Privacy policy
Last updated 15 September 2026 · This is a draft and has not yet been reviewed by a lawyer.
M4RCO is check-in software for swimming pools. A club — your club — decides what goes into it. We hold that data on their behalf and do not sell it, mine it, or use it to train anything.
Who is responsible for what
Your club decides what member data is collected and why. We are their processor: we store and serve it, and we act on their instructions. If you are a member and want your data changed or removed, your club can do it, and we will help them.
What we hold
- Household and member records — names, the household they belong to, whether they are an adult or a child, and the birth month and year if given.
- Photographs — added by the family or by club staff, so a lifeguard can recognise who is at the gate.
- Safety information — allergies and emergency contacts, where a family chooses to provide them.
- Check-in history — who entered the pool and when.
- Account data — email address and a hashed password for anyone with a login.
Photographs of children
This is the most sensitive thing we store and we treat it that way.
- A photo appears on the gate screen at the moment of check-in and in that family's own app. It never appears in a list, an export, a report or an email.
- Photos are stored in a private bucket. Every request for one re-checks who is asking; there is no public or shareable link.
- We do not run facial recognition, generate face embeddings, or create any biometric template. Not now and not later — it is a design rule, not a preference.
- A household admin can remove any photo at any time. Removal deletes the file, not just the reference.
- We do not use photographs for marketing. Every face on our website is synthetic.
Safety information
Allergy notes and emergency contacts live in a separate store from the rest of a member record, reachable only by the check-in screen. Every time one is opened we record who opened it, when, and about whom, and your club can see that log. This is deliberate: the information is there to help in an emergency, not to be browsed.
What we never do
- Sell or rent personal data.
- Use member data to train machine-learning models.
- Hold or move your club's membership dues. Money between a club and its members never passes through us.
- Show occupancy publicly. A signed-in member may see how busy the pool is; the open internet may not, because that broadcasts when a neighbourhood is out.
Who else touches it
We use a small number of processors to run the service: cloud hosting and database in the United States, object storage for photographs, and an email provider for account invitations. We will keep a current list here and name them before launch.
How long we keep it
Member and household records last as long as the club's account. Check-in history is kept for the club's audit retention period, which is between 90 days and three years depending on their plan. If a club closes their account we delete their data within 30 days, except where we are required to keep records of payments to us.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Start with your club — they hold the account. If that does not resolve it, write to [email protected] and we will respond within 30 days.
Children
Children do not have accounts. A child appears in the system because a parent or their club put them there, and only a household admin or club staff can change their record. A parent may remove their child's photograph, or ask their club to remove the child entirely.
Changes
If we change this in a way that matters, we will email account holders rather than quietly updating the date at the top.