1. Infrastructure & Data Protection
Athlete Intro implements industry-standard security measures to protect your data. Our security practices include:
- Hosted on providers (Vercel and Supabase) that hold SOC 2 Type II reports. These are our providers' certifications, not a certification of Athlete Intro itself.
- Data encrypted in transit (HTTPS/TLS) and at rest (AES-256, provided by our database and storage provider)
- Daily automated database backups through our database provider
- Network protections from our hosting provider, plus limits on repeated requests to sensitive features
- Database access rules that block direct public access to sensitive tables. Account data is read through our server, which checks who you are before returning it.
2. Activity Records
We record key account and profile events, such as profile submission and publication, terms acceptance, and access code use. We do not keep a full edit-by-edit history of every profile change.
3. Where Profile Data Comes From
Profile information comes from you, editors you authorize, or our team building your profile from what you provide. We don't pull information about you from other websites.
4. Authentication
- Sign in with a password or a one-time email link
- Email sign-in links are designed to work once and expire quickly
- Sign-in sessions use short-lived tokens that are renewed automatically
5. Third-Party Security Compliance
Our payment processing partner Stripe maintains PCI DSS Level 1 certification, the highest level of security compliance in the payment card industry.
6. Reporting Security Issues
Report potential vulnerabilities to info@getzoptic.com.
7. Limitations
No system is 100% secure. We implement industry-standard practices but cannot guarantee absolute security.