The short version
- We collect what the app needs to work: how you sign in, your profile, what you post, and who you play with.
- We don't sell your information, and we don't run ads or advertising trackers.
- Your location during a round is never saved today. It's relayed live to the people in your group and then it's gone — there's no database row to delete, because one is never written. Some features we're building would need to keep a rough position, and section 2 sets out exactly what we'll do and tell you if that happens.
- If you look for friends by contacts, we never see your contacts. Your device turns each one into a scrambled code first, and the codes aren't kept after the search.
- Your email and phone number are hidden by default — not hidden-if-you-find-the-setting. You choose to reveal them.
- Photos are re-encoded when you upload them, which strips out the hidden location and camera data most phones bury in an image file.
- You can get your account and data deleted by asking us. Here's how.
1. Who we are, and what this covers
GolfBook is made and run by WhiteHat Software Inc., a company based in British Columbia, Canada. In this policy, "we" and "GolfBook" mean WhiteHat Software, and "you" means someone using GolfBook as a player.
This policy covers the GolfBook player app and this website, golfbook.ca. It does not cover the separate tools we build for golf facilities and their staff, and it does not cover the golf course you happen to be playing — a course has its own privacy practices for its own bookings, tee sheet and point of sale.
Our privacy officer is Shaun Benzies. You can reach him, or anyone else on the team who handles this, at legal@golfbook.ca.
2. What we collect, and why
Signing in
You can sign in two ways, and each one tells us something slightly different.
- A code by email or text. You give us an email address or a mobile number, we send a six-digit code, you type it back. We store the address or number, and we store a scrambled (hashed) copy of the code — not the code itself — with a short expiry and a limit on how many guesses it accepts. Codes are single-use.
- Google, Apple, Microsoft or Facebook. The provider tells us your email address, your name, a picture if you have one, and the account ID they use for you. We keep those. We never receive your password for that account, and we don't get access to your posts, photos, or anything else on it.
An email address and password also works, if you'd rather. We store passwords scrambled, never as text we could read.
Staying signed in works with a session that renews for as long as you keep using the app, up to thirty days of inactivity.
Your profile
Your name, your profile photo, your handicap and your home course, if you fill those in. There's also a longer set of optional details — where you're based, your favourite local courses, your bucket-list courses, a favourite quote, a favourite movie. All optional, all blank until you write something in them.
We also ask for your date of birth, once, so we know whether the account belongs to an adult or a minor — see section 7. We never show your date of birth back to anyone, including you; the app only ever passes around "adult" or "minor," never the date.
Every one of those details is set to hidden the moment your account is created — your email address, your phone number, and each of the optional profile fields. Not hidden after you go and find a setting: hidden as the starting position, written into the account in the same instant the account itself is created. Each one is separate, so you might show your bucket-list courses publicly and keep your location hidden. For each, you choose: everyone, your friends, one particular person, or no one.
If you're a touring professional
GolfBook keeps a reference database of professional players and their tournament results, built from public sources. If you're one of those players, we can link your GolfBook account to your professional record so it's marked as genuinely yours. What that database holds about professional golfers — including those who have no GolfBook account at all — has its own page.
That link is only ever made by our staff, after checking two independent things — that you control a social account the tour's own player directory links to, and a reply from an email address on the tour's or your agency's domain. We record who made the link, when, and a short written note of what was checked. We don't ask for or keep identity documents. There's no self-service way to claim a professional record, precisely because a wrongly-verified account is a bigger problem than a slow one. The link doesn't change who can see anything on your account — your visibility settings still decide that, exactly as before.
Finding people you know
Contact-based friend-finding is optional, and it's built so that we never receive your address book.
Instead of sending us contacts, your device converts each email address and phone number into a fixed-length scrambled code and sends only the codes. We compare them against the same kind of code computed from our own users' details, and tell you which of your contacts are already on GolfBook. The codes you send aren't written to any table, aren't logged, and are gone when the request finishes. There's a hard cap on how many can be checked at once and a rate limit on how often, so the feature can't be turned into a bulk "is this number registered?" lookup.
