Club OroOpen Club Oro
Last updated 5 August 2026

Privacy notice

Club Oro is operated by Natalie Chan in the United Kingdom. This notice explains how Club Oro handles information about members and the people they meet. Contact privacy@cluboro.co for any privacy request.

Data protection framework

Club Oro acts as controller for the product data described here and applies the UK GDPR and Data Protection Act 2018. The lawful basis depends on the activity: contract for the core service, legitimate interests for security and service improvement, legal obligation where required, and consent for optional access where consent is the appropriate basis.

Information we use

We process account identifiers, profile and contact-card fields, connection context, private notes, events and follow-up reminders, device/session identifiers, referrals, membership and transaction references, support messages, and—only after permission—data returned by connected services such as Google Calendar, LinkedIn or Luma. Payment-card details stay with Stripe.

Why we use it

We use this data to provide the card, exchange and relationship-memory service; perform a contract or take steps you request; protect accounts and prevent abuse; meet legal obligations; and, where required, act on consent. Optional provider access can be refused or withdrawn without losing the core card service.

Traffic and performance analytics

We use Cloudflare Web Analytics to understand aggregate visits, referral sources, broad device and region information, and real-user performance measures such as loading speed, responsiveness and layout stability. Cloudflare Web Analytics does not use analytics cookies, local storage or fingerprinting and does not collect visitors’ personal data. We use these limited measurements under our legitimate interests in keeping Club Oro reliable, secure and useful, and we do not include private profile fields, contact details or exchange contents in analytics events.

Sharing and international transfers

Service providers may process data for hosting, authentication, storage, payments, communications and integrations. Current providers include Vercel, Supabase, Stripe, Google and LinkedIn when their feature is used. We require appropriate contractual and transfer safeguards before production use of each provider.

Retention

Expired exchange identifiers are short-lived. OAuth state is retained only long enough to complete authorisation. Unclaimed temporary cards and their uploaded images are automatically deleted seven days after creation, and can be deleted sooner from Profile. Account data is retained while the account is active and then deleted or anonymised, except where law requires transaction or security records to be kept.

Your choices and rights

You can change public-field visibility at any time. Account holders can request access, correction, export, restriction, objection or deletion from Profile → Account & data, or by email. You can complain to the UK Information Commissioner’s Office at ico.org.uk.

Event suggestions

Calendar, location and crowd signals may suggest where a connection happened, but Club Oro requires confirmation before attaching an event to a person. We do not use this feature to make legal or similarly significant decisions.

Children

Club Oro is intended for professional users aged 18 or over.