Skip to content
Security

Your data is safe with us.

This page is maintained by Clubstance to answer common security questions about our platform. It describes the controls currently enabled — not a third-party certification.

Encryption

Data is encrypted in transit with TLS 1.2+ and at rest on our managed cloud database. Backups inherit the same protections.

Access controls

Role-based access controls in-app, mandatory strong passwords, and optional two-factor authentication for owner and admin accounts.

Hosted in India

Production workloads run on managed cloud infrastructure in Indian regions where available, with redundancy across availability zones.

Backups

Automated daily backups with point-in-time recovery for the production database. You can also export your data on demand.

Least privilege

Our team accesses customer data only when required for support, with audited access and time-bound credentials.

Incident response

We have an internal runbook for handling incidents and will notify affected customers without undue delay.

Shared responsibility

Security is a partnership. Clubstance secures the platform, the infrastructure, and the underlying services. Gym owners are responsible for managing their team's access, keeping credentials safe, and using strong passwords and two-factor authentication.

Responsible disclosure

If you believe you've found a security issue, please email [email protected]with steps to reproduce (our disclosure contact is also published at /.well-known/security.txt). We acknowledge legitimate reports within two business days, keep you updated while we fix the issue, and credit reporters who want it.

  • In scope: clubstance.com, app.clubstance.com, and our APIs.
  • Out of scope: denial of service, spam/social engineering of our users, physical attacks, and issues in third-party services we don't control.
  • Safe harbour: we will not pursue legal action for good-faith research that respects user privacy, avoids data destruction and service disruption, accesses only the minimum data needed to demonstrate the issue, and gives us reasonable time to fix it before public disclosure.

Compliance

We operate in line with applicable Indian data protection rules. We don't currently claim formal SOC 2, ISO, or HIPAA certifications — if your business needs evidence for a specific framework, contact us and we'll share what we can.