Trust & Data
How SARScore collects evidence, protects contributors and works with technology providers. This page explains the system we actually operate, in plain language. The contractual rules are in the Terms of Use; the formal statement of personal-data processing and your rights is the Privacy Notice; on-device storage and the usability opt-out are described in the Cookie & Storage Notice. Where the documents overlap, the Terms and the Privacy Notice take precedence.
1. Our data principles
SARScore describes places, not people. Evidence records what someone found at a kerb, an entrance, a lift: structured facts about buildings and journeys. We collect the minimum personal data the system needs to work (an account, a location check at the moment of reporting, a verification photograph), we say plainly what each piece is for, and nothing about contributors is sold or shared for advertising. Every number the platform publishes is generated from this evidence; nothing is bought in from data brokers.
2. What we collect
An account is an email address, a display name and a password (stored hashed by our authentication provider). A visit report is structured observations about the route: steps, lifts, surfaces, timing. Report questions ask what the route was like, for example whether it was usable with a wheelchair, never about you: SARScore does not ask for, and does not want, information about any person's disability, medical condition or personal access needs. We do not infer or record your access needs, and we do not treat contributors differently on that basis; we assess the residual privacy risk that a report could indirectly reveal an access need in a data-protection impact assessment. Please keep free-text notes about the route rather than about yourself or others; if personal detail ends up in a report, write to privacy@sarscore.com and we will remove it. Anonymous reports are accepted without any account at all.
We also record first-party usability measurements (see the Cookie & Storage Notice); these use pseudonymous identifiers, are not shared with any third party, and can be turned off.
Contributing and creating an account are for people aged 18 or over during the pilot; anyone may browse.
3. How location verification works
Location is requested only when you actively start a report, quick confirmation or check-in, through your browser's own permission prompt, and it is used for one thing: confirming you are within tolerance of the route you are reporting, so the evidence is bound to the place. The precise capture position is used to compute that distance check and is not kept. SARScore never tracks background movement, never records a movement history, and the site's own security policy (the Permissions-Policy header) restricts location and camera access to the reporting pages that need them.
4. Photographs and public evidence
A live photograph is what turns a report into verified evidence. Photographs must show the route (the door, the steps, the ramp, the approach) and must avoid faces, vehicle number plates and the interiors of private homes. We remove location and camera metadata embedded in the image file before storage; uploads whose metadata cannot be removed are not stored. Photographs are stored in a private bucket, reviewed by a moderator, and never published. What the public sees is the score, its evidence summary and the route facts; public contributions never reveal a contributor's email address or identity.
5. Service providers
SARScore runs on a small number of named providers. The register below states what each one does, what information is involved, where it is processed and under what safeguards, verified against each provider's published documents and, where stated, the provider's own written confirmation. This register is kept under review and updated when a provider, region or document changes; last verified 11 August 2026.
| Provider | Service and purpose | Personal data involved | Processing location | Transfer safeguards | Retention | Legal role | Documents |
|---|---|---|---|---|---|---|---|
| Supabase | Accounts, authentication, database and private evidence photo storage | Email address, display name, hashed password, contributions, check-ins, photographs | AWS eu-west-2 (London): our project's dedicated region | Primary database, authentication and photographs are held in the UK region; Supabase's subprocessors and its own usage data (for which Supabase is a controller) may involve other locations under EU Standard Contractual Clauses and the UK Addendum | Daily backups with 7-day retention; 7-day platform-log retention (Pro plan); point-in-time recovery not enabled. Evidence records follow the retention section below | Processor (controller only for its own usage data) | Privacy · DPA |
| Vercel | Website hosting and delivery | IP address and technical request information (standard web server logs) | Functions configured for London (lhr1); content delivery, build systems, logs and subprocessors may involve other locations under Vercel's transfer safeguards | 2021 EU standard contractual clauses and the UK IDTA, incorporated in the Vercel DPA | Operational and observability logs retained around 30 days (infrastructure monitoring, not browser analytics; Speed Insights and Web Analytics are disabled); no contributor content is stored with Vercel | Processor for our data; independent controller for its own service-generated data | Privacy · DPA |
| Resend | Transactional email (account confirmation, password reset), sent via our authentication provider's SMTP configuration | Email address, message content and delivery metadata | United States (Resend processes and stores customer data primarily in the US) | EU-US Data Privacy Framework and its UK Extension, and standard contractual clauses under its DPA | Email content and delivery, bounce and complaint logs are retained for 30 days, after which they are no longer stored; point-in-time backups are retained for 7 days. We do not use Resend's webhook event ingestion and keep no separate long-term email-event store | Processor (stated in its DPA) | Privacy · DPA |
| Optional “Continue with Google” sign-in, and business email for our public contact addresses (hello@, privacy@, support@ and similar). A Google account is never required. | Sign-in: your name, email address and profile identifier (basic identity scopes only; never contacts, location or files). Email: the content of messages you choose to send us | Google data centres under the Google Workspace terms | Google's Cloud Data Processing Addendum with EU SCCs | Correspondence kept as long as needed to handle the matter; deletion on request | Processor for customer email content (per the Cloud DPA); independent controller for its own sign-in service | Privacy · DPA | |
| Mapbox | Map display only (your browser loads map tiles and styles from api.mapbox.com). Mapbox is never used for address search, geocoding or deciding what a place is | When you view a map, your browser sends Mapbox your IP address, the map area requested and anonymised service telemetry (a map-load event Mapbox uses for billing and service statistics). Nothing you type reaches Mapbox: contributor answers, place names, search text and evidence never enter this channel | United States | UK to US transfer for tile requests, covered by Mapbox's standard safeguards | Retained under Mapbox's own privacy policy (no fixed period published) | Independent controller for its own service data (per its privacy policy) | Mapbox privacy policy |
