Trust & Data

How SARScore collects evidence, protects contributors and works with technology providers. This page explains the system we actually operate, in plain language. The contractual rules are in the Terms of Use; the formal statement of personal-data processing and your rights is the Privacy Notice; on-device storage and the usability opt-out are described in the Cookie & Storage Notice. Where the documents overlap, the Terms and the Privacy Notice take precedence.

1. Our data principles

SARScore describes places, not people. Evidence records what someone found at a kerb, an entrance, a lift: structured facts about buildings and journeys. We collect the minimum personal data the system needs to work (an account, a location check at the moment of reporting, a verification photograph), we say plainly what each piece is for, and nothing about contributors is sold or shared for advertising. Every number the platform publishes is generated from this evidence; nothing is bought in from data brokers.

2. What we collect

An account is an email address, a display name and a password (stored hashed by our authentication provider). A visit report is structured observations about the route: steps, lifts, surfaces, timing. Report questions ask what the route was like, for example whether it was usable with a wheelchair, never about you: SARScore does not ask for, and does not want, information about any person's disability, medical condition or personal access needs. We do not infer or record your access needs, and we do not treat contributors differently on that basis; we assess the residual privacy risk that a report could indirectly reveal an access need in a data-protection impact assessment. Please keep free-text notes about the route rather than about yourself or others; if personal detail ends up in a report, write to privacy@sarscore.com and we will remove it. Anonymous reports are accepted without any account at all.

We also record first-party usability measurements (see the Cookie & Storage Notice); these use pseudonymous identifiers, are not shared with any third party, and can be turned off.

Contributing and creating an account are for people aged 18 or over during the pilot; anyone may browse.

3. How location verification works

Location is requested only when you actively start a report, quick confirmation or check-in, through your browser's own permission prompt, and it is used for one thing: confirming you are within tolerance of the route you are reporting, so the evidence is bound to the place. The precise capture position is used to compute that distance check and is not kept. SARScore never tracks background movement, never records a movement history, and the site's own security policy (the Permissions-Policy header) restricts location and camera access to the reporting pages that need them.

4. Photographs and public evidence

A live photograph is what turns a report into verified evidence. Photographs must show the route (the door, the steps, the ramp, the approach) and must avoid faces, vehicle number plates and the interiors of private homes. We remove location and camera metadata embedded in the image file before storage; uploads whose metadata cannot be removed are not stored. Photographs are stored in a private bucket, reviewed by a moderator, and never published. What the public sees is the score, its evidence summary and the route facts; public contributions never reveal a contributor's email address or identity.

5. Service providers

SARScore runs on a small number of named providers. The register below states what each one does, what information is involved, where it is processed and under what safeguards, verified against each provider's published documents and, where stated, the provider's own written confirmation. This register is kept under review and updated when a provider, region or document changes; last verified 11 August 2026.

Register of SARScore service providers, their purpose, data involved, processing location, transfer safeguards, retention and legal role
ProviderService and purposePersonal data involvedProcessing locationTransfer safeguardsRetentionLegal roleDocuments
SupabaseAccounts, authentication, database and private evidence photo storageEmail address, display name, hashed password, contributions, check-ins, photographsAWS eu-west-2 (London): our project's dedicated regionPrimary database, authentication and photographs are held in the UK region; Supabase's subprocessors and its own usage data (for which Supabase is a controller) may involve other locations under EU Standard Contractual Clauses and the UK AddendumDaily backups with 7-day retention; 7-day platform-log retention (Pro plan); point-in-time recovery not enabled. Evidence records follow the retention section belowProcessor (controller only for its own usage data)Privacy · DPA
VercelWebsite hosting and deliveryIP address and technical request information (standard web server logs)Functions configured for London (lhr1); content delivery, build systems, logs and subprocessors may involve other locations under Vercel's transfer safeguards2021 EU standard contractual clauses and the UK IDTA, incorporated in the Vercel DPAOperational and observability logs retained around 30 days (infrastructure monitoring, not browser analytics; Speed Insights and Web Analytics are disabled); no contributor content is stored with VercelProcessor for our data; independent controller for its own service-generated dataPrivacy · DPA
ResendTransactional email (account confirmation, password reset), sent via our authentication provider's SMTP configurationEmail address, message content and delivery metadataUnited States (Resend processes and stores customer data primarily in the US)EU-US Data Privacy Framework and its UK Extension, and standard contractual clauses under its DPAEmail content and delivery, bounce and complaint logs are retained for 30 days, after which they are no longer stored; point-in-time backups are retained for 7 days. We do not use Resend's webhook event ingestion and keep no separate long-term email-event storeProcessor (stated in its DPA)Privacy · DPA
GoogleOptional “Continue with Google” sign-in, and business email for our public contact addresses (hello@, privacy@, support@ and similar). A Google account is never required.Sign-in: your name, email address and profile identifier (basic identity scopes only; never contacts, location or files). Email: the content of messages you choose to send usGoogle data centres under the Google Workspace termsGoogle's Cloud Data Processing Addendum with EU SCCsCorrespondence kept as long as needed to handle the matter; deletion on requestProcessor for customer email content (per the Cloud DPA); independent controller for its own sign-in servicePrivacy · DPA
MapboxMap display only (your browser loads map tiles and styles from api.mapbox.com). Mapbox is never used for address search, geocoding or deciding what a place isWhen you view a map, your browser sends Mapbox your IP address, the map area requested and anonymised service telemetry (a map-load event Mapbox uses for billing and service statistics). Nothing you type reaches Mapbox: contributor answers, place names, search text and evidence never enter this channelUnited StatesUK to US transfer for tile requests, covered by Mapbox's standard safeguardsRetained under Mapbox's own privacy policy (no fixed period published)Independent controller for its own service data (per its privacy policy)Mapbox privacy policy
Ideal Postcodes (IDDQD Limited)National address autocomplete and selected-address resolution, server side, while you add a place to contribute a report. The active datasets are Royal Mail PAF and Multiple Residence; returned UPRN and location enrichment may be derived from Ordnance Survey dataThe address text you type; the selected address identifier; and the returned formatted address, postcode, UPRN and valid coordinates. If you came from the location-assisted map route, your approximate contributor location is also sent to bias nearby suggestions. On paid address resolution only, SARScore forwards your validated source IP to Ideal Postcodes solely so it can enforce lookup limits. SARScore does not return, retain or log that IP in this address-search flow. The API key and UPRN are never shown to contributorsAddress processing uses Ideal Postcodes and its listed hosting processors in the UK and EU; Cloudflare provides global load balancingIdeal Postcodes' DPA requires lawful safeguards, including standard contractual clauses where processing outside the EEA is necessaryIdeal Postcodes may hold the forwarded source IP temporarily in its usage logs and applies its published log-redaction policy. Its DPA provides for deletion or return of personal data on request after termination or completion, except where law requires retention; SARScore retains only a selected address as described belowProcessor for address validation and cleansing (stated in its DPA)Privacy · DPA · Processors
Ordnance SurveyImmediate rollback provider for server-side national address search, and the historical address provider for applicable stored place records. OS map tiles are no longer used: map display is MapboxAddress text reaches OS from our server only when the rollback provider is explicitly selected and redeployed. Your browser never contacts OSUnited KingdomNone required: UK organisationRetained for as long as necessary under Ordnance Survey's own privacy policy (no fixed period published)Independent controller for its own service data (per its privacy policy)Privacy

