This Privacy Policy for Lentil Association Ltd ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you visit our website at https://lentilscout.com or use LentilScout, our AI-powered football recruitment platform.
1. What Information Do We Collect?
Personal information you provide: We collect information you provide when you register, including your name, email address, password, and role (club, agent, or player). Clubs additionally provide club name and league. Agents provide agency name and FA license number.
Payment information: Payment processing is handled by Stripe. We do not store your card details. We receive confirmation of subscription status from Stripe.
Profile and content data: Player profiles (name, position, stats, video URLs, photos), recruitment requirements, messages, and shortlist/watch list entries you create within the platform.
Automatically collected data: Standard server logs including IP addresses, browser type, and pages visited.
2. How Do We Process Your Information?
We process your personal information to: provide, improve and administer our Services; process payments; send you account and service-related communications; ensure the security of our platform; comply with legal obligations; and respond to user enquiries and support requests.
We process your information only where we have a valid legal basis to do so under applicable law, including where you have given consent, where processing is necessary to perform a contract with you, where we have a legitimate business interest, or where we are required to comply with a legal obligation.
3. AI Features
LentilScout uses AI technology provided by Anthropic (Claude) to power player matching, recruitment requirement interpretation, and contingency contract drafting. When you use these features, relevant data (such as recruitment requirements and player attributes) is sent to Anthropic's API for processing. Anthropic's use of this data is governed by their own privacy policy. We do not use your data to train AI models. The AI features are clearly identified within the platform and are optional for certain subscription tiers.
4. When and With Whom Do We Share Your Information?
We may share your information with third-party service providers who help us deliver our Services:
- Stripe — payment processing and subscription management
- Anthropic — AI-powered search and contract drafting features
- Resend — transactional email delivery
- Cloudinary — image and video file storage
- Railway.app — cloud hosting and infrastructure
We do not sell your personal data to third parties.
5. Player Profiles and Visibility
Player profiles created on LentilScout are visible to registered clubs and agents. If you are an agent adding a player profile, you are responsible for ensuring you have the player's consent to share their information on the platform. Players who create their own accounts control their own profile visibility.
6. How Long Do We Keep Your Information?
We retain your personal information for as long as your account is active or as needed to provide our Services. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.
7. How Do We Keep Your Information Safe?
We implement appropriate technical and organisational measures to protect your personal information against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure. All data is transmitted via HTTPS. Passwords are stored as cryptographic hashes (BCrypt). Authentication uses JWT tokens with expiry.
8. Your Privacy Rights
Depending on your location, you may have rights including:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request we correct inaccurate data
- Right to erasure — request deletion of your personal data
- Right to data portability — receive your data in a portable format
- Right to object — object to processing of your data in certain circumstances
- Right to withdraw consent — where processing is based on consent
To exercise your rights, contact us at lentilassociation@gmail.com. We will respond within 30 days.
9. UK & EU Data Protection (GDPR)
Lentil Association Ltd is based in the United Kingdom. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our lawful bases for processing are: contract performance (to provide the Services you subscribed to), legitimate interests (platform security and service improvement), consent (marketing communications, where applicable), and legal obligation (compliance with applicable laws).
10. California Privacy Rights (CCPA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) including the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at lentilassociation@gmail.com.
11. Cookies
LentilScout uses localStorage (not cookies) to store your authentication session. We do not use tracking cookies or third-party analytics cookies. If you use Stripe's checkout, Stripe may set cookies in accordance with their own privacy policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice within the platform. Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
Lentil Association Ltd
Email: lentilassociation@gmail.com
Website: https://lentilscout.com