Security overviewLast updated May 2026

How we handle your data.

We're a small team and we want to be direct about what we do. This page covers the data we store, how we protect it, what rights you have, and where we still have work to do. No jargon. No empty reassurances.

Questions or concerns? security@thurzy.com

What we store.

Only what the platform needs
─ Player data

Name, email address, optional phone number, and sport-specific profile fields (jersey number, skill rating). No government-issued IDs, no biometrics.

─ Payment records

Payment amounts, dates, and method labels (Stripe, Zelle, Venmo, cash). For Stripe payments, card data is held exclusively by Stripe — Thurzy stores only the last four digits and card brand for display purposes.

─ Communications

RSVP responses, reminder delivery status, and audit logs of admin-triggered broadcasts. Message content is not retained beyond 90 days.

─ Scheduling and attendance

Event schedules, RSVP history, and attendance records for your group's sessions. This is the core operational data that makes the platform useful.

Encryption.

TLS · passwords · encryption
01
─ Connections

All connections to Thurzy use TLS.

02
─ Passwords

Passwords are hashed before storage.

03
─ Your data

Data is encrypted in transit and at rest.

Your rights.

Q.01

Can I export my data?

Group admins can export player rosters and payment history as CSV from the admin dashboard. We are building a full account-level data export endpoint — available in a future release.
Q.02

Can I delete my account?

Yes. Email security@thurzy.com with your account email and the subject 'Account deletion request'. We will permanently delete your personal data within 30 days and confirm in writing. Active billing relationships must be cancelled first.
Q.03

Can admins see players' data?

Group admins can see contact and profile data for players in their own group. They cannot see data from other groups. Superusers at Thurzy can access all data for support and operational purposes.
Q.04

How long do you keep data after account closure?

Financial records (payment ledger entries) are retained for seven years to satisfy accounting obligations. All other personal data is deleted within 30 days of an account-deletion request.
Q.05

Do you sell personal data?

No. We do not sell, share for compensation, or trade personal data with third parties. Data is shared only with service providers needed to run the platform, as described in our Privacy Policy.

What we don't have yet.

We believe in honest positioning. Here's where we stand today — and what we're working toward.

─ No SOC 2 yet

We have not completed a SOC 2 Type II audit. We follow the practices documented on this page, but we do not have a third-party attestation. This is on our roadmap as we grow.

─ No published bug bounty

We do not currently operate a public bug bounty programme. If you find a security issue, please disclose it responsibly to security@thurzy.com and we will respond promptly.

─ Small team

Thurzy is built and operated by a small team at Par72 Labs, LLC. We take security seriously and apply good practices, but we do not have a dedicated security operations team or 24/7 monitoring.

─ GDPR is a work in progress

We serve users across North America and make reasonable efforts to honour data rights. Formal GDPR compliance infrastructure (DPA agreements, supervisory authority registration) is in progress.

── Contact

Found something? Tell us.

Responsible disclosure is always appreciated. Email security@thurzy.com with a description of the issue. We aim to respond within one business day.

security@thurzy.com →