Trust & safety
Security
How we protect your payments, your account and your data. If you find a security problem, we want to hear about it — details at the bottom of this page.
Payments
We never see or store your card details
Card payments are handled entirely by our payment provider on their own hosted payment pages. Your card number never passes through Premiership Survivor's systems and is never stored on our servers or in our database.
PCI-compliant processing
Our payment provider is PCI-DSS compliant and is responsible for the capture, encryption and processing of card data. We hold only the outcome of a payment — amount, date, reference and which entries it paid for.
Server-side verification
Every payment is verified server-side against the amount we expected for that competition and entry count before any entry is created. A payment that does not match is not accepted, and no entry is issued.
Encryption in transit
The entire site is served over HTTPS with TLS. Connections to the browser, to our database and to our payment provider are all encrypted in transit. There is no unencrypted route into the platform.
Account security
- Passwords are never stored in readable form — they are salted and hashed by our authentication provider, and nobody at Survivor Limited can see them.
- Sessions are cookie-based, HTTP-only and expire; signing out invalidates the session.
- Password resets are done by emailed, single-use, time-limited link — we will never email or ask for your password.
- Administrative functions are restricted to a named allow-list of accounts and are checked server-side on every request, not hidden in the interface.
Data protection
- Player data is held in access-controlled data centres operated by our infrastructure provider, with encryption at rest.
- Database access is protected by row-level security, so one player's account, picks and payment records cannot be read by another player.
- We collect the minimum we need to run the competition: name, email, date of birth (to confirm the 18+ requirement), optional phone number, and a record of entries and picks.
- We do not sell player data, and we do not share it except with the providers needed to run the service (payment, email, SMS and hosting).
Full detail of what we collect and why is in our Privacy Policy.
Fraud and game-integrity monitoring
- Every pick is written with a server-side timestamp and cannot be created or changed after the published deadline for that round.
- Picks are hidden from other players until the deadline passes, so no player can gain an advantage by watching others.
- Entry counts per player are capped, and duplicate or automated account creation is monitored.
- Results are settled from an official fixture and results feed, applied identically to every entry — they are not entered by hand on a per-player basis.
- Payments that do not reconcile against an expected entry are held and reviewed before any entry is issued.
Reporting a security issue
If you believe you have found a vulnerability, email support@premiershipsurvivor.com with the detail and we will acknowledge it. Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and do not access or alter other players' data while testing.
Questions about anything on this page? Email support@premiershipsurvivor.com and a real person will come back to you.