← Back to sign in

Privacy Policy

Pool Command Center — Effective June 1, 2025

1. Who We Are

Pool Command Center is a membership management system operated by Twyckenham Hills Community Club ("the Club," "we," "us," or "our"). It is used exclusively by authorized Club staff to manage pool memberships, record daily check-ins, and administer the Club's aquatics programs.


2. Information We Collect

We collect and store the following categories of personal information about Club members, their guests, and Club staff:

Club Members

  • Full name, date of birth
  • Home address, email address, phone number
  • Membership type and status (active / inactive)
  • Member photograph (optional, uploaded by staff)
  • Check-in dates and times
  • Emergency contact name, phone number, and email address
  • Membership notes added by staff
  • Identity verification status (reset annually)

Day Guests

  • Full name, date of birth
  • Phone number (optional)
  • Date and time of visit
  • Name of the member who brought them

Staff Accounts

  • Full name, work email address
  • Role and access level
  • Clock-in and clock-out timestamps
  • Hashed login credentials (passwords are never stored in plain text)
  • Login activity and audit trail

3. How We Use This Information

We use the information collected solely to:

  • Verify membership status at the point of entry
  • Record and report daily pool attendance
  • Manage guest admissions and collect guest fees
  • Administer aquatics programs (swim lessons, swim team, water aerobics)
  • Communicate with members and staff about Club matters
  • Maintain accurate membership records for billing and renewals
  • Comply with Club rules, safety requirements, and applicable law
  • Detect unauthorized access and protect system security

We do not sell, rent, or share member personal information with third parties for marketing purposes.


4. Third-Party Services

We use a small number of third-party services to operate this system, including:

  • A membership purchase / website integration that securely transmits order data (name, email, membership type) to this system when a membership is purchased online. Only the data necessary to create or update a membership record is processed.
  • A transactional email provider used to send operational messages such as staff account setup links and password reset links.
  • A managed cloud hosting and database provider that stores Club data in an encrypted database with encryption in transit.

Each service is contractually obligated to handle data in accordance with applicable privacy law and is not permitted to use Club member data for their own purposes.


5. Who Can Access Your Data

Access to member data is role-restricted:

  • Front-desk staff can look up memberships and record check-ins. They cannot access payroll, audit logs, or administrative settings.
  • Club administrators have access to all membership data, attendance reports, and system settings within their organization.
  • System administrators have access across all organizations for technical support and maintenance purposes only.
  • Employees (guards, instructors) can only access their own clock-in/out records and assigned schedules.

All access is logged in an audit trail. Accounts are protected by password authentication with automatic lockout after repeated failed attempts.


6. Data Retention

Member records are retained for as long as the membership is active or as required by Club policy and applicable law. Inactive memberships may be retained for up to seven years for historical reference and dispute resolution. Member photographs are deleted when a member's record is removed. Staff accounts are deactivated when employment ends; log data is retained per the Club's records retention policy.


7. Your Rights

Depending on your location, you may have the right to:

  • Request a copy of the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of your information, subject to legal and operational requirements
  • Object to or restrict certain types of processing

To exercise any of these rights, please contact the Club office. We will respond within a reasonable timeframe and in accordance with applicable law.


8. Security

We implement reasonable technical and organizational measures to protect personal information against unauthorized access, loss, or disclosure. These include encrypted connections (HTTPS), hashed passwords, role-based access controls, session management with automatic expiry, and per-account and site-wide login rate limiting. No internet-based system is completely secure, and we encourage staff to use strong, unique passwords and report any suspected unauthorized access immediately.


9. Children's Privacy

Family memberships include minors. The name, date of birth, and (optionally) photo of minor members are collected solely to verify membership status at check-in and to comply with age-based program eligibility requirements. This information is accessible only to authorized Club staff and is not shared with third parties or used for marketing.

Children under 13 (COPPA). The Club complies with the Children's Online Privacy Protection Act. When a member under 13 is added to a household, the system requires the name, email address, and phone number of a parent or legal guardian, and emails that guardian a verification link. We do not retain the child's name, date of birth, or photo on a permanent basis until the guardian clicks the verification link (or a Club administrator records consent from a signed paper form). If parental consent is not verified within seven (7) days of enrollment, the child's record is automatically and permanently deleted from active systems.

Parents and legal guardians have the right to (a) review the personal information the Club has collected from or about their child, (b) refuse to permit further collection or use of that information, and (c) request the deletion of that information at any time. To exercise any of these rights, please contact the Club office. Honoring a deletion request will require the child to be removed from their membership, and may affect access to age-restricted programming.

Information collected from or about minors is limited to what is reasonably necessary to operate membership and check-in functions and is retained only as long as the minor remains an active member of the household, plus a short audit-trail retention period required for billing and program-attendance records.


10. Changes to This Policy

We may update this policy periodically to reflect changes in our practices or applicable law. The effective date at the top of this page will be updated whenever material changes are made. Continued use of the system by authorized staff following any update constitutes acknowledgment of the revised policy.


11. Contact

If you have questions about this privacy policy, want to review or delete records held about your child, or wish to withdraw parental consent at any time, please contact:

Twyckenham Hills Community Club — Privacy Officer
info@thccsb.com

Members may also speak with any front-desk staff member, who can connect you with Club administration. We will respond to verified parental requests within 30 days.

© 2025 Twyckenham Hills Community Club — Pool Command Center