Security at ClubPal

We handle personal data on behalf of hundreds of sports clubs across the UK and beyond. Here's how we protect it, from infrastructure and encryption to incident response and responsible disclosure.

Last reviewed: April 2026

Hosted on
Microsoft Azure
Encryption
TLS 1.3 + AES-256
Backups
30-day point-in-time
Payments
PCI DSS compliant
Section 01

Infrastructure and Hosting

ClubPal is hosted on Microsoft Azure infrastructure in the North Europe region (Dublin, Ireland). Azure operates ISO 27001 and SOC 2 certified data centres with physical security controls, redundant power, and 24/7 monitoring.

All traffic between users and the ClubPal platform is encrypted using TLS 1.3. We enforce HTTPS-only access and do not support unencrypted HTTP connections.

Section 02

Database Security

ClubPal uses Azure Cosmos DB for data storage. All data is encrypted at rest using AES-256. The database is not accessible from the public internet and requires authenticated, encrypted connections from within our application infrastructure.

Customer data is logically isolated using partition keys. Staff access to production data requires multi-factor authentication and is restricted to authorised personnel only. We use managed identity where possible to avoid storing credentials in configuration.

Section 03

Card Payments

ClubPal does not store card or payment details. Payment details entered by members are sent directly to the payment processor and are never handled or stored by ClubPal.

Payments are processed via ClubPal Payments, our payment processing partner. Our processor is PCI DSS Level 1 certified and supports Strong Customer Authentication (SCA) as required by UK FCA regulations. We also support Apple Pay and Google Pay.

Section 04

Backups and Recovery

ClubPal's database is backed up continuously by Azure Cosmos DB with point-in-time restore available for up to 30 days. In the event of data loss or corruption, we can restore data to any point within this window.

Backup integrity is validated regularly. In the event of a major incident, our recovery time objective (RTO) is 4 hours and our recovery point objective (RPO) is 1 hour.

Section 05

Access Control

Access to ClubPal's production systems is restricted to authorised staff only. All staff with access to production systems must use multi-factor authentication. We follow the principle of least privilege, staff are given only the minimum access required to perform their role.

Access rights are reviewed regularly and revoked immediately upon staff departure. We maintain an audit log of access to sensitive systems and review it periodically for anomalous activity.

Section 06

Incident Response and Monitoring

ClubPal operates continuous monitoring of its infrastructure and application. In the event of a security incident or data breach, we will notify affected Customers within 24 hours of becoming aware of the incident, in accordance with our obligations under UK GDPR.

We maintain a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. All incidents are logged and reviewed to prevent recurrence.

Section 07

Vulnerability Management

ClubPal conducts regular penetration testing of its infrastructure and application. Findings are risk-assessed and remediated in order of severity. Critical findings are treated with the same urgency as P1 support incidents.

Ongoing practices

  • Automated dependency updates and security patching via Dependabot and GitHub Actions
  • Secure development practices including pull request code review and static analysis
  • Continuous monitoring for anomalous traffic patterns and unauthorised access attempts
  • Security considerations embedded in our development and release lifecycle
Section 08

Email Security

ClubPal email domains are protected by SPF, DKIM, and DMARC records to prevent spoofing and phishing. Transactional emails (receipts, notifications, password resets) are sent from authenticated domains only.

ClubPal will never ask members for their password or payment details by email. If you receive a suspicious email claiming to be from ClubPal, please report it to security@clubpal.app.

Section 09

Subprocessors

The following third-party subprocessors are used in the delivery of the ClubPal platform:

SubprocessorServiceLocation
Microsoft AzureCloud infrastructure, database, and application hostingUK / Ireland
Payment processing partnerPayment processing (ClubPal Payments)United Kingdom

Changes to our subprocessor list will be communicated to affected customers in advance of any change taking effect.

Section 10

Responsible Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue with the ClubPal platform, please report it to us privately at security@clubpal.app. We will acknowledge your report within 2 business days and keep you informed of our progress toward a fix.

Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and address them. We will not take legal action against researchers who act in good faith and follow this policy.

Security Team

Email: security@clubpal.app
General questions: support@clubpal.app

Need a formal Data Processing Agreement?

Our DPA sets out ClubPal's obligations as a Data Processor under UK GDPR and is available to download or request as a countersigned copy.

View DPA