Security & safeguarding

Trust needs more than a reassuring badge.

Clubs hold personal information and make decisions that affect real people. We explain how YourZown approaches access, consent and accountability. We are clear about what is live, what is improving and what evidence is available.

How we think about trust

The controls are only useful if people can understand them.

We keep the marketing language plain, then go deeper with your IT lead, DPO or safeguarding owner when the organisation needs technical detail and supporting evidence.

Identity and access

Access should change when people do.

Sign-in, account recovery, administrator access and volunteer handovers belong in the same conversation. We explain which methods are live and how access is removed when a role ends.

Sensitive data

Protect sensitive information deliberately.

We distinguish protection in transit, at rest and at field level, then explain key management, backups and role-based access without using ‘encrypted’ as a catch-all answer.

Consent enforcement

Make consent part of the workflow.

We can show what happens when consent is missing, how its state is recorded, how withdrawal behaves and where the club’s own legal responsibility begins.

Audit evidence

Leave a trail that helps answer what happened.

We can show what is recorded, who can see it, how records are protected from casual alteration and which sensitive values are deliberately kept out of the audit view.

Data lifecycle

Plan for data arriving and leaving.

We’ll make exports, deletion and retention responsibilities clear, including the exceptions that apply to financial or safeguarding records.

Independent assurance

No borrowed badges or vague assurances.

YourZown does not currently claim ISO 27001 or SOC 2 certification. We share the architecture, testing, incident-response and sub-processor information available for your review.

Security FAQs

What committees and DPOs ask us.

Where is our data hosted?

We provide the current hosting region, sub-processors and relevant transfer information during your security and data-protection review.

Could another club ever see our data?

Organisation boundaries are a critical part of the platform. We can explain how access is separated and share the testing evidence available for your review.

Do you hold our members' payments?

We will walk your treasurer through the payment provider, settlement route, responsibilities and fees before payments are enabled.

Can we export or delete our data?

We can show the available export and deletion workflows, including the cases where legal retention duties or a person’s relationship with another organisation affect what can be removed immediately.

Are you ISO 27001 or SOC 2 certified?

Not currently. We would rather say that plainly and share the architecture, testing, incident-response and sub-processor information that is relevant to your review.

Want to take a closer look with your IT or safeguarding lead?

Book a walkthrough and bring the questions that matter to your organisation.