Privacy Policy
Last updated: 20 July 2026
This policy explains what personal data SOC.GOLF collects when you or your golf society use our platform (the "Service"), how we use it, who we share it with, how long we keep it, and the rights you have over it.
Contents
1. Who we are
We're the data controller for the personal data described in this policy: we're based in the United Kingdom, and this policy is written around UK data protection law (UK GDPR and the Data Protection Act 2018), which applies regardless of where in the world you or your society's members are based.
2. What data we collect
We collect the following categories of personal data:
- Account data — name, email address and password (handled for us by our authentication provider, Supabase; we never see your password in plain text).
- Society and membership data — which golf societies you belong to, your role (admin or member), and membership status.
- Content you or your society add — events, results, handicaps, competition entries, notices, diary entries, awards, and any photos uploaded (for example a society's hero image or a photo attached to a notice).
- Membership dues records — where a society opts in to tracking dues, who has paid for a given period (payment is handled in person by the society; we don't process dues payments ourselves).
- Billing data — for paid subscriptions, Stripe (our payment processor) holds your card details directly; we hold only what's needed to manage the subscription, such as your Stripe customer/subscription IDs, plan, and billing status.
- Technical data — standard web server logs (e.g. IP address, browser type, timestamps) generated as part of running the Service, and session cookies used to keep you signed in.
- Usage data — aggregate, cookieless analytics (pages viewed, referring site, approximate country and device type) collected via Cloudflare Web Analytics, plus aggregate counts of key events such as sign-ups, which we use to run and improve the Service. This is not linked to your identity.
- Communications — anything you send us via the contact form or by email, and transactional emails we send you (invites, password resets, billing and trial notifications).
3. How we use it
- to create and run your account and your society's use of the Service;
- to process subscription payments and keep billing status accurate;
- to send service emails — invites, password resets, trial reminders, payment notices;
- to respond to support and contact requests;
- to keep the Service secure and prevent abuse or unauthorised access;
- to meet our legal obligations, for example around tax and accounting records for payments.
We don't sell personal data, and we don't send marketing emails today.
4. Our legal basis
For almost everything above, our legal basis is that the processing is necessary to perform our contract with you (running the Service you've signed up to). Where that doesn't quite fit — for example, keeping logs to detect abuse, or handling a support enquiry you've sent us — our basis is legitimate interests, balanced against your rights. Where we're legally required to keep records (for example, billing records for tax purposes), our basis is legal obligation.
5. Who we share data with
We use a small number of service providers ("sub-processors") to run SOC.GOLF. We don't sell or rent your data to anyone; these providers process it only to provide their service to us:
- Supabase — hosts our database, handles user authentication, and stores uploaded images.
- Stripe — processes subscription payments and holds your card details; we never see or store full card numbers.
- Resend — delivers our transactional emails (invites, password resets, notifications).
- Google Fonts — serves the typeface used in the SOC.GOLF app, which means your browser requests it directly from Google when you use the app.
- Google reCAPTCHA — protects our contact form from spam submissions.
- Cloudflare — provides our content-delivery and security layer, and privacy-friendly, cookieless web analytics (aggregate page-view statistics only — no cookies and no cross-site tracking).
We may also disclose data where required by law, to protect our rights, or in connection with a sale or reorganisation of the business (in which case this policy would continue to apply to your data under the new owner).
6. How long we keep data
We keep data for as long as your account or society is active. For trials and closed societies specifically:
- An unconverted free trial that lapses is closed roughly 90 days after its final reminder email, after we've warned you it's happening.
- A closed society (whether it lapsed, was deleted by its admin, or was removed by us) sits in a recycle bin for 90 days, during which it can still be restored, and is then permanently and irreversibly deleted — every record connected to that society, across every part of the Service.
- Billing records may be kept for longer where we're legally required to (for example, for UK tax purposes).
7. Your rights
Under UK GDPR, you have the right to:
- access the personal data we hold about you;
- rectify it if it's inaccurate or incomplete;
- erase it in certain circumstances ("the right to be forgotten");
- restrict or object to certain processing;
- receive a copy of your data in a portable format ("data portability").
To exercise any of these, get in touch via our contact page. Note that a society administrator can also directly manage or remove a member's data within their own society (for example, removing a member).
8. Cookies
The SOC.GOLF app uses a single strictly necessary session cookie to keep you signed in — it doesn't track you across other sites and isn't used for advertising. Our contact form uses Google reCAPTCHA, which sets its own cookies to tell humans from bots. For visitor statistics we use Cloudflare Web Analytics, which is cookieless — it sets no cookies, doesn't track you across sites, and doesn't identify you, so no analytics-consent banner is needed. We don't run any advertising cookies. If we ever adopt cookie-based analytics or advertising, we'll update this section and add a consent option where required.
9. Age requirements
Registering a society and acting as an administrator requires you to be 18 or over. A society's members may be younger — from age 16 — since an administrator invites and manages them. We don't knowingly collect personal data from anyone under 16, and an administrator inviting a member under 18 is responsible for making sure that's appropriate for their society.
10. International transfers
Some of our service providers may process data outside the UK. Where that happens, we rely on appropriate legal safeguards — such as the UK's International Data Transfer Addendum or Standard Contractual Clauses, or the destination country having its own adequacy decision — so your data stays protected to a standard broadly equivalent to UK law.
11. Changes to this policy
We may update this policy from time to time, for example as the Service or our providers change. We'll post the updated version here with a new "last updated" date, and for material changes we'll make reasonable efforts to let existing customers know.
12. Contact and complaints
Questions about this policy, or want to exercise one of your rights above? Get in touch via our contact page. If you're unhappy with how we've handled your data, you also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO).