PASS legal information
Privacy Notice
Last updated 2 September 2026
How PASS processes account, team and player-reflection information. PASS is designed to minimise unnecessary personal data and restrict reflection access to authorised staff for the relevant team.
1. Controller and contact
Shammy Shack Limited, trading as DOT Sport, is the controller for PASS. It is registered in England and Wales under company number 08155132 at 32 Roberts Road, Lancing, BN15 8AR.
For privacy questions or requests, email info@dotsportapp.com.
2. Information PASS processes
- Staff account information: email address, authentication identifiers, account status and team membership/role.
- Team information: team display name, compatibility identifiers, manager/coach memberships and invitation records.
- Player reflection information: player name, session date, session type, optional mood, PASS reflection responses, requested support and commitment.
- Staff workflow information: archive/follow-up state and staff notes associated with a reflection.
- Operational/security information needed to operate secure submission links, staff invitations, entitlement checks and service diagnostics.
- PASS Plus information: plan/entitlement status and payment-provider subscription/event references needed to fulfil and support the purchase. PASS does not store payment-card details.
- Support information: messages sent to DOT Sport and information needed to respond.
3. Why PASS uses the information
- To authenticate authorised staff and operate team access controls.
- To let players submit reflections to the correct team through secure submission links.
- To let authorised staff review, search, follow up and manage reflection records for their team.
- To provide optional PASS Coach AI and Team Pulse analysis when an authorised staff user chooses to use those tools.
- To apply PASS Plus entitlements to the correct team and reconcile payment-provider subscription events.
- To protect the service against misuse, investigate faults and respond to support requests.
4. Players and junior users
Players do not need to create PASS accounts for the current reflection flow. A player normally receives a secure team submission link from an authorised coach or team representative.
PASS is designed for use in amateur sport, including teams that may contain junior players. We therefore keep the player submission flow short, use age-readable privacy messaging and avoid asking players for date of birth, home address or direct contact details as part of the ordinary PASS reflection.
Team staff remain responsible for following their organisation's safeguarding and data-handling procedures when deciding how PASS is introduced to players and parents/guardians.
5. Who can see a reflection
A submitted reflection is associated with the team identified by the secure submission link. PASS uses team-scoped access controls so authorised staff can access records for the relevant team rather than reflections from unrelated teams.
Platform administration access is reserved for authorised support/administrative purposes and is separate from ordinary team membership.
6. AI processing
PASS Coach AI and Team Pulse are initiated by authorised staff; a player's reflection is not automatically sent to an AI tool merely because the player submits it.
When an AI feature is used, PASS sends the reflection information needed for that request through the configured AI service. PASS removes direct player/team labels from AI prompts where they are not required and does not send private staff follow-up notes where those notes are unnecessary for the requested analysis.
AI output is coaching assistance, not a diagnosis or safeguarding decision. Staff must review the output before using it.
7. Hosting, processors and payment provider
PASS is deployed through Lovable and uses its Supabase-backed application services for database and authentication-backed operations. DOT Sport maintains processor/DPA and subprocessor evidence as part of its operational controls.
Paddle acts as Merchant of Record for PASS Plus transactions. Paddle handles payment details, buyer transaction/tax information and transaction-side billing administration. PASS stores only the provider references and subscription state needed to fulfil and support PASS Plus.
GitHub is used for private source code and release evidence. Normal production reflection records and server-only secrets are not intentionally exported to the source repository.
8. Retention, correction and deletion
PASS does not rely on sporting history alone as a reason to retain identifiable reflection information indefinitely. DOT Sport maintains a PASS-specific retention and deletion process.
If you believe personal information in PASS is inaccurate, no longer required or should be restricted, contact info@dotsportapp.com. Requests are assessed in light of applicable rights, team record responsibilities, security and any legal obligations.
9. Your rights
Depending on the circumstances and applicable law, you may have rights relating to access, correction, deletion, restriction, objection and data portability, and the right to complain to the relevant data-protection authority.
Email info@dotsportapp.com to exercise a privacy right or ask how PASS handles your information.
10. Security
PASS uses authenticated staff access, team-scoped database controls, secure no-login submission links, hashed invitation/submission tokens and server-side entitlement/payment-event checks. No internet service can guarantee absolute security, but PASS is designed so a player submission link does not grant staff-dashboard access.