Skip to main content
Version 1.0. Effective 28 September 2026.

1. Who is responsible for your information

Blades is operated by Tahmid Azam, trading as Blades Rowing, United Kingdom. Contact us about privacy at [email protected], or write to Emmanuel College, St Andrew’s St, Cambridge, CB2 3AP, United Kingdom. This policy covers the Blades application, our marketing website, our documentation and correspondence with us. Accepting our terms of service does not mean consenting to every use of your information. For our own account administration, security, customer relationships, invoicing and service analytics, Tahmid Azam is the data controller. A controller decides why and how personal information is used. Your club is normally the controller for the member records, crew assignments, availability, outings and coaching feedback it manages through Blades. When we host and process those records on the club’s instructions, we act as its data processor. Your club must explain its own purposes, legal bases, sharing and retention through its privacy information. This policy does not replace that information. We are not required to appoint a Data Protection Officer. Privacy questions go to the contact address above. You can contact us even if you are unsure whether a request concerns Blades or your club. We will deal with the parts for which we are responsible and help direct the rest to the relevant club.

2. Information we collect and where it comes from

You need a name, email address and authorised club membership to use the application. Without the information needed to identify you and sign you in, we cannot provide account access. Other profile details are only needed for the features or club activities that use them.

About the competition category field

The category field records whether you compete in the open or women’s category under British Rowing’s rules, so that organisers can build eligible crews for competition. It is optional, you can leave it unset or clear it at any time in your profile settings, and other members of your clubs can see it. If recording a category would reveal something about you that you would rather not share, leave it blank and speak to your club about how they handle eligibility.

3. If your club added you before you signed in

Club organisers can create member records, including by importing a list. Before doing that, the club must have your permission to create an account in your name and a lawful basis for giving us your details. Telling you that it has done so is the club’s responsibility, not ours. We do not send an announcement or invitation when a club creates your record, so the club must give you this policy and its own privacy information when it adds you. The first email we send you is the sign-in code you request yourself, and it links to this policy. If you have found an account you did not expect, contact your club organiser, and contact us if you would rather raise it with us directly. Section 12 covers your rights, including deletion.

4. Why we use information

For information we control, the legal bases are set out below. A contract with a club does not, by itself, provide a contract basis for every use of its members’ information. Where we rely on legitimate interests, we consider the effect on you and whether those interests are outweighed by your rights. You can object as explained in section 12. For club-controlled rowing records, the club must identify its own lawful basis. We process those records under its instructions and the applicable data-processing agreement. We do not use this policy to give ourselves a right to reuse club records for our own purposes.

Sensitive information in notes

Coaching or availability notes can reveal sensitive information if someone includes it. Such information can require an additional legal condition beyond the ordinary lawful basis. Clubs must establish and explain that condition before collecting it. If a club relies on explicit consent, it must ask for it separately and explain how to withdraw it. Accepting the terms is not explicit consent to every use of sensitive information. Do not include medical histories or unnecessary sensitive details in free-text fields. Contact us and your club if a note contains information that needs to be corrected or removed. Blades provides scheduling and assignment checks to assist organisers. It does not make decisions solely by automated means that have legal or similarly significant effects on you. Organisers make the decisions about selection and participation.

5. Who can see your club information

Organisers can access the records needed to administer their club, including member information, availability, assignments and coaching feedback. Access also depends on your membership, crew and session permissions. You have one profile and one availability calendar, not one per club. This is deliberate. You record when you are busy once, and every club you row for works from the same picture, so nobody has to enter the same availability twice. It follows that your profile and your busy times are visible to the other members of every club you belong to, not only to the club you had in mind when you entered them. Availability notes are shared on the same basis, so keep the reason for an absence out of the note if you would not want each of your clubs to read it. When an organiser adds members, they can check whether an email address already has a Blades account, so that an existing member is linked rather than duplicated. That check returns only whether an account exists. It does not disclose the person’s name, profile, availability or other clubs. Members can see information about the crews and sessions available to them, including other participants and their assignments. Session-wide feedback is available to the relevant participants. The ordinary member view restricts individual feedback to its intended recipient; club organisers have wider access. Authorised Blades personnel may need access to provide support, investigate a fault, protect the service or meet a legal obligation. We do not sell personal information or use private club records for advertising. We seek separate permission before publishing a testimonial, identifiable screenshot or other marketing material about a club or member.

