Security
How we protect your data
Last updated 7 September 2026
Elite Rugby App is a trading name of BPM Performance Zone Limited, a company incorporated in New Zealand (NZBN 9429051799557), based in Christchurch, New Zealand. Version 2.0. Contact: help@eliterugbyapp.com.
Coaches, clubs and players trust us with their accounts, their training records, their squad lists and their payments. This page explains, in plain terms, what we do to protect that information. It describes what is actually in place. It does not promise the impossible: no service can guarantee perfect security, and we will not tell you otherwise.
The short version
- Every connection to our website, portals and app is encrypted.
- Your card number never touches our systems. It goes straight to our payment provider.
- Passwords are stored only as one-way hashes. Nobody at Elite Rugby App can read yours.
- Our staff must use two-step sign-in, and each staff member only sees the parts of the system their role needs.
- Found a problem? Email us. We reply within two business days and we do not take action against good-faith researchers.
1. How we think about security
- Least access. People and systems get the access they need for their job and no more.
- Trusted providers. We build on established infrastructure providers rather than running our own servers, and we hold them to written terms.
- Defence in layers. Sign-in protection, database-level access rules, hosted payment fields, signed integrations and audit trails each cover for the others.
- Honesty. We describe what we do. When something changes, this page changes.
2. Encryption
- Every page and every request to our website, account pages and portals is served over HTTPS. Traffic between our systems and our providers is encrypted in transit.
- Information we store is encrypted at rest by our database and hosting providers, and their backups are encrypted too. These are the providers’ controls, described in their own published security documentation.
- Passwords are never stored in readable form. Our authentication provider stores them as one-way hashes. We never see, log or store your plain-text password. Because your website login and your mobile app login are the same, the password you set is passed once, over an encrypted connection, to the company that hosts our app so that it works there too.
3. Signing in
- You can sign in with your email address and password, with a one-time code we email you, or with a passkey (Face ID, Touch ID, a fingerprint or a device PIN). A passkey only works on our own domain and only after your device has verified you.
- Passwords must be at least 8 characters. We recommend a long, unique password or a passkey.
- Repeated failed sign-in attempts and repeated wrong reset codes are slowed down automatically, so someone guessing at your account is stopped.
- Sessions expire and refresh automatically. Signing out ends the session on that device.
- Our own staff must complete a second step with an authenticator app before any internal page will load. Coaching partners can enrol an authenticator as an extra step for their portal. For members, the strongest option today is a passkey.
4. Payments
- Card details are entered into fields supplied and rendered by our payment provider inside their own secure frame, or passed as a token from Apple Pay or Google Pay. The card number, expiry and security code go from your browser to the provider. Our servers receive a token, never the card.
- Our payment provider is certified to PCI DSS Level 1, the highest level of the card industry security standard.
- What we keep is the minimum needed to show you which card is on file and to prevent fraud: the card brand, the last four digits, the expiry date, the issuing country and a card identifier from the provider that is the same each time the same card is used.
- Coaching partners who receive commission give their bank details to our payment provider through our portal. We keep the provider’s reference for the payout destination, not the account number.
5. Who can see your information
- Each member of our team has a named account with a defined role. Roles control which sections of our internal systems a person can open. Actions involving money, such as refunds and commission changes, are limited to owner accounts.
- Access limits are enforced inside the database as well as in the interface, so a person signed in as one role cannot read data that belongs to another.
- Administrative actions such as refunds, cancellations and account changes are written to an append-only audit trail that records who did what and when.
- Only a company email address can send messages to members from our systems.
- Within a club or school, coaching staff and the administrator can see their own squad’s activity and nobody else’s. Members of one club never see another.
- Coaching and affiliate partners see aggregate results and limited details about the people they referred. They never see payment details or messages.
6. Our providers
We run on established cloud infrastructure. Our website and application hosting provider and our database and authentication provider both publish SOC 2 Type II reports and operate hardened data centres with continuous monitoring and physical access controls. We are not ourselves SOC 2 certified and we do not claim to be. Our payment provider is a licensed payment institution. Coaching video files and our match-analysis service are stored with a major cloud provider in Australia. Our Privacy Policy lists every provider and what each one receives.
- Every automated message from a provider into our systems (payments, email events, meetings, messaging) is checked against a signature before we act on it.
- Scheduled background jobs require a secret to run and cannot be triggered from the public internet.
- Our public site sits behind automated bot and attack protection at the network edge.
7. The mobile app
The Elite Rugby App mobile app is built and hosted for us by a specialist app platform provider, named in our Privacy Policy, and distributed through the Apple App Store and Google Play. Data between the app and the provider travels over an encrypted connection. The provider runs its own infrastructure; we describe our own controls here and do not restate theirs. If you have a security concern about the app itself, tell us and we will raise it with the provider.
8. Monitoring and backups
- Automated health checks watch our payment flows, our integrations and app access many times a day, and alert our team when something is wrong, so problems are found by us rather than by you.
- Our database provider takes automatic daily backups, held encrypted.
- We review who has access to our systems and remove access when someone leaves.
9. Young players
Squads added by clubs and schools often include players under 18. Their records are flagged, they are excluded permanently from marketing and advertising audiences, each receives an activation email addressed only to them, and only their own club’s coaching staff and our team can see their activity. Our Privacy Policy explains the rules in full.
10. Your part
- Use a long, unique password or a passkey. Do not reuse a password from another site.
- Do not share your login. One account is for one person.
- Sign out on shared devices.
- We will never ask you for your password by email, chat or phone. If someone does, it is not us.
- If you think someone else has used your account, email us straight away.
11. Reporting a security problem
Found something? We would rather hear it from you than from a bad actor. Email help@eliterugbyapp.com with the subject line “Security”, the details, and steps to reproduce. We will acknowledge within two business days, keep you informed as we work on a fix, and credit you if you would like. We do not take legal action against researchers who act in good faith: test only accounts you own, do not access or change other people’s data, do not disrupt the service, and give us a reasonable time to fix the problem before talking about it publicly.
12. If something goes wrong
If a security incident affects your information, we investigate immediately, contain it, and tell you without undue delay. Where the incident is likely to cause serious harm we notify the New Zealand Privacy Commissioner as soon as practicable, and where United Kingdom or European Union rules apply we notify the relevant authority within 72 hours of becoming aware. We will explain what happened, what information was involved, what we have done about it, and what you can do to protect yourself. We treat an unauthorised disclosure as an incident, not only a break-in.
Security or compliance questions?
Email help@eliterugbyapp.com and we will route it to the right person.