Trust starts with transparency.
TeamFeePay is built for the people who run grassroots football clubs — and for the trust they place in us with their members' data. Explore our certifications, security practices, and the controls that keep your data safe.
Explore our trust posture
Every control we operate, mapped to the standards your team cares about.
Security practices
How we protect the platform, our people, and the data clubs entrust to us.
Data protection
Encryption, key management, retention, and how we handle data subject rights.
Identity & access
Authentication, MFA, RBAC, and how we manage access to systems and customer data.
Infrastructure
Where the service runs, how it is hardened, and how we maintain availability.
Privacy
GDPR, ISO 27018 cloud privacy controls, and how we minimise personal data.
Incident response
How we detect, contain, and communicate security incidents — and the SLAs we hold.
Recent updates
The latest from our security and compliance teams.
Incident response programme
Severity tiers, SLAs, and how we communicate incidents to customers.
International data transfers
How we manage cross-border transfers under UK and EU rules.
Our role under UK GDPR
Where we act as a processor, where we act as a controller, and what that means.
Data retention and deletion
Defaults, customer overrides, and how we honour deletion requests.
Common questions
Quick answers to the questions security and procurement teams ask us most.
How do I request your SOC-style report or pen-test summary?
Visit the Compliance page and click the document you need. You'll be asked to provide your business email and accept a short NDA — after that the download is immediate and stored against your visitor record for re-download.
Where is customer data stored?
All production data is stored in UK and EU regions on tier-1 cloud providers. We do not store production data outside of the UK/EEA.
Are you GDPR compliant?
Yes. We process personal data in line with UK GDPR and the Data Protection Act 2018. ISO/IEC 27018 governs our handling of personal data in cloud environments.
How do you handle cardholder data?
We are a PCI DSS Level 2 service provider and minimise the cardholder data we ever see by routing card capture directly to our PSP. The platform itself stores only token references.