Calendar subscriptions

A subscription feed can include session times, locations, outing plans, crew members’ names, coaching roles, equipment and seat assignments. It does not include your personal busy-time entries or coaching feedback. Other participants may therefore appear in the feed a crew member subscribes to. Anyone with the subscription link can retrieve its contents without signing in to Blades. If you subscribe through Apple Calendar, Google Calendar, Outlook or another provider, that provider receives the feed and processes it under its own arrangements. Keep the link private. If your link is exposed, you can replace it yourself. Open Settings, then Sync, and use Replace calendar link. The old link stops working immediately, along with the cached copies of the feed we hold for it, and you subscribe again with the new link on each device. Email us if you would rather we did it for you. Replacing the link does not remove sessions a calendar app has already downloaded. Removing a subscription from a calendar app does not replace the link either, so replace it if you think someone else has it.

6. Providers and other recipients

We use providers to deliver the service and handle correspondence. They receive the information needed for their role. Your chosen calendar provider receives subscribed session data. This is separate from our core hosting arrangements. If we add or replace a provider that processes club records, we will tell the club customer at least 30 days before the change, so that it can raise an objection with us first. We may also share information with professional advisers where necessary for their advice, with payment or banking providers to administer invoices, or with authorities where disclosure is legally required. Disclosure must have an appropriate legal basis and be limited to the information needed.

7. Analytics, cookies and browser storage

We use PostHog on the application and marketing website to count how features are used and to find faults. The integration sends page or screen identifiers and selected actions, such as creating a session, changing availability, booking equipment or submitting feedback. It does not send the contents of a feedback message, availability entry or booking form. The integration disables session replay, automatic click capture and identified user profiles, and removes URL and referrer properties before sending events. Error reports contain the error type and the code location, and we remove the error message before it is sent, because a message can quote what you were typing. PostHog is configured for cookieless measurement, so analytics sets no cookie and stores no tracking identifier in your browser. PostHog receives technical information, including the connection’s IP address and browser information, and derives a daily counting identifier from it. Analytics requests go to our own address rather than to PostHog directly, and our hosting provider passes them on. This means a browser extension that blocks requests by address will not stop them, so use the setting below if you do not want us to count your usage. Your IP address still reaches PostHog, because the daily counting identifier is derived from it.

Turning analytics off

You can turn analytics off for yourself in the application. Open your profile page and use the Analytics setting. Your choice takes effect immediately and stops further events being sent from that browser. Because the choice is stored in the browser and analytics does not identify you, set it on each browser and device you use. The marketing website has no such setting. Measurement there is cookieless and anonymous, it stores nothing on your device, and we cannot connect it to you or to an account. You can block it with your browser’s privacy settings or an ad blocker, and you can email us to object.

Browser storage we use for functions you request

  • Authentication cookies maintain your signed-in session. Blocking them can prevent sign-in or continued access.
  • A sidebar preference cookie remembers whether the sidebar is open, with a seven-day lifetime that can be renewed when the preference changes.
  • Local storage remembers your theme, your calendar display preferences and your analytics choice. These remain until cleared or replaced.
You can clear cookies and local storage through your browser settings. This may sign you out, reset your preferences and reset your analytics choice; it does not delete your server-side account. This documentation site is hosted by Mintlify, which sets its own cookies and collects its own usage information under its arrangements. The settings described above apply to the Blades application and marketing website, not to this documentation site.

8. Marketing

We do not send marketing newsletters, and we do not use club records or member information to advertise to anyone. We do contact club representatives about enquiries they have made, trials, quotes, invoices and renewals, and we send service messages such as sign-in codes and notices about changes to the service. These are not marketing, and you cannot unsubscribe from service messages while you have an active account. If we ever start sending marketing emails, we will ask for your consent first, or rely on the limited soft opt-in the law allows for our own existing customers, and every message will carry an unsubscribe link. You can tell us at any time that you do not want marketing.

