Security & Trust
Estadio handles squad medical records, contracts, salaries, and financials — material a club's board, players, and staff would never want leaked. Here's exactly how we protect it, where it lives, who can see it, and what happens if something goes wrong.
01 · Hosting
Estadio runs on Vercel for application hosting and Supabase for database and authentication. Both are deployed in EU-West (Frankfurt). Production data does not leave the EU.
Vercel and Supabase both maintain SOC 2 Type II attestations on the underlying infrastructure we build on. Their reports are available on request.
02 · Data protection
03 · Access control
04 · Backups & recovery
05 · Compliance
06 · Sub-processors
The following providers process customer data on Estadio's behalf. We commit to notifying customers at least 30 days before adding a new sub-processor.
| Provider | Purpose | Location | Privacy |
|---|---|---|---|
| Vercel | Application hosting | EU-West (Frankfurt) | Policy → |
| Supabase | Database & authentication | EU-West (Frankfurt) | Policy → |
| Stripe | Payments & subscriptions | Ireland / United States | Policy → |
| Resend | Transactional email delivery | United States | Policy → |
| Sentry | Error monitoring | EU (Frankfurt) | Policy → |
07 · Incident response
08 · Vulnerability disclosure
If you believe you've found a security vulnerability in Estadio, please email security@estadio.io rather than disclosing it publicly. We commit to:
09 · Shared responsibility
Estadio is responsible for
Your club is responsible for