Privacy Policy

Last updated: May 2026

Overview

Sporr is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR). Sporr operates as a data controller for the personal data of club administrators and as a data processor for sponsor contact data entered by clubs.

Data we collect

We collect only what is necessary to provide the service:

Account data

  • Name and email address of club administrators
  • Encrypted password (we never store passwords in plain text)
  • Club name, country, and sports

Sponsorship data (entered by your club)

  • Sponsor company names and contact details
  • Contract values, dates, and terms
  • Obligation descriptions and delivery contexts

Proof data

  • Photos uploaded during match day sessions
  • Geo-location data (latitude and longitude) attached to proof captures
  • Timestamps of proof captures

Usage data

  • Session activity (audit sessions created and completed)
  • Proof Packs generated and sent
  • Storage usage

Why we collect it

Contract performance: To provide the core service — contract tracking, obligation management, proof capture, and Proof Pack generation.
Account management: To authenticate users, manage subscriptions, and provide support.
Service improvement: Aggregated, anonymised usage data helps us understand how clubs use Sporr and improve the platform.
Legal compliance: To meet our obligations under Norwegian law and GDPR.

Where your data is stored

All Sporr data is stored in the European Union — specifically in Frankfurt, Germany — using Supabase infrastructure. We do not transfer personal data outside the EU/EEA. Storage is encrypted at rest and in transit.

Who we share data with

We do not sell your data. We share data only with the following third-party services required to operate Sporr:

Supabase: Database, authentication, and file storage (EU-hosted)
Vercel: Application hosting and delivery (EU region)
Resend: Transactional email delivery for Proof Packs

Each of these providers operates under appropriate data processing agreements and GDPR-compliant terms.

Sponsor contact data

When a club adds a sponsor's contact details to Sporr, the club is responsible for ensuring they have a lawful basis for storing and processing that data — for example, an existing contractual relationship. Sporr processes this data on behalf of the club as a data processor. Clubs act as data controllers for sponsor data they enter.

Geo-location data

The Sporr field auditor requests location permission to geo-tag proof photos. This is optional — declining location access does not prevent proof capture. Location data is stored only for the purpose of verifying where proof was captured, and is visible only to the club that captured it.

How long we keep your data

Active accounts: Data is retained for as long as your account is active.
Cancelled accounts: Data is deleted within 30 days of a confirmed account deletion request.
Proof photos: Deleted with the account or upon specific request.
Billing records: Retained for 5 years as required by Norwegian accounting regulations.

Your rights under GDPR

You have the right to:

Access: Request a copy of the personal data we hold about you.
Rectification: Correct inaccurate or incomplete data.
Erasure: Request deletion of your personal data ("right to be forgotten").
Portability: Receive your data in a machine-readable format.
Restriction: Request that we limit how we process your data in certain circumstances.
Objection: Object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@sporr.io. We will respond within 30 days. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.

Cookies

Sporr uses only essential cookies required for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie consent banner is required because we do not set non-essential cookies.

Children

Sporr is intended for use by adults acting on behalf of sports clubs. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

Changes to this policy

We may update this policy as the platform evolves. We will notify users by email at least 14 days before material changes take effect. The current version is always available at sporr.io/privacy.

Contact

For any privacy-related questions or requests, contact us at privacy@sporr.io.

Sporr · sporr.io

Terms of Service →