Security & Good Practice
- Give every Administrator their own User account. Do not share Administrator passwords.
- Disable former Administrators promptly while keeping at least one Active Administrator.
- Check Payer email addresses carefully; access codes are sent there.
- Treat verification codes as private and use only the newest code.
- Never share a Stripe password or unrestricted secret key with ClubPayee or another Administrator.
- Use only the Restricted Key workflow and grant only the listed permissions.
- Keep reasons for Adjustments and Refunds specific and professional.
- Review Payment Activity, Refunds, Stripe fees, and outstanding balances regularly.
- Before changing a catalogue Fee across Open Seasons, check every affected Team.
- Sign out on shared devices.
Preserved history
Section titled “Preserved history”ClubPayee protects membership and financial history. A used Member, Team, Season, Fee, or Payer may not be deletable. Use supported Inactive or Closed states where appropriate.
Adjustments are reversed with correcting entries rather than silently changed. The original and correcting actions remain visible.
Online Payment safety
Section titled “Online Payment safety”Stripe-hosted Checkout handles card entry. ClubPayee does not ask a Payer or Administrator to enter card details into a ClubPayee form.
The Payer sign-in and Online Payment flows include abuse protections. If a security check or temporary Online Payment lock appears, do not repeatedly resubmit. Wait for the stated period or email ClubPayee Support at support@clubpayee.com if normal access does not return.
