Security & your data

Trustees are responsible for their hall's records, so you deserve straight answers about where they live and how they are looked after. Here they are, in plain English.

Where your data is stored

Village Hall Hub runs on servers located in a data centre in the United Kingdom. Your bookings, hirers, invoices and documents are held there. The one exception is the optional AI assistant on the Professional plan, which sends the booking and hirer names it needs to answer a question to OpenAI in the United States - see "Who else handles your data" below, and you can switch it off.

Encryption

Every connection to Village Hall Hub is encrypted in transit using HTTPS (TLS) - the same protection your bank uses. Especially sensitive fields, such as your bank account details for invoices, are additionally encrypted at rest inside the database, so they are unreadable even to someone with a copy of the raw data.

Backups

The whole database is backed up automatically every week, overnight on a Sunday, and kept securely off the server so your records can be restored if something goes wrong with it. On top of that, you can export your own data whenever you like - your bookings, invoices and compliance records are yours, and there is nothing to stop you taking a copy for your own records or keeping one with your minutes.

Who can see your hall's data

Each hall's data is separated from every other hall's - your committee can only ever see your own venue. Within your hall, you control who sees what through team member roles: a trustee can view compliance and reports without being able to edit bookings; a read-only member can look but change nothing. Village Hall Hub staff access accounts only to provide support you have asked for, or to fix a fault.

Passwords and signing in

Passwords are stored using strong one-way hashing - nobody, including us, can read them. Two-factor authentication is available for every account under Settings, and we recommend committee members switch it on.

UK GDPR

Village Hall Hub is built for UK charities and community groups and operates under UK GDPR. The product itself helps your hall meet its own obligations, with a GDPR dashboard, consent records, data subject request tracking and a privacy notice generator.

Who else handles your data

Running the service means using a small number of other companies, and you are entitled to know which. Our servers are provided by a UK hosting company. Card payments, where a hall takes them, are handled by Stripe - we never see or store card numbers. Emails are sent through our email provider. On the Professional plan only, the AI assistant sends the booking names and hirer names it needs to answer your question to OpenAI in the United States; it never sends email addresses, phone numbers, postal addresses or payment details, it cannot change anything, and your committee can switch it off under GDPR in your admin. We do not sell your data or your hirers\x27 data to anybody, ever.

Your data is yours

If you ever decide to leave, your records belong to your hall, not to us. You can export invoices, payments and income summaries as spreadsheets at any time, and we will help you take a full copy of your data with you.

Got a question we haven't answered - or does your committee need something in writing? Email hello@villagehallhub.co.uk and we will reply personally.