Privacy Policy

Last updated: 18 August 2026

This page is available in English only.

1. Who we are

Skorre is a competition scoring and management platform operated by Fingercomps (ABN 83 363 016 526) of PO Box 299, Moorooka QLD 4105, Australia ("Skorre", "we", "us"). For data protection purposes we are the controller of the personal data described in this policy, except where section 3 says otherwise.

Contact for privacy matters: info@fingercomps.com.

2. Scope

This policy covers the Skorre web application at www.skorre.com. It applies to:

  • Organisers: people with Skorre accounts who run competitions.
  • Competitors: people entered in competitions, who may or may not hold accounts.
  • Visitors: people viewing public results pages and live scoreboards.

3. Our role for competitor data

Organisers enter, or collect through registration, competitor details for their competitions. For that data the organiser decides what is collected and why; we process it on the organiser's behalf to run their competition. In GDPR terms the organiser is the controller and we are their processor for organiser-entered competitor data. If you are a competitor with questions about why your data was entered, contact your competition organiser first; we will assist where we can.

For everything else (accounts, sessions, platform operations, and any future advertising described in section 7), we are the controller.

One thing we do across competitions. When you sign in, we match your verified email address against competitor registrations that carry the same address and link them to your account, so your past competitions appear under your profile. This runs across all competitions on Skorre, not just one organiser's, and it is our own processing rather than something an organiser asked us to do. Only unlinked registrations are claimed, and proving control of the email address is what authorises it. If you would rather your registrations were not linked this way, contact us.

4. What we collect

What we collect, in summary:

Account data (organisers and account-holding competitors): name, email address, optional avatar image, organisation memberships and roles.

Sign-in and security data: session tokens, IP address and browser user agent at sign-in, passkey public keys and authenticator metadata (passkeys never give us your biometrics; verification happens on your device), one-time magic-link tokens. We do not use passwords.

Competition data: competitions, scoring formats, and competitor records: name, bib number, category, optional email (only where the organiser enables email collection), optional organiser-defined registration fields, team membership, scores, and calculated results and placings. Scores may be entered by the organising team or, through score-entry links, by competitors themselves or by someone on their behalf (for example a friend, parent or guardian). We keep a best-effort record of how a score arrived, though an organiser editing a score later replaces that record.

Communications data: the transactional emails we send (magic links, registration confirmations, organisation invitations, profile-linking emails, account-deletion confirmations) and the addresses they went to.

Technical data: server request logs held by our hosting provider (include IP addresses and requested URLs).

AI feature input: for organisations on the paid AI feature, the text you type to generate a scoring format. Do not include personal data in prompts.

We do not run analytics or advertising trackers, and we collect no data from visitors who merely view public pages beyond standard server logs. Our pages load no third-party resources at all: fonts and assets are served from our own domain, so viewing a public results page does not tell any other company that you were there.

5. Why we use it and our lawful bases

UseDataLawful basis (GDPR)
Providing accounts and signing you inAccount, sign-in dataContract (Art 6(1)(b))
Running competitions: registration, scoring, results calculationCompetition dataContract with organisers; processor on organiser instructions for organiser-entered competitor data
Displaying results publicly where the organiser enables itCompetitor name, bib, category, scores, placingsOrganiser's instructions; our legitimate interests in operating a results platform (Art 6(1)(f))
Sending transactional email (magic links, confirmations, invitations)Email addresses, comp detailsContract; legitimate interests for invitations to non-users
Linking competitor registrations to your account by matching your verified email at sign-inAccount email, competitor emailLegitimate interests in giving you your competition history (Art 6(1)(f))
Security, abuse prevention, debuggingIP address, user agent, server logsLegitimate interests (Art 6(1)(f))
AI format generation (paid feature)Prompt textContract
Future first-party advertisingSee section 7Consent, when the feature exists (Art 6(1)(a))

We do not sell personal data, and we do not use third-party advertising networks.

6. Public display of results

Competition results are the purpose of the product. When an organiser enables a public results page or live scoreboard, the competitor's name, bib number, category, scores and placing are visible to anyone with the link, without authentication. The live scoreboard also shows the competitor's team name, and their state of origin where the organiser has turned that option on. Organisers control whether these displays are on. If you are a competitor and object to public display, contact your organiser; you can also contact us and we will work with the organiser on removal or pseudonymisation.

7. Future first-party advertising (forward-looking disclosure)

Skorre does not currently show advertising. We plan to introduce first-party advertising: ads sold and served by Skorre itself, not by third-party ad networks, with no third-party tracking.

When we do, we may use your platform activity, including your competition history (for example, the kinds of competitions you take part in or run), to choose which ads are relevant to you. What this means:

  • Ad relevance would be determined by Skorre using data already held on the platform; your data would not be shared with advertisers.
  • Before any such use begins, we will update this policy with the specifics, and introduce a consent mechanism and a standing opt-out. Using competition history for ad relevance will not happen silently under this policy alone.
  • For Australian users, this addresses APPs 6 and 7: using competition history for advertising is a secondary use you would not reasonably expect, so it will proceed only with consent and with a simple way to opt out of direct marketing at any time.

