Privacy Notice
Pilot version · 11 August 2026 · SARScore (London contributor pilot). This notice explains what personal data SARScore collects, why, who we share it with, how long we keep it, and the rights you have. It applies to the SARScore website and contribution tools at www.sarscore.com. We keep this notice under review and update it as the platform develops; we flag material changes on the site.
Who we are
SARScore is operated by SARSCORE LTD, a private limited company registered in England and Wales (company number 14224333), registered office 61 Crescent Road, London, England, E6 1EB. SARSCORE LTD is the data controller for the personal data described here and is registered with the Information Commissioner's Office (registration reference ZB661626).
For any privacy question, or to exercise your rights, contact privacy@sarscore.com. We have not appointed a Data Protection Officer; privacy@ reaches the person responsible for data protection.
What SARScore is (in one line)
SARScore records real, observed journeys and turns verified evidence into an access-difficulty score for places, from 1 (very easy) to 5 (very difficult). It describes places, not people. We do not sell personal data, we do not run advertising, and we do not use third-party analytics or tracking services.
Who can contribute
During the pilot, you must be aged 18 or over to create an account or to submit a report. Anyone can browse and read the site without an account.
The personal data we collect, why, and our lawful basis
We only collect what a purpose needs. We rely on contract (running your account), legitimate interests (building and maintaining a truthful, moderated evidence record, and keeping the service secure), and, for storing information on your device for usability measurement, the statistical-purposes exception under the Privacy and Electronic Communications Regulations. We do not currently rely on your consent as a lawful basis for processing: the photo/location permission your browser asks for is a technical control you manage, which is separate from our lawful basis (see below).
1. Running your account (if you create one)
We store your email address and a display name (and, if you sign in with Google, the name, email address and account identifier Google supplies, nothing else; we never request your Google contacts, files or location). Your password, if you use one, is stored and checked by our authentication provider and never reaches us in readable form.
Lawful basis: performance of a contract (providing your account), Article 6(1)(b). An account is optional: you can search, and contribute, without one.
2. Recording and moderating contributions
When you report a visit we store your answers about the route, the time you spent, and technical information about the submission (a per-journey reference, a session identifier, and build/version information). If you are signed in, the contribution is linked to your account; if not, it is stored without an account link.
Lawful basis: our legitimate interests in building and maintaining a truthful, moderated evidence record of real-world accessibility, Article 6(1)(f). We have weighed this against your interests in a written assessment; the data is limited to what verification and moderation require, and you can object at any time (see “Your rights”).
3. Verifying reports: photographs and capture location
When you attach a photograph to make your report a verified visit, we record the photograph and, so we can confirm it was taken at the place, the location your device reports at that moment. We use that location only to compute a distance check and do not keep the precise coordinate. The photograph is stored privately, is reviewed by a moderator, and is never published. We ask you to photograph buildings, entrances and routes only: never people, faces, vehicle number plates, access codes or the interiors of private homes; moderators reject photographs that do. We remove location, camera and other metadata embedded in the image file itself before the photograph is stored; if that removal cannot be completed, the upload is not stored.
Lawful basis: our legitimate interests in a verifiable, trustworthy evidence record, Article 6(1)(f), assessed in a written legitimate-interests assessment. Your device asks your permission before sharing its location; that permission is a control you manage and is separate from our lawful basis. If you don't share a photograph or location, your report is still accepted. It just isn't a verified visit.
4. Understanding and improving how the contribution tool works (usability measurement)
We record first-party, on-site measurements of how the contribution tool is used: which screen you are on, how long steps take, whether a step is revisited, and your device and browser as a broad category (e.g. “iOS / Safari”). We do not record your name, your typed answers, your precise location, your IP address, or your full device details for this purpose, and we share these measurements with no analytics company.
Lawful basis: for storing and reading this information on your device, the statistical-purposes exception under PECR as amended by the Data (Use and Access) Act 2025; for the analysis, our legitimate interests in improving the service, Article 6(1)(f). You can turn these measurements off at any time: see the Cookie & Storage Notice; turning them off stops future measurement and clears the identifiers on your device.