9. Processing outside the United Kingdom

Our Convex application database is hosted in the United States. Our PostHog project is hosted in the European Union. Other providers and their subprocessors may process information in additional countries, including through support access. UK data-protection rules require an appropriate safeguard for restricted international transfers. The safeguards in place are: Email [email protected] to ask which safeguards apply to a particular recipient and to request a copy of them.

10. How long we keep information

We keep personal information only for as long as needed for its purpose, taking account of legal obligations and any justified need to resolve a dispute. These periods apply to the information we control: For the rest, these criteria apply:
  • Account and security records are kept while access is active and, where justified, for a limited period afterwards to investigate security issues or close the account.
  • Club records follow the club’s instructions and agreed retention arrangements. Relevant factors include the current rowing season, the need for training history and outstanding member requests.
Sign-in codes expire after five minutes. Leaving one club does not automatically delete an account used by another club, or historical records a club may lawfully retain. The terms give a club 30 days after closure to request a copy of its data. Backups, cached copies and provider logs follow their own deletion schedules, and a record deleted from the live service can persist in a backup for a short further period.

11. Security

We restrict access to club records through authenticated accounts and permission checks applied on the server for every request. You can sign in with an emailed code or a registered passkey; we never ask for a password, and we do not store one. Traffic between your browser and Blades is encrypted in transit, and our hosting and email providers encrypt stored data at rest. Administrative access is limited to authorised Blades personnel and used only for support, fault investigation, security and legal obligations. Keep your email account and devices secure and treat calendar subscription links as private. No system can guarantee complete security. Tell us promptly if you suspect unauthorised access or disclosure. Where we act as a club’s processor, we will tell the club about a personal data breach affecting its records without undue delay after becoming aware of it, whether or not the breach is one the club must report. Where we are the controller, we will notify the Information Commissioner’s Office and affected people where the law requires it. A security concern never requires you to send us your sign-in code or any credential.

12. Your rights and choices

Depending on the circumstances and legal basis, you can ask to:
  • Access your personal information and receive a copy.
  • Correct inaccurate or incomplete information.
  • Delete information we no longer have a lawful reason to keep.
  • Restrict how information is used.
  • Receive information you provided in a portable format where the right to portability applies.
  • Withdraw consent where processing relies on it, without affecting the lawfulness of earlier processing.

Your right to object

You can object to processing based on legitimate interests, including our use of personal information for analytics, for reasons relating to your situation. We must stop unless we can demonstrate overriding grounds recognised by law or need the information for legal claims. You can always object to use of your information for direct marketing. Section 7 explains how to turn analytics off yourself in the application, which takes effect immediately without needing to contact us. Email [email protected] to make a request or raise a concern. No particular wording or form is required. We may ask for proportionate information to confirm your identity. We normally respond within one calendar month, subject to any lawful extension, which we will explain. Requests are free. For information controlled by your club, you can contact its organiser directly or ask us to help route the request. We will assist the club where we act as its processor. We will not require club permission before handling a request about processing for which we are the controller. These rights have limits. For example, we may need to retain information required by law or protect another person’s information when providing a copy. We will explain any refusal or limitation and how you can challenge it. You can complain to the Information Commissioner’s Office, the UK’s data-protection regulator. You do not have to obtain our permission or finish our complaints process first.

13. Adults only

Blades is for people aged 18 and over. Clubs must not add records about people under 18, and each club is responsible for checking that everyone it adds meets that requirement. We do not collect dates of birth, so we do not verify ages ourselves. Contact us if you believe a record concerns someone under 18. We will investigate, restrict access where appropriate and arrange removal of information that we have no lawful reason to retain.

14. Changes to this policy

We will update this policy when our processing changes and show the version and effective date at the top. We will bring material changes to your attention through the service or by an appropriate direct notice. If a new use requires consent, we will ask separately rather than treat continued use as consent.