Privacy notice

Effective 26 August 2026. Version 1, pre-launch.

Where TeamNa is right now. The product is not publicly available. It is being run with a small number of pilot businesses in the United Arab Emirates, and this notice describes what happens today, not what we hope to do later.

We hold no independent security certification. We are not SOC 2 audited and we are not ISO 27001 certified, and this page will say so until that changes.

Who we are

TeamNa is a mobile app for managing classes and sessions at small activity businesses: swimming academies, pilates studios and similar clubs. It is operated by the company building it, based in the United Arab Emirates. During the pilot the fastest way to reach us about anything on this page is the business you signed up through, and they will put you in touch with us directly.

Two kinds of relationship

When you use TeamNa as a member or a parent, most of what we hold about you is held on behalf of the business you joined. They decide who is in their classes, what the policy is, and what they keep. We hold and process it for them, and we do not use it for our own purposes.

A smaller set of information is ours: your account itself, the device you get notifications on, and the diagnostic records that keep the service running. Those we decide about.

What we collect

When you create an account

Sign-in is handled by Clerk, an identity provider. They send the one time code to your phone and tell us that the number is verified.

When you use the app

When you pay

Card details never reach our servers. Payments are taken by a licensed payment provider who handles the card and tells us only the amount, the currency, the outcome, and a reference. What we store is the record that a payment for a package or a fee succeeded or failed, so the business and the member can both see it.

When you fill in the early access form

The business name, contact name, phone or email, business type, role, whatever you typed about the tools you use today, and how you arrived at the page. We use it to contact you about the pilot. It is not a newsletter list and we do not sell it.

Automatically

Our servers keep request logs (the time, the route, a request identifier, and the outcome) and error reports, which is how we find out something is broken. We use Sentry for error reporting and PostHog for product analytics. The marketing pages you are reading now set no cookies and run no analytics script.

Children's data

Children do not have TeamNa accounts. A parent or guardian creates a child profile inside their own account, and only the parent can see it or act on it.

A child profile holds the child's name and, optionally, a date of birth. That is all, and each field is there for one reason: the name so the club knows who is in the lane or on the mat, the date of birth so the child is placed in the right age group. There is no photo, no address, no medical record and no free-form profile.

We never send marketing to children, and we never send a notification to a child. Every message goes to the parent's phone. We do not profile children, we do not build advertising audiences from any of this, and we do not share child profiles with anyone other than the business the child attends.

A parent can archive a child profile in the app at any time. If you want it erased outright rather than archived, ask the business or ask us and we will do it, subject to the records the business has to keep about sessions that already happened.

Why we are allowed to hold it

Who else sees it

Only the businesses you belong to, and the suppliers we need to run the product. Each one gets the minimum it needs to do its job:

We do not sell personal data, we do not rent it, and we do not hand it to advertisers. Businesses on TeamNa cannot see each other's members: separation between businesses is enforced in the software on every read and every write.

Where it lives

The database is hosted in Frankfurt, Germany, and some of the suppliers above operate elsewhere, including the United States. That means data about you may be processed outside the UAE. We choose established providers who commit to protecting it, and we send them only what the job requires.

How long we keep it

What you can ask for

Ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or ask us to stop sending you something. During the pilot, ask through the business you joined and they will reach us; we answer as quickly as we can and never later than a month. If part of a request is something the business decides rather than us, we will tell you that plainly instead of quietly ignoring it.

Security, honestly

Traffic is encrypted in transit. The database is managed, access to it is restricted, and secrets are held in a secrets manager rather than in code. Separation between businesses is enforced by the application on every query, and a test in our build fails if a developer forgets. Card data never touches our systems.

What we are not claiming: no independent audit, no penetration test report, no certification. This is a small product early in its life, run carefully, and we would rather say that than imply otherwise.

Changes

When this notice changes we update the date at the top. If a change materially affects what we do with your data, we will tell you in the app rather than expect you to notice a new date on a web page.