Skip to main content

Privacy Policy

Last updated: July 4, 2026

Who we are

Data controller: Golf Venues, based in the United Kingdom. Throughout this policy "we", "us", "our" refers to Golf Venues.

Privacy contact: [email protected]. We aim to respond to all data-subject requests within 30 days as required by UK GDPR.

What we collect

How we use your information

Lawful basis

We process personal data on the following lawful bases:

Subprocessors

We rely on the following third-party services to operate the site. Each is bound by a data-processing agreement (DPA). Where data leaves the UK/EEA, the transfer is covered by the EU-US Data Privacy Framework (DPF), UK extension to the DPF, or Standard Contractual Clauses.

Provider Purpose Location Transfer safeguard
DigitalOcean Server hosting, database, file storage UK (London / LON1) UK data, no transfer
Cloudflare CDN, DDoS protection, bot management, R2 image storage Global edge EU-US DPF + SCCs
Google (Analytics 4) Anonymous usage analytics (Analytics consent only) USA EU-US DPF
Microsoft (Clarity) Anonymous heatmap and session-replay analytics (Analytics consent only) USA EU-US DPF
Google (Sign-In / OAuth) "Continue with Google" sign-in (only if you choose it) USA EU-US DPF
Gmail SMTP (Google) Outbound transactional email USA EU-US DPF
CARTO Basemap tiles for the interactive maps — your browser requests tiles directly from CARTO's CDN so your IP reaches them USA EU-US DPF
Google (AdSense) Advertising — serves ads, and may set advertising cookies, only to visitors outside the EEA, UK & Switzerland. EEA/UK/Switzerland visitors are not served ads. USA EU-US DPF

International transfers

Some of the subprocessors above are based in or operate from the United States. Following the Schrems II decision (C-311/18), transfers of personal data from the UK/EEA to the USA require additional safeguards. We rely on the EU-US Data Privacy Framework and its UK extension (Google LLC, Microsoft Corporation and Cloudflare Inc. are all certified) or, where the provider is not DPF-certified, on the Standard Contractual Clauses approved by the European Commission and recognised by the UK ICO. You can request a copy of the safeguards in place by emailing the privacy address above.

Sharing your information

We do not sell your personal data. We share it only with:

How long we keep it

Your rights

Under UK GDPR and the Data Protection Act 2018 you have the right to:

To exercise any of these rights — including requesting a copy of your cookie consent log — email us at [email protected].

Global Privacy Control (GPC)

If your browser or extension sends a Global Privacy Control (GPC) signal, we treat that as a binding "reject all" for non-essential processing: no banner is shown, no analytics or marketing cookies are set, and Google AdSense ads are not loaded — including for visitors outside the EEA, UK and Switzerland, who would otherwise see them. This satisfies the opt-out of "sale/sharing" expected under California's CPRA. For analytics, you can still open the Cookie Settings link in the footer to opt back in voluntarily.

Security

We use industry-standard security measures (TLS encryption, hashed passwords with bcrypt, role-based access controls, automated backups, intrusion-protection rules at the CDN edge). No method of transmission is 100% secure; you should also use a strong, unique password.

Children

This service is not directed at children under 13. We collect a date of birth at signup specifically to enforce age-gated features. If you believe a child has provided us with personal data, please contact us so we can delete it.

Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and update the "Last updated" date. If a change is material (new subprocessor, new processing purpose), we will re-prompt you for cookie consent.

Contact

Questions or requests: [email protected].