Rapport Host Management · IndianapolisBuilt by the team behind SNFRadar

Security and data

The member list is the most private thing a club has.

We say here only what we can show you on screen. No uptime figure, no certificate on the wall. Ask us for the walkthrough on the consultation and we will open the office and show each of these controls where staff use them.

Roles and permissions

Four roles. Each sees what its job needs.

RoleSeesCan doNever
MemberTheir own profile, the events and groups they opted into, other members only where both have opted in to be seenEdit their own profile and contact choices, RSVP, book, message another member through the club without exposing a number or an addressExport a list, see another member's contact details, see anything the other member did not choose to show
StaffThe members and reservations for their own area: front desk, dining, eventsCheck in, add a note, apply an approved charge, reply in the club's texting inboxBroadcast, change consent, export, change another role's permissions
Club adminThe whole club: roster, consent log, suppression list, the audit log, every draft waiting for approvalApprove a send, run the importer, connect or disconnect a system, set quiet hours, answer a data request, invite staff and set their roleSee a member's private messages to another member; change what a member chose to show
EnterpriseThe roll-up across every club in the group, drill-down to a club with that club's own admin viewMessage a club's managers inside the product, set group-wide policy, provision single sign-onBypass a club admin's approval on a member send; export a member roster the club did not release

Every action by every role is written to an audit log the club admin can read: who, what, when, and from which door.

Ownership and provenance

The data stays the club's.

The club's system of record stays the system of record

We read the roster, the statements and the reservations from the system the club already runs. We write back a note, a charge, or the member's own profile. Nothing else. If the club leaves, the club takes its data in an open format and we delete our copy on a date the club sets.

Every fact carries its source and its as-of date

A balance says which system it came from and when it was read. A preference says whether the member typed it or a staff member did. A stale fact says it is stale rather than pretending to be current. Nothing on a screen is a number without a label.

Nothing sold, nothing shared for marketing

No advertising, no public directory, no data brokers, no list sales. A vendor we connect to sees only what its connection needs and only for the club that connected it. The privacy policy says the same thing in the words a lawyer wants.

Derive, never maintain

We do not keep a second roster that drifts from the club's. The member's spend view, the office's minimums page and the board report are derived from the source each time, so there is one truth and it is the club's.

Protection

Encrypted in transit and at rest.

In transit

Every connection to the member surface, the office and every vendor runs over TLS. There is no plain-HTTP door.

At rest

Databases, backups and uploaded files are encrypted on disk by the hosting provider's managed storage. Credentials for vendor connections are held in a secrets store, never in code or in a file the office can open.

Sign-in

Members sign in with a link sent to the email or phone the club already holds for them; no new password to forget. Staff sign in through the club's own Microsoft or Google accounts. Single sign-on is available for groups.

Consent

A signal is not a send.

Nothing sends itself. The system drafts; a person approves. Every outbound message, on every channel, checks the suppression list first, and the ledger row is written before the send leaves.

Consent log on every channel. How a member opted in, when, from where, and to what. Text, email and in-app are recorded separately, because a member can say yes to one and no to another.
Suppression on every channel. STOP on a text, unsubscribe on an email, or a word to the front desk lands on the suppression list the same minute, and every channel checks it before a send. A carrier opt-out is mirrored to the club's log.
Quiet hours. No text before 8 am or after 9 pm in the member's own time zone, with the club able to set a narrower window. A draft that would land inside quiet hours waits.
One ask per message, a person behind each one. Broadcasts are approved by a club admin. Replies in the inbox are typed by staff. The system never texts a member on its own.
Data requests honoured. A member can ask what the club holds about them in the product, ask for a correction, or ask for deletion. The club admin answers from one screen and the answer is logged. See the privacy policy for how to ask.

Next step

Ask to see it, not read it.

On the consultation we open the office and show the consent log, the suppression list and the audit log where staff use them.

Book a consultation