Test mode — payments here are simulated. Use card 4242 4242 4242 4242, any future expiry, any CVC. More test cards

Trust & security

How we look after your data and payments

Evening Class Connect is a booking platform used by adult-education colleges. This page is maintained by the platform team and explains — in plain language — what we do to keep learner information and payments safe. It is not a certification and it is not independent audit evidence; it is a summary of the controls that are currently in place.

Payments

Card payments are handled end-to-end by Stripe, which is PCI-DSS Level 1 certified. We never see, store or transmit your full card number. When you pay, your details go directly from your browser to Stripe.

The price you see on the checkout page is verified on our server before the payment is created — a database rule recomputes it from the course record every time, so a tampered page can't change what you're charged.

Learner data (PII)

We store the information you give us on a booking form (name, contact details, any eligibility fields the college asks for) so the college can run its courses. Each college can only see its own bookings — the database enforces this at the row level, not just in the app UI.

You can request a copy of your data or ask for it to be deleted at any time from My data on the college's site. GDPR requests are logged and rate-limited to prevent abuse.

Access to your bookings

The "My bookings" link you receive by email is a private, one-off URL. Don't share it — anyone with the link can view (but not change) your bookings. Links expire and can be re-issued.

College staff and admins sign in with a password; senior staff must also use two-factor authentication (TOTP) before they can reach admin screens.

Platform & hosting

The application runs on managed infrastructure:

  • Lovable Cloud — application runtime, daily project scans, dependency updates.
  • Cloudflare — HTTPS/TLS, HSTS, DDoS protection and web application firewall at the edge.
  • Supabase — Postgres database, authentication, encryption at rest and automated daily backups.
  • Stripe — card processing and PCI compliance.
  • Resend — transactional email delivery.

What each side is responsible for

Platforms cover

  • TLS, DDoS, WAF
  • Card processing & PCI
  • Database engine & backups
  • Runtime patches

We cover

  • Per-college data isolation
  • Server-side price verification
  • Webhook signature checks
  • Rate-limits on public forms
  • Monthly security review

Learners help by

  • Not sharing magic-link URLs
  • Using a strong, unique password if creating an account
  • Reporting suspicious emails to the college

Ongoing review

The platform team runs a monthly internal security review covering row-level security, dependency vulnerabilities, response headers, retention/auto-purge health and open data requests. Findings and their fixes are logged in each college's admin area.

An independent penetration test is scheduled before real card payments are enabled at meaningful volume, and at least annually thereafter.

Report a security issue

If you think you've found a security problem — a way to see another learner's data, a payment that behaved unexpectedly, a suspicious email pretending to be us — please email security@eveningclass.app.

Please don't publicly disclose the issue until we've had a chance to look at it. We aim to acknowledge within 2 working days.

This page is app-owned editable content maintained by the platform team. It is not a certification. Facts about third-party services (Stripe, Cloudflare, Supabase, Resend, Lovable Cloud) are summarised in good faith from their public documentation — refer to each provider for authoritative statements.

security@eveningclass.app