Security & compliance

World-class security for your padel club

Padel365 is built on the same certified infrastructure trusted by banks, hospitals and governments. We encrypt every piece of data, isolate every club and comply with European data protection regulations.

SOC 2

Type 2

ISO 27001

2022 certified

GDPR

EU compliance

PCI DSS

Secure payments

AES-256

Data encryption

99.99%

Uptime

Certifications & compliance

Built on certified infrastructure

Padel365 doesn't improvise security: it relies on world-leading, independently audited providers. These are their current, publicly verifiable certifications.

Vercel

Hosting & global network (CDN/Edge)

The layer where the app lives and is served, with DDoS protection and encryption in transit.

Certifications

  • SOC 2 Type 2 (Security, Confidentiality & Availability)
  • ISO/IEC 27001:2022
  • PCI DSS v4.0 (Service Provider)
  • GDPR + EU-U.S. Data Privacy Framework
  • DDoS mitigation and TLS encryption
View security center

Supabase

Database, authentication & storage

Where club, player and booking data is stored, encrypted.

Certifications

  • SOC 2 Type 2 (audited annually)
  • ISO/IEC 27001:2022
  • HIPAA (sensitive health data)
  • PCI DSS
  • GDPR with per-region data residency
View security center

Mercado Pago

Payment processing

Processes payments and subscriptions. Card data never passes through Padel365's servers.

Certifications

  • PCI DSS Level 1 (the industry's highest)
  • Card data never touches our servers
  • End-to-end encryption on every transaction
  • Fraud detection and 24/7 monitoring
View PCI documentation

The SOC 2, ISO 27001, HIPAA and PCI DSS certifications belong to our infrastructure providers and are verifiable in their respective trust centers. Padel365 implements its own security controls on top of that certified foundation.

Application security measures

How we protect every piece of data inside Padel365

On top of certified infrastructure, we apply security controls at every layer of the application.

Club isolation (RLS)

Row-level security on every database table: your club's data is invisible to any other club on the platform.

End-to-end encryption

TLS 1.3 for data in transit and AES-256 encryption at rest. All communication travels protected.

Strong authentication

JWT token sessions, mandatory email verification, Google sign-in and two-factor authentication (MFA) available.

Role-based access control

Strict permissions for superadmins, club admins, coaches and players, with protection against privilege escalation.

Secrets vault

Payment credentials and sensitive keys are stored encrypted in a dedicated vault, never in plain text.

Payments without exposing cards

Payments are processed by Mercado Pago. Padel365 never sees or stores your card details.

Backups and recovery

Automatic backups, point-in-time recovery and geographic redundancy so no data is ever lost.

Monitoring and auditing

Event logging, webhook signature (HMAC) verification and continuous observability to detect anomalies.

Data protection & privacy

Designed for EU GDPR

Clubs in Italy and across the European Union can use Padel365 with the confidence of complying with the General Data Protection Regulation.

Right to erasure

Anyone can request the deletion of their personal data whenever they wish.

Data portability

Export your club's or profile's information in a reusable format.

Data minimization

We only collect the information strictly necessary to deliver the service.

Consent and transparency

We clearly explain what data we use and why, with no fine print.

Data processing agreements (DPA)

Processing agreements with all our providers, backed by EU Standard Contractual Clauses.

Data residency

Infrastructure with regions available in the European Union to keep data close to your users.

Our technology

The tools we trust

We choose each provider for its reputation, its certifications and its proven reliability at global scale.

Vercel

Hosting & global network

Edge deployment with high availability and attack protection.

Supabase

Database & authentication

Managed PostgreSQL with secure authentication and encrypted storage.

Mercado Pago

Payments

PCI DSS-certified payment processing, a leader in Latin America.

Resend

Transactional email

Reliable email delivery with a verified domain (SPF and DKIM).

Cloudflare

DNS & network protection

Domain management, DDoS mitigation and malicious-traffic filtering.

Next.js

Application framework

A modern, secure foundation with server rendering and best practices by default.

Why Padel365 is safe to use

Four reasons to trust us

World-class providers

We rely on the same platforms used by banks, hospitals and governments.

Security by design

Data protection isn't an add-on: it's the foundation we build every feature on.

Full transparency

Public, auditable privacy policies written in plain language.

European compliance

Designed to meet the requirements of clubs in Italy and the European Union.

Frequently asked questions

Questions about security and certification

Padel365 runs on infrastructure certified to SOC 2 Type 2, ISO 27001 and PCI DSS (Vercel, Supabase and Mercado Pago) and applies its own security controls on top. We can provide our providers' certification documentation on request.

Have questions about security or compliance?

Our team can help with vendor assessments, data processing agreements (DPAs) and certification documentation.

Last updated: July 2026. The certifications mentioned (SOC 2, ISO 27001, HIPAA, PCI DSS) belong to Padel365's infrastructure providers โ€” Vercel, Supabase and Mercado Pago โ€” and are verifiable in their public trust centers. Padel365 implements additional security controls on top of that certified foundation.