If you connect Google Contacts instead of using your device's address book, we ask Google only for email addresses and phone numbers — not names, not anything else — scramble them the same way the moment they arrive, run the same comparison, and keep neither the contacts nor the access token afterwards. If you connect Facebook, we ask only for the list of your Facebook friends who also use GolfBook, which is all Facebook will give an app anyway, and match those against people who signed in here with Facebook.
Anyone whose details are set to fully hidden is left out of these results entirely — you won't even be told that someone matched. That's deliberate: telling you "one of your contacts is on GolfBook but won't say who" would leak the exact fact their setting is meant to keep private.
What you post
Chat messages, feed posts, comments, reactions, photos, scores and round results. Who you're friends with, who you've blocked, and who you've muted.
Feed posts go to your friends by default. You can choose to make one public, which means any active GolfBook account can see it. Minors' posts can't be made public at all — the app refuses the request rather than quietly downgrading it.
Chat is not end-to-end encrypted. Messages are stored in our database in a form our systems can read, which means our staff technically can too. We don't read messages as a matter of routine, and we access message content only to look into a complaint about harassment or abuse, to enforce our Terms, or where the law requires it.
Photos and videos
Images you upload are decoded and fully re-encoded on our servers before they're stored. That's a security measure, and it has a privacy side effect worth stating plainly: re-encoding throws away everything that isn't picture data — including the GPS coordinates, camera serial number, and timestamps that phones commonly embed in a photo file. Those never make it into storage, so they can't be handed on to whoever views the picture.
GolfBook has no face detection and no face tagging. We don't scan photos for people, we don't build face templates, and we don't store anything of that kind. If that ever changes, this policy will say so before it ships.
Where you are during a round
Read this one carefully, because it's the part most apps get wrong.
GolfBook has exactly one location feature today: a live map inside a booking lobby, showing where the people in your group are while you play. It is off until you turn it on, it asks again every round, and there's a "stop sharing" control on screen the whole time it's running.
In that feature, your position is never written down. It doesn't go into a database, it isn't cached on the server, and it isn't written to our logs. Each reading is relayed live over the same short-lived channel that carries "someone is typing," and then it's gone. Only people in your lobby who have also turned sharing on can see your pin. Pins vanish from the map about a minute after your last update, and immediately if you stop sharing, leave the lobby, close the tab, or the round ends.
Because nothing is stored, there is no trail, no replay, and no history of where you've been — not for you, not for the course, and not for us. There's nothing to hand over, because there's nothing there. That is true of everything GolfBook does today, and we'd rather tell you precisely that than promise it forever.
We are working on features that would need location differently — showing players on a tournament map, getting a food and drink order to the right place on the course, and making our own course maps more accurate. Some of those would mean keeping location data rather than relaying it and forgetting it. So that you have something specific to hold us to, rather than a promise we'd end up breaking, here is what we're committing to for when that day comes:
- Approximate, not precise. Anything kept would be coarse — which hole you're on, or roughly where on it — not a metre-by-metre record of the walk you took.
- For the feature you turned on, and nothing else. Kept location would be used to make that feature work and to improve course maps. Never to advertise to you, never to build a profile of you, and never sold.
- Asked for separately, and stoppable. Each such feature would ask for location on its own, and turning it off would stop it, without taking the rest of the app with it.
- Said out loud before it ships, not after. We'll change this page, and tell you in the app, before any GolfBook feature starts keeping location data. While this section still reads as it does above, nothing is being kept.
Precise, continuous tracking of where you walked is not something we have decided to do. If that ever changes, it will get its own announcement and its own explanation here — not a quiet re-reading of the list above.