8. Who we share data with

We use these service providers (processors) to run Skorre:

ProviderPurposeLocation
VercelApplication hosting and deliveryFrankfurt (fra1), Washington DC (iad1), Sydney (syd1)
NeonDatabase hostingAustralia
ResendTransactional email deliveryTokyo, Japan (ap-northeast-1)
Vercel AI Gateway + AnthropicAI format generation (paid feature only)United States

We also share competitor data with the relevant competition organiser (it is their competition), and public results with anyone viewing pages the organiser has made public. We may disclose data where the law requires, or in a business restructure with equivalent privacy commitments.

9. International transfers

We are based in Australia, and so is the database: your competition data is stored at rest in Australia. The application itself is served from Frankfurt, Washington DC and Sydney, transactional email is sent from Tokyo, and the optional AI feature calls a provider in the United States.

For EU/UK users. Although we serve pages from Frankfurt, your data is stored in Australia, which is a transfer outside the EEA and UK. Australia does not have an EU adequacy decision, so we rely on the standard contractual clauses in our providers' data-processing agreements for that transfer. Email is processed in Japan, which the EU has recognised as providing adequate protection. The AI feature is the only route to the United States, and it is off unless your organisation turns it on.

For Australian users. APP 8 cross-border disclosure obligations apply to the hosting, email and AI arrangements above.

10. Retention

A daily job clears out data we no longer need. In plain terms (detail in the data inventory):

  • Account data is kept while the account exists, and removed when you delete your account (see section 11 for exactly what goes and what stays).
  • Expired sign-in data is deleted after a short grace period: sessions 30 days after they expire (which removes the stored IP address and browser user agent), sign-in and account-deletion tokens 7 days, unaccepted organisation invitations 30 days.
  • Deleted competitors are not kept as-is. Thirty days after an organiser deletes a competitor, we strip the personal details from the record: the name is replaced with a neutral placeholder and the email, linking token and any custom fields are cleared. We keep the emptied record so the bib number stays reserved and the competition's results still add up.
  • Competition data (competitors, scores, results) is kept for the life of the competition. Deleted competitions are currently retained rather than erased.
  • Server logs are retained per our hosting provider's defaults.

11. Your rights

EU/UK (GDPR / UK GDPR). You have the rights of access, rectification, erasure, restriction, portability, and objection (including to legitimate-interests processing), and the right to withdraw consent where processing is based on consent. Contact info@fingercomps.com; we will respond within one month. You may complain to your local supervisory authority (or the UK ICO).

Australia (Privacy Act 1988 / APPs). You may request access to and correction of your personal information (APPs 12 and 13). Complaints go first to us at info@fingercomps.com; if unresolved, to the Office of the Australian Information Commissioner (oaic.gov.au).

Deleting your account. You can delete your account yourself from your profile. Because we do not use passwords, we email you a confirmation link first. If you are the only owner of an organisation you will need to transfer it or delete it before your account can go.

Deleting your account removes your sign-in data (sessions, passkeys, sign-in records), your organisation memberships and any invitations you sent. It also unlinks your account from competitor registrations and removes your name from things you created, like scoring formats and score entries.

What it does not do is erase the competition records themselves. If an organiser entered you in a competition, that record (including the name and any email on it) belongs to their competition and stays with it, along with the scores and results, so their event history stays intact. If you want those removed, ask the organiser, or contact us and we will help.

For organiser-entered competitor data generally we may need to refer your request to the organiser as controller, but we will not leave you without an answer.

There is no automated decision-making producing legal or similarly significant effects.

12. Security

Sign-in is passwordless (magic links and passkeys), so there are no user passwords to breach. Score-entry link passphrases are stored as salted scrypt hashes, never plaintext (once a link is unlocked, the browser holds a token for that link only, for 12 hours). Data is encrypted in transit (TLS) and at rest by our database provider. Access to production data is limited to the operating team. No system is perfectly secure; we will notify affected users and regulators of eligible data breaches as required (including under the AU Notifiable Data Breaches scheme and GDPR Articles 33-34).

13. Children

Competitions often include youth categories, so competitor records may relate to minors, entered by organisers who are responsible for the appropriate parental consent (see the terms). Skorre accounts require a minimum age of 16. Because competitor records are entered by organisers rather than by the competitors themselves, this account age limit does not prevent children from taking part in competitions.

14. Cookies and local storage

We use no tracking or advertising cookies. We set:

  • a session cookie (essential, keeps you signed in),
  • a locale cookie (remembers your language),
  • an unlock cookie on passphrase-protected score-entry links (essential; set only when you unlock such a link, scoped to that one link, expires after 12 hours),
  • a skorre-theme value in localStorage (remembers light/dark mode; never sent to us).

Because all cookies are strictly necessary or simple preferences, no consent banner is currently required. If future advertising changes this, we will add consent controls first.

15. Changes to this policy

We will post updates at www.skorre.com/privacy and, for material changes (including activating the advertising described in section 7), notify account holders by email or in-product notice before the change takes effect.

16. Contact

info@fingercomps.com — Fingercomps, PO Box 299, Moorooka QLD 4105, Australia.