Privacy Policy
Last updated: July 4, 2026
Who we are
Data controller: Golf Venues, based in the United Kingdom. Throughout this policy "we", "us", "our" refers to Golf Venues.
Privacy contact: [email protected]. We aim to respond to all data-subject requests within 30 days as required by UK GDPR.
What we collect
- Account information: name, email address, username, date of birth, address, country, and (optionally) handicap index, home club, profile photo, and header image.
- Golf activity: rounds you play, scores, courses visited, friends added, and equipment in your bag.
- Technical data: IP address, browser type, device, pages visited and timestamps. Used to keep the site secure and to understand usage.
- Communications: any messages or enquiries you send us.
- Cookie consent records: the choice you made, when, the policy version, your hashed IP and user agent. Used to prove consent if a regulator asks.
How we use your information
- To create and manage your account.
- To deliver core features: round tracking, friends, notifications, leaderboards, your profile.
- To respond to support requests and sponsor enquiries.
- To improve the site and detect abuse.
- To send service-related emails (e.g. password reset, security alerts). We do not send marketing email without your consent.
Lawful basis
We process personal data on the following lawful bases:
- Contract — to provide the service you've signed up for.
- Legitimate interest — to keep the site secure, prevent fraud, and improve our service.
- Consent — for non-essential cookies and any optional marketing communications.
- Legal obligation — where we have to retain or disclose information by law.
Subprocessors
We rely on the following third-party services to operate the site. Each is bound by a data-processing agreement (DPA). Where data leaves the UK/EEA, the transfer is covered by the EU-US Data Privacy Framework (DPF), UK extension to the DPF, or Standard Contractual Clauses.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| DigitalOcean | Server hosting, database, file storage | UK (London / LON1) | UK data, no transfer |
| Cloudflare | CDN, DDoS protection, bot management, R2 image storage | Global edge | EU-US DPF + SCCs |
| Google (Analytics 4) | Anonymous usage analytics (Analytics consent only) | USA | EU-US DPF |
| Microsoft (Clarity) | Anonymous heatmap and session-replay analytics (Analytics consent only) | USA | EU-US DPF |
| Google (Sign-In / OAuth) | "Continue with Google" sign-in (only if you choose it) | USA | EU-US DPF |
| Gmail SMTP (Google) | Outbound transactional email | USA | EU-US DPF |
| CARTO | Basemap tiles for the interactive maps — your browser requests tiles directly from CARTO's CDN so your IP reaches them | USA | EU-US DPF |
| Google (AdSense) | Advertising — serves ads, and may set advertising cookies, only to visitors outside the EEA, UK & Switzerland. EEA/UK/Switzerland visitors are not served ads. | USA | EU-US DPF |
International transfers
Some of the subprocessors above are based in or operate from the United States. Following the Schrems II decision (C-311/18), transfers of personal data from the UK/EEA to the USA require additional safeguards. We rely on the EU-US Data Privacy Framework and its UK extension (Google LLC, Microsoft Corporation and Cloudflare Inc. are all certified) or, where the provider is not DPF-certified, on the Standard Contractual Clauses approved by the European Commission and recognised by the UK ICO. You can request a copy of the safeguards in place by emailing the privacy address above.
Sharing your information
We do not sell your personal data. We share it only with:
- The subprocessors above, under appropriate data-processing agreements.
- Other users of the site, where you choose to share content (e.g. your public profile, rounds played with friends, friends-in-common).
- Authorities, where legally required.
- A buyer or successor in the event of a merger, acquisition, reorganisation or sale of some or all of our assets, in which case your personal data may be transferred as part of that transaction. Any successor will be bound by this policy (or one offering equivalent protection), and we will notify you of any such change of ownership or control of your personal data.
How long we keep it
- Account data: for as long as your account is active. When you delete your account it's soft-deleted for 30 days (so accidental deletion is reversible) and then anonymised — username + email cleared, avatar/header removed. Historical round records may be retained in aggregate or anonymised form for other players' records.
- Cookie consent records: 3 years after the date of consent, to satisfy our obligation to demonstrate consent under UK GDPR Art. 7(1).
- Server logs: 14 days.
- Email logs: 90 days.
Your rights
Under UK GDPR and the Data Protection Act 2018 you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict processing.
- Request a copy of your data in a portable format.
- Withdraw consent at any time, where consent is the lawful basis.
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk).
To exercise any of these rights — including requesting a copy of your cookie consent log — email us at [email protected].
Global Privacy Control (GPC)
If your browser or extension sends a Global Privacy Control (GPC) signal, we treat that as a binding "reject all" for non-essential processing: no banner is shown, no analytics or marketing cookies are set, and Google AdSense ads are not loaded — including for visitors outside the EEA, UK and Switzerland, who would otherwise see them. This satisfies the opt-out of "sale/sharing" expected under California's CPRA. For analytics, you can still open the Cookie Settings link in the footer to opt back in voluntarily.
Security
We use industry-standard security measures (TLS encryption, hashed passwords with bcrypt, role-based access controls, automated backups, intrusion-protection rules at the CDN edge). No method of transmission is 100% secure; you should also use a strong, unique password.
Children
This service is not directed at children under 13. We collect a date of birth at signup specifically to enforce age-gated features. If you believe a child has provided us with personal data, please contact us so we can delete it.
Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and update the "Last updated" date. If a change is material (new subprocessor, new processing purpose), we will re-prompt you for cookie consent.
Contact
Questions or requests: [email protected].