These measurements use identifiers that do not contain your name but that can, in combination with a contribution, relate to you. We therefore treat them as pseudonymous personal data, not anonymous.
5. Security, reliability and diagnosing failures
We keep short-lived technical logs and a data-minimised record of certain site errors so we can keep the service working and secure. Our infrastructure providers also process standard request information, including IP addresses, in their server logs.
Lawful basis: our legitimate interests in the security and reliability of the service, Article 6(1)(f).
Health, disability and access needs
SARScore is about places, not people. We do not ask for, infer, or record any contributor's disability, medical condition or personal access needs, and we do not treat contributors differently on that basis. We do not process special-category (health) data as part of the contribution process.
We recognise that, because a report describes how easy or hard a place is to reach and enter, a report linked to you could in some circumstances indirectly suggest something about your own access needs. We take that residual privacy risk seriously and assess it in a data-protection impact assessment. Please do not include other people's health information in a report. If we ever add features that intentionally collect or infer health or access-needs information, we will put the appropriate additional protections in place first and update this notice.
Reporting without an account
You can contribute without creating an account. A report made without an account is not anonymous: it stores your answers, the private photograph, and technical identifiers. Because no account is attached, you cannot sign in later to view, change or delete it yourself, but you can still ask us to help: quote the report reference shown when you finished, to support@sarscore.com, and we can correct it or withdraw it from scoring (subject to the usual moderation). If you want to manage your own reports directly, create an account before you submit.
Who we share data with
We do not sell or share personal data for advertising, and we do not buy data from data brokers. We use a small number of service providers:
- Supabase: our database, authentication and private photo-storage processor, under its Data Processing Addendum (EU Standard Contractual Clauses and the UK Addendum). Your data is held in the UK region (London); some of Supabase's operational and subprocessor processing may take place elsewhere under those safeguards.
- Vercel: hosts and delivers the website (a processor for our data; an independent controller for its own operational data). It processes standard request information, including your IP address, in operational logs retained around 30 days, under the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Our functions are configured to run in London; content delivery, build and logging may involve other locations under the same safeguards.
- Resend: sends our account-confirmation and password-reset emails (through our authentication provider's email configuration), acting as our processor. Resend processes and stores this data primarily in the United States, under the EU-US Data Privacy Framework and its UK Extension, and Standard Contractual Clauses. Resend retains email content and delivery, bounce and complaint logs for 30 days, after which they are no longer stored, plus short-lived (7-day) backups. We do not keep a separate long-term record of email events.
- Ideal Postcodes (IDDQD Limited): processes address text and a selected suggestion identifier from our server to autocomplete and resolve an address. If location bias is used, it also receives your approximate location. It returns the formatted address, postcode, UPRN and valid coordinates. On paid resolution only, SARScore forwards your validated source IP solely so Ideal Postcodes can enforce lookup limits. SARScore does not return, retain or log that IP in this address-search flow; it may appear temporarily in Ideal Postcodes' usage logs under its published redaction policy. Ideal Postcodes acts as our processor under its DPA; its listed hosting processors are in the UK/EU, with global Cloudflare load balancing and contractual safeguards for any necessary transfer outside the EEA.
- Ordnance Survey (OS Data Hub): is the historical address provider for applicable stored place records and the immediate rollback provider. Address text reaches OS from our server only if that rollback is explicitly configured and redeployed. OS acts as an independent controller for its own service data.
- Mapbox: provides map styles and tiles directly to your browser and therefore receives your IP address, the map area requested and service telemetry. It is not used for address search or geocoding and acts as an independent controller for its own service data.
- Google: if you choose to sign in with Google, Google processes your sign-in as an independent controller for its own authentication service.
We do not use public Nominatim or Overpass as data recipients: full-address search runs through Ideal Postcodes and fails safely if that service is unavailable.
