Security and privacy
ActivityRoster holds rotas, qualifications and contact details for the people who run and teach at sailing centres, including some under-18 instructors. This page says plainly what we do to protect that, in the order most centres ask.
Where your data lives
Everything is hosted on Cloudflare in Western Europe: the database, uploaded documents and the application itself. Uploaded files sit in storage pinned to the EU jurisdiction. The few other companies that touch data (email delivery, card payments, error monitoring) are listed in our data-processing terms, each under a signed data-processing agreement.
One centre can never see another
Every record carries the centre it belongs to, and every read and write goes through one data-access layer that enforces that. An automated test creates two centres and proves one cannot read, list, change or export the other’s records; it runs before every deployment.
Signing in
Passwords are at least 8 characters with letters and numbers, checked against known breached-password lists, and stored only as salted slow hashes. Centre admins sign in with email and password, then confirm a code we email the first time on a device and after 12 hours away. Everyone sets a 4-digit PIN that is asked for after 30 minutes without activity. Optional two-factor authentication with an authenticator app is available. New devices and countries trigger an extra check and an email. Sign-ins are rate-limited.
Encryption and hardening
All traffic is HTTPS with HSTS. Database queries are parameterised. Every input is validated on the server. Security headers (Content-Security-Policy, frame-ancestors none, nosniff, referrer and permissions policies) are set on every response. Card details never touch our systems: payments run through Stripe Checkout.
Who sees what
Instructors see their own shifts, hours and leave, and their colleagues’ names and shift times. Contact details, pay rates, documents and exports are for centre admins. Every change to the roster, staff, settings and billing is written to a change log the centre can read.
Backups and resilience
The database keeps point-in-time history for 30 days, with nightly encrypted exports kept in the EU and a second copy outside Cloudflare. Restores are tested each quarter. If the platform is ever down, centres can still print the day’s rota in advance.
Your rights and complaints
Anyone can ask for, correct or delete their data, or complain, through our data request form or by emailing privacy@activityroster.com. We acknowledge within 30 days. Centres can export all their data at any time from Settings.
Reporting a security problem
If you believe you have found a vulnerability, email security@activityroster.com with enough detail to reproduce it. Please don’t access other people’s data, degrade the service or keep anything you come across. We’ll acknowledge within three working days, keep you informed, fix confirmed issues promptly and, with your permission, credit you. We will not take legal action against good-faith research that follows these rules. Our machine-readable policy is at /.well-known/security.txt.
See also: Privacy · Data processing · Terms. Last reviewed 3 October 2026.