1. Where data lives
The service runs on Amazon Web Services in the Ireland region. The database is Amazon Aurora PostgreSQL with storage encryption on, automated backups kept for seven days, and deletion protection. Uploaded files (photos, identity documents, receipts) are in a private storage bucket that is not publicly readable; the app fetches them through signed links that expire.
Every connection between a browser or phone and the service, and between the service and its providers, uses TLS. Secrets such as database credentials and provider keys are held in the platform's secret store, never in code.
2. One club cannot see another
Every record a club owns carries that club's identifier, and every request is resolved to the club of the person signed in before any data is read or written. No code path may supply a club identifier it was not given. Three automated checks in our build pipeline enforce this from different angles, and a change that would let a request read across clubs cannot be merged.
Within a club, what each person sees is set by the roles and permissions the club's administrators assign. Families see their own children only. Coaches see their groups and teams. A player under eighteen cannot receive private messages, and a child's identity documents are visible only to the family and the club's staff; these rules are enforced by the server, not by the app.
3. Accounts and sign-in
Passwords must be at least eight characters and are stored only as salted bcrypt hashes; we cannot read them. Password resets and account set-up use time-limited links sent by email. Sessions use signed tokens; signing out on a device ends its session. The demo request form is rate-limited and carries a bot trap. Platform administration by Sporit staff is a separate application with its own accounts.
4. Payments
Card payments are processed by Stripe under each club's own Stripe account. Card details are entered on Stripe-hosted pages and never pass through or rest on Sporit's systems; we hold the outcome of a payment, its amount, fee and net, and a reference. Stripe's webhook messages to us are verified against Stripe's signature before they are trusted. Bank-transfer receipts uploaded by families are stored as files under section 1.
5. How the software is built and run
- Every change goes through a pull request and an automated gate suite before it can reach production: formatting, static analysis, type checks, unit and integration tests, the tenancy checks above, a check that every API route declares its contract, and a check that no raw database query is missing its club scope.
- Every pull request deploys to its own throw-away environment for review, and is torn down when it closes.
- Production is reached only by promoting what is already on the main branch; nothing is authored in production.
- Database changes run as a discrete deployment step, never at start-up, and are checked for drift on every build.
- Dependencies are audited on every build for known vulnerabilities.
- Production infrastructure is defined as code, and access to it is through short-lived, role-based credentials.
6. Incidents
If we become aware of a security incident affecting a club's data we contain it, tell the club's administrators without undue delay and within seventy-two hours with what we know, what it affects and what we are doing, and follow up with a written account when the incident is closed. Where Sporit is the controller, we tell the people affected directly.
7. Reporting a vulnerability
If you believe you have found a security problem in Sporit, email the address on the Contact page with "Security" in the subject, with enough detail for us to reproduce it. We acknowledge within two business days, keep you informed, and credit you if you wish once the problem is fixed. We do not take legal action against people who research in good faith, keep to the rules below and give us reasonable time to fix what they find.
- Do not access, change or delete data that is not yours; use your own test accounts, and stop as soon as you have shown the problem exists.
- No denial of service, no social engineering of our staff or clubs, no physical attacks.
- Do not publish the problem before we have fixed it or ninety days have passed, whichever is first.
Customers who wish to run their own penetration test against the service may do so by prior written agreement, so that we can provide a separate environment.
8. Sub-processors
These are the providers that handle personal data for us, what for, and where. We give clubs thirty days' notice before adding one (Terms of Service, section 10).
| Provider | Purpose | Data | Location and safeguard |
|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage, email relay | All service data | Ireland (EU). AWS Data Processing Addendum with standard contractual clauses. |
| Stripe | Card payments and payouts to clubs | Payer name and email, amount, card details (held by Stripe only) | United States and Ireland. Stripe Data Processing Agreement, standard contractual clauses, PCI DSS Level 1. |
| Resend | Sending transactional email (invitations, password links, receipts, reminders) | Recipient email address and the message | United States. Data Processing Agreement with standard contractual clauses. |
| Expo | Delivering push notifications to phones | Push token and the notification text | United States. Data Processing Agreement with standard contractual clauses. |
| Apple, Google | Final delivery of notifications to iOS and Android devices; app distribution | Device token and the notification text | Global, under their platform terms. |
| HubSpot | Sales records for demo requests | Demo request details (section 3 of the Privacy Policy) | European Union data centre. HubSpot Data Processing Agreement. |
| Google Analytics | Visitor statistics on sporit.app, only with consent | Anonymised IP, pages viewed, browser type | United States. Google Ads Data Processing Terms, standard contractual clauses. Not used in the product. |
9. What we do not claim
Sporit does not yet hold an ISO 27001 or SOC 2 certification, does not yet offer two-factor sign-in, and has not yet published an independent penetration test. We say so here so that a club can decide with the facts, and we will update this page when any of that changes.
Questions?
Write to us. We answer in English and Arabic, within one month for requests about your data and usually much sooner.
hello@sporit.app