Security and data handling
Leagues run registration, payments, and player records through LeagueArc. Here's how that data is protected, in plain language.
Your league's data stays yours
- Every organization's data is kept separate. The app limits data access to your organization, and automated tests check that one league can't see another's data.
- Admins can export your organization's data from its settings at any time.
- Your league's data stays while your account is active. You can export it anytime, or ask us to delete it.
Signing in, and who can do what
- Passwords are stored as one-way bcrypt hashes, never as readable text.
- Two-step sign-in works with any authenticator app and comes with recovery codes.
- An organization can require two-step sign-in for everyone on its account.
- Roles control what each person can do: owner, admin, editor, coach, scorekeeper, player, and viewer.
- We limit repeated sign-in and password-reset attempts to stop password guessing.
- Admins can review an audit log of changes made in their organization.
Payments
- Registration payments are processed by Stripe. Card details are typed into Stripe's own secure fields, so they go straight to Stripe and never reach LeagueArc's servers. We don't store card numbers.
- Your LeagueArc subscription is billed through Helcim, which keeps the card on file.
Protecting data in transit and in storage
- Every connection uses HTTPS, and our servers tell browsers to refuse insecure connections.
- Sign-in cookies are marked secure and can't be read by page scripts, and forms are protected against cross-site request forgery.
- Saved integration passwords, connection tokens, and two-step sign-in secrets are encrypted in our database.
Services that handle your data
LeagueArc runs on a small set of outside services. Here's each one and what it's for.
| Service | What it's for |
|---|---|
| Render | Hosts the LeagueArc app and database. |
| S3 file storage | Stores uploaded files such as logos, photos, and documents. |
| Stripe | Processes registration payments. |
| Helcim | Bills LeagueArc subscriptions. |
| Resend | Delivers email. |
| Twilio | Sends text messages, if your league uses texting. |
| OpenAI | Reads scoresheet photos and drafts FAQ answers, only when you use those features. |
| Sign-in with Google, and Calendar and Sheets sync, only if you connect them. | |
| Sentry | Collects error reports so we can fix problems. It's set not to collect personal details by default. |
| Google Analytics | Measures visits to this website. |
| PostHog | Shows us which features get used in the app. |
Reporting a security issue
If you think you've found a security problem, email [email protected] with "Security" in the subject line. We'll look into it and get back to you.