Director. Reach our Privacy Officer at hello@votanoasia.com, or by mail at VOTANO ASIA SOLUTIONS LIMITED, Unit 2A, 17/F, Glenealy Tower, No. 1 Glenealy, Central, Hong Kong.

3. Personal information we collect

  • Account details — name, email, phone, hashed password, and any profile photo.
  • Organization & billing — organization profile, payout account identifiers, billing contact, and subscription details.
  • Participant information (including children’s) — names, dates of birth, gender, medical notes, emergency contacts, custom form answers, and signed waivers. We collect this on behalf of the organization you register with.
  • Payment information — payments are processed by our payment provider (Stripe). We do not store full card numbers; we keep only references such as card brand, last four digits, amounts, and receipts.
  • Communications — messages we send you, whether emails were delivered or opened, and your marketing consent and preferences.
  • Documents — files you or an organization upload (e.g. client or HR documents).
  • Usage & technical data — log data, first-party page-view analytics, general device/browser information, and a random visitor identifier stored in your browser.

4. Why we use it

  • Provide, operate, and secure the platform and your account.
  • Process registrations, payments, refunds, and receipts.
  • Send transactional messages (confirmations, receipts, reminders) and — only with your consent — marketing messages you can unsubscribe from at any time.
  • Provide customer support and respond to requests.
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Produce aggregate analytics to maintain and improve the service.
  • Comply with legal, tax, and accounting obligations.

5. Consent — and consent for children

We rely on your consent and on what is necessary to provide a service you have requested. Marketing email is sent only with your opt-in consent, which you can withdraw at any time.

Children. A parent or guardian must create the account and provide the information used to register a minor. Consent for a minor’s personal information must be given by a parent or guardian, unless the law of the minor’s place of residence allows the minor to consent themselves. By registering a child, you confirm you have the authority to provide their information and consent on their behalf.

6. Who we share it with, and cross-border processing

We do not sell personal information. We share it with service providers who help us run the platform, under contracts that limit their use of the information to providing their service to us:

  • Stripe — payment processing and payouts (United States / Ireland).
  • Resend — sending email (United States).
  • Cloudflare R2 — file/document storage (global).
  • Turso — database hosting (United States / global).
  • Vercel — application hosting (United States).
  • Upstash — rate limiting and service protection; processing regions depend on the configured account.
  • Twilio — SMS delivery when enabled.
  • OpenAI, Anthropic, Mistral, DeepSeek — available AI providers. Only the selected and assessed provider receives a request; listing an option does not mean it is active. Any intermediary connection must also be assessed.

Personal information may be stored, processed or accessed outside your country or region, including in Hong Kong, where Ubouk is based, and the United States. Authorized administration may also take place from mainland China and Belgium. Before processing real personal information through a provider or an overseas access arrangement, Ubouk requires a documented privacy assessment and the applicable contractual safeguards.

The organization you register with also receives your registration data and is responsible for that data. We may also disclose information where required by law or to protect rights and safety.

7. Automated processing

The optional Ubouk Assistant helps authorized staff work with their organization’s data. Messages, requested records and reviewed image or PDF attachments are sent to the selected AI provider. Free text and attachments can contain sensitive information; users must remove information that is unnecessary for their request.

The assistant does not make decisions based exclusively on automated processing that produce legal or similarly significant effects about an individual. If that changes, we will disclose it and provide information about the automated decision-making involved.

8. How long we keep it

We keep personal information for the purposes described above and applicable legal obligations, then delete or anonymize it. Portal page-view events become eligible for scheduled deletion after 365 days, and assistant conversations after 90 days without activity. Documented retention holds can postpone deletion.

Individual marketing email and SMS copies become eligible for deletion three years (1,095 days) after sending. Individual opening and click events become eligible three years (1,095 days) after each event. This removes the recipient-level message content and engagement details at their respective deadlines; campaign totals, templates, contacts and consent records follow separate retention rules. Deletion takes place on the next successful scheduled run, subject to documented holds.

Managed encrypted backups become eligible for deletion after 30 days and are limited to 30 versions. Deletion runs on the next successful scheduled pass. Documented retention holds can extend that period. Deleting information from the active service does not immediately remove every backup copy.

9. How we protect it

We use encryption in transit, hashed passwords, role-based access controls, strict per-organization data isolation, and time-limited signed links for private documents. No system is perfectly secure, but we work to protect your information and to limit access to those who need it.

10. Your rights

Subject to legal limits, you may ask us to:

  • Access the personal information we hold about you;
  • Correct or update it;
  • Delete it, or stop disseminating it where the law allows;
  • Withdraw your consent (for example, to marketing);
  • Receive a copy of the computerized personal information you provided, in a structured technological format (portability).

To exercise a right, contact our Privacy Officer (section 2). We will respond within 30 days. If you are not satisfied, you may file a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD) or the data-protection authority in your own jurisdiction.

For matters subject to Québec privacy law, you may also contact the Commission d’accès à l’information du Québec.

11. Confidentiality incidents

If a confidentiality incident involving personal information presents a risk of serious injury, we will notify the affected individuals and the relevant authorities where required, with diligence, and keep a register of such incidents.

12. Cookies and tracking

We use essential cookies needed to keep you signed in, and first-party page-view analytics. We do not use third-party advertising or cross-site trackers. You can turn off page-view tracking using the “Do not track me” link in the footer of any portal page.

Email tracking is optional and chosen separately for each club. When you authorize it, new marketing emails may include a tracking image and tracked links provided by Resend. These record openings and clicks associated with the recipient and message, so the club can measure its campaigns and personalize follow-ups. Without this authorization, new emails use a sender without opening or click tracking.

You can withdraw email tracking in your club communication preferences or through the preference link in a marketing email, while continuing to receive marketing emails you have authorized. Essential registration emails are unaffected. Portal page-view tracking has its own “Do not track me” choice. Withdrawing tracking does not automatically delete information already collected: contact the club or our Privacy Officer for these requests. Email privacy features can affect opening statistics, which do not prove that a person read a message.

13. Changes to this policy

We may update this policy. If changes are material, we will take reasonable steps to notify you. The “last updated” date above shows the current version.

14. Contact

Privacy questions or requests: hello@votanoasia.com. General contact: VOTANO ASIA SOLUTIONS LIMITED, Unit 2A, 17/F, Glenealy Tower, No. 1 Glenealy, Central, Hong Kong.

Terms of ServicePrivacy Policy