Security
How we protect club and member information.
Separation between clubs
Each club’s data is isolated at the database level rather than by the application remembering to filter it. One club cannot see another’s members, bookings or documents.
Documents
- A certificate file exists only while the club is checking it: from the moment you upload it until the club records its verdict, when it is deleted. A daily sweep deletes anything a verdict missed.
- Stored privately, with no public web address; a club’s link to it lasts ten minutes.
- Uploaded from your browser straight to storage, never through our own servers.
- What is kept afterwards is the record of the check — the type, the number, the expiry, the verdict, who and when — and it belongs to that club’s record of you. It is not shared with any other club.
Payments
Card details are entered directly with Stripe and never reach us. We hold the record of a payment, not the means of making it.
Privacy between members
A member sees that a lane is taken, how many places are left, and how many people are waiting — never who. Names are for the club’s administrators and, for one session, the range officer running it. If the person before you on a lane has not checked out, you are told that somebody hasn’t, not who.
A record of what leaves
When a club takes a copy of its register, or a person downloads their own data, the export is recorded: who, when, what it covered and how many rows. Every verdict on a document, every check-in and check-out, and every ending of a membership records who did it.
Where data is held
In the United Kingdom. The services we rely on are listed on our sub-processors page along with where each operates.
Accounts and access
- Data is encrypted in transit and at rest, including backups.
- Passwords are stored hashed. We cannot see them.
- Club administrators can only act on their own club.
- A range officer can act only on the sessions they have been assigned to run, and only on who is booked on them.
- Access to sensitive settings is limited to the people who need it.
- Deleted data is held in backups for up to thirty days, then gone.
Reporting a problem
If you think you have found a security issue, please email support@shootday.co.uk rather than raising it publicly. We will acknowledge it and keep you informed. If a breach affects personal data we will tell the clubs concerned without undue delay.