Back to dashboard

SportGether Admin

Privacy Policy

Last updated: June 22, 2026

SportGether Admin is used by authorized organizers to manage activities, workspaces, attendance, invite links, uploaded activity images, and operational records. This Privacy Policy explains how information is handled in the admin portal.

1. Information we collect

We may collect administrator account details, including display name, username, email address, role, organization membership, password authentication data, session records, selected workspace, language preference, security metadata, login-attempt records, and audit records created when administrators manage activities.

2. How we use information

We use information to authenticate administrators, authorize workspace access, create and update activities, manage attendance, generate and revoke public invite links, display activity images, prevent unauthorized access, troubleshoot errors, and maintain an accurate operational history.

3. Activity and participant information

Administrators may view and manage participant names, emails, RSVP status, guest/member account type, notes to organizers, attendance history, and guest management links. Administrators should treat this information as confidential and use it only for activity coordination.

4. Public visibility

Some admin-managed information may appear on public activity pages, including activity title, description, schedule, location, capacity, organization name, uploaded activity images, attendee status counts, and partially masked participant names. Participant emails, private notes, guest tokens, admin account details, and admin audit details are not intended for public display.

5. Sharing and service providers

Information may be processed by infrastructure used to run SportGether, including the API service, MariaDB database, S3-compatible object storage for images, hosting, logging, backup, and security systems. We do not sell administrator or participant information.

6. Cookies and sessions

The admin portal uses essential cookies and session tokens to keep administrators signed in, keep admin access separate from public access, remember the selected workspace and language, and protect security-sensitive actions. See the Cookie Notice for more detail.

7. Retention

Activity records, attendance records, uploaded images, image metadata, invite-link records, registration history, and audit records are retained while needed for activity management, accountability, troubleshooting, legal compliance, or backup recovery. Session and login-attempt records may be removed or rotated when no longer needed.

8. Administrator responsibilities

Administrators should enter only information needed to manage activities, avoid uploading sensitive or unauthorized images, keep credentials private, keep guest links private, and remove or correct participant information when it is no longer appropriate.

9. Security controls

SportGether uses separate admin and public sessions, username-or-email login, password hashing, CSRF protection, server-side authorization, organization-scoped access checks, database storage, object storage controls, and login-attempt controls. No system is completely secure, so suspected unauthorized access should be reported promptly.

10. Rights and requests

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection relating to personal information. Requests should be sent to the organization or operator responsible for this SportGether site.

11. Operator and contact

SportGether Admin is operated by the organization that controls this site. Privacy requests, account questions, and data correction or deletion requests should be sent to that organization through its published contact channel.

12. Changes to this policy

This policy may be updated when SportGether changes features, infrastructure, data handling, or legal requirements. The effective date will be updated when material changes are made.