Security
Encryption
All traffic is encrypted in transit with TLS. Subscription billing is handled by Paddle, our merchant of record; Padel+ does not collect or store any card details, and player money never passes through Padel+.
Access controls
Role-based permissions keep staff access scoped to their club. Internal access to production data is limited, logged, and reviewed. Sign-in is passwordless: a one-time code is emailed for every login, so there is no password to steal, guess or reuse.
Reliability
We monitor the service continuously and are alerted to faults as they happen, so problems are found and fixed quickly.
Reporting an issue
Found a vulnerability? We appreciate responsible disclosure. Email security@padelplus.net and we'll acknowledge within 48 hours.
If something goes wrong
If personal data on Padel+ is exposed, lost, or reached by someone who should not have it, we tell the affected club without undue delay - with what we know so far and what we are doing about it - so the club can meet its own legal deadlines to its regulator and its players. Where we are the controller of the data, we notify the regulator ourselves within the deadline the law sets.
Processors & data protection
We work only with vetted subprocessors and hold Data Processing Agreements with them. See the Privacy Policy for the current subprocessor list, retention periods, and your data-protection rights. A DPA is available on request.
