Removing a member’s records for good

Members → Remove Records. Archiving somebody says they have left; it deliberately removes nothing, because a member who left in October is still in last season’s accounts. This screen is the other thing — actually getting rid of them.

🔍 It shows you first, every time

Choose the member and press See what is linked. You get a line for everything the club holds about them, with a count, and — the part that matters — what would happen to each one.

  • Removed — gone for good. Bookings, sign-ins, guests they brought, availability, rota history, their original application form.
  • Anonymised — the row stays, the name comes off. Attendance figures, the locker they had, equipment issued to them.
  • Kept — untouched, with the reason given. Payments, till sales, Gift Aid, the accident book, match results, safety checks they signed.

Those are three different promises and the screen never runs them together into one word, because they are not the same thing to say to somebody who has asked to be forgotten.

💷 Why the money is never deleted

Because a treasurer who finds last year’s figures have quietly changed will not trust the software again, and they would be right not to. A subscription paid in April is part of that year, whatever happens to the member afterwards. So the payment rows stay and the name on them becomes Former member #214 — your own membership number where you use one, so a line in the accounts can still be matched to a stub.

🚪 The clean case

Where nothing at all is linked — somebody entered twice, an application approved and then thought better of, a test record — you are offered a plain delete instead, and everything goes including the login. Pavilion checks again at the moment you press it, in case a booking arrived while you were reading.

🗓 Everybody who left years ago

The lower half does the same job over a list: everybody archived more than a chosen number of years ago. It always shows you who it would touch before it touches anybody — there is no button that goes straight to doing it. Six or seven years is the usual answer, because that is how long the financial records have to stay anyway.

It works in batches of twenty-five. A club turning this on after fifteen years may have three hundred people on the list, and each one means looking through thirty tables. Press it again for the next batch.

🔑 What happens to their login

It stays, renamed, with the email removed, the password randomised and every role taken away. Nothing can sign into it and nothing can be sent to it. It survives only so the financial rows that had to stay still resolve to a name rather than a blank.

Common questions

Can I undo it?
No, and nothing here pretends otherwise. Take a database backup before the first bulk run. For one member the list you are shown is exactly what will happen, so read it rather than the button.
How is this different from GDPR → erase?
Erase answers one member asking to be forgotten, and leaves their membership record in place so past seasons still count. This goes further: it also removes the record itself, blanks the membership number and puts a placeholder name on everything retained. Use erase for a request, this for housekeeping.
Somebody rang up asking why they are not on the list any more.
The bottom of the screen keeps one line per person removed — their name, when it was done and who did it. That looks contradictory on a screen about removing personal data, and it is the one thing a club actually needs afterwards. It ages out with everything else under Data Retention.
Why will it not let me remove myself?
Because it would take your own access with it, and the same guard stops you removing the only administrator on the site. Make somebody else an administrator first if that is really what you want.
What about somebody who died?
Archive them with the reason “deceased” first — that is what stops every mailing list, newsletter and renewal chaser. Whether and when to remove the record afterwards is a decision for the committee, and there is rarely any hurry.