Trust Center
Security & trust at CoachRoost.
We handle data about kids. We treat that responsibility seriously. Here’s how we keep your team’s information safe.
Encryption everywhere
- All traffic served over HTTPS/TLS
- Passwords hashed with bcrypt, never stored in plain text
- Data encrypted at rest by our cloud provider
Built for youth data
- COPPA-aware: parents control what's shared about each child
- GDPR rights: access, export, correct, and delete on request
- Per-role visibility for medical and sensitive custom fields
Access controls
- Role-based access by team and organization
- Sensitive fields gated behind coach-only visibility
- Audit-friendly account deletion with a 30-day grace period
Reliability
We work to keep CoachRoost available whenever your team needs it. Check the status page any time.
Sub-processors
We use a small set of trusted vendors to run CoachRoost. Full contractual detail lives in our DPA.
| Vendor | Purpose | Location |
|---|---|---|
| Turso | Managed database (primary application data store) | USA / global edge |
| Amazon Web Services | Object storage for uploaded files & photos (S3) | USA |
| Cloudflare | Bot protection (Turnstile) & content delivery | Global edge network |
| Stripe | Payment processing for paid subscriptions | USA |
| Resend | Transactional email delivery | USA |
| Traffic analytics (consent-gated) & optional Google sign-in | USA |
Found a security issue? Report it through our contact form and we’ll respond promptly.
Get your team organized in 90 seconds.
Free for coaches. No credit card. No catch.
