Last updated: 24 July 2026
This page is maintained by SCOUTLE to answer common security and privacy questions. It describes the controls and practices we have enabled. It is not an independent audit, certification or legal guarantee.
SCOUTLE provides the platform, but athletes are responsible for the accuracy of the data they enter or upload, for keeping their credentials safe, and for choosing which recipients receive their CV. Guardians are responsible for providing and managing consent for athletes under 18.
Accounts are protected by email and password. We support password reset and account verification. Administrative access is restricted to authorised SCOUTLE staff and is logged.
SCOUTLE runs on Lovable Cloud, which provides managed infrastructure including PostgreSQL, authentication and private storage. Data is encrypted in transit and at rest by the platform. We do not operate our own physical data centres.
We use a small set of service providers for hosting, authentication, email delivery and AI-assisted document extraction. We only integrate with external sports platforms (such as Strava, ProCyclingStats and WHOOP) when an athlete explicitly connects their account and initiates a sync.
We use athlete data only to build and deliver the CV service. CV snapshots are immutable so athletes can review what was sent. Data is retained while an account is active and removed or anonymised when an account is deleted, except where retention is required by law.
To report a security issue, abuse or unauthorised data exposure, contact us at scoutle@cyclinghustler.com. We will investigate and respond as promptly as possible.
We welcome responsible disclosure. If you discover a vulnerability, please contact us at scoutle@cyclinghustler.com with enough detail for us to reproduce and address it. Do not exploit vulnerabilities or access data that is not your own.
This page is maintained by SCOUTLE as an AI-generated draft. It is not an independent verification or certification.