How we protect your data
Encrypted in transit.
Every connection to XCTimer runs over HTTPS/TLS. Nothing you send or view crosses the internet in the clear.
Locked behind sign-in.
Rosters, results, and contact details are only reachable by signed-in users. The one thing that can be public is a live results page — and only when a coach chooses to share its link.
Your district, fenced off.
Each district's data is isolated. A coach or admin in one district cannot see another district's athletes, meets, or results.
Least privilege by role.
Coaches, timers, district admins, and platform admins each see only what their job needs — nothing more.
Hardened sessions.
Sign-in cookies are locked to your browser (HttpOnly, Secure, SameSite), sessions expire on their own after inactivity and on a hard cap, and every action that changes data carries an anti-forgery (CSRF) token.
Defense in depth.
A strict Content-Security-Policy, modern security headers, parameterized database queries, and a no-cache rule on every page that shows student data.
Locked down at rest.
The database lives on a private server with no public inbound access — reachable only through the authenticated app, behind a managed network edge.
Daily backups.
Rosters and results are backed up automatically every night, so a bad day never means lost data.
What we hold — and what we don't
What's in your account.
Athlete rosters (name, grade, school, bib), meet entries and results/times, and any optional contact, parent, emergency, physical, or waiver details a coach chooses to add. That's the whole list.
What we deliberately don't collect.
- ✕ No Social Security numbers.
- ✕ No bank account or credit-card numbers.
- ✕ No third-party advertising or tracking scripts.
- ✕ We never sell or share your data — with anyone.
Only what a meet needs.
Because these are junior-high athletes, we keep the footprint small on purpose. A field exists because a real meet or a real waiver uses it — and it's built with student-privacy expectations (FERPA / COPPA) in mind.
Your data on the way out.
Export full results to Excel anytime. Want a student's — or your whole district's — data removed? Ask us and we'll delete it.
If something goes wrong
We'll tell you.
If a security incident ever affected your data, we'll notify affected districts promptly — our target is within 72 hours of confirming it — with what we know and what we're doing about it.
Where it runs.
XCTimer is hosted on dedicated servers in the United States (Hillsboro, Oregon).
Talk to us
Security researchers.
Found something? Email [email protected]. We welcome good-faith reports and won't pursue researchers acting in good faith.
Schools, districts & vendor reviews.
Need a security questionnaire filled out, or have a district data-privacy requirement? Email [email protected] — happy to help.
← Back to XCTimer