DOT Player Passport
Privacy Notice
Effective date: 11 September 2026
Looking for the shorter child-friendly version? Read the child-friendly privacy summary.
1. Controller and contact
Shammy Shack Limited, trading as DOT Sport, is the controller for Player Passport.
Shammy Shack Limited is registered in England and Wales under company number 08155132. Its registered office is 32 Roberts Road, Lancing, BN15 8AR.
For privacy questions or to exercise your rights, email info@dotsportapp.com.
2. What Player Passport is
Player Passport is a private longitudinal sporting record.
It is designed to let one athlete retain a persistent Athlete ID over time, with multiple sport profiles, sporting-development records, private supporting Evidence and controlled sharing.
A user account and an athlete identity are separate.
3. Information we process
Depending on how the service is used, we may process:
Account information
- email address;
- authentication identifiers;
- account status;
- account-security and recovery information.
Athlete identity information
- athlete display name;
- birth year;
- optional birth month;
- jurisdiction;
- whether the athlete was recorded as a minor at creation;
- persistent Athlete ID;
- athlete status and timestamps.
We deliberately do not require a full date of birth in the current MVP.
Relationship and guardian information
- whether the signed-in adult is the athlete or a guardian;
- relationship status;
- authority basis;
- guardian attestation state;
- versioned guardian consent/attestation records;
- relationship creation, change and audit information.
A guardian attestation is recorded as an attestation. It is not represented as independent legal verification.
Sport information
- sports selected by the athlete/guardian;
- sport-profile status;
- participation dates or other optional sport context provided through the product.
Journey and development information
- Journey moments;
- dates and sport context;
- athlete-authored titles or descriptions;
- goals and progress updates;
- achievements;
- provenance/source information.
Evidence
- Evidence titles/descriptions;
- Evidence metadata;
- file type and upload state;
- private uploaded files;
- links between Evidence and relevant Passport records.
Evidence files remain private unless deliberately included in a valid controlled share.
Controlled-sharing information
- the athlete whose information is being shared;
- selected sports/records/Evidence;
- intended audience description;
- expiry;
- share status;
- revocation information;
- access/audit information needed to enforce and investigate sharing.
We do not display reusable database Storage paths or expose a reusable signed Storage URL as the normal private-file delivery mechanism.
Product analytics
The current service uses first-party analytics inside the existing Supabase application environment.
Raw analytics contains only:
- a generated event ID;
- Athlete ID;
- one allow-listed product event name;
- event time;
- recording time.
The current allow-listed events are limited to core product-use events such as athlete creation, sport-profile creation, Journey creation, Evidence creation, controlled-share creation and goal completion.
Raw product analytics does not intentionally contain names, emails, free text, Evidence content, filenames, Storage paths, share secrets, IP addresses, user-agent/device fingerprints, location or advertising identifiers.
Raw analytics is retained for no more than 90 days under the current design.
Support information
- messages you send to support;
- contact/account information needed to respond;
- information needed to investigate a technical, privacy or security issue.
Please do not send private Evidence files, active share links, medical information, safeguarding information or other unnecessary sensitive material by support email unless an authorised process specifically requires it.
4. Information we do not ask Player Passport to hold
The current MVP is not intended to hold:
- safeguarding case files;
- medical-treatment records;
- injury-treatment records;
- private mental-health journals;
- emergency information;
- payment-card details;
- public social-profile content;
- behavioural-advertising identifiers.
If a future feature materially changes these categories, the privacy assessment and notice must be updated before activation.
5. Why we use personal information and our proposed lawful bases
This section is a solicitor-review item. The current proposed mapping is:
Structural Processing of Incidental Health/Sensitive Data
Where user-submitted Evidence files or Journey text entries incidentally contain details regarding physical health, injuries, or disability parameters despite product restrictions, our legal condition for processing under Article 9 of the UK GDPR is that the processing is carried out based on the explicit direction of the user to fulfill a core contractual service requirement, or concerns data that has been manifestly made public by the data subject or their authorized guardian through deliberate platform upload.
Adult account administration and service provision
Purpose: create, authenticate, secure and administer the service requested by the adult account holder.
Proposed basis: contract, with legitimate interests for proportionate security, fraud/abuse prevention and dispute handling.
Adult athlete Passport records
Purpose: provide the requested longitudinal athlete record, sporting-history features, Evidence and controlled sharing.
Proposed basis: contract where processing is necessary to provide the service requested directly by the adult athlete, and legitimate interests where needed to preserve security, provenance, service integrity or proportionate audit records.