| Ideal Postcodes (IDDQD Limited) | National address autocomplete and selected-address resolution, server side, while you add a place to contribute a report. The active datasets are Royal Mail PAF and Multiple Residence; returned UPRN and location enrichment may be derived from Ordnance Survey data | The address text you type; the selected address identifier; and the returned formatted address, postcode, UPRN and valid coordinates. If you came from the location-assisted map route, your approximate contributor location is also sent to bias nearby suggestions. On paid address resolution only, SARScore forwards your validated source IP to Ideal Postcodes solely so it can enforce lookup limits. SARScore does not return, retain or log that IP in this address-search flow. The API key and UPRN are never shown to contributors | Address processing uses Ideal Postcodes and its listed hosting processors in the UK and EU; Cloudflare provides global load balancing | Ideal Postcodes' DPA requires lawful safeguards, including standard contractual clauses where processing outside the EEA is necessary | Ideal Postcodes may hold the forwarded source IP temporarily in its usage logs and applies its published log-redaction policy. Its DPA provides for deletion or return of personal data on request after termination or completion, except where law requires retention; SARScore retains only a selected address as described below | Processor for address validation and cleansing (stated in its DPA) | Privacy · DPA · Processors |
| Ordnance Survey | Immediate rollback provider for server-side national address search, and the historical address provider for applicable stored place records. OS map tiles are no longer used: map display is Mapbox | Address text reaches OS from our server only when the rollback provider is explicitly selected and redeployed. Your browser never contacts OS | United Kingdom | None required: UK organisation | Retained for as long as necessary under Ordnance Survey's own privacy policy (no fixed period published) | Independent controller for its own service data (per its privacy policy) | Privacy |
Nominatim (OpenStreetMap) and Overpass (FOSSGIS) are not used as active data recipients: full-address search runs through Ideal Postcodes and fails safely if it is unavailable; Ordnance Survey is retained only as an explicit redeploy-based rollback provider and as the historical provider for applicable records; and the Overpass access-hint layer is dormant and cannot be enabled by configuration. Register last verified 11 August 2026. Everything else you do on the site talks only to sarscore.com; the one exception is map tiles, which your browser fetches directly from Mapbox.
6. Data retention
Evidence is an append-only record: observations are kept because published scores must remain auditable against the evidence that produced them, and superseded evidence is retired from calculations rather than erased. Verification photographs are time-bounded: accepted photographs are reviewed at 12 months and deleted at 24 months, or within 90 days of no longer supporting a live score; rejected photographs are deleted within 30 days of the decision and superseded ones within 90 days. The structured accessibility fact and its audit record are what endure. Event-level usability measurements are kept for 90 days. Account data lives for the life of the account. The full schedule is in the Privacy Notice.
7. International transfers
The evidence database and photo storage live in the UK (AWS London). Website delivery, email delivery and business email involve providers with operations outside the UK; each transfer is covered by the safeguards named in the register above (standard contractual clauses, the UK IDTA or Addendum, and Data Privacy Framework certification where held). SARScore does not transfer contributor data internationally itself.
8. Account deletion and your rights
You can ask for access to, correction of, or deletion of your account information at any time by writing to privacy@sarscore.com from your account email, or from your account page. On account closure we delete your account credentials and display name and carry out a controlled de-attribution of your past contributions, removing direct identifiers and unnecessary free text and replacing the link to you with a non-identifying marker that preserves distinct-contributor counting without identifying you. Anything we cannot de-identify, or must retain to defend a legal claim, is explained case by case. The formal statement of your rights, including complaint routes, is in the Privacy Notice.
9. Residential locations
During the pilot, SARScore does not publish exact addresses, coordinates or access profiles for private houses, bungalows or individual flat doors: those reports are held privately. Shared residential-building (communal) entrances are considered separately. If a place listing concerns your home and you want it removed or corrected, contact privacy@sarscore.com.
10. Security and vulnerability reporting
Concretely: all traffic is HTTPS; the site ships a content security policy, frame-embedding denial and restrictive permissions headers; database access is governed by row-level security with server-side keys that never reach the browser; evidence photographs live in a private bucket accessible only to moderation; and API keys are scoped to single purposes. No online service can be completely secure, but we work to protect your data and to respond quickly if something goes wrong. If you find a security problem, email support@sarscore.com with “Security” in the subject line; we will acknowledge it and act on it. Please do not test against other people's data.
11. Policy and processor change log
Changes to this page, to the provider register or to the Privacy Notice are recorded here with dates, so the account stays verifiable over time.
- 11 August 2026: Ideal Postcodes added as the active server-side address provider after written PAYG approval for SARScore's stated use; PAF and Multiple Residence enabled; approximate-location bias and trusted source-IP forwarding for provider-enforced lookup limits disclosed; the provider's usage-log redaction policy recorded; Ordnance Survey retained as the explicit rollback provider and historical source for applicable records; Mapbox remains the map-display provider.
- 29 July 2026: Register re-verified end to end. Resend entry corrected to its published United States position with its confirmed 30-day email/log retention and 7-day backup window; Supabase region confirmed (AWS eu-west-2, London) with backup/log retention stated; Vercel entry updated (London function configuration, ~30-day observability logging, browser analytics disabled); OpenStreetMap/Overpass reclassified as not active recipients (full-address search at that review point ran only through Ordnance Survey). Retention, deletion, residential-publication, age and photograph-metadata sections aligned to the deployed controls. Cookie & Storage Notice linked.
- 16 July 2026: “Continue with Google” sign-in introduced as an optional alternative to email (basic identity scopes only). Google register entry updated accordingly.
- 16 July 2026: Page published. Provider register verified against each supplier's current privacy and data-processing documents.
Data and privacy: privacy@sarscore.com · General: hello@sarscore.com