Security and trust

Reskoo looks after real people's details, including children's. This page sets out, in plain English, what we do to keep your club's data safe. Everything here is something we can point to in how the product is built, not a wish list.

Your club's records are held in the UK

Your club's records are held in Amazon Web Services' London region (eu-west-2). We do not move your core member data out of the UK.

Card details never touch our servers

Payments are handled by Stripe. When someone pays, their card details go straight to Stripe and never pass through Reskoo, so we cannot see or store card numbers. Your club is the merchant: the money is your club's, in your club's own Stripe account. We take no cut and never hold your club's funds.

Each club's data is kept apart

One club can never read or change another club's data. That separation is enforced on our servers, not just hidden in the app. We check it with an automated suite of more than 350 checks, run against a live environment whenever we change how club data is stored or accessed.

Safeguarding notes sit behind a separate lock

Safeguarding records are gated by their own permission, granted person by person. It is separate from someone's role, so even an Owner or a committee member sees nothing unless they have been given that specific access. The safeguarding history is kept apart from the ordinary activity log for the same reason.

Staff sign-in uses two steps

Anyone with staff access (Owners, Managers and Staff) must set up two-step verification, using an authenticator app or a text code, on top of their password. We check for it every time they reach the staff side of the app.

Members sign in without a password

Members sign in with a one-time code sent to their email, so there is no member password to guess, reuse or leak. That member sign-in cannot be used to slip past a staff account's two-step verification.

Sensitive records keep a full history

Changes to the things that matter most, such as money, roles and permissions, consent and safeguarding, are written to an audit trail that records who did what and when. Safeguarding and audit entries cannot be quietly edited or deleted.

Data can be fully erased on request

When someone exercises their right to be forgotten under UK data protection law, your club can permanently erase that person's records from Reskoo, including their photos, subject only to the financial and safeguarding records the law requires clubs to keep.

Encrypted connections

Every connection to Reskoo is encrypted (HTTPS), and browsers are told to only ever reach us over a secure connection.

We keep our software patched

The software Reskoo is built on is checked automatically and regularly for known weaknesses, so we hear about a problem in a building block we use and can update it quickly.

Who we are, and where to go next

Reskoo is operated by BN3 Consulting Limited, trading as Reskoo.

ICO registered: ZC178630 (BN3 Consulting Limited). You can check our entry on the Information Commissioner's Office register.