We may also disclose personal data if the law requires it, or to establish, exercise or defend legal claims.
International transfers
Where a provider processes data outside the UK, that transfer is covered by an appropriate safeguard: Supabase: EU Standard Contractual Clauses with the UK Addendum (primary data held in the UK); Vercel: the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum; Resend: the UK Extension of the EU–US Data Privacy Framework and Standard Contractual Clauses; Ideal Postcodes: safeguards required by its DPA for necessary processing outside the EEA; Mapbox: its published transfer safeguards for map delivery. SARScore does not itself transfer contributor data outside the UK for its own purposes.
How long we keep it
- Account data: for as long as your account exists; if you close your account, we delete your account credentials and display name (see “Your rights”).
- Contributions and evidence: SARScore's evidence record is append-only: a report is never silently edited, and a correction or withdrawal is added as a new, dated entry while the original is retained for audit. Superseded or withdrawn evidence is retired from scoring.
- Photographs: kept privately while they support a route's record, and deleted on a fixed schedule: accepted evidence photographs are deleted no later than 24 months after capture (reviewed at 12 months, and deleted earlier once they stop supporting a live score); rejected photographs are deleted after 30 days and superseded photographs after 90 days. The structured, non-photographic record of the visit is what endures.
- Usability and error measurements: kept for no longer than 90 days and then deleted automatically; only anonymous aggregates are kept longer.
- Transactional email: our email provider retains message content and delivery logs for 30 days (see “Who we share data with”).
Automated processing
A SARScore is produced automatically: a deterministic engine interprets the observed facts and publishes a score. This is an assessment of a place, not a decision about you, and it does not produce legal or similarly significant effects on you. The exact calculation is proprietary to SARScore; how the methodology works is explained in full on our methodology pages. We do not carry out profiling of individuals.
Your rights
You have the right to: ask for a copy of the personal data we hold about you; ask us to correct inaccurate data; ask us to delete your account and personal data; ask us to restrict processing; and object to processing based on our legitimate interests. Where it applies, you also have the right to data portability.
Because most of our processing rests on legitimate interests, the right to object is important: tell us at privacy@sarscore.com and we will stop unless we have compelling legitimate grounds that override your interests, or we need the data to establish or defend legal claims.
Deleting your account. When you ask us to delete your account, we delete your account credentials and display name and stop associating you with new activity. For the reports you have already contributed, we carry out a controlled de-attribution: we remove your direct identifiers and any unnecessary free text, and we replace the link to you with a non-identifying marker that lets the evidence record keep counting distinct contributors (which is how a route earns confidence) without identifying you. Where a specific report cannot be de-identified, or where we must retain something to establish or defend a legal claim, we will tell you exactly what and why. We assess that case by case, not as a blanket rule. You can also download a copy of your account data from your account page; the download currently covers your account and reports, and we provide any further data we hold on request while we extend it.
To exercise any right, email privacy@sarscore.com from your account email address (or, for a report made without an account, quote its reference to support@sarscore.com). We respond within one month, and may extend by up to two further months for complex or numerous requests, telling you if we do.
Security
We take appropriate technical and organisational measures to protect personal data: encryption in transit (HTTPS), a content security policy, restrictive browser-permission and framing policies, database access governed by row-level security with server-side keys that never reach your browser, private storage for photographs accessible only to moderation, and single-purpose API keys. No online service can be completely secure, but we work to protect your data and to respond quickly if something goes wrong. To report a security problem, email support@sarscore.com with “Security” in the subject line.
How to complain
If you have a concern about how we handle your data, please tell us first at privacy@sarscore.com: you can complain electronically, we will acknowledge your complaint within 30 days, and we will respond without undue delay. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or by calling 0303 123 1113.
Changes to this notice
This is the notice for the current pilot. We keep it under review and update it as the platform develops; material changes are flagged on the site.
See also the Terms of Use, the Cookie & Storage Notice and Trust & Data.