Privacy Policy - Shrewsbury Book Club 

Last updated: May 2026

Shrewsbury Book Club ("we", "us", "our") operates the Shrewsbury Book Club mobile application and club management site. This policy explains how we handle your information across both platforms. 

What we collect and why 

  • Account information - When you sign in to the mobile app, we collect your phone number for verification. Club administrators sign in to the club management site using an email address and password. Your account may also include your display name and email address. This information is used to identify you within the service and manage your membership.

  • Session bookings and attendance - When you book, cancel, or swap a session, we store those records against your account. Administrators may also record attendance on your behalf, including whether you attended, cancelled, or were absent. We track attendance history, including dates, cancellations, total sessions attended, and any notes or reasons you or an administrator choose to provide (for example, a cancellation or leave reason). 

  • Book ratings - When you rate a book in the app, that rating is stored alongside your account and may be visible to other members. 

  • Membership and administration data - Your account may include information relating to leave status and history, access permissions, and other administrative fields necessary for running the club. Administrators may create or update member records, grant or revoke access, and manage leave on your behalf. 

  • Voting - When the club runs a vote on upcoming books, we store voting period information (candidate books, dates, status, and results) as well as individual votes linked to your account (including your selected book and vote timestamps). 

  • Book information - When administrators add books to the system, details such as title, author, and cover image URLs may be sourced from the Google Books API and stored in our database. 

What we do not collect 

  • We do not collect your location, contacts, or photos from your device. 

  • We do not use advertising or tracking tools. 

  • Neither the mobile app nor the club management site includes any analytics SDK. 

Third-party services 

  • Google Firebase - We use Firebase as our backend infrastructure, including Firebase Authentication (phone number and email/password sign-in), Cloud Firestore (data storage), and Cloud Functions (server-side processing). Google processes your data as part of providing these services. 

  • Google Books API - When administrators search for books to add to the club, search queries are sent to Google's Books API. This is used solely to retrieve book metadata and does not involve any member personal data. 

  • Expo (EAS) - We use Expo's update service to deliver mobile app updates. When checking for updates, some device and network metadata may be processed by Expo's servers. 

  • Apple and Google platform services - Depending on your device, Apple or Google may process certain device metadata as part of normal app delivery and operation, subject to their own privacy policies. 

Data storage and retention 

Your data is stored securely using Google Firebase infrastructure. We retain your data for as long as your account is active or as needed to manage your membership. If you wish to have your account and associated data deleted, please contact us and we will process your request within 30 days. 

Your rights 

Under UK GDPR, you have the right to: 

  • Access the personal data we hold about you 

  • Request correction of inaccurate data 

  • Request deletion of your data 

  • Object to or restrict processing of your data 

  • Lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk

Contact 

For any questions or data requests, please contact: 

Nadine Cossie - Shrewsbury Book Club

Email: shrewsburybookclub@outlook.com