Skip to content

Security and data protection

Security and privacy, built into the database.

POWA holds information about athletes, many of them children. These are the rules it runs on, and where each one is enforced.

Three checks on every request

  1. The pageWhat a signed-in role may open, with the role read from the database on every request
  2. The server actionWhat that role may change, checked again before anything is written
  3. The databaseRow-level security on every table, and checked functions for the most sensitive records

Each club is separate, and who can see what

Every club has its own address, its data is kept apart from every other club's at the database level, and a record from one club cannot point to another's.

Roles are read from the database on every request; sign-in belongs to the club's own address, an unknown address shows not found, and a child's own login never shows billing.

  • Coaches do not see money
  • Coach notes never reach athletes or parents
  • One family never sees another's child or data

Children in chat

Every chat with someone under 18 has adult staff and a second adult in it: two adult staff in team and group chats, or one and the child's own parent in the child's own chat. Staff under 18 and athletes with no date of birth on file count as minors, and only adult staff can mention a child.

A staff photo of a child under 18 needs a recorded parent or guardian agreement, and chat photos are re-encoded with their location data removed.

A coach's view of a 15-year-old's chat. With one adult coach in it and no second adult, the chat is paused, and the database refuses new messages until another adult staff member or, in the athlete's own chat, their parent is in it. Team and group chats with children always need two adult staff. Names and figures are sample data.

Files, sign-in and records

Photos, voice messages and staff documents sit in private storage behind short-lived links issued after a fresh check, and the app keeps no personal data in the browser's storage.

Admins and owners can read the audit log and nobody can edit it.

  • Access tokens last an hour; refreshes are rotated
  • Invoice links stored as a one-way hash, expiring and revocable
  • Permanent deletion needs a dry run and the full name typed

Tested before every change.

Family separation and club separation each have their own automated test suite, run against the live database and rolled back before every database change. There are no advertising or tracking scripts in the app or on this site, and club workspaces are kept out of search engines.

Security questions

Can POWA staff see our athletes?

POWA's staff console shows each club's name and two email switches, and nothing about members. Every change to those switches needs a written reason and appears in the club's audit log.

Which services does POWA use, and where is our data hosted?

The application runs on Vercel, and the database, sign-in and file storage are on Supabase. Email is sent through Resend. Ask us for the hosting region.

Does POWA hold a security certification?

Not today. This page describes how POWA is built. Ask us about anything it does not answer.

Does POWA support two-step sign-in?

Not today. Sign-in is by email and password, with limits on repeated attempts.

Does a parent count as the second adult in a child's chat?

Yes, in the chat of a child with their own login: one adult staff member and that child's parent or guardian are enough. Team and group chats with children always need two adult staff, and parents never count there.

Security questions go to team@powa.co.

Read the privacy policy and child-safe chats for families.

See how your club would run on POWA.

Book a demo and we will walk you through it with your programs, schedule and families in mind.