Trust Center

Trust, Security & Privacy

This page is maintained by the team behind Where Fans Watch to answer common security and privacy questions. It describes our current practices and the platform capabilities we rely on. It is editable project content, not an independent certification or third-party audit.

Shared responsibility

Where Fans Watch is built on the Lovable Cloud platform. Lovable provides the underlying hosting, database, authentication and storage services. We — the app owners — are responsible for how the app is configured, what data is collected, and how user content is moderated. You, as a visitor or account holder, are responsible for keeping your sign-in credentials safe and for the accuracy of submissions you make.

Accounts & authentication

  • Accounts are optional for browsing venues, teams and schedules.
  • Signing in is required to save favorites, RSVP to watch parties, claim or manage a venue listing, and submit supporter or alumni groups.
  • Sign-in is handled by the Lovable Cloud authentication service using email and password or Google OAuth. Sessions are protected by signed tokens; staff actions require an explicit admin or moderator role.

What we collect

  • Account data: email address, display name and avatar (when supplied through Google).
  • App content you submit: venues, supporter or alumni groups, watch-party RSVPs, ratings, check-ins, photos and reports.
  • Billing data (venue owners only): handled by Stripe. We store the subscription identifier and status returned by Stripe; we never see or store full card numbers.

How data is protected

  • Database access is gated by row-level security policies so users can only see and modify rows they are entitled to.
  • Subscription and payment columns are restricted at the database level and are not returned to anonymous visitors or other signed-in users.
  • Internal moderation notes about user submissions are kept in staff-only tables and are not exposed to the people being reviewed.
  • Traffic between your browser and our services is encrypted via HTTPS.

Subprocessors we rely on

  • Lovable Cloud — application hosting, database, file storage and authentication.
  • Stripe — payment processing for venue verification.
  • ESPN public schedule feeds and football-data.org — read-only sources for sports schedules.
  • Google OAuth — optional sign-in provider when you choose “Continue with Google”.

Data retention & deletion

You can request deletion of your account from the account settings page. When you delete your account we cancel any active venue subscriptions and remove your profile, role and personal submissions. Public content you created (for example a venue listing claimed by you) is detached from your account and may remain visible.

Reporting a security issue

If you believe you have found a security or privacy issue, please reach out through the contact channels on the homepage so we can investigate. Include steps to reproduce the issue and avoid accessing data that does not belong to you.