Some map imagery is drawn from OpenStreetMap's public tile servers. Your browser fetches those images directly, which means OpenStreetMap can see your IP address and roughly which part of the map you're looking at — the same as any website that shows a map. We don't send them your position.
Paying
Where paying through GolfBook is available, your card details never reach our servers. They go straight to Stripe, our payment processor. We keep the customer reference Stripe gives us, a note of which saved card you'd like pre-selected, and ordinary transaction records — amount, date, status. We never see or store a full card number.
If you order food or drink through GolfBook while you're playing, we keep the order — what you asked for, when, and at which course — and pass it to the facility that's making it. Ordering is only available at the course you have a confirmed booking at today.
Notifications
If you turn on push notifications, we store the token your device's push service issues, so we know where to send them. You can turn notifications off in the app or in your device settings.
Technical and security records
Ordinary server logs, plus a record of administrative actions taken on accounts — who did what, to which account, when, and from which IP address and browser. This is what lets us answer "who changed this" if something goes wrong, and it's a record we keep about our own staff as much as about you.
3. Why we're allowed to collect it
Canadian privacy law works on consent and on what a reasonable person would consider appropriate. In practice, that splits into two groups:
- Things the app can't work without — your sign-in details, your profile, what you post, who you play with. By creating an account and using GolfBook you're consenting to these, and if you withdraw that consent the answer is to close the account.
- Everything optional — sharing your location during a round, finding friends from your contacts, push notifications, saving a card. Each is off until you switch it on, each asks separately, and each can be switched off again without affecting the rest of the app.
We don't use your information to profile you for advertising, and we don't make automated decisions about you that have a legal or similarly significant effect.
4. Who else is involved
We don't sell personal information and we don't share it with advertisers. We do use other companies to run parts of the service. Here's the complete list, what each one gets, and why.
| Who | What they get | Why |
|---|---|---|
| Amazon Web Services | Everything the app stores, because it's stored on their infrastructure | Hosting — servers, databases, backups |
| Twilio | Your mobile number and the message text | Sending sign-in codes and invitations by text |
| Resend | Your email address and the message text | Sending sign-in codes, verification and guardian-consent emails |
| Google, Apple, Microsoft, Facebook | The fact that you're signing in to GolfBook, if you use their button | Sign-in. We receive your name, email and account ID from them; they receive nothing about your GolfBook activity |
| Google Contacts / Facebook | Only if you connect them: contact emails and numbers, or your list of mutual friends | Optional friend-finding (section 2). Contacts are scrambled on arrival and not retained |
| Stripe | Your card details and payment amounts, directly from you | Processing payments, so that we never handle card numbers |
| Firebase Cloud Messaging (Google) | Your device's push token and the notification text | Delivering push notifications, if you've enabled them |
| OpenStreetMap | Your IP address and which part of the map you're viewing | Map images. Requested by your browser, not by us |
| Pro-golf data sources | Nothing about you | Professional tour scores, schedules and world rankings, read from public feeds (ESPN and the world ranking bodies). Information flows one way, towards us — nothing about you is ever sent to them |
Beyond that list, we'll disclose information if the law requires it — a court order, a valid demand from law enforcement, a regulator — or where it's necessary to protect someone's safety.
5. Where your information is stored
GolfBook runs on Amazon Web Services in Oregon, in the United States. That means your information is stored and processed outside Canada, and while it's there it can be reached by US authorities under US law, through US legal processes that don't involve a Canadian court.
We don't currently run any infrastructure in Canada. We're telling you this plainly because Canadian privacy regulators expect you to be able to take it into account when deciding whether to use a service.
6. How long we keep it
While your account is open, we keep what section 2 describes, because that's what makes the app work.
We'd rather be straight with you than impressive here: most of what we hold does not yet have an automatic clean-up schedule. Deletion happens when you ask for it, and it's done by a person. The deletion page explains exactly what that involves and how long it takes.
