ClubTide
Security and data protection

Security at ClubTide

Clubs trust us with information about their members, and much of it belongs to children. This page explains, in plain language, how ClubTide is hosted, who can see what, how accounts are protected and how card payments are kept out of our systems.

14-day free trial · no credit card · cancel anytime

What we do, stated precisely

Security pages are full of vague promises. We would rather tell you exactly what is in place today, so you can judge it for yourself and answer your own members' questions. Everything below describes how the platform works now; when something changes, we update this page.

If you have a question that is not answered here, or you believe you have found a security issue, email us at [email protected]. We read every report and reply as quickly as we can.

Hosting in the European Union

ClubTide runs on servers from Hetzner Online in Germany, and the application database is stored there too. Traffic to clubtide.app passes through Cloudflare, which protects the site against attacks and abusive traffic before it reaches our servers.

All connections use HTTPS, including the app, the parent portal, the public sign-up forms and this website. Session cookies are marked secure and HTTP-only, so browsers only send them over encrypted connections and page scripts cannot read them.

  • Servers and database in Germany (Hetzner Online)
  • Cloudflare in front of the platform
  • HTTPS everywhere, secure HTTP-only session cookies

Account protection and two-factor sign-in

Passwords are never stored in readable form: we keep only a bcrypt hash. Staff can turn on two-factor sign-in with any authenticator app (TOTP) and receive one-time recovery codes in case they lose their phone. The two-factor secret is stored encrypted, and recovery codes are stored only as hashes.

Club owners can require two-factor sign-in for every staff member. Once required, staff without it are asked to set it up before they can use the app.

Sign-in, two-factor codes and password reset requests are rate limited, so repeated guessing is blocked after a few attempts. Email verification links are signed and expire, and password reset links use single-use tokens that expire after an hour.

  • Passwords stored only as bcrypt hashes
  • TOTP two-factor sign-in with recovery codes
  • Owner setting to require two-factor sign-in for all staff
  • Rate limiting on sign-in, two-factor codes and password resets
  • Signed, expiring email verification links

Role-based access and coach scoping

Every staff account has a role: owner, admin, coach or front desk. Each role grants a defined set of permissions, and owners can grant admins extra permissions individually. Parents have their own portal and never reach staff screens.

Coaches only see the members and classes of the groups they teach. Sensitive medical fields, such as allergies and medical restrictions, are only visible to staff whose role includes that permission; the front desk role does not.

  • Roles: owner, admin, coach, front desk and parent
  • Coaches limited to their own groups
  • Medical notes restricted by permission
  • Subscription and billing of the club account limited to the owner

Each club's data kept separate

ClubTide is a multi-tenant platform: many clubs use the same application, but every record belongs to exactly one club. Every lookup is scoped to the signed-in user's club, and a request for another club's record behaves as if it did not exist. Our automated tests check this isolation.

  • Every record tied to a single club
  • Cross-club requests return "not found"
  • Covered by automated tests

Audit log of important actions

Important actions are recorded in an audit log with who did it and when: member changes and archiving, promotions, payments and refunds, data exports and anonymization, consent signatures and withdrawals, settings changes and two-factor changes, among others. Owners and admins with the right permission can review the log from the app.

  • Who did what, and when
  • Covers members, ranks, billing, privacy and security events
  • Visible to owners and authorized admins

Card data stays with Stripe

Card payments, both for your ClubTide subscription and for members paying your club, are processed by Stripe. Card details are entered only on Stripe-hosted pages and never pass through or get stored on our servers. ClubTide keeps only Stripe identifiers plus the card brand and last four digits, for display.

Because card entry happens entirely on Stripe, our part of card handling falls under the simplest PCI DSS scope (SAQ A). Member payments go to the club's own Stripe account.

  • Card entry only on Stripe-hosted pages
  • We store Stripe ids, card brand and last four digits only
  • PCI DSS SAQ A scope for ClubTide

GDPR roles and privacy tools

For member, family and guardian data, the club is the data controller and ClubTide acts as its processor, processing the data only to provide the service. For club account and staff data, we are the controller. The details are in our privacy policy.

The app gives clubs the tools to meet their obligations: export a member's data, anonymize a member while keeping invoices and payments for accounting, track data requests, and set a retention period after which archived members are anonymized automatically. Consent forms are versioned, and each signature keeps a snapshot of the text that was accepted.

  • Club is controller, ClubTide is processor for member data
  • Member data export and anonymization
  • Retention period with automatic anonymization of archived members
  • Versioned consent forms with signature records

Sub-processors

We use a small number of providers to run the service. The same list appears in our privacy policy.

  • Hetzner Online GmbH (Germany): server and database hosting in the EU
  • Cloudflare: network protection and delivery for clubtide.app
  • Stripe: payment processing for subscriptions and member payments
  • Our email delivery provider: platform emails such as notifications, invoices and password resets
  • Google: only if you choose to sign in with a Google account

Reporting a security issue

If you believe you have found a vulnerability, please email [email protected] with the details and steps to reproduce it. Please give us reasonable time to fix the issue before sharing it publicly, and do not access or change other clubs' data while testing.

Members and parents with questions about their own data should contact their club first, since the club controls that data. We will help the club respond.

  • Security contact: [email protected]
  • Please report privately first
  • Members and parents: contact your club about your data

Read the legal details in our privacy policy, or see how the features that handle member and payment data work.

FAQ

Security questions

Still have questions? Email us and we will get back to you.

Where is our club's data stored?

On servers from Hetzner Online in Germany, in the European Union. Traffic reaches them through Cloudflare. Some providers, such as Stripe for payments, may process data outside the EU under appropriate safeguards described in our privacy policy.

Does ClubTide store credit card numbers?

No. Card details are entered only on Stripe-hosted pages and never reach our servers. We keep only Stripe identifiers and the card brand and last four digits for display.

Can we require two-factor sign-in for our staff?

Yes. The club owner can require two-factor sign-in for all staff. Staff then set it up with an authenticator app before using the app, and receive recovery codes.

Can coaches see every member's medical information?

Coaches only see members of the groups they teach. Medical fields are visible only to roles with that permission, which the front desk role does not have.

How do I report a security problem?

Email [email protected] with a description and steps to reproduce. Please report privately and give us reasonable time to fix the issue before disclosing it.

Spend less time on spreadsheets and more time on the mat

Set up your club in two minutes and try every feature free for 14 days.

No credit card required to sign up.