For school IT, data protection and safeguarding leads. Read before you buy.
Covers EasyAthletics and EasyFixtures. Each tool is listed separately where they differ.
Reviewed 19 September 2026
Your Google account
where all student data is stored
0
student records sent to EasyPE
1
outside service contacted (licence check)
0
analytics or advertising scripts
Each tool is a Google Sheet with a Google Apps Script web app attached, set up in the school’s own Google account. EasyPE does not host the tool or the data and holds no copy, so there is nothing on our side to secure, back up or delete.
Both tools share the same architecture: a Google Sheet with a Google Apps Script web app, set up in the school’s own Google account, with no EasyPE hosting and no copy of school data.
This website is separate from the tools and never receives student data.
EasyAthletics is the reference tool described on this page. The other tools in the suite use the same architecture, and each tool’s data fields are available on request.
Each tool stores its data only in the spreadsheet it is attached to. Where a tool needs anything beyond that file, it is listed in its own table below. Google’s consent screen at installation is the authoritative wording.
| Permission | What it lets the tool do | Why it is needed |
|---|---|---|
| View and manage only the spreadsheet the script is attached to (spreadsheets.currentonly) | read and write its own data | this is where all records live. |
| Connect to an external service (script.external_request) | make one kind of web request | the licence check only. |
| Run when you are not present (script.scriptapp) | install time-based triggers | keeps the roster sync running. |
| Display content in Google apps (script.container.ui) | add a menu and dialogs to the spreadsheet | the EasyAthletics menu. |
| See your email address (userinfo.email) | read the signed-in user's domain | only to build the licence label. |
What EasyAthletics does NOT request
Gmail, Drive files other than the one spreadsheet, Calendar, Contacts, Classroom, or domain-wide delegation. EasyAthletics does not send email.
| Permission | What it lets the tool do | Why it is needed |
|---|---|---|
| View and manage only the spreadsheet the script is attached to (spreadsheets.currentonly) | read and write its own data | this is where all records live. |
| Send email as you (script.send_mail) | email parents the fixture invitations, reminders and chasers from the school account | this is how permission requests reach families. |
| See, edit, share and permanently delete all the calendars you can access (calendar) | write fixtures and training to one Google Calendar the school chooses | Google offers no narrower calendar permission, so this is broader than EasyFixtures needs. The school picks a single calendar in Settings, events are identified by a tag line in the description, and an event without that tag is never touched. |
| Run when you are not present (script.scriptapp) | daily calendar sync and reminder triggers | keeps fixtures and reminders up to date without anyone opening the sheet. |
| Display content in Google apps (script.container.ui) | its menu and dialogs in the spreadsheet | the EasyFixtures menu. |
| See your email address (userinfo.email) | identify the signed-in user | only to label who is signed in. |
How EasyFixtures differs
EasyFixtures does send email on the school’s behalf, unlike EasyAthletics. It has a TEST mode that redirects all mail to one address until the school switches it on. It also asks for calendar access, which EasyAthletics does not.
Not asked for or used
date of birth, home address, phone numbers, parent or guardian details, photographs, medical or SEN information.
Not asked for or used
home address, photographs, payment details.
Phone numbers are printed on the match register the coach carries, so staff can reach a family on the day.
The parent reply form invites a note about an injury, an early collection or a medical detail, so treat that field as capable of holding health information. It is stored in the school’s own sheet and printed on the register staff carry to the fixture.
EasyFixtures holds more personal data than EasyAthletics because it emails parents and arranges transport — in particular date of birth and parent contact addresses.
Students who leave are moved to a hidden Archive sheet, and the school can delete any record at any time.
1. The licence check
Contacts the licence service from Google’s servers, sending the licence key and an instance label beginning “easyPE-” followed by the school’s Google domain where it can be read. It returns valid or not valid. No student data is included.
2. In the browser
Page fonts load from Google Fonts and two open-source libraries (SheetJS and qrcode.js) load from cdnjs. No student data is sent to them.
3. EasyFixtures: email and calendar
Email is sent through the school’s own Google account to the parent addresses the school has entered, and calendar events are written to the school’s chosen Google Calendar. No student data is sent to EasyPE.
Domains to allow on the school network
No cookies, no analytics, no advertising scripts.
A password screen on its own only hides a page. The data behind it can still be reachable by anyone who has the link. This is the most common weakness in tools like this, so it is what we test hardest.
EasyFixtures is in final preparation for release. It is built on the same architecture and is going through the same access review and attacker-style testing described below before it ships. The detailed security summary for EasyFixtures will be published here when that work is complete, and is available on request in the meantime.
How we test before every release
We make no claim to be unhackable, and we claim no certifications.
All student data is stored in your school's own Google account, in the spreadsheet the tool is attached to. EasyPE does not host the tool or the data and holds no copy.
Questions from your IT or data protection team are welcome before purchase.
Email contact@easype.storeThis page describes the EasyAthletics and EasyFixtures implementations. Google’s consent screen at installation is the authoritative wording for the permissions a tool requests.