SPOTR
Security and privacy

Your club’s scouting data stays in your club environment.

Scouting reports are often about minors. That calls for a system that says exactly what it does — and that hands everything back when the collaboration ends.

  • EUservers and database
  • 30 daysexport window after the end
  • 1 working dayresponse to urgent problems
Roles

Who sees what in your club environment?

Four fixed roles, checked by the server on every request, not just by the screen. A scout’s device never even receives colleagues’ reports.

PermissionAdminruns the appHead scoutleads the scoutingScoutreportsOn trialnew scout
Write reportsnoyesyesawaits release
Read reportsPlayer cards, matches and tournaments are shared across the club.all scoutsall scoutsown onlyown only
Give and schedule assignmentsyesyesnono
Release reports from scouts on trialWith feedback to the scout.yesyesnono
Invite scouts, change roles, block accessOnly an admin can change an admin.yesyesnono
Delete someone else’s workAnyone can delete their own report.yesyesnono
Roll back to a restore pointUp to 30 days back.yesyesnono
Export the full club copyyesnonono
Activity log: who did whatExports, roles, invitations, failed sign-ins. Never the content of a report.yesnonono
Branding and invoicesyesnonono
Adminruns the app
  • Read reports all scouts
  • Give and schedule assignments
  • Release reports from scouts on trial
  • Invite scouts, change roles, block access
  • Delete someone else’s work
  • Roll back to a restore point
  • Export the full club copy
  • Activity log: who did what
  • Branding and invoices
Head scoutleads the scouting
  • Write reports
  • Read reports all scouts
  • Give and schedule assignments
  • Release reports from scouts on trial
  • Invite scouts, change roles, block access
  • Delete someone else’s work
  • Roll back to a restore point
Scoutreports
  • Write reports
  • Read reports own only
On trialnew scout
  • Write reports awaits release
  • Read reports own only

This is the setup for a club starting now. The club decides who gets which role; what a role can do is fixed.

Data flow

Where does your data live?

In three places, each with its own boundary. Below: what SPOTR itself receives.

On the scout’s devicephone, tablet or laptop
  • Encrypted copy for reporting without signal
  • The key never leaves the device
  • Club data expires after 7 days offline
  • Signing out wipes the copy
In your club environmentown installation and database
  • Own subdomain with HTTPS
  • Roles checked on the server
  • Activity log: who did what
  • Restore points up to 30 days
In the backupevery night
  • 14 days on the server
  • 30 days in separate storage
  • Extra copy before every update
  • Restore test every month
What SPOTR itself receives

Reports never leave your club environment and its backups. To run the app and track down faults, SPOTR does receive:

  • Technical error reports, without content
  • Daily usage figures: counts, plus the names of whoever reports most
  • What someone reports themselves via Help, with name and email address
  • The app’s emails, which SPOTR sends on behalf of the club via Microsoft 365
Safeguards

What sits behind it, technically

For each safeguard, the facts your IT team can check.

  • Own installation and databaseEvery club gets its own installation, its own database with its own access and its own subdomain: club data is never mixed. No club mail server needed: SPOTR sends the app’s emails on behalf of the club.One database per clubOwn subdomainNo mail server needed
  • Hosted in the European UnionThe servers and databases are in the EU, with HTTPS on every club address. Processing is set out in a data processing agreement with the list of sub-processors; you receive them before the trial, not after.Servers in the EUHTTPSProcessing agreement up front
  • Roles and accessRoles are enforced on the server, with a fixed permissions table per role. Passwords only as a bcrypt hash, login attempts limited, session cookies HttpOnly, Secure and SameSite. With Remember this device you stay signed in as long as you use the app; after 60 to 90 days without use the session expires. Without it, the cookie disappears when the browser closes. A blocked scout is signed out everywhere at once.bcryptHttpOnly · Secure · SameSiteBlocking signs out at once
  • Daily backupsEvery night a copy of each club’s database and settings: 14 days on the server and 30 days in separate SPOTR backup storage. An extra copy before every update. Every month we restore the latest copy into a throwaway database and count reports, players and users again: a backup you have never restored is a guess.Nightly backupBefore every updateMonthly restore test
  • Export and exitFull club copy as JSON by the administrator, also per season; CSV from the lists of players, matches, clubs and scouts; PDF per player and per report; a copy can be re-imported yourself. If the collaboration ends, you export until 30 days after the end date. After that we wipe the environment; the last backups disappear within 30 days.JSON · CSV · PDFAlso per season30 days after the end
  • Data of minorsPurpose, minimal data fields, transparency towards players and parents, retention periods and rights are agreed per club, with an information sheet the club can hand out. SPOTR has no field for medical data; the club agrees with its scouts not to record it in free text either. In the event of a data breach we notify the club within 48 hours.No medical data fieldNotice within 48 hInformation sheet for parents

How we align IT and privacy

Before a trial or contract we discuss what your club needs: the data processing agreement, the list of sub-processors, the roles and, for professional clubs, an SLA. The final legal texts are reviewed by a lawyer before they enter a contract.

We do not promise "100% secure". We say what you can check: EU hosting, a separate installation and database per club, roles on the server, bcrypt and HttpOnly cookies, nightly backups with a restore test, and export as JSON, CSV and PDF.

  1. 01Short inventory: which data, which roles, which retention period
  2. 02Data processing agreement and sub-processors for review
  3. 03Agreements on backup, export and closing the environment
  4. 04Help by email and phone on working days, urgent issues within one working day, 99.5% availability as the target; professional clubs: SLA with fixed response times
Questions

What clubs usually ask.

Does our IT department need to be involved?

On the Club plan, no. SPOTR runs in the browser at an address of its own that we set up: nothing to install on club computers, no app store, no club mail server needed — invitations and password resets go through SPOTR. If your club has an IT department, it receives the data processing agreement and the list of sub-processors up front.

What if a scout leaves?

The admin or the head scout blocks their account. They are then signed out everywhere at once. If their device connects again, the copy of the club data disappears immediately; without a connection it expires after seven days. Their reports stay with the club.

What happens without signal?

You simply keep taking notes. The device holds an encrypted copy with a key that never leaves the device. What still has to reach the club disappears once it is there; when you log out, everything disappears. After seven days without a connection the copy of the club data expires, but a report that has not been sent yet is kept until it reaches the club.

What happens after the trial?

We decide together in week 12. If you continue, everything noted during the trial stays. If you stop, you export until 30 days after the end; after that we delete the environment, and the last backups disappear within 30 days.

Ask your questions to the people who build the system — not a service desk.

Discuss IT and privacy