PCI-DSS Level 1
Stripe is certified to the highest level of PCI compliance. HometownLift never stores, processes, or transmits card numbers.
Security
Payment processing, data storage, access controls, and platform infrastructure are all designed with security as a baseline, not an afterthought.
Payment security
Stripe is certified to the highest level of PCI compliance. HometownLift never stores, processes, or transmits card numbers.
Each organization connects their own Stripe account. Funds flow directly from Stripe to the organization's bank account.
Card information is entered directly into Stripe's hosted checkout. HometownLift never sees or stores payment credentials.
All connections use HTTPS/TLS. Data in transit between the browser, HometownLift, and Stripe is encrypted.
Data security
Every database query is scoped to the authenticated user's organization. Admins cannot see other organizations' data.
Directors, coaches, and athletes each see only what their role requires. Coaches cannot access financial data or other teams.
Users can only join an organization through an explicit invite from an admin. There is no self-registration for org membership.
Application data is hosted on Supabase with PostgreSQL, row-level security policies, and automated backups.
Access controls
Directors
Manage organization settings, Stripe connection, campaigns, rosters, reporting, refunds, and team permissions.
Coaches
Import rosters, send athlete invites, and track participation. No access to financial data, other teams, or org settings.
Athletes
Claim their personal fundraising page, add a photo and message, and share their link. No access to donations or admin tools.
Donor experience
Donors give through a standard Stripe checkout. No login, no profile, no stored data on HometownLift.
Donors receive an email receipt from Stripe immediately after their donation is processed.
Related