Carefully Structured Consent
We build your checkout step-by-step to ensure parental consents are granular and unbundled — Terms, Privacy, and Critical Medical Data are separated natively.
Safeguarding & Compliance
Meeting your safeguarding and data obligations takes more than standard templates or generic user terms. Kimshi partners with you to establish a secure, independent web infrastructure where your setup and your data belong entirely to you.
When a platform leaves configuration entirely in your hands, managing compliance becomes an extra administrative burden.

The Configuration GapStandard platforms provide the form builder but generally leave the compliance logic up to the user. For example, accidentally bundling marketing consents with critical medical declarations can unintentionally fall short of UK data guidelines.
A Responsible ApproachBecause Kimshi integrates directly with your unique domain and your own Stripe account, your customer relationships remain entirely yours. Parents deal strictly with your brand, ensuring they never see, interact with, or sign terms with an outside software intermediary.
A Dedicated Support PartnerWe don’t expect you to figure out how to translate complex data protection needs into software configurations alone. We work directly alongside you to review your specific operational workflows, giving you the quiet confidence that your setup is handled properly.
We don’t hand you a blank box. We architect your safety net.
We build your checkout step-by-step to ensure parental consents are granular and unbundled — Terms, Privacy, and Critical Medical Data are separated natively.
Children’s medical profiles are Special Category Data. Your club’s data is strictly segregated and access-controlled, hosted on UK and EU AWS infrastructure, and encrypted in transit and at rest — with a published DPA and subprocessor list.
Our Security page shows exactly where data lives and who can reach it, alongside our Data Processing Addendum.
Your booking engine runs natively on your own custom subdomain (booking.yourclub.com), keeping your data lineage transparent, professional, and entirely under your own brand.
Kimshi provides the infrastructure and works with you on the setup — your club remains responsible for its own compliance. This page is guidance, not legal advice.

The records inspectors and parents ask about, kept where you already work.
DBS checks (England & Wales) or PVG membership (Scotland) and training records are held alongside everything else, with renewal and expiry dates — so an out-of-date certificate is something you see coming, not something an inspection finds.
Session registers show which children have medical or care needs and how serious they are — category and severity only, visible to the people who need it, with every access logged.
A timestamped, versioned record of each consent a parent gives — what was agreed, by whom, and when. Withdrawals are recorded the same way, so your paper trail holds up.
Plain labels, no scare tactics. Here’s where the real lines are.
UK GDPR applies to every club holding children’s personal data — whatever its size, and whether or not it is registered with a regulator.
Barred-list and DBS checks for staff in regulated activity with children in England and Wales; in Scotland, PVG scheme membership is mandatory for regulated roles.
Written safeguarding policies are mandatory for Ofsted or Care Inspectorate–registered settings — and expected practice for every other club working with children.
Safeguarding shouldn’t have a premium tier.
Fixed PricingOur plans start at just £15/month and are based strictly on the technical infrastructure we manage for you.
Grow For FreeWe never raise your bill just because your registers fill up. Your software costs stay predictable, no matter how successful you become.

We will build a secure, branded preview of a properly structured checkout completely free of charge.
Request Your Managed Setup