Trust & Stewardship

Security & Data Handling

You are asked for identifying, emergency, and sometimes medical information before you ever step onto a range with us. Here is exactly how that information is protected.

Version 1

1. In Transit

Every page and every form on this site is served over HTTPS. Anything you type into a registration, consultation, feedback, or contact form is encrypted between your device and our systems.

2. Submissions Are One-Way

Registration, consultation, and contact forms are built to write only. Once your submission is saved, it cannot be read back from the website by you, by another visitor, or by anyone browsing the site. Records are reachable only through an authenticated staff session.

3. Staff Access Is Restricted

The operations dashboard is behind a separate staff sign-in. Public sign-up is disabled — staff accounts are created only by an administrator.

  • Staff passwords must be at least 12 characters and are checked against known breached-password lists.
  • Permissions are stored server-side and verified on the server for every request. They cannot be granted or faked from a browser.
  • The database enforces its own row-level access rules independently of the website code, so a mistake in one layer does not expose records in the other.

4. Sensitive Fields Are Separated

Accessibility and medical notes are stored apart from your general contact record and are surfaced only to instructional staff who need them to keep a session safe. They are also on a shorter retention clock than the rest of your file.

5. Payments

Card entry happens on our payment processor's own hosted checkout. Full card numbers, expiry dates, and security codes never reach this website and are never stored in our records. We retain only the amount, date, status, and receipt reference, together with an audit trail of every change to a payment record.

6. Permanent Records vs. Disposable Data

Signed waivers and issued certificates are deliberately locked after creation — they cannot be silently edited, which protects you as much as it protects us. Everything that is not a required training or financial record is cleared automatically by a scheduled retention process, with each run logged and reviewable by an administrator.

7. Monitoring & Maintenance

We run automated security and dependency scans against this site and keep its software components patched. Access rules on new features are reviewed before they go live.

8. Reporting a Concern

If you believe you have found a security problem with this website, or you think your information has been exposed, contact us before disclosing it publicly. Email inquiries@ssdtrain2protect.com with the subject line "Security" or call (312) 912-2137. We will acknowledge your report and tell you what we find.

Please do not attempt to access another participant's record, run destructive tests, or submit large volumes of automated traffic while investigating.

9. What We Do Not Claim

We are a small training company, not a certification body. We do not claim SOC 2, ISO, HIPAA, or PCI certification, and no system can be promised to be immune from every attack. What we do commit to is limiting what we collect, restricting who can see it, deleting what we no longer need, and telling you directly if something goes wrong.

For the full account of what we collect and how long we keep it, read the Privacy Notice.

Privacy Notice