Skip to main content

ClubRight security and data protection: common questions

Answers to common questions about how ClubRight secures and stores your data, including encryption, hosting, retention, and passwords.

Clubs and their members often want to know how their data is kept safe in ClubRight. This article answers the most common questions about how we secure, store, and handle your data, so you can give your members confidence and meet your own due-diligence needs.

How is my data encrypted?

Your data is encrypted both in transit and at rest. Connections use TLS, and data is encrypted at rest using SSL RSA SHA-256.

Where is my data stored?

Your data is stored in Microsoft Azure cloud storage, in London-based data centres, with replication in Cardiff and Ireland.

How long is my data stored?

Transient logs of inbound data are kept for 30 days. Deleted data is permanently removed after 30 days. All data relating to clubs and members is subject to your club's own data policies.

How is access to data secured?

Access to ClubRight is role based, so staff only see what their role allows. When someone sets up a new account, their email address is verified as part of the sign-up process.

Do you test your security?

Yes. We carry out penetration testing of the application using OWASP standards.

What are the password requirements?

Passwords must be at least 6 characters. We recommend making them longer and using a mix of uppercase and lowercase letters, numbers, and special characters such as @, #, $, or !, to keep accounts secure.

Does ClubRight store payment details?

No. ClubRight does not store any payment information. Payment details are held securely by the payment providers ClubRight integrates with.

Who owns the personal data in my account?

The personal data in your account belongs to your club. ClubRight does not share it. You control the information held, such as members' names and addresses, in line with your own data policies.

Related help articles

Did this answer your question?