TOXO

Privacy Policy.

Effective: September 18, 2026

The short version. Toxo holds what an archery club needs to run: who is in the club, when it trains, who said they are coming, and who turned up. Your club decides what it records about you and for how long — we store it for them. Everything lives in the European Union. We do not sell data, do not show ads, and do not use anything about a club’s members to train models. A child’s name is not shown to other families unless a guardian turns that on.

1. Who is responsible for what

Two different answers, and the difference matters.

Your club is the controller of its membership data. It decides who to enrol, what to record, and how long to keep it. Questions about your own record — correcting it, deleting it, asking what the club holds — go to the club first.

CodeEnsis Ltd (Cyprus) provides the app and stores that data on the club’s instructions, as its processor. The agreement that says so is the Data Processing Agreement, which every club accepts before it can hold anything about a child.

For a few things we are the controller in our own right: keeping the service running and secure, the crash reports and usage statistics described in section 5, and our correspondence with you. This policy covers both roles and says which is which.

2. What Toxo collects

WhatWhy
Your nameSo the club and other members know who you are on a list.
Your email addressIt is how you sign in, and where the club’s notices are sent.
Date of birth, if your club records itTo tell a minor from an adult, which decides what the app allows.
Who your guardian is, or whose guardian you areSo a parent can answer for a child and see what concerns them.
Your club, groups and roleTo show you your own schedule and to decide what you may do.
RSVPs and attendanceThe point of the app: the coach knows who is coming, and the club has a record of who trained.
Consents a guardian givesSo the club can show what was agreed, when, and to which version of the text.
A push notification tokenSo a cancelled training reaches your phone. It identifies an app installation, not you.

Toxo is not built for special-category data. Do not put health information into free-text fields, and clubs should not ask for it there.

3. What Toxo does not collect

4. Where it is stored

The database and the server-side logic run in Frankfurt, Germany (Google Cloud europe-west3). Email is delivered by Mailjet in the EU. Where a supplier’s wider group leads to a transfer outside the EEA, it is covered by the European Commission’s Standard Contractual Clauses.

5. Crash reports and usage statistics

Release builds of Toxo include Firebase Crashlytics and Firebase Analytics, and we are the controller for both. Crashlytics sends us a stack trace, the device model and the OS version when the app crashes. Analytics records which screens are opened and how often the app is used, against a random installation identifier. Neither is given any club membership data, any name, or any email address, and neither is used for advertising. Our lawful basis is legitimate interest in keeping the app working and understanding which parts of it people actually use.

You can stop analytics collection on your device at any time: on iOS turn off Allow Apps to Request to Track and Toxo’s analytics permission in Settings; on Android use Settings → Google → Ads and the device’s usage-and-diagnostics switch. Turning them off does not affect anything else the app does.

6. Who else sees it

7. How long it is kept

Your club chooses. The default is three years, which suits a club that needs to show who trained when. Delete your account and your profile, memberships, RSVPs and the consents about you go with it; what remains is impersonal counts on sessions that already happened, which nobody can trace back to you.

8. Children

A club cannot enrol anyone under 18 until we have verified that it is a real club and its owner has accepted the DPA. A child’s record is reached through a guardian, who is asked separately about photographs and about showing the child’s name to other families — both off unless the guardian turns them on. Obtaining whatever consent the law of the club’s country requires is the club’s responsibility; Toxo records it with a date and a version so the club can show it.

9. Your rights

Under the GDPR you may ask for a copy of your data, have it corrected, have it deleted, restrict or object to processing, and receive it in a portable form. Because your club is the controller of its membership data, start with the club. If that does not resolve it, or if your question is about the crash reports and statistics in section 5, write to [email protected] and we will answer within 30 days.

You can delete your own account at any time from inside the app, without asking anyone. You also have the right to complain to your national data protection authority.

10. Security

Data is encrypted in transit and at rest. Every read and write is authorised on the server, so what you are allowed to see is decided by the server and not by the app on your phone. Access to production is limited to named CodeEnsis personnel with multi-factor authentication, and real club data is never copied into development.

11. Changes

We will update this page as Toxo changes, with a new date above. Where a change materially affects what we do with your data, we will say so in the app rather than hope you re-read the page.

12. Contact

CodeEnsis Ltd, Cyprus — [email protected].