Legal Centre

Security Policy

Effective date: 4 July 2026 Version: 1.0

This Security Policy describes the reasonable safeguards Cluboom uses to help protect Club and member information. No online service can be guaranteed to be completely secure, and this policy does not make any claim of absolute security.

1. Our security principles

Cluboom is designed around a small set of security principles:

  • Only the people who need access to a piece of information should have it.
  • Sensitive data should be protected in transit and stored only where it is needed.
  • Actions that change important data should leave an audit trail.
  • Security controls should be reviewed as the platform evolves.

2. Access control

Cluboom uses role-based access control within the application. Coaches, team admins, parents, players and Club administrators each see only the information appropriate to their role and their Club. Access to a Club’s data is scoped to that Club.

Player accounts on device-installed apps are protected with a per-device PIN. Staff, parent and admin accounts are protected by password authentication provided by our identity provider, with support for password reset flows.

3. Encryption in transit

Traffic between end-user devices and Cluboom is served over HTTPS using TLS. Traffic between Cluboom and its backend suppliers likewise uses encrypted transport.

4. Session management

Signed-in sessions are managed by our identity provider. Session tokens are stored in the browser and rotated according to the provider’s policies. Users can sign out from their device at any time, and staff or Club administrators can revoke access where appropriate.

5. Auditability

Sensitive actions in the application — for example changes to player records, safeguarding-relevant fields, invitations and role changes — generate audit entries that can be reviewed by Club administrators and Cluboom operators as appropriate.

6. Suppliers and hosting

Cluboom is delivered using reputable cloud infrastructure and managed services for hosting, database, authentication and transactional email. Suppliers are chosen for their operational maturity and their commitments to security. We do not claim UK-only hosting; where suppliers process data outside the UK we rely on the safeguards described in the Privacy Policy.

7. What we do not claim

To keep this policy accurate we do not claim any of the following unless and until they have been formally verified:

  • Any formal security certification (for example ISO 27001, SOC 2).
  • Independent penetration testing.
  • Encryption at rest as a platform-wide guarantee.
  • 24/7 security monitoring.
  • UK-only data hosting.

We will update this policy as further controls are formally introduced and verified.

8. Reporting a vulnerability

If you believe you have found a security vulnerability in Cluboom, please report it in confidence to support@cluboom.co.uk. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and respond. Please avoid any testing that could disrupt the service or affect other users’ data.

9. What you can do

Use a strong, unique password for your account, do not share your account with others, and sign out on shared devices. Report any suspicious activity on your account to support@cluboom.co.uk.

Questions about this document? Contact us at support@cluboom.co.uk.

Cluboom is a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079), 24 Brynaeron, Dunvant, Swansea, United Kingdom, SA2 7UX.

  • Built in the UK
  • Designed with privacy in mind
  • Secure cloud infrastructure
  • Designed for grassroots sport