Security

Data & Security Policy

Our data-access principles and security approach.

Last Updated: June 24, 2026

Introduction

Shot Roster is designed to help sports photographers manage events, bookings, client information, payment status, shoot sheets, and checklists.

This policy explains our data-access principles and security approach.

Section 1 — Data Access Principle

Photographers should only be able to access:

  • Their own account information
  • Their own branding settings
  • Their own packages
  • Their own events
  • Their own bookings
  • Their own clients
  • Their own shoot sheets/checklists
  • Their own event analytics

No photographer should be able to access another photographer's private dashboard data.

Section 2 — Required Access Controls

Enforce strict backend access rules using:

  • photographerId checks
  • userId checks
  • eventId ownership checks
  • booking ownership checks
  • authenticated session checks

For every dashboard query and mutation:

  • Confirm the current authenticated user belongs to the correct photographer account
  • Confirm the event belongs to that photographer
  • Confirm the booking belongs to that photographer and event
  • Reject access when ownership does not match

Do not rely only on frontend filtering. Backend authorization must enforce the same rules.

Section 3 — Booking Data Access

A booking should only be visible to:

  • The photographer who owns the event
  • Authorized support/admin users when necessary for platform operations
  • The client only where a public confirmation flow explicitly permits it

Do not expose another photographer's athlete/client details through public routes, dashboard routes, API calls, exports, print sheets, or search results.

Section 4 — Event Route Security

Public routes should use:

  • photographer public slug
  • event slug
  • event ownership validation

For /[photographerSlug]/[eventSlug], confirm:

  1. Photographer exists
  2. Event exists
  3. Event belongs to that photographer
  4. Event is active/public if public viewing is required

For /[photographerSlug]/[eventSlug]/book, use the same ownership validation.

Section 5 — Data Minimization

Only collect information needed for:

  • Booking management
  • Sports event organization
  • Photographer/client communication
  • Package selection
  • Payment tracking
  • Event-day workflow
  • Delivery coordination

Do not collect highly sensitive data unless there is a clear, necessary reason and a compliant process.

Section 6 — Minor Information

Because athletes may be minors:

  • Require adult/parent/legal guardian confirmation before booking submission
  • Do not allow children under 13 to directly submit booking information
  • Limit information collected to what is reasonably needed for the booking
  • Do not use minor information for unrelated advertising or sale

Section 7 — Security Measures

Use reasonable administrative, technical, and organizational safeguards designed to protect user data. At minimum:

  • Secure authenticated dashboard access
  • Enforce userId/photographerId/eventId ownership checks
  • Restrict admin access
  • Protect passwords through the platform's authentication system
  • Use secure transport where supported
  • Log important errors/security events where possible
  • Avoid exposing private booking data in public URLs

Section 8 — Exports and Print Sheets

CSV exports, print sheets, checklists, and booking summaries must only include data for the current authorized photographer and selected event. Never allow bulk export of another photographer's bookings.

Section 9 — Incident Response

If Shot Roster becomes aware of a suspected security incident involving personal information, we will investigate, take reasonable steps to contain the issue, and provide notices when required by applicable law.

Section 10 — User Responsibilities

Photographers should:

  • Use strong passwords
  • Keep login access private
  • Log out on shared devices
  • Avoid downloading client data unnecessarily
  • Protect printed shoot sheets and exports
  • Use booking data only for legitimate event and service purposes

Section 11 — Data Retention and Deletion

Shot Roster keeps account and booking information while accounts are active and as reasonably necessary for platform operations, security, legal obligations, dispute resolution, and recordkeeping.

Users may request deletion by contacting Tacoflickzphotography@gmail.com, subject to legitimate operational, legal, fraud-prevention, and security needs.

Section 12 — Contact

For security or privacy questions, contact:

Shot Roster
Tacoflickzphotography@gmail.com

Questions about these terms? Contact Shot Roster at Tacoflickzphotography@gmail.com.

Legal & Policies

Shot RosterShot Roster

The booking platform built for sports photographers.

Product

Company

Support

© 2026 Shot Roster. All rights reserved.