Security and data protection

Your club's data is not something we secure after the fact. Here is exactly what we put in place to keep your information confidential, intact and available.

Security approach

An ISMS built on international information security standards

Secure hosting

European data centres

GDPR compliant

Fully aligned with European data protection rules

Secure payments

Processed by our payment provider, certified PCI-DSS Level 1

Secure EU hosting

All your data is hosted in data centres located in France and the European Union. This guarantees that your information never leaves European jurisdiction. Our hosting providers are listed on the Sub-processors page.

Encryption in transit

Everything traveling between your browser and our servers runs over TLS (HTTPS), so nobody in between can read it.

Encryption at rest

Sensitive data stored in our databases is encrypted at rest, one more barrier against physical or logical access that should not happen.

Automated backups

Backups run daily and are kept on a rolling 90-day window, so your data can be brought back whatever happens. We test that those backups actually restore.

Data separation

Each club's data is logically isolated inside our infrastructure. One organization can never reach another one, by design.

Controlled deletion

Close your account and your personal data is deleted for good or anonymized, within the timeframes and legal exceptions spelled out in our privacy policy.

Role-Based Access Control (RBAC)

Permissions are granular: everyone sees the data and the features their role in the club calls for, and nothing else. Admins decide who gets what.

Principle of least privilege

By default, an account gets the bare minimum it needs to work. Smaller attack surface, smaller blast radius if something goes wrong.

Secure authentication

Passwords are hashed with modern algorithms. Two-factor authentication is available for an extra layer, and sessions expire on their own.

Administrative audit trail

Role changes, deletions, access changes, configuration changes: every sensitive action is logged with full traceability, so a security review has something to work with.

Session management

Sessions are protected against hijacking and fixation. Idle sessions time out on their own instead of waiting around.

Invitation-based access

Getting into a club space goes through a secure invitation. Nobody joins without an admin saying so.

OWASP Top 10 protection

Our development practices build in protection against the main application vulnerabilities OWASP tracks: XSS, CSRF, SQL injection, IDOR and the rest.

Penetration testing

We run security testing on a regular basis to find and fix weaknesses before somebody else finds them.

Dependency management

Third-party dependencies are audited automatically and patched when a known vulnerability shows up, keeping our supply chain clean.

Code review

No code change reaches production without another pair of eyes on it: quality, consistency and no security regressions.

Secure development lifecycle

Security is part of every stage, from architecture decisions through testing and deployment, following industry practice.

Monitoring and alerting

Our systems are watched continuously for unusual activity, performance anomalies and potential threats, with automated alerts so somebody responds fast.

Centralized account management

Internal access runs through a centralized account management system, which makes it far easier to control and review who can reach what.

Password management

Credentials are handled through a proper password management system, and two-factor authentication is mandatory on every internal account, no exceptions.

Principle of least privilege

Internal privileges follow the same least-privilege rule: the minimum access needed for the job, nothing beyond it.

Security watch

We keep a standing watch on vulnerabilities, emerging threats and evolving best practice, so our defenses move before the threats do.

Awareness and training

Security awareness is ongoing: regular training, involvement in professional security communities and continuous self-education, so decisions reflect current standards and current threats.

Incident management

A documented procedure covers how we detect a security incident, respond to it and communicate about it, quickly and openly, and what we change afterwards.

Our approach

Information Security Management System (ISMS)

Clubify runs an Information Security Management System (ISMS) built on internationally recognized information security standards. That framework shapes how we protect your data, end to end.

It rests on formal risk assessment, safeguards proportionate to those risks, and continuous improvement, rather than on good intentions.

  • Risks to user data identified and assessed formally
  • Technical and organizational measures sized to the risk
  • Continuous monitoring, auditing and improvement of our practices
  • Policies, procedures and controls, written down

Management statement

Clubify's leadership is committed to an information security approach that protects the confidentiality, integrity and availability of the information users trust us with.

That commitment shows up as an ISMS built on internationally recognized information security standards, and as a continuous improvement process on our security posture.

Real resources are allocated to maintaining and raising our security level, and every team member knows their part in protecting information.

Evan Petit, founder & president of Clubify

Questions about how we secure things?

Our team will answer anything you want to know about how your data is protected.