Junior athlete Passport records
Purpose: provide a guardian-managed sporting Passport for the child, preserve a coherent sporting record and allow controlled disclosure selected by the guardian.
Proposed basis: legitimate interests, balancing the athlete's interests and rights against the limited sporting-record purpose, private-by-default design, data minimisation, no public discovery, no behavioural advertising, no direct junior messaging and enhanced guardian controls.
The guardian's recorded consent/attestation is currently an authority and product-governance record. It should not be described as the UK GDPR lawful basis unless professional review confirms that consent is the appropriate basis for a particular processing purpose.
Guardian relationship and consent evidence
Purpose: record who is authorised to manage a junior Passport and what guardian statement was accepted.
Proposed basis: legitimate interests in access control, accountability, child protection and dispute handling.
Private Evidence
Purpose: store and display supporting material selected by the athlete/guardian and deliver selected items only through authorised controlled sharing.
Proposed basis: contract for adult athletes and legitimate interests for guardian-managed junior Passports, subject to data minimisation and user control.
If Evidence contains special-category personal data despite the product instructions, a separate lawful-condition analysis may be required. The current product does not invite such data.
Controlled sharing
Purpose: create, expire, revoke and enforce an unlisted share deliberately requested by the authorised user.
Proposed basis: contract for an adult athlete's requested share and legitimate interests for guardian-managed junior sharing, with the user's deliberate action and strict access controls forming key safeguards.
Security and operational error handling
Purpose: protect accounts and athlete records, investigate failures and defend the service from misuse.
Proposed basis: legitimate interests in security and service integrity.
Operational error reporting is designed not to forward raw private content, share secrets or unnecessary identifiers.
First-party product analytics
Purpose: understand whether the core Passport workflows are functioning and being used, without optimising for screen time or behavioural profiling.
Proposed basis: legitimate interests, subject to strict minimisation, first-party processing, an allow-listed event set and 90-day raw retention.
No third-party analytics provider, behavioural advertising or cross-site tracking is active in the current design.
Support
Purpose: answer questions, resolve faults and manage privacy/security requests.
Proposed basis: contract where needed to support the requested service and legitimate interests for security, service improvement and dispute handling.
Legal and regulatory records
Purpose: comply with applicable law and respond to lawful claims or regulatory requests.
Basis: legal obligation where applicable, and legitimate interests for establishing, exercising or defending legal claims.
6. Legitimate interests and the right to object
Where we rely on legitimate interests, we consider:
- the limited sporting-development purpose;
- the sensitivity of the information;
- the athlete's reasonable expectations;
- whether the athlete is a child;
- private-by-default settings;
- relationship-based access;
- RLS and server-side authorisation;
- minimisation of identity information;
- controlled and revocable sharing;
- short raw-analytics retention;
- absence of behavioural advertising and public athlete discovery;
- deletion/pseudonymisation options where appropriate.
YOU HAVE THE RIGHT TO OBJECT to processing based on legitimate interests.
Email info@dotsportapp.com and explain the processing you object to. We will consider the request in accordance with applicable data-protection law.
7. Children and guardian-managed Passports
Player Passport is designed to be junior-safe by default.
The current MVP uses guardian-first junior onboarding:
- the junior does not receive a direct login;
- the adult creating the junior Passport must make an explicit guardian-authority attestation;
- the platform records the authority as attested, not independently verified;
- the junior Passport is private by default;
- there is no public athlete directory;
- there is no direct junior messaging;
- there is no behavioural advertising;
- there is no AI profiling in the current MVP;
- access is restricted to authorised relationships and deliberately created shares.
The current identity model stores birth year and optional birth month rather than full date of birth.
A child-friendly privacy summary is provided alongside this notice for junior athletes and families.
8. Who can see information
Within Player Passport
An authenticated user can only access an athlete where an active authorised relationship permits that access.
A guardian does not receive general access to other athletes.
DOT support does not have a routine product feature for browsing all Passports.
Controlled-share recipients
A recipient can see only the information deliberately included in a valid share.
If a selected private Evidence file is included, the recipient obtains it through a server-mediated delivery route that re-checks the share on each request.
A recipient who downloads or copies information before revocation may retain their own copy. Revocation stops future service access; it cannot guarantee deletion from the recipient's own systems.
9. Processors, recipients and service providers
The production application uses Lovable Cloud and its managed Supabase-backed services for application hosting, database, authentication and related application operations.