Nominatim (OpenStreetMap) and Overpass (FOSSGIS) are not used as active data recipients: full-address search runs through Ideal Postcodes and fails safely if it is unavailable; Ordnance Survey is retained only as an explicit redeploy-based rollback provider and as the historical provider for applicable records; and the Overpass access-hint layer is dormant and cannot be enabled by configuration. Register last verified 11 August 2026. Everything else you do on the site talks only to sarscore.com; the one exception is map tiles, which your browser fetches directly from Mapbox.

6. Data retention

Evidence is an append-only record: observations are kept because published scores must remain auditable against the evidence that produced them, and superseded evidence is retired from calculations rather than erased. Verification photographs are time-bounded: accepted photographs are reviewed at 12 months and deleted at 24 months, or within 90 days of no longer supporting a live score; rejected photographs are deleted within 30 days of the decision and superseded ones within 90 days. The structured accessibility fact and its audit record are what endure. Event-level usability measurements are kept for 90 days. Account data lives for the life of the account. The full schedule is in the Privacy Notice.

7. International transfers

The evidence database and photo storage live in the UK (AWS London). Website delivery, email delivery and business email involve providers with operations outside the UK; each transfer is covered by the safeguards named in the register above (standard contractual clauses, the UK IDTA or Addendum, and Data Privacy Framework certification where held). SARScore does not transfer contributor data internationally itself.

8. Account deletion and your rights

You can ask for access to, correction of, or deletion of your account information at any time by writing to privacy@sarscore.com from your account email, or from your account page. On account closure we delete your account credentials and display name and carry out a controlled de-attribution of your past contributions, removing direct identifiers and unnecessary free text and replacing the link to you with a non-identifying marker that preserves distinct-contributor counting without identifying you. Anything we cannot de-identify, or must retain to defend a legal claim, is explained case by case. The formal statement of your rights, including complaint routes, is in the Privacy Notice.

9. Residential locations

During the pilot, SARScore does not publish exact addresses, coordinates or access profiles for private houses, bungalows or individual flat doors: those reports are held privately. Shared residential-building (communal) entrances are considered separately. If a place listing concerns your home and you want it removed or corrected, contact privacy@sarscore.com.

10. Security and vulnerability reporting

Concretely: all traffic is HTTPS; the site ships a content security policy, frame-embedding denial and restrictive permissions headers; database access is governed by row-level security with server-side keys that never reach the browser; evidence photographs live in a private bucket accessible only to moderation; and API keys are scoped to single purposes. No online service can be completely secure, but we work to protect your data and to respond quickly if something goes wrong. If you find a security problem, email support@sarscore.com with “Security” in the subject line; we will acknowledge it and act on it. Please do not test against other people's data.

11. Policy and processor change log

Changes to this page, to the provider register or to the Privacy Notice are recorded here with dates, so the account stays verifiable over time.

Data and privacy: privacy@sarscore.com · General: hello@sarscore.com

Trust & Data · SARScore