← Back to EasyPE

IT and security overview

For school IT, data protection and safeguarding leads. Read before you buy.

Covers EasyAthletics and EasyFixtures. Each tool is listed separately where they differ.

Reviewed 19 September 2026

A. At a glance

Your Google account

where all student data is stored

0

student records sent to EasyPE

1

outside service contacted (licence check)

0

analytics or advertising scripts

B. How EasyPE tools are made

Each tool is a Google Sheet with a Google Apps Script web app attached, set up in the school’s own Google account. EasyPE does not host the tool or the data and holds no copy, so there is nothing on our side to secure, back up or delete.

Both tools share the same architecture: a Google Sheet with a Google Apps Script web app, set up in the school’s own Google account, with no EasyPE hosting and no copy of school data.

This website is separate from the tools and never receives student data.

EasyAthletics is the reference tool described on this page. The other tools in the suite use the same architecture, and each tool’s data fields are available on request.

C. Permissions the tools ask Google for

Each tool stores its data only in the spreadsheet it is attached to. Where a tool needs anything beyond that file, it is listed in its own table below. Google’s consent screen at installation is the authoritative wording.

EasyAthletics

PermissionWhat it lets the tool doWhy it is needed
View and manage only the spreadsheet the script is attached to (spreadsheets.currentonly)read and write its own datathis is where all records live.
Connect to an external service (script.external_request)make one kind of web requestthe licence check only.
Run when you are not present (script.scriptapp)install time-based triggerskeeps the roster sync running.
Display content in Google apps (script.container.ui)add a menu and dialogs to the spreadsheetthe EasyAthletics menu.
See your email address (userinfo.email)read the signed-in user's domainonly to build the licence label.

What EasyAthletics does NOT request

Gmail, Drive files other than the one spreadsheet, Calendar, Contacts, Classroom, or domain-wide delegation. EasyAthletics does not send email.

EasyFixtures

PermissionWhat it lets the tool doWhy it is needed
View and manage only the spreadsheet the script is attached to (spreadsheets.currentonly)read and write its own datathis is where all records live.
Send email as you (script.send_mail)email parents the fixture invitations, reminders and chasers from the school accountthis is how permission requests reach families.
See, edit, share and permanently delete all the calendars you can access (calendar)write fixtures and training to one Google Calendar the school choosesGoogle offers no narrower calendar permission, so this is broader than EasyFixtures needs. The school picks a single calendar in Settings, events are identified by a tag line in the description, and an event without that tag is never touched.
Run when you are not present (script.scriptapp)daily calendar sync and reminder triggerskeeps fixtures and reminders up to date without anyone opening the sheet.
Display content in Google apps (script.container.ui)its menu and dialogs in the spreadsheetthe EasyFixtures menu.
See your email address (userinfo.email)identify the signed-in useronly to label who is signed in.

How EasyFixtures differs

EasyFixtures does send email on the school’s behalf, unlike EasyAthletics. It has a TEST mode that redirects all mail to one address until the school switches it on. It also asks for calendar access, which EasyAthletics does not.

D. The usage model

  1. 1Purchase a licence and receive a licence key and access to the tool.
  2. 2Set the tool up in your school Google account (a copy of the Sheet with its script), deployed as a web app that runs as your account.
  3. 3Paste the licence key and set your own teacher password in the Setup Wizard sheet.
  4. 4Teachers sign in with the password; students open a personal link or QR card, and no student accounts are created.
  5. 5Ongoing: the licence is re-checked about hourly and the tool works through up to 7 days offline; updates arrive as a new script version the school chooses to install; licences renew annually.

E. Personal data held

EasyAthletics

nameyearclassgenderageage groupschool email (optional)MIS ID (optional)athletics resultspointsgrades and ranks

Not asked for or used

date of birth, home address, phone numbers, parent or guardian details, photographs, medical or SEN information.

EasyFixtures

full namenicknamedate of birthclassgenderage groupparent email addressesparent contact phone numberstudent email addresssquad and selectionpermission repliestransport choiceabsence datesfree-text note from parents, up to 500 characters

Not asked for or used

home address, photographs, payment details.

Phone numbers are printed on the match register the coach carries, so staff can reach a family on the day.

The parent reply form invites a note about an injury, an early collection or a medical detail, so treat that field as capable of holding health information. It is stored in the school’s own sheet and printed on the register staff carry to the fixture.

EasyFixtures holds more personal data than EasyAthletics because it emails parents and arranges transport — in particular date of birth and parent contact addresses.

Students who leave are moved to a hidden Archive sheet, and the school can delete any record at any time.

F. What leaves the school's Google account

1. The licence check

Contacts the licence service from Google’s servers, sending the licence key and an instance label beginning “easyPE-” followed by the school’s Google domain where it can be read. It returns valid or not valid. No student data is included.

2. In the browser

Page fonts load from Google Fonts and two open-source libraries (SheetJS and qrcode.js) load from cdnjs. No student data is sent to them.

3. EasyFixtures: email and calendar

Email is sent through the school’s own Google account to the parent addresses the school has entered, and calendar events are written to the school’s chosen Google Calendar. No student data is sent to EasyPE.

Domains to allow on the school network

  • script.google.com
  • *.googleusercontent.com
  • fonts.googleapis.com
  • fonts.gstatic.com
  • cdnjs.cloudflare.com

No cookies, no analytics, no advertising scripts.

G. How access is protected

A password screen on its own only hides a page. The data behind it can still be reachable by anyone who has the link. This is the most common weakness in tools like this, so it is what we test hardest.

EasyAthletics

  • Teacher sign-in is checked on the server, not just on the screen, and no student list is sent to the browser until sign-in succeeds.
  • Each teacher session ends after 6 hours.
  • Eight wrong passwords lock sign-in for 15 minutes.
  • A blank or default password is refused.
  • The school's password and licence key can never be requested by the web page.
  • The class leaderboard shows classmates' names and results but never their personal IDs.
  • Administrative commands such as recalculating grades or exporting can only be run by a signed-in staff member from the spreadsheet itself, not from the web page.
  • Students identify themselves with a random 8-character ID on their personal link, so there are no student passwords to leak.

EasyFixtures

EasyFixtures is in final preparation for release. It is built on the same architecture and is going through the same access review and attacker-style testing described below before it ships. The detailed security summary for EasyFixtures will be published here when that work is complete, and is available on request in the meantime.

How we test before every release

  1. 1List everything a stranger holding only the link could reach.
  2. 2Act as that stranger: call every function with no credentials and confirm nothing comes back and nothing changes.
  3. 3Run the real web page against the real code: before sign-in, with a wrong password, with the right one, and after a session expires.
  4. 4Rebuild the protected release and repeat every check on it.

We make no claim to be unhackable, and we claim no certifications.

I. Questions IT teams ask

All student data is stored in your school's own Google account, in the spreadsheet the tool is attached to. EasyPE does not host the tool or the data and holds no copy.

Questions from your IT or data protection team are welcome before purchase.

Email contact@easype.store

This page describes the EasyAthletics and EasyFixtures implementations. Google’s consent screen at installation is the authoritative wording for the permissions a tool requests.