← Klubo

Security

Klubo is operated by Allyvate Pte Ltd (UEN 201934150N), 160 Robinson Road, #05-08 SBF Center, Singapore 068914. Last updated 23 September 2026.
The short version

Your club’s records live in a Singapore database that refuses to show one club’s rows to another. Nobody outside Klubo has a login to them, and inside Klubo only the founder does, behind two-factor authentication. An automated security review runs twice a week. If something goes wrong, you hear from us within 72 hours, with what happened and what to do.

1. Where your data lives

Members, parents, attendance, packages and payments are stored with Supabase in Singapore (ap-southeast-1): database, sign-in and file storage. The application is delivered by Vercel. Everything travels over HTTPS, and the database and files are encrypted at rest.

Card payments are taken by Stripe on its own pages. Klubo never sees or stores a card number. PayNow and bank-transfer payments are recorded by your club; no bank credentials are held.

2. One club cannot see another

Every table in the database is protected by row-level security, with a restrictive club-isolation rule on top: each row belongs to one club, and the database itself refuses to return it to anyone outside that club. The rule is enforced below the application, so a bug in a screen cannot leak another club’s members. A parent who signs in sees their own children’s rows and the club’s notices and schedule, never other families’ records.

Someone who is not signed in gets nothing: the anonymous role can read no member data and write none. A new member who joins through your club’s link sees nothing until a club admin approves them.

3. Who can reach it
  • Your club. Admins see and manage everything in the club; coaches see what their role allows. Passwords are hashed by the sign-in service and are never visible to us.
  • Us. Administrative access to live data is held by the founder only, behind two-factor authentication, and every administrative look at a club’s data is logged and kept for review. We use it to run the service and to help you when you ask; we do not browse club records.
  • Nobody else. No third party has a login to your data. The processors below run the infrastructure; they do not use your records.
4. What we check, and how often
  • An automated security review runs twice a week against the live service: row-level security on every table, the anonymous role’s permissions, database advisories, the security headers the site sends, the dependencies the app is built from, and who has changed the code.
  • Security headers on every page: HTTPS enforced for two years (HSTS), a content-security policy that limits what the page may load, and no framing by other sites.
  • Daily platform backups of the database, so records can be restored if something is lost or corrupted.
  • Every change to the product goes through a reviewed pull request before it reaches the live site, and the app reports its own errors to us so a broken screen is seen the same day.
5. If something goes wrong

If we learn of unauthorised access to, or loss or disclosure of, your club’s personal data, we tell you without undue delay and in any event within 72 hours of becoming aware: what happened, what data was affected as far as we know, what we are doing about it, and what we suggest you do. Under the PDPA your club is the organisation responsible for its members’ data and Klubo is your data intermediary; we help with any assessment or notification you must make to the Personal Data Protection Commission. The full commitment is section 14 of our terms.

6. Who processes data on our behalf
SupabaseDatabase, sign-in, file storageSingapore
VercelHosting and delivery of the app; cookieless page-view counts on the public siteGlobal edge network; no personal data in the counts
StripeCard payments, on Stripe’s own pagesCard details never reach Klubo
Email delivery providerReceipts, password resets, the reminders your club sendsOutside Singapore, under protection comparable to the PDPA
Apple and GoogleDelivering push notifications to the phone app, if turned onThe delivery address only, never the content of your records

The same list is in section 12 of our terms. We add a provider only after checking it can meet these commitments, and we update both pages when we do.

7. Found a problem? Tell us

If you believe you have found a security weakness in Klubo, email hello@getklubo.com with what you saw and how to reproduce it. We reply within three working days, we will not take action against anyone who reports in good faith and does not access or alter other people’s records, and we will tell you when it is fixed. The machine-readable version is at /.well-known/security.txt. There is no paid bounty programme.

Questions about security or personal data, including for our Data Protection Officer: hello@getklubo.com. See also the privacy policy and terms.