How we secure your personal, medical, and financial data using modern cloud infrastructure.
We collect personal identifiers (Name, Age), contact data (Phone, Email), and vital medical history. Medical data is accessed only by head coaches and emergency responders to ensure athlete safety.
Our platform uses phone-based OTP authentication for secure access. All sensitive documents and profile images are hosted on encrypted AWS S3 buckets. We do not store raw passwords on our servers.
Financial transactions are handled securely by Razorpay. VCA does not see or store your credit card or bank details. All billing data is processed in compliance with PCI-DSS standards.
User data is shared only with essential service providers (e.g., AWS for storage, Razorpay for payments, SMS gateways for OTP). We never sell your data to third-party marketing firms.
Users may request account deactivation and data deletion via the dashboard. However, certain transaction logs and attendance records will be retained for 7 years to meet legal and audit obligations.