Exported spreadsheets don't just leak — they freeze. Why out-of-date club records are a safety problem, and what real-time data prevents.

Most committees worry about the wrong thing. The instinct is that data stored online is exposed, and data kept on the club's own computer is safe.
In practice it's usually the reverse — and not for the reason people expect. The problem with an exported spreadsheet isn't only that it leaks. It's that it stops being true the moment it's created.
A club exports its member list for a report. That file gets emailed to two committee members. One opens it on a home laptop, makes edits, sends it back. A copy lands in someone's personal cloud drive. A share link goes out so a third person can "just have a look."
Six months later there are five versions on four devices and nobody can say where all of them are.
At that point the club has lost the things that actually constitute security. You can't revoke an email attachment. You can't log who opened it or forwarded it on. And you can't delete what you can't locate.
But the one that does the real damage is quieter: that file is frozen. It reflects the club as it was on the day it was made. Everything that has changed since — a new address, a renewal that didn't happen, a certificate that expired last Tuesday — simply isn't in it.
A spreadsheet that's three weeks out of date doesn't announce itself. It looks exactly like a current one. That's what makes it dangerous.
Contact details drift constantly. People change email addresses and phone numbers without telling their club. If your working copy was exported a month ago, the notices you send — a renewal reminder, a safety notice, a cancellation — go to addresses that no longer work. You'll think the message was delivered. The member will never know it was sent.
Accreditation and expiry data goes stale faster still. Much of what a club relies on isn't generated by the club at all. It comes from a governing body, a state association, or an external authority. If that information only reaches you in periodic exports — a file sent through, a list someone re-keys — then between those transfers, your club is operating on a picture that is already wrong.
Nobody is being careless. The club simply doesn't know yet.
Two examples make the stakes obvious.
Access to a facility. Many clubs operate activities where participation depends on a member holding something current — a permit, a licence, an accreditation, a clearance. If the club's record of that is a file exported weeks ago, then someone whose authorisation lapsed in the meantime still appears eligible. They sign in. Nobody queries it, because nothing in front of the person on the desk says otherwise. The club has no way of knowing it has a problem until something forces the question.
That isn't a compliance failure in the paperwork sense. It's a safety control that silently stopped working.
Working With Children Checks. A coach's check expires in March. It was sighted when they joined in 2023 and recorded in a spreadsheet the previous secretary kept. They continue coaching juniors for eight months without a current clearance. It surfaces only when someone asks — an insurer, the governing body, a parent — and by then the club has a retrospective problem it cannot undo.
In both cases the club would have acted immediately if it had known. The failure isn't willingness. It's visibility.
This is why "is our data online?" is the wrong question, and "does our data tell us something has changed?" is the right one.
A record that lives in one connected system can do things a file cannot. An expiry date can be watched continuously rather than checked when someone remembers. A lapse can raise a flag against the member before it becomes an incident. A credential that has fallen out of date can gate an action — hold a renewal, stop a check-in, mark someone as ineligible for a role — at the moment it matters, not in a review months later.
None of that is possible with an exported copy, because an exported copy has no idea what happened after it was made. You cannot monitor a spreadsheet. It doesn't know that a certificate expired, and it can't tell you.
That's the part worth sitting with. The purpose of holding this data isn't record-keeping for its own sake. It's so the club finds out in time to do something.
SquadSpot has a built-in secure file transfer system. We will never ask a club to email us its member data, because emailing personal information around is exactly the practice this article is about. If we need to move data — during onboarding, or a migration from an older system — it moves through the platform rather than through anyone's inbox.
To be fair about the other side of it: exporting data isn't the enemy. Clubs legitimately need exports — for reports, for obligations to a governing body, for their own records. SquadSpot exports too. The distinction that matters is whether the export is a controlled transfer or whether it becomes the working copy.
A file generated for a specific purpose and used once is fine. A file that gets emailed on, edited by three people, stored in a personal drive and consulted for the next six months has quietly become your club's database — without any of the protections a database has.
Worth putting to your committee, regardless of what software you use:
None of these require new software to think about. They require someone asking, once.
If you want the detail on how SquadSpot stores and protects club data — where it's hosted, who can access it, and how it's backed up — that's set out on our security and data protection page. For credentials specifically, accreditation and credential tracking covers how expiry monitoring works.