Trust & Security

Verified against the running system on 16 August 2026

This page is for the person doing due diligence before moving an academy's records onto someone else's software. Every number on it was read out of the live system rather than written from memory, and anything that could not be checked that way has been left out.

Who you are dealing with

Sleek&Tech System Ltd, a company registered in Nigeria with the Corporate Affairs Commission, RC 9771734, incorporated 13 August 2026. We make software. We are not a payment processor, we hold no customer funds, and we store no card details — there is nothing in the product that can take a payment, and during early access the checkout endpoint refuses at the server rather than being hidden in the app.

Where your data lives

ProviderWhat it doesWhere
SupabaseDatabase and sign-inCanada — AWS ca-central-1
VercelServes the panel, booking and check-in pagesGlobal edge network
ResendSends email — welcomes, invoices, repliesEmail delivery

PostgreSQL 17.6. These are our only subprocessors. If that list changes, this page changes with it.

One academy cannot see another

This is the question worth asking, so here is the specific answer. Separation is enforced inside the database, not by the app hiding buttons. All 41 tables have row-level security enabled — not most of them, all of them — under 47 policies, and 23 carry FORCE ROW LEVEL SECURITY, which applies the rules even to the table's owner.

The practical consequence: a bug in our code, or someone reaching past the app straight to the API, still cannot read another academy's records. The database refuses, not the interface.

We have tested that by trying to break it — deliberately attempting to read and to modify another academy's rows from an authenticated session. The database refused both.

Who inside your academy sees what

Three roles. An assistant coach sees the sessions they teach; an admin sees the money; the owner sees everything. Those limits are enforced by the same database rules, so a coach cannot reach a colleague's pay by knowing a web address.

Payslips are locked once issued — to the coach and to the owner alike. Five tables carrying account, membership, payment and settings changes write to an audit log that cannot be edited or deleted, including by us.

In transit

Served only over HTTPS, with HSTS set to two years, plus X-Frame-Options, X-Content-Type-Options: nosniff and a strict referrer policy. You can check those response headers yourself without asking us.

Phone notifications deliberately carry no text. These records name children, and a notification payload sits on a third-party service and appears on a lock screen anyone can read. Your phone says something needs you; the panel says who.

Backups, and a restore we have actually performed

Daily snapshots. More usefully: on 9 August 2026 we restored the entire database to a separate project and timed it. It came back in about seven minutes, with every row count matching a committed baseline and all 46 security policies intact — a restore that returns the data but not the rules would be worse than no restore, so both are checked.

Worst-case data loss is up to 24 hours. Point-in-time recovery would narrow that to minutes; it costs money and is not currently enabled. We would rather tell you the real number than a comfortable one.

Your data is yours

The export matters more than it sounds. The honest worry about a young company is not whether it is careless but whether it will still be here. Being able to walk out with everything is the answer to that, and it does not depend on us being cooperative on the day.

Children's data

Registers hold children's names and dates of birth, and parents' phone numbers. We say that plainly because it shapes everything above: the payload-free notifications, the role limits, the isolation testing.

Your academy is the controller of that data and we are the processor acting on your instructions.

Download our data processing agreement — the whole thing, including the country schedule that applies to you and Annex E, which lists what is not in place. If your own policy needs a separately signed copy, ask and we will sign one.

Built to work outside one country

Our NDPC registration

Sleek&Tech System Ltd is registered with Nigeria's Data Protection Commission, registration NDPC/DCP/14079.

It was granted in August 2026 in the business name the platform launched under, and the Commission approved the change to the company on 14 August 2026. This paragraph carried that as an open question for a day rather than a tidy claim, and it is recorded here because a page that only ever shows settled answers is not one you can check.

The number is printed so it can be checked with the Commission rather than taken on our word. That is the only reason to quote one — and until this was granted, the same paragraph said "approval is pending, we are not registered or approved yet", because it was not going to say anything else before the day it was true.

We also have a Data Protection Officer registered with the Commission, reachable at info@sleektechsport.com.

Being registered means we have told the regulator what we do with personal data and satisfied it that we are entitled to. It is not a security certification and we do not present it as one; the things it is not are in the section below.

What we do not claim

We hold no SOC 2 report, no ISO 27001 certificate, and no HIPAA, PCI DSS or GDPR certification. We have not been independently audited.

Any vendor can buy a badge for a website. We would rather you knew exactly which controls exist, could verify several of them yourself from outside, and could hold us to the ones you cannot.

Reporting a problem

Email info@sleektechsport.com. A person reads it — there is no queue to get lost in. If you have found a security problem, say so in the subject line and we will come back to you the same day.

If a breach affects your academy's data we will tell you what happened, what was affected and what we did, without waiting to be asked.

Privacy policy · Cookies · Terms · Back to site