Trust & Security

This system holds
other people's children's data

Names, dates of birth, home addresses, emergency contacts and payment details — most of them belonging to somebody's child. That shapes how access works.

Not everyone who works for you needs to see everything

Staff are given a security level, and it is set per Location. An instructor who teaches the Tuesday class does not need the billing screen, and someone covering the desk at one site does not need the other site's member records.

This is the control that matters most in practice, because the realistic risk to a membership business is not a sophisticated attacker. It is a part-time employee with more access than the job requires, and a password shared between three people because it was easier.

Each person gets their own sign-in, which is also what makes the logging below worth anything.

Sign-ins are logged

Account logins are recorded. When you need to answer "who was in the system on Saturday", there is a record rather than a recollection — and the question usually arrives at the worst possible moment, after something has already gone wrong.

Blocking by IP and by country

Access can be blocked by IP address and by country. Blocking runs at the request level, before the application does any work, so a blocked request never reaches a page at all.

For a business operating in one town, this is a blunt instrument that works: the overwhelming majority of unwanted traffic comes from somewhere you will never have a member.

The record keeps its own history

Changes are kept as history rather than overwritten. Member records, account changes, promotions and gradings, inventory movements and support tickets all retain their trail.

Two reasons this matters more than it sounds. The obvious one: when a figure is disputed, you can see what it was and when it changed.

The less obvious one is that the same history is what makes the retention reporting possible. A system that overwrites cannot tell you how long members lasted before they left, because it no longer knows they were ever anything else. See what the history is for

Card details

Card numbers are held by the payment provider, not by us. We keep the last four digits and the card type so you can tell which card is on file, and the record of what was charged and when.

What we deliberately do not publish

You will not find a list of our infrastructure security measures on this page, and that is a decision rather than an omission.

A public page is the wrong place to describe how a system is defended. And a security claim on a marketing site is worth very little to you anyway — every vendor has the same adjectives, and none of them is checkable from a website.

If you are evaluating us and need specifics, ask. You will get a direct answer from someone who knows, rather than a page written to be reassuring. Ask us

Whose data it is

Your members' records belong to you. We hold them on your instructions and use them for nothing else: not sold, not shared with other customers, not used to train anything. A parent asking about their child's record is your conversation to have, because it is your record.

The full position is in our privacy policy, including how long things are kept and how to have them deleted.

Every feature, on every plan

Thirty days, no card, no contract.

Start your 30-day trial