Security
Security and privacy are foundational to GoodTimes. This page summarizes how we protect your data, how we handle payments, and how to report a vulnerability.
1. Architecture
GoodTimes runs entirely on Cloudflare’s edge network. There are no traditional origin servers. Our API is a Cloudflare Worker written in Hono; our web frontend is a Next.js application deployed via OpenNext on Cloudflare Workers. All business data lives in Cloudflare D1 (SQLite at the edge), and file uploads (waivers, images) live in Cloudflare R2. This edge-first architecture dramatically reduces the attack surface compared to conventional VPS or VM hosting.
2. Data Protection
- Encryption at rest: D1 and R2 provide automatic encryption at rest managed by Cloudflare.
- Encryption in transit: TLS 1.3 is enforced across all public endpoints; HTTP requests are redirected to HTTPS automatically.
- Authentication: scoped JSON Web Tokens signed with HS256, rotated per session, validated on every API call.
- Authorization: every mutation is checked against a two-axis role model (site permissions + per-team roles) before it executes.
3. Payment Security
All payments are processed by Stripe using Stripe Checkout. Your card number, CVV, and billing details are entered directly into Stripe’s PCI-DSS Level 1 certified systems and are never transmitted to or stored by GoodTimes. We retain only a transaction reference, the amount, and the last four digits for accounting and support.
4. Vulnerability Disclosure
If you discover a security issue, please report it to security@goodtimes.events. We practice responsible disclosure: we ask researchers to give us a reasonable window (at least 30 days) to remediate before publicly disclosing, and we commit to responding to initial reports within two business days.
Please do not access or modify other users’ data, disrupt the Service, or perform any testing that could negatively impact live events or real participants.
5. Open Data, Open Exits
We do not sell your data, and we do not lock you in. Every organization on GoodTimes can export its full dataset — registrants, teams, games, scores, transactions, spirit scores — in CSV at any time from the admin dashboard. If you decide GoodTimes is not the right fit, you walk away with everything you brought.
6. Incident Response
In the event of a confirmed security incident affecting your data, we will notify affected organization administrators by email within 72 hours of confirmation, share the known facts, and provide guidance on any steps we recommend participants take. We will follow up with a post-incident summary once remediation is complete.
Contact
Security team: security@goodtimes.events
