Skip to main content
Legal hub

Legal and privacy

Service Providers and Data Recipients

Last updated:
29 August 2026
Effective:
26 July 2026
Version:
2026-07-26
ScoreSocial uses service providers and data recipients to host, secure, support, bill for, and operate the product. This page is updated when material provider use changes.

1. Provider inventory

ScoreSocial service provider and data recipient inventory
ProviderRole and purposeData categoriesRegion and safeguardsRetention
SupabaseDatabase, authentication support, file storage, private buckets, signed URLs.Account, organisation, membership, invite, access request, prediction, score, standing, audit, notification, push, storage, screenshot, and legal acceptance data.Production project region: AWS eu-west-2. Service terms, privacy terms, security controls, and DPA materials apply where available.Database/storage records follow ScoreSocial retention rules and Supabase backup/storage settings.
VercelHosting, serverless functions, deployment, request handling, application logs.IP address, headers, route metadata, request IDs, deployment logs, application diagnostics.Provider infrastructure may process data in multiple regions. Vercel account terms and data protection terms apply where available.Request and deployment logs follow Vercel project/account settings.
StripeOrganiser subscription checkout, billing portal, invoices, payment method handling, webhooks.Billing email where supplied, customer IDs, subscription IDs, plan/status, invoice/payment metadata held by Stripe, webhook metadata.Stripe acts under its own services agreement and privacy notices, with controller/processor roles depending on the billing activity.Billing and tax records are retained for subscription, accounting, tax, dispute, and legal obligations.
ResendEmail delivery for recovery and OTP flows.Email address, message content, delivery metadata, bounce/error data.Provider terms, privacy terms, and data protection materials apply where available.Email delivery metadata follows provider/project settings and operational need.
SentryErrors, diagnostics, performance, logs. Session Replay is disabled by default.Error context, route metadata, device/browser data, logs, technical identifiers, and replay data only if separately enabled.Provider terms, privacy terms, security controls, and DPA materials apply where available.Diagnostics retention follows active Sentry project settings.
GitHubPrivate issue tracker for bug reports and support/development work.Bug report text, labels, metadata, platform/version, signed screenshot links.Repository access is limited to authorised support/development users. GitHub terms and privacy notices apply.Issues and comments are retained for support, audit, and development history unless removed.
Expo, Apple/APNs, Google/FCM/Google PlayMobile push delivery, app distribution, and related platform services.Push tokens, notification metadata, app diagnostics depending on platform settings.Provider platform terms, privacy notices, and store policies apply.Push tokens are retained until logout, opt-out, token replacement, account cleanup, or app data removal.
Upstash/Redis where configuredCaching, rate limiting, tenant/sports data cache.Cache keys/values may include organisation, tenant, IP/rate-limit, or sports data depending on configuration.Provider terms and selected region/settings apply.Cache records follow configured TTLs and cleanup behavior.
Reddit / Devvit and installation-scoped RedisHosts the optional owner-authorised read-only Reddit companion and stores its subreddit installation mapping/state.Mapped subreddit, consent state, post registration, eligible online-only leaderboard/fixture data and dedicated public-join metadata. Manual Entry photos, QR values, diagnostics, extracted paper picks and assignment data are excluded.Reddit/Devvit platform terms, review requirements and installation isolation apply.Installation state is kept while the integration is active and as needed for consent/security evidence; owner revocation stops responses and revokes dedicated joining.
API-SPORTS / API-Football (when enabled)Football fixture, score, result, status, standings, form, head-to-head, and prediction-statistics source.Sports data and server request metadata only; ScoreSocial does not send player predictions or account data.Provider API terms and request logging apply. Public/commercial display rights and competition rights require separate confirmation before production cutover.Provider metadata and sports snapshots are retained for operational and historical accuracy under the applicable rights agreement.
Legacy ESPN sports feedsTemporary football rollback source and a separate disabled-by-default golf source.Sports data and server request metadata only; no player data is required.Legacy football use is removed after the compatibility window. Golf remains separately gated because datacentre reliability is unconfirmed.Stored historical sports records follow ScoreSocial retention rules.

2. First-party aggregate analytics

ScoreSocial calculates its growth dashboard inside the existing application and Supabase database. It does not use a dedicated analytics provider, third-party analytics SDK, tracking pixel, or device-side analytics storage. Registration CTA, registration-page, completed-registration and first-prediction events are retained only as daily aggregate counters by source and competition; they are not joined into individual visitor journeys. Vercel and Supabase continue to provide the hosting and database infrastructure described above, but no extra provider receives analytics events for this feature.

3. Updates

This page is updated when ScoreSocial adds or removes providers, changes production regions, changes retention settings, adds analytics, changes push providers, or changes bug/support workflows.

Service Providers and Data Recipients - ScoreSocial