Skip to content

Security & youth data

Private where it must be. Public where it should be.

Wrestlers are mostly kids. ScoreOps is built so that results can be public while the details about the athletes behind them are not.

Or email support@score-ops.com.

What we collect

Less data to protect.

The simplest protection is not having the data at all.

No dates of birth

ScoreOps does not collect dates of birth. Older records that held one were scrubbed, and automated tests refuse a date of birth or birth year on any public page.

Private rosters, weigh-ins and eligibility

Weights, eligibility and roster details are read and written only through signed-in, role-checked server requests. The database rules do not let a browser read them directly.

Payments handled by Stripe

Card details are entered with Stripe and never reach ScoreOps. Subscription status is updated only from Stripe's own notifications, never from the browser.

Who can do what

Access by role, checked on the server.

Every sensitive action is checked on our servers against the person's role, not just hidden in the interface.

Owner

Runs the workspace: billing, staff and ownership transfer.

Admin

Manages the team or league: rosters, schedules, approvals and results.

Operator

Runs events and the table on match day.

Scorekeeper

Scores bouts and records results.

72-hour operator links

A volunteer who only needs to run one event gets a link instead of an account. The link is checked on the server and stops working after 72 hours. Creating and using one is recorded.

Audit logs

Sensitive actions leave a record: result recording and corrections, score-sheet approvals and disputes, roster exceptions, weigh-ins, season rule and lifecycle changes, staff removal, ownership transfer and access links. Owners and admins read it in Activity in their own workspace and can export it; it names the staff member who acted, never an athlete, and no one can edit or delete a row. Activity is kept for the life of the workspace and for two seasons after it closes, then deleted.

Understand roles and permissions

Public pages

Public pages you control.

Public team and league pages are built from a separate, published copy of results — never read straight from the operational records — so private fields cannot leak onto them.

  • Rosters can be public, visible only to signed-in visitors, or hidden.
  • Grades can be visible only to signed-in visitors, or hidden.
  • Results can be public or visible only to signed-in visitors.
  • Tournament public display can be turned off.
  • These controls only ever make a page more private than the default.

Your data

Take it with you, or ask us to delete it.

Export

Workspace owners and admins can export their workspace's data, including after a trial ends.

Deletion requests

A signed-in user can request deletion of their account from the account menu, or email support. Each request is reviewed and carried out by a person, and the request itself is logged.
Security & Youth Data Privacy · ScoreOps