The Player Passport project is in the same Lovable workspace currently recorded for DOT's Business-plan DPA evidence. DOT's existing provider evidence records that the Business workspace is covered by Lovable's applicable Data Processing Agreement and managed subprocessor chain. This should be rechecked at launch.
GitHub is used for private source code and release evidence. Normal production athlete records and private Evidence are not intentionally exported to the source repository.
Support is provided through info@dotsportapp.com, hosted through DOT Sport's business email provider. Support correspondence may therefore be processed by that provider under the processor/transfer arrangements maintained by DOT.
No Paddle/payment processing is active for Player Passport under this draft because no live paid Passport product is active.
A current internal processor/recipient/transfer register is maintained and should be completed/rechecked before pilot launch.
10. International transfers
Where a provider or subprocessor makes a restricted transfer of UK personal data, DOT requires an applicable lawful transfer mechanism, such as UK adequacy regulations or appropriate contractual safeguards.
DOT's existing Lovable evidence records use of the provider's applicable contractual transfer framework, including the UK Addendum where required.
Current provider locations and safeguards should be rechecked at launch and after material provider changes.
You may email info@dotsportapp.com to ask about safeguards applying to your personal information, subject to lawful confidentiality redactions.
11. Retention
Player Passport uses a defined retention schedule rather than assuming that all identifiable information should remain forever.
Current draft rules include:
- active account/authentication information — while the account remains active;
- raw first-party product analytics — maximum 90 days;
- closed support matters — normally 24 months;
- ordinary security/diagnostic records — normally up to 12 months unless isolated for an active incident;
- expired/revoked controlled-share operational records: retained for a fixed period of 24 months post-expiry or revocation solely for system integrity, security audits, and dispute investigation purposes;
- active Passport content and Evidence — while the athlete/guardian keeps the record active, subject to deletion rights and product lifecycle rules;
- deleted Evidence — removed from active service, with deleted copies potentially remaining temporarily in provider backups for the provider-defined backup cycle;
- relationship/guardian-attestation records — retained while needed to establish authority and for a proposed limited post-relationship audit period;
- account/athlete deletion — subject to preserving another valid relationship, avoiding orphaned junior records, applicable legal claims and a final operational deletion process.
These retention rules are supported by the service's lifecycle and scheduled-retention controls where applicable.
12. Account closure, athlete history and deletion
Player Passport distinguishes the user account from the athlete record.
Closing one user's account must not automatically destroy an athlete's Passport if another valid authorised relationship continues.
A junior athlete must not be silently orphaned.
Where the sole valid relationship ends and deletion is requested, the service should delete, anonymise or pseudonymise personal information where legally required and technically appropriate, while retaining only limited information that must lawfully remain for security, dispute or legal purposes.
Account closure and athlete-erasure controls are implemented through the service's lifecycle and retention controls, subject to the limits described above.
13. Your data-protection rights
Depending on the circumstances, you may have rights including:
- access to your personal information;
- correction of inaccurate information;
- erasure;
- restriction of processing;
- objection to processing based on legitimate interests;
- data portability where applicable;
- withdrawal of consent where consent is the lawful basis;
- complaint to the UK Information Commissioner's Office.
Some rights are not absolute and may depend on the purpose and lawful basis.
To exercise a right, email info@dotsportapp.com.
We may need proportionate information to verify that the request comes from the correct person or authorised guardian.
14. Security
Player Passport uses layered controls including:
- authenticated accounts;
- relationship-based access;
- deny-by-default database permissions;
- row-level security;
- server-side authorisation;
- private Evidence storage;
- server-mediated private-file sharing;
- expiry and revocation;
- sanitised operational error reporting;
- no routine support browser across athlete records.
No system can be guaranteed completely secure. Users must also protect their account credentials and private-share links.
15. Device storage and cookies
The current application uses browser/device storage needed for authentication and may store limited convenience state, such as the currently selected athlete.
Client-side convenience state does not grant server-side authority.
Before public legal activation, the exact cookies/device-storage inventory should be documented and any non-essential technology assessed separately for the appropriate consent/exemption treatment.
16. Changes to this notice
We may update this Privacy Notice where the service, law or processing changes.
For a material change, we will provide reasonable notice where practicable.
The effective date will be shown on the published notice.
17. Contact and complaints
Privacy questions and rights requests:
info@dotsportapp.com
You also have the right to complain to the UK Information Commissioner's Office if you believe your personal information has been handled unlawfully.