Privacy and data protection
Privacy policy
How ViaRoster handles information about organisers, families and travellers.
Last updated: 17 September 20261. Who is responsible for your information?
ViaRoster is currently operated by Martin Chamberlain in the United Kingdom. For information used to run this website, administer organiser accounts and manage the ViaRoster service, ViaRoster acts as the data controller.
When a club, academy or tour operator uses ViaRoster for a trip, that organisation will normally decide why traveller information is collected and how it is used. It is therefore normally the data controller and ViaRoster provides the platform as its data processor. The trip-specific privacy notice should identify the relevant controller and any other organisations involved.
2. Information we may process
- organiser names, email addresses, roles and account activity;
- family and traveller names, dates of birth, nationality and family or guardian relationships;
- adult contact details, emergency contacts and relevant accessibility, dietary or health information;
- passport, eligibility, flight, booking, accommodation and local transport information;
- trip costs, payment references, payment status and reconciliation records;
- invitation, access, audit, security and technical service records; and
- communications and requests sent to ViaRoster or a trip organiser.
Trip organisers should collect only information that is necessary for the trip. Children’s information and passport or health-related details receive additional protection and are not displayed on public summary pages.
3. Why information is used
Information is used to provide and secure the platform, manage accounts and permissions, organise travel, confirm eligibility and bookings, coordinate guardians and emergency contacts, calculate and reconcile payments, communicate trip updates, meet legal or safeguarding responsibilities, and investigate service or security issues.
Depending on the context, the lawful basis may be performance of a contract, steps requested before entering a contract, compliance with a legal obligation, legitimate interests in securely administering group travel, consent, or protection of vital interests. A trip controller is responsible for confirming the appropriate basis for its trip, including an additional condition where special-category information is required.
4. Who information may be shared with
Access may be provided to authorised club or trip organisers and, where necessary, to the relevant tour operator, accommodation provider, airline, transport provider, tournament organiser, insurer, payment provider, emergency service or public authority.
ViaRoster also uses trusted technology providers to operate the service, including Google Firebase for authentication and database services and Vercel for website hosting and delivery. Providers may process limited technical information under contractual and security controls.
5. International transfers
Some suppliers may process information outside the United Kingdom. Where this happens, the responsible controller must use an approved transfer mechanism or another lawful safeguard and can provide further information on request.
6. How long information is kept
Trip information is kept only for as long as it is needed to organise and complete the trip and deal with any legal, safeguarding, insurance, dispute or accounting requirements. The PSF Milan 2027 pilot is configured to review sensitive traveller and emergency information for secure deletion 90 days after the trip, subject to those exceptions.
Account, audit, contractual and payment records may be kept for longer where needed for security, legal claims or financial record-keeping. Each commercial trip will have a documented retention schedule agreed with its controller.
7. Security
ViaRoster uses role-controlled access, organisation-separated records, encrypted connections, secure session cookies, audit records and retention controls. No online service can remove every risk, so access codes and account credentials should be kept private and suspected misuse reported promptly.
8. Your rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict your information, object to certain uses, receive portable information, or withdraw consent. For trip data, contact the organisation named in the trip privacy notice. You can also contact ViaRoster using the address above.
You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.
9. Changes to this policy
This policy will be reviewed as ViaRoster develops. Material changes will be highlighted before new uses of personal information begin.
Back to website