One category is the exception: on-course station chat (the messages you exchange with facility staff during a round) is automatically archived after 7 days and permanently deleted after 90. As more categories move to a real automatic schedule, this section will say so and give the timescales.
Three things are worth calling out:
- Location during a round is not retained at all today, so it isn't subject to any of this. If a future feature keeps a rough position, section 2 explains what we've committed to first.
- Payment and tax records have to be kept for six years after the relevant tax year. That's a legal requirement, not our choice, and it survives account deletion.
- Things you shared with other people — a message in someone's inbox, a round you played in a foursome — are part of their record too. We remove your name and profile from what remains rather than deleting other people's history along with yours.
7. Accounts for people under 18
You have to be at least 13 to have a GolfBook account. If someone tells us they're younger than that during sign-up, the account isn't created — the partly-made record is deleted then and there, not kept in a rejected pile.
Between 13 and 17, an account exists but can't do anything until a parent or guardian approves it. We ask for a guardian's email address, send them a single-use link that expires, and until they use it the account can't chat, post, book, pay, or share location. We keep a record that consent was given, by which email address, and when, because that's the evidence that it happened.
For accounts we know belong to a minor:
- Location sharing is off and stays off — a minor can't turn it on. The app re-checks age status every time the map screen opens rather than trusting a stale copy, and blocks sharing if the check fails or hasn't finished.
- Posts are limited to friends. Public posting is refused outright.
- The profile picture is removed from what other players are shown, and the optional profile details in section 2 start hidden, as they do for everyone.
A guardian can withdraw consent at any time by emailing legal@golfbook.ca, which suspends the account. If you believe a GolfBook account belongs to someone under 13, or to a 13-to-17-year-old whose guardian never agreed to it, tell us at the same address and we'll investigate and remove it.
8. How we protect it
The measures we can point at concretely:
- Traffic between your device and GolfBook is encrypted in transit, and the disks our servers and databases sit on are encrypted at rest.
- Sign-in codes are stored scrambled, expire quickly, are single-use, and lock out after a few wrong guesses.
- Card numbers never touch our systems.
- Uploads are checked by inspecting the file itself rather than trusting what it claims to be, capped in size and dimensions, and re-encoded — which is also what strips the embedded location data.
- Sign-in, password-reset, code-request and friend-finding endpoints are rate-limited.
- Administrative actions on accounts are recorded in an audit log.
None of that adds up to a guarantee. No service can promise it will never be breached, and we won't pretend otherwise. If a breach ever happens that creates a real risk of significant harm to you, we'll tell you and the relevant regulator.
9. Your choices and your rights
Under Canadian privacy law you can ask us to:
- Show you what personal information we hold about you.
- Correct anything that's wrong.
- Delete your account and the personal information attached to it — see the deletion page.
- Send you a copy of your data in a portable form.
- Withdraw consent for anything optional, at any time — turn off location sharing, disconnect contacts, turn off notifications, remove a saved card.
- Complain, to us first at legal@golfbook.ca, and to the Office of the Privacy Commissioner of Canada if we don't resolve it.
Email legal@golfbook.ca from the address on your account, or tell us the phone number you sign in with, and we'll take it from there. There's no charge for a reasonable request, and we'll respond within 30 days.
A note on where you live: GolfBook is a Canadian service, and this policy is written to Canadian law — PIPEDA nationally and British Columbia's PIPA locally. If you're in Quebec, Law 25 gives you some additional rights and we'll honour them. We don't currently offer GolfBook in the European Union or the United Kingdom, and we don't claim to comply with the GDPR; if that changes, we'll update this policy first.
10. Changes to this policy
We'll update this page when the product changes. If a change matters to you — new kinds of information, a new company involved, a new use for what we already have — we'll tell you in the app or by email before it takes effect, rather than quietly editing the page and hoping you re-read it.
11. Who to contact
Anything about this policy, your data, or a request: legal@golfbook.ca. A real person reads it.