Privacy Policy
Last updated: August 28, 2026. Plain language version below — the legal version follows. Where they conflict, the legal version controls.
The short version
- We collect what we need to make scoring work — account info, match data, and basic usage analytics.
- We don’t sell your data. We don’t share it with advertisers. There are no advertisers.
- You own your match data. You can export a match as CSV, PDF, or awards certificates, ask us by email for a copy of your personal data, and delete your account anytime.
- Deleting your account removes you, not the match: your profile and personal details go, and scores you shot stay in the club’s results with your account and contact details removed. Export anything you want to keep before you delete.
- We use industry-standard security (TLS, JWT auth, bcrypt-hashed passwords) and we don’t store payment information: payment details go straight to PayPal, our payment processor, and never touch our servers.
- Staff access to your data is scope-gated, hashed, optionally IP-allowlisted, and fully audit-logged.
- If you import a
.pscfile from another scoring app, you confirm you have authority to share that data.
What we collect
Account information: Username, email address, optional profile name, club affiliation, optional membership numbers (SASS, USPSA, IDPA — held on one profile as a structured map, one ID per organization), optional category preferences, optional profile details (first/last name, phone, city, state, postal code, country, notes). You provide this when you create an account or edit your profile.
Match data: Match metadata (name, date, type, discipline, organization, league, ruleset), shooter rosters, stage scores, squad / posse rotations, check-in records, grant claims, offline-queue entries until reconciled. This is the core data the app exists to manage.
Photos and images: Match, stage, and club records can carry attached photos — a stage diagram, a scoresheet, a target, an awards or group shot. Where your app version or club tooling offers photo attachment, an image you capture with the camera or choose from your photo library is uploaded to our servers and stored against the record you attached it to, along with an optional caption, a category, and the account that uploaded it. We access an image only when you explicitly capture or select it; we never scan, index, or read your photo library in the background. Photos attached to a match are kept for the life of that match record and are visible to the club that owns it — and to the public if that match is published. Camera access is used separately to scan QR codes for check-in and shooter registration; QR scanning reads the code only and stores no image.
Founding club list: If you claim founding club status before the iPhone app is on the App Store, we store the name, email address, club name, state and current scoring method you submit, along with how you found us. We use it for three things: getting you onto the app for your platform (Google Play on Android, TestFlight on iPhone), setting up your club account, and — when the iPhone app reaches the App Store — carrying that account across as a permanently free founding club. It is not a newsletter list, and it is not shared with anyone outside Snapshot Scoring. Ask us to remove you at any time at privacy@snapshotscoring.com.
Club nominations: If you nominate a club you do not run, we store the name, email address and state you submit, the club you named, and how you found us. We use it to follow up with you about that nomination. We do not ask for, store, or contact any address at the club you named — a nomination is not permission to contact anyone, and we treat it that way. Ask us to remove you at any time at privacy@snapshotscoring.com.
Location: The app asks for location permission for two distinct reasons. First, Bluetooth: Android requires an app to hold location permission before it may scan for nearby Bluetooth devices, so the permission is what lets the app find your shot timer — used this way it discovers timers only, and your coordinates are not read, stored, or sent to us. Second, venue and discovery: where offered, coarse or precise location is used to associate a match with the place it is held and to surface clubs and matches near you. Location is never sold, never shared with advertisers, and never used to track you across other apps or websites. You can grant or withdraw the permission at any time in your device settings; scoring works fully without it, and a match location can always be typed in by hand.
Match grants (Temp Auth): When a match director issues a stage-scoped grant, we record the creator, the permission set, the stage scope, the expiry time, and any revocation. Grants auto-expire 12 hours after the match end date. Claiming a grant does not currently work, so no claimant identity or claim timestamp is being recorded; extra scorers are added to a club as Scorekeepers instead.
Device & technical data: Device type (iOS / Android), app version, crash reports and error logs. Crash and error reports go to an error tracker we host ourselves, not a third-party service; when you are signed in they carry your account id and email so we can find and fix the failure you hit. Used to diagnose bugs and improve reliability.
Push notification tokens: If you opt in to notifications, we register your FCM (Android) or APNs (iOS) device token so the backend can deliver registration approvals, waitlist promotions, and match-publish announcements. Tokens are auto-deactivated when the device reports them as invalid.
Bluetooth devices: When you pair a BLE shot timer (AMG Commander, Shooters Global SG Timer, Special Pie M1A2), the device’s advertised name and identifier are stored locally on your phone so the app can reconnect. We do not transmit the pairing record to our servers.
Usage analytics: Aggregate usage patterns (which screens are used, which features get traction). Never tied to individual identity in our analytics.
Purchases: If you buy a club or circuit-host seat on this website, we store your name, billing email, the order (product, amount, date, status) and the seat it created, plus a WooCommerce customer account if you choose to create one at checkout. Payment is completed on our payment processor’s (PayPal’s) secure checkout and card or account details never reach our servers; we keep only the transaction reference PayPal returns. The billing email is used to attach the seat to your Snapshot account and to send order and renewal emails. Order records are kept for as long as tax and accounting rules require.
Match data imports (.psc files and other formats)
PractiScore .psc import is not available at present; the in-app import screen exists but the import fails. SASS Premier and Round-Up Scoring System files are handled on request. Where we do process a match-data file you supply, we parse it as a standard database (no decryption, no DRM circumvention) and create matching records in your club’s data on Snapshot Scoring. The terms below govern any such file you send us.
When you import a file containing match data:
- You warrant lawful authority. By uploading the file, you confirm you have lawful authority to share the data (e.g., as the match director, club administrator, or with explicit shooter consent under your club’s membership agreements).
