Security & Trust

How RANQD protects your coaching data

Coaches trust RANQD with their trainees’ details - including, for juniors, health information a parent has shared. This page explains, in plain language, how that data is stored, protected and handled, and what to do if you ever spot a problem.

Where your data lives

All coaching business and trainee data is stored in the United Kingdom (AWS London region) on Neon, and the application runs on Vercel. Both providers hold SOC 2 attestations and industry-standard certifications for their infrastructure. Data is encrypted in transit (TLS) and at rest (AES-256).

Payments

  • Card details never touch RANQD’s servers. All card entry happens on the payment provider’s own hosted, PCI-DSS-certified pages (Stripe is PCI Level 1).
  • Money paid to a coaching business settles directly into that business’s own Stripe account. RANQD takes no cut of a coach’s takings and never holds their funds - the platform fee on every session and credit-pack charge is zero.
  • Every payment notification is cryptographically signature-checked before it is trusted. Anything that fails verification is rejected.

Access control & accounts

  • Sign-in credentials are stored only as strong one-way hashes (bcrypt) - nobody at RANQD can read your PIN.
  • Optional two-factor authentication for the account owner, with one-time recovery codes.
  • Repeated failed sign-ins are rate-limited and temporarily locked, with an alert email to the account owner.
  • Role-based access: the business owner, its coaching staff, trainees and guardians each see only what their role allows. Staff permissions are set section by section.

One coaching business can never see another’s data

RANQD is multi-tenant: every read and write is scoped to your business on the server, on every request. Tenant isolation is re-verified whenever new features ship, and it is a standing focus of our internal security reviews.

Monitoring, audit & recovery

  • Every coaching business has its own audit trail of admin actions; security-relevant events are retained indefinitely.
  • The database supports point-in-time recovery, so data can be restored to a moment before an incident.
  • We run regular internal security reviews with documented findings and verified fixes.

Juniors, health information & consent

Coaching children means holding things most software never touches. These are the specific rules, not a reassurance.

  • Medical notes, allergies and emergency contacts appear on your coach’s own register and are never published. They are erased automatically 24 months after the last session booked, whether or not the rest of the record is deleted.
  • Photo and video permission are asked separately, because a parent may be content with one and not the other. Video permission is enforced on the server: without it, a clip of a junior cannot be added at all, and none is shown to them.
  • A junior’s account is run by their guardian until they turn 18 - or earlier, if the guardian chooses to hand it over. After 18 a guardian’s access ends unless the now-adult decides to give it back.
  • Every permission given and every one withdrawn is kept as a dated record, so what was agreed can always be shown.
  • A coach’s DBS, safeguarding, first aid and insurance are shown as live badges on their public page, which disappear the day a check expires. How these checks work explains what a badge does and does not mean.
  • A coach whose DBS or safeguarding training is out of date cannot take a junior booking. Not a warning - the booking is refused. It covers junior sessions and any booking made for someone under 18 on any session, and in an academy it is judged per coach, on whoever is on court. A check that was never recorded counts the same as one that has expired.
  • Bookings already made are not cancelled on the spot. The coach has 30 days to record the renewal; after that, any junior bookings still outstanding are cancelled and refunded in full, with the coach’s own cancellation policy set aside. Guardians receive the ordinary cancellation notice and are not told why.

Data protection (UK GDPR)

  • For trainee data, the coaching business is the data controller and RANQD is the processor - we process it only to run that business’s sessions, memberships and coaching. A data processing agreement is available on request.
  • We never sell personal data. Promotional email from your coach is opt-in only and carries a one-click unsubscribe; service email - session confirmations, cancellations, refunds and announcements from your coach - is kept separate and is never used for marketing, so unsubscribing can never stop you being told a session is off.
  • When a coaching business leaves, its data is retained for 90 days (in case you return) and then deleted, except where the law requires longer retention of financial records.
  • Subprocessors we rely on: Vercel (hosting), Neon (database), Resend (transactional email), Upstash (rate limiting) and Stripe (payments). Each is bound by a data processing agreement.

Found a vulnerability?

We welcome responsible disclosure. Email hello [at] ranqd.app with the details and we’ll respond promptly. Please don’t access data that isn’t yours or disrupt the service while investigating. A machine-readable policy lives at /.well-known/security.txt.

Questions from a parent, a venue or a governing body? Write to hello [at] ranqd.app - we’re happy to complete security questionnaires for venues and academies.