Trust Center

Security & trust at CoachRoost.

We handle data about kids. We treat that responsibility seriously. Here’s how we keep your team’s information safe.

Encryption everywhere

  • All traffic served over HTTPS/TLS
  • Passwords hashed with bcrypt, never stored in plain text
  • Data encrypted at rest by our cloud provider

Built for youth data

  • COPPA-aware: parents control what's shared about each child
  • GDPR rights: access, export, correct, and delete on request
  • Per-role visibility for medical and sensitive custom fields

Access controls

  • Role-based access by team and organization
  • Sensitive fields gated behind coach-only visibility
  • Audit-friendly account deletion with a 30-day grace period

Reliability

We work to keep CoachRoost available whenever your team needs it. Email is held to the same bar: one-click unsubscribe on every notification (the Gmail/Yahoo bulk-sender standard), automatic suppression of hard-bounced and complained addresses, and retry-with-backoff so a failed send is never silently dropped. Check the status page any time.

View status

Sub-processors

We use a small set of trusted vendors to run CoachRoost. Full contractual detail lives in our DPA.

VendorPurposeLocation
TursoManaged database (primary application data store)USA / global edge
DigitalOceanApplication hosting (the server CoachRoost runs on)USA
CloudflareObject storage for uploaded photos (R2) & bot protection (Turnstile captcha)Global edge network
StripePayment processing for paid subscriptionsUSA
ResendTransactional email deliveryUSA
GoogleTraffic analytics (consent-gated), optional Google sign-in & address autocomplete for event locationsUSA
DatadogProduct analytics & error monitoring, including session replay (consent-gated)USA

Found a security issue? Report it through our contact form and we’ll respond promptly.

Get your team organized in 90 seconds.

Free for coaches. No credit card. No catch.