How long things are kept

“We keep everything for ever” is not a retention policy, and until 9.99.163 it was the only one Pavilion had — nothing anywhere deleted or anonymised a single piece of member data on any schedule. A declined applicant’s date of birth and address sat in the database indefinitely. So did the name of every guest ever signed in, and the full personal details of a member who left in 2013.

The rule under UK GDPR is not complicated: keep personal data no longer than you need it for the purpose you collected it. What “no longer” means is a decision for your committee, not for us — so nothing here is switched on by default, and a Pavilion update will never start deleting your records. Set a period and Pavilion tidies up overnight.

🗑 Deleted, or anonymised?

Some things are deleted: a declined application, old newsletter open-tracking, the member activity log. Nothing needs them once they are old.

Others are anonymised — the row stays, the name comes off. Sign-ins, check-ins and guest visits are exactly the figures a club uses to argue its case for rates relief, or to decide when it is worth opening the bar. Deleting them loses the argument; cutting the name off does not.

The same goes for a member who left long ago: their address, phone, date of birth and emergency contact are wiped, but the membership record stays, so past seasons still add up and so do their appearances and the accounts.

💷 What is never on this list

Payments, Gift Aid declarations and the accident book. HMRC wants a Gift Aid declaration kept for six years after the last claim it supports; your independent examiner needs the financial records for the years they examine; your insurer needs the accident book. None of that is a setting a club secretary should be able to change from a dropdown, so it is not offered.

👀 Before you switch anything on

Press “Show me what this would affect”. The number you see comes from the same query the tidy-up itself runs, so it is exactly what would happen — not an estimate. Nothing is touched until the overnight run, or until a site administrator presses “Run the tidy-up now”.

Common questions

What periods should we choose?
Each row suggests what most clubs settle on. A declined application at twelve months, attendance logs at two years, and ex-members at seven are defensible and unremarkable. The important thing is that the committee has decided and can say why.
Can I undo it?
No. Deleted is deleted and anonymised cannot be reversed — that is the point of it. Use the preview first, and take a database backup before the first run if it will touch a lot.
Does this replace erasing an individual member?
No. This is routine housekeeping on a timer. When one member asks to be forgotten, use GDPR → erase, which deals with everything about that one person at once.
Will it delete a member who has just left?
Only if you set the ex-member period short enough to catch them, and it only ever wipes personal details rather than the membership record. Seven years is the usual choice, which is long past any query about a past subscription.
Our club has never had a retention policy. Is that a problem?
It is a gap rather than a disaster, and it is a common one for a volunteer-run club. Setting these, writing a paragraph in your privacy notice saying what you keep and for how long, and minuting the decision is the whole job.