Legal

Security

How Sporit protects clubs' and families' data: where it lives, who can reach it, how the software is built, and who to tell if you find a problem.

Effective
22 September 2026
Last updated
22 September 2026
Version
1.0

In short

  • Hosted on Amazon Web Services in Ireland. Encrypted in transit and at rest. Backed up daily, kept seven days.
  • Every record is tagged with its club, and automated checks in our build refuse code that could read across clubs.
  • We never hold card numbers. Cards go to Stripe; we see the outcome.
  • Found something? Email us with "Security" in the subject. We acknowledge within two business days and do not pursue good-faith researchers.

The key points in plain words. The full text below is what applies.

1. Where data lives

The service runs on Amazon Web Services in the Ireland region. The database is Amazon Aurora PostgreSQL with storage encryption on, automated backups kept for seven days, and deletion protection. Uploaded files (photos, identity documents, receipts) are in a private storage bucket that is not publicly readable; the app fetches them through signed links that expire.

Every connection between a browser or phone and the service, and between the service and its providers, uses TLS. Secrets such as database credentials and provider keys are held in the platform's secret store, never in code.

2. One club cannot see another

Every record a club owns carries that club's identifier, and every request is resolved to the club of the person signed in before any data is read or written. No code path may supply a club identifier it was not given. Three automated checks in our build pipeline enforce this from different angles, and a change that would let a request read across clubs cannot be merged.

Within a club, what each person sees is set by the roles and permissions the club's administrators assign. Families see their own children only. Coaches see their groups and teams. A player under eighteen cannot receive private messages, and a child's identity documents are visible only to the family and the club's staff; these rules are enforced by the server, not by the app.

3. Accounts and sign-in

Passwords must be at least eight characters and are stored only as salted bcrypt hashes; we cannot read them. Password resets and account set-up use time-limited links sent by email. Sessions use signed tokens; signing out on a device ends its session. The demo request form is rate-limited and carries a bot trap. Platform administration by Sporit staff is a separate application with its own accounts.

4. Payments

Card payments are processed by Stripe under each club's own Stripe account. Card details are entered on Stripe-hosted pages and never pass through or rest on Sporit's systems; we hold the outcome of a payment, its amount, fee and net, and a reference. Stripe's webhook messages to us are verified against Stripe's signature before they are trusted. Bank-transfer receipts uploaded by families are stored as files under section 1.

5. How the software is built and run

  • Every change goes through a pull request and an automated gate suite before it can reach production: formatting, static analysis, type checks, unit and integration tests, the tenancy checks above, a check that every API route declares its contract, and a check that no raw database query is missing its club scope.
  • Every pull request deploys to its own throw-away environment for review, and is torn down when it closes.
  • Production is reached only by promoting what is already on the main branch; nothing is authored in production.
  • Database changes run as a discrete deployment step, never at start-up, and are checked for drift on every build.
  • Dependencies are audited on every build for known vulnerabilities.
  • Production infrastructure is defined as code, and access to it is through short-lived, role-based credentials.

6. Incidents

If we become aware of a security incident affecting a club's data we contain it, tell the club's administrators without undue delay and within seventy-two hours with what we know, what it affects and what we are doing, and follow up with a written account when the incident is closed. Where Sporit is the controller, we tell the people affected directly.

7. Reporting a vulnerability

If you believe you have found a security problem in Sporit, email the address on the Contact page with "Security" in the subject, with enough detail for us to reproduce it. We acknowledge within two business days, keep you informed, and credit you if you wish once the problem is fixed. We do not take legal action against people who research in good faith, keep to the rules below and give us reasonable time to fix what they find.

  • Do not access, change or delete data that is not yours; use your own test accounts, and stop as soon as you have shown the problem exists.
  • No denial of service, no social engineering of our staff or clubs, no physical attacks.
  • Do not publish the problem before we have fixed it or ninety days have passed, whichever is first.

Customers who wish to run their own penetration test against the service may do so by prior written agreement, so that we can provide a separate environment.

8. Sub-processors

These are the providers that handle personal data for us, what for, and where. We give clubs thirty days' notice before adding one (Terms of Service, section 10).

ProviderPurposeDataLocation and safeguard
Amazon Web ServicesHosting, database, file storage, email relayAll service dataIreland (EU). AWS Data Processing Addendum with standard contractual clauses.
StripeCard payments and payouts to clubsPayer name and email, amount, card details (held by Stripe only)United States and Ireland. Stripe Data Processing Agreement, standard contractual clauses, PCI DSS Level 1.
ResendSending transactional email (invitations, password links, receipts, reminders)Recipient email address and the messageUnited States. Data Processing Agreement with standard contractual clauses.
ExpoDelivering push notifications to phonesPush token and the notification textUnited States. Data Processing Agreement with standard contractual clauses.
Apple, GoogleFinal delivery of notifications to iOS and Android devices; app distributionDevice token and the notification textGlobal, under their platform terms.
HubSpotSales records for demo requestsDemo request details (section 3 of the Privacy Policy)European Union data centre. HubSpot Data Processing Agreement.
Google AnalyticsVisitor statistics on sporit.app, only with consentAnonymised IP, pages viewed, browser typeUnited States. Google Ads Data Processing Terms, standard contractual clauses. Not used in the product.

9. What we do not claim

Sporit does not yet hold an ISO 27001 or SOC 2 certification, does not yet offer two-factor sign-in, and has not yet published an independent penetration test. We say so here so that a club can decide with the facts, and we will update this page when any of that changes.

Questions?

Write to us. We answer in English and Arabic, within one month for requests about your data and usually much sooner.

hello@sporit.app