- Shooter notification. You confirm that shooters in the imported match have been informed — whether through your club’s general data processing agreements or directly — that their match data is being processed by Snapshot Scoring.
- Same processing terms. Imported data is stored, secured, and processed under the same terms as data scored directly in the app: audit-logged, under the same access controls, and deleted with your account. You can ask for a copy of your personal data at privacy@snapshotscoring.com; there is no self-serve export of your account data today.
- Auditable origin. The import action is logged to the match’s audit trail with the source filename and timestamp so the chain of custody is preserved — anyone reviewing the match later can see it originated as an imported file rather than scored on Snapshot Scoring directly.
- If you’re not sure. If you’re not sure whether you have authority to import a particular file, don’t import it. Email privacy@snapshotscoring.com with questions.
Imported data is the responsibility of the importing user (you) under your club’s data processing agreements with shooters. Snapshot Scoring acts as a data processor for that data, processing it on your behalf.
How we use it
To run the scoring app and the WordPress publishing integration. That’s it. We don’t use your data for advertising (we don’t have ads), profiling, or any third-party data brokerage.
How we share it
With your club: Match data you participate in is visible to the match director and your club’s administrators. That’s the whole point.
With the public: When a match is published to your club’s website, the leaderboards become public — overall and per-category placements with shooter aliases. Your real name is not published unless you set it as your alias.
With extra scorers you add to your club: Someone you add as a Scorekeeper gets that role’s permission set (Score Matches, View Scores, Check In) for your club’s matches, and nothing else. Stage-scoped match grants would narrow this further, but claiming one does not currently work.
With service providers: Hosting, email (transactional), analytics, and payment processing (PayPal, for seats bought on this website; PayPal receives your payment details and billing name and email directly, under its own privacy policy). These vendors have access only to what they need to do their job, and act under their own privacy terms and data-processing agreements.
With Snapshot Scoring staff (scoped + audited): A small number of named staff accounts have scope-gated service-account tokens for support operations — resolving stuck scores, force-verifying an email at user request, investigating an abuse report. Access is hashed (SHA-256), optionally pinned to a known office IP (CIDR allowlist), and every action lands in our audit log with actor, timestamp, before/after deltas, and a required reason where destructive.
Never: We do not sell, rent, or trade your personal information.
Audit log & data integrity
Every destructive operation — score edits, match unlocks, ownership transfers, grant revocations, staff admin actions, and .psc/CSV imports — is written to an append-only audit log with actor, timestamp, IP, and before/after deltas. You can request a copy of log entries concerning your own account by emailing privacy@snapshotscoring.com. Staff-action entries are retained indefinitely; automated-event entries (login, token refresh) are retained for 90 days.
Your rights
Access: See everything we have on you. Email privacy@snapshotscoring.com.
Export: Email privacy@snapshotscoring.com and we will put together a copy of your personal data. There is no self-serve export of your account data today. Separately, a match you can see in the app can be exported from its Results screen as CSV, PDF, or awards certificates.
Correction: Edit your profile, fix errors in your match history. Self-serve.
Deletion: Delete your account from Settings in the app, confirmed with your password. Deletion is permanent, takes effect immediately, and cannot be undone. It removes your profile and account details (name, email, phone, membership numbers), your club memberships and follows, your device and push notification tokens, your notification history and preferences, and your personal gear. Match entries and stage scores are the club’s match records, so they are not deleted: they stay in that match’s results with your account, email and contact details removed, the same way a walk-on shooter’s results are held. If you want your own copy of your history, export it before you delete.
Security
TLS for everything in transit. JWT for app authentication with automatic refresh. Bcrypt for password hashing with enforced strength validation (8+ characters, upper/lower/number). OAuth 2.0 PKCE for the WordPress site connection. The OAuth client secret is held on your WP site AES-256 encrypted; the access and refresh tokens themselves are stored as ordinary WordPress options in plain text, readable by anything with database or administrator access to that site. Neither is shared beyond your site. Rate limits on sensitive actions: password change (5/15 min), email verification (10/hr), grant claims (20/hr). Email verification required on signup. Password reset via 6-digit email code with rate limiting. Offline mutation queue payloads obfuscated at rest with a key in the device Keychain (iOS) or Keystore (Android).
Children
Snapshot Scoring is not directed at children under 13. Junior shooters (for example SASS Buckaroo or junior divisions) may take part through an account created and managed by a parent or legal guardian, consistent with our Terms. We don’t knowingly collect personal information from anyone under 13. SASS Buckaroo and Buckarette categories, USPSA and IDPA junior divisions, and similar exist for younger shooters — accounts for those shooters should be created and managed by a parent or legal guardian.
Trademarks
Snapshot Scoring and the Snapshot Results plugin are trademarks of Snapshot Scoring. PractiScore, PractiScore 2, CAS Scoring, ACES, SASS Premier Scoring System, and Round-Up Scoring System are trademarks of their respective owners. References on this site (including in our comparison page, feature lists, and import/export documentation) are made under nominative fair use for purposes of factual product description and interoperability. Snapshot Scoring is not affiliated with, endorsed by, or sponsored by PractiScore, Niftybytes, Scoring Technologies, 129bit, ACES, SASS, USPSA, IDPA, or any other organization referenced on this site.
Contact
Snapshot Scoring is operated by InnovaERP Solutions LLC, Lancaster County, Nebraska. Mailing address: 1102 Douglas St, Omaha, NE 68102, United States.
Privacy questions, data requests, or just curious how something works under the hood — privacy@snapshotscoring.com.
Changes
If we change this policy materially, we’ll notify active users via email and post a notice in the app. The “Last updated” date at the top reflects the most recent revision.