Security and privacy

Your members trusted you with their details

Here’s how EzyClub keeps each club’s members, money and messages safe, and what we can and can’t see.

Each club behind its own wall

Every record belongs to exactly one club, and the rule that keeps clubs apart lives in one place in the code. Automated tests try to reach another club’s members, money and keys on every release, and must fail.

No card details, ever

Cards are typed into Square’s, Stripe’s or PayPal’s own form and never touch our servers. Payments go straight to the club’s own account.

We see only what you let us

Our staff can’t open a club’s member records. If your committee wants help, it grants support access for one, four or 24 hours; everything done is written to your club’s own audit log, and you can end it at any time.

Keys locked per club

Each club’s payment, email and notification keys are encrypted with that club’s own key. Operators sign in with two-factor codes.

Members choose what’s shared

In the members’ directory, each member decides whether they appear and which details show. Unsubscribes are honoured automatically.

Built to be hard to break

Passwords are stored only as secure hashes, repeated wrong guesses are slowed down, one-time links work once, and the site’s code is never reachable from the web — only its public pages are.

Australian privacy law

EzyClub is hosted in Australia and run under the Australian Privacy Principles. Every club gets a data-processing agreement setting out what we hold for it and why.

Read the data-processing agreement

Leaving is easy

The committee can export the member list whenever it likes, and we hand over a full copy of a club’s data on request. A club that closes is given notice first; nothing is deleted silently.