DPA
Available on request for clubs that need procurement review.
Security and trust
A factual trust packet for boards, accountants, and IT reviewers: data flow, vendors, access controls, DPA status, and the path for security questions.
Trust packet
Lobby avoids unsupported certification claims. Active posture and roadmap items are described as such.
DPA
Available on request for clubs that need procurement review.
Privacy roles
Lobby acts as service provider (processor) for clubs; players are handled under the club relationship.
Data location
Application services run on Railway in the United States; the database region and backups are documented in the security pack.
Payments
Card data is handled by Stripe, not stored in Lobby.
Incident path
Security and compliance requests route to a monitored inbox.
Data flow
The diagram is plain because the system is plain. Each vendor has one operational job.
Booking, profile, and checkout actions from the club booking surface.
Tenant routing, authorization, booking writes, reminders, and admin workflows.
Operational data for clubs, members, bookings, classes, payments, and audit records.
Card capture, payment processing, refunds, and payout reporting where Stripe is supported.
Transactional booking, login, payment, and staff notification emails.
Scoped staff access for migration, debugging, and operator-requested support.
Access controls
Support work is tied to migration, debugging, or an operator request. Lobby does not use support access as a hidden analytics path.
Subprocessors
Procurement can review the current vendor list before launch. Additions should be communicated through the DPA process.
Service
Region
Purpose
DPA
List last reviewed 2026-05-11
Subscribe to subprocessor changes →Hosting and privacy posture
Database
Railway · United States
Payments
Stripe-supported markets
DPA
Available on request
Compliance claims
No fake badges
This page does not claim that every dependency uses the same region. It states the procurement facts: the application services run on Railway in the United States, a DPA and state-privacy review are supported, and Stripe handles card data under its own payment compliance program.
Contact path
[email protected] for responsible disclosure and sensitive reports.
Contact path
[email protected] for DPA, vendor, and procurement questions.
Contact path
Affected operators are contacted through their account owner and admin email.