Name, email address, optional phone number, and sport-specific profile fields (jersey number, skill rating). No government-issued IDs, no biometrics.
How we handle your data.
We're a small team and we want to be direct about what we do. This page covers the data we store, how we protect it, what rights you have, and where we still have work to do. No jargon. No empty reassurances.
Questions or concerns? security@thurzy.com
What we store.
Only what the platform needsPayment amounts, dates, and method labels (Stripe, Zelle, Venmo, cash). For Stripe payments, card data is held exclusively by Stripe — Thurzy stores only the last four digits and card brand for display purposes.
RSVP responses, reminder delivery status, and audit logs of admin-triggered broadcasts. Message content is not retained beyond 90 days.
Event schedules, RSVP history, and attendance records for your group's sessions. This is the core operational data that makes the platform useful.
Encryption.
TLS · passwords · encryptionAll connections to Thurzy use TLS.
Passwords are hashed before storage.
Data is encrypted in transit and at rest.
Your rights.
- Q.01
- Group admins can export player rosters and payment history as CSV from the admin dashboard. We are building a full account-level data export endpoint — available in a future release.
- Q.02
- Yes. Email security@thurzy.com with your account email and the subject 'Account deletion request'. We will permanently delete your personal data within 30 days and confirm in writing. Active billing relationships must be cancelled first.
- Q.03
- Group admins can see contact and profile data for players in their own group. They cannot see data from other groups. Superusers at Thurzy can access all data for support and operational purposes.
- Q.04
- Financial records (payment ledger entries) are retained for seven years to satisfy accounting obligations. All other personal data is deleted within 30 days of an account-deletion request.
- Q.05
- No. We do not sell, share for compensation, or trade personal data with third parties. Data is shared only with service providers needed to run the platform, as described in our Privacy Policy.
Can I export my data?
Can I delete my account?
Can admins see players' data?
How long do you keep data after account closure?
Do you sell personal data?
What we don't have yet.
We believe in honest positioning. Here's where we stand today — and what we're working toward.
We have not completed a SOC 2 Type II audit. We follow the practices documented on this page, but we do not have a third-party attestation. This is on our roadmap as we grow.
We do not currently operate a public bug bounty programme. If you find a security issue, please disclose it responsibly to security@thurzy.com and we will respond promptly.
Thurzy is built and operated by a small team at Par72 Labs, LLC. We take security seriously and apply good practices, but we do not have a dedicated security operations team or 24/7 monitoring.
We serve users across North America and make reasonable efforts to honour data rights. Formal GDPR compliance infrastructure (DPA agreements, supervisory authority registration) is in progress.
Found something? Tell us.
Responsible disclosure is always appreciated. Email security@thurzy.com with a description of the issue. We aim to respond within one business day.
security@thurzy.com →