Privacy Policy
Effective date: April 27, 2026
This Privacy Policy explains what information GolfGames ("we", "us", "the app") collects, how we use it, who we share it with, and the choices you have. We've tried to write it in plain language. If anything here is unclear, email support@golfgames.gg.
1. Who we are
GolfGames is a mobile app for tracking golf rounds, handicaps, and friendly competition. The app is operated by the publisher listed in the App Store and Google Play listing for "GolfGames". Throughout this policy, "you" means the person using the app.
2. Information we collect
2.1 Information you give us
- Account information. When you sign up, we collect your email address and display name. If you sign in with Google or Apple, we receive your email and the name you've shared with that provider.
- Profile. An optional username, avatar URL, and any profile fields you choose to fill in.
- Round data. Scores you enter, the courses and tees you play, the players in your round, and statistics derived from those scores (handicap, fairway/green hits, putts, etc.).
- Social activity. Friend connections, friend requests, and activity feed entries you generate (for example, completing a round).
- Support correspondence. If you email us, we keep the message and our reply.
2.2 Information collected automatically
- Authentication tokens. Stored on your device in the operating system's secure storage so you stay signed in.
- Push notification token. If you grant notification permission, we store an Expo push token tied to your account so we can deliver friend, round, and achievement notifications.
- Sync metadata. Timestamps that tell us when your scores were last synced from your device to our servers.
- Crash and error logs. If the app crashes or hits an error, we may collect diagnostic information (operating system version, app version, the type of error). At launch, this is logged locally only and not sent to a third-party service. If we add a crash-reporting provider in the future, we'll update this policy before turning it on.
2.3 Information we do not collect
- We don't collect your precise location. The only "location" data in the app is the courses you choose to play, which you select yourself.
- We don't use third-party advertising, ad networks, or advertising identifiers (IDFA / Android Advertising ID).
- We don't see or store your payment card details — purchases are processed entirely by Apple and Google.
- We don't sell your personal information to anyone, ever.
3. How we use your information
- To run the app. Authenticate you, save your rounds, calculate your handicap, show your friends' activity, and sync data between your devices.
- To send notifications you've opted into. Friend requests, round invitations, achievements, and other in-app events. You can disable these any time in your device settings or in Settings → Notifications.
- To provide support. Diagnose problems and respond to your questions.
- To keep the service safe. Detect abuse, enforce our Terms, and respond to legal requests.
- To improve the app. Understand which features are useful — using your data only in aggregate, never to single you out.
4. Who we share information with
We share data only with the providers that make the app work, and only what each provider needs:
- Supabase — our database, authentication, and real-time provider. Your account, profile, rounds, and friendships are stored in a Supabase-managed PostgreSQL database.
- Apple Sign In and Google OAuth — used only when you choose to sign in with Apple or Google. They tell us your email and the name you've consented to share; we don't get your password.
- Apple App Store and Google Play — process all subscription purchases. We never see your card or bank details.
- RevenueCat — manages subscription entitlements (whether you have an active Pro plan). We send RevenueCat your account ID and the platform receipt; RevenueCat tells us if your subscription is active.
- Resend — sends transactional emails such as signup confirmation and password reset, on our behalf.
- Expo — delivers push notifications via the Expo push service, which forwards to Apple's APNs and Google's FCM.
We may also disclose information if we're legally required to (subpoena, court order, lawful government request) or to protect the rights, property, or safety of our users or the public. If we ever sell or transfer the business, your information may transfer with it; we'll notify you before that happens.
Other GolfGames users see only the information you've made available to them: your username and display name when they search for you, your profile and round history if you're friends, and your live round scores if you've added them to a round in progress. They never see your email address.
5. How long we keep your information
- Account and rounds. Until you delete your account, plus a short window for backups.
- Friend activity. Until you or the friend deletes the underlying round or unfriends.
- Live ("active") rounds. Removed automatically when the round ends.
- Support emails. Up to 2 years after the conversation ends.
- Crash logs. Up to 90 days.
6. How we protect your information
Data is encrypted in transit using TLS. Data at rest in Supabase is encrypted using industry-standard methods. Authentication tokens on your device are stored using Apple Keychain (iOS) or Android Keystore. We use Row Level Security policies in our database so that one user's data is not accessible to another user except where you've explicitly enabled it (for example, by becoming friends).
No system is perfectly secure. If we ever discover a breach affecting your information, we'll notify you and any required regulators in line with applicable law.
7. Your rights and choices
Depending on where you live, you may have some or all of the following rights:
- Access — get a copy of the personal data we hold about you.
- Correction — fix anything inaccurate. Most fields you can edit yourself in Settings → Edit Profile.
- Deletion — delete your account and the data tied to it.
- Portability — receive your data in a machine-readable format.
- Objection / restriction — ask us to stop or limit certain uses.
- Withdraw consent — for any processing that relies on your consent (for example, push notifications).
To exercise any of these, email support@golfgames.gg from the address on your account, or use the in-app delete-account option once available. We respond within 30 days.
If you're in the EEA, the UK, or Switzerland, our legal basis for processing your data is one or more of: performance of our contract with you (running the app), our legitimate interests (improving the service, preventing abuse), your consent (notifications), or legal obligation (responding to lawful requests). You also have the right to lodge a complaint with your local data protection authority.
If you're a California resident, you have rights under the CCPA / CPRA including access, deletion, correction, and the right to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising.
8. Children's privacy
GolfGames is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, please email us and we'll delete it.
9. International transfers
Our infrastructure is hosted primarily in the United States. If you use the app from outside the U.S., your information will be transferred to and processed in the U.S. We rely on Standard Contractual Clauses (where required) and similar safeguards for transfers from the EEA, UK, and Switzerland.
10. Changes to this policy
We'll update the "Effective date" at the top whenever we change this policy. For material changes, we'll notify you in-app or by email before the change takes effect.
11. How to reach us
Questions, requests, or concerns: support@golfgames.gg.