CorSports
Legal

Privacy Policy

Last updated: 15 September 2026

CorSports & Event Management (“CorSports”, “we”, “us”) builds and operates the CorSports platform: software for running rugby competitions, match days and venues. We are based in Cape Town, South Africa. This policy explains what personal information we process, why, and the rights you hold under the Protection of Personal Information Act, 2013 (POPIA). Where we serve users in other jurisdictions, we apply the same standard of care.

1. The two roles we play

POPIA distinguishes between a responsible party, who decides why and how personal information is processed, and an operator, who processes it on the responsible party's behalf. We play both roles, for different data.

We are the responsible party for the information you give us directly: your account details, billing records, messages you send through this website, and technical logs generated by your use of the platform.

We are an operator for the content that organisations (unions, schools, clubs, tournament organisers) load into their own workspace: player and team details, team sheets, squad lists, compliance documents, bookings and event information. The organisation is the responsible party for that information. We process it only on their instruction, under the data-processing terms in our Terms of Service. If you are a player, parent, team manager or booker and want to know why an organisation holds your information, that question belongs with the organisation first. We will assist them in answering it.

2. What we collect

Account information. Name, email address, organisation, and the permissions assigned to you inside a workspace.

Workspace content. Whatever an organisation records to run its operations: fixtures, squads, team sheets, match events, bookings, documents and messages. Some of this is personal information about players, officials and staff. Some of it is special personal information, covered in section 4.

Payment information. Payments are processed by PayCloud. We receive transaction references, amounts and settlement status. We never see or store card numbers.

Technical information. Server logs, IP addresses, and an audit trail of state-changing actions inside the platform. The audit trail exists so that organisations can see who changed what, which is a feature, not surveillance.

Public pages. Spectator boards, booking pages and manager portals work through tokenised links and do not require an account. We deliberately keep personally identifying detail off public spectator surfaces.

3. Children's information

School and age-grade rugby means the platform holds information about children. POPIA sections 34 and 35 restrict this, and we treat those restrictions as a design constraint, not a footnote. We process children's information only as an operator, on the instruction of the organisation that governs the competition. That organisation is responsible for obtaining the consent of a competent person (normally a parent or guardian) before loading a child's information, and our Terms of Service oblige them to do so. Children's information is never used for marketing and never sold.

4. Special personal information

Eligibility and player-welfare workflows can involve medical information: clearance certificates, head-injury and blood replacement records, and similar documents required by the laws of the game. This is special personal information under POPIA. It is collected under the authority of the organisation running the competition, stored encrypted, restricted to the roles that need it, and never used for any purpose beyond the competition it was submitted for.

5. How we use personal information

To provide the platform you or your organisation signed up for. To authenticate you and enforce workspace permissions. To process payments and issue statements. To communicate with you about your account and, where you have opted in, about the product. To keep the audit trail organisations rely on. To meet our legal obligations. We do not sell personal information, and we do not use it for third-party advertising.

6. AI features

Some paid features use large language models, for example reading a compliance document to check its type, expiry and signature. When an organisation enables such a feature, the relevant document or text is sent to our AI provider (Anthropic, with OpenAI as fallback) for processing only. Our agreements with these providers do not permit them to train models on this data. Every AI call is logged with its input, output and cost so that its use is auditable. AI verdicts on documents are advisory; a person makes the decision.

7. Who we share information with

We share personal information only with the service providers required to run the platform, each bound by contract to protect it:

  • Railway — application hosting and databases.
  • Vercel — hosting for this website.
  • Cloudflare — content delivery, email routing and file storage (R2) for uploaded documents and images.
  • PayCloud (AddPay) — payment processing.
  • Anthropic / OpenAI — AI processing, only for the features described in section 6.
  • Transactional email and SMS providers — for notifications you or your organisation have configured.

Beyond this list we disclose personal information only when the law requires it, or when you direct us to.

8. Cross-border transfers

Some of the providers above store data outside South Africa. Where they do, the transfer happens as POPIA section 72 requires: under contracts that hold the recipient to a standard of protection substantially similar to POPIA, or with your consent, or because the transfer is necessary to perform our contract with you.

9. How we protect it

Data is encrypted in transit and at rest. Every workspace is isolated: the query layer enforces the tenant boundary on every read and write, so one organisation's data cannot leak into another's through normal product use. Integration credentials are stored encrypted. Access follows least privilege, and state-changing actions are written to an audit log. No system is perfectly secure, but if we become aware of a breach affecting your personal information we will notify the Information Regulator and affected parties as POPIA section 22 requires.

10. Retention

We keep account and workspace data for as long as the subscription is active. After closure we keep an archive for a limited period for audit, dispute and tax purposes, after which it is deleted. Organisations can request deletion of their workspace content at any time, subject to records we are legally required to keep. Match records that form part of a competition's official history are retained at the instruction of the organisation that owns the competition.

11. Cookies

The platform uses essential cookies for sign-in and session state. This marketing site does not run third-party advertising trackers. If that ever changes, this policy and a consent mechanism will change first.

12. Your rights

Under POPIA you may ask us to confirm whether we hold personal information about you, request access to it, ask for correction or deletion, and object to processing. Email privacy@corsports.app and we will respond within a reasonable time and at most within the periods the law allows. Where we hold your information as an operator for an organisation, we will refer the request to that organisation and help them meet it.

You also have the right to complain to the Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg; inforegulator.org.za.

13. Access to information (PAIA)

Our manual under the Promotion of Access to Information Act, 2000 (PAIA) is available on request from privacy@corsports.app.

14. Changes to this policy

If we make material changes we will give notice by email and an in-app notice at least 14 days before they take effect. The date at the top of this page always reflects the current version.

15. Contact

Our Information Officer can be reached at privacy@corsports.app for any privacy question, request or concern.