Legal

Privacy Policy

How Golf Passport handles personal data when you use the Android app or this website.

Effective: 16 August 2026 · Last updated: 16 August 2026

1. Who is responsible for your data?

Golf Passport is developed and operated by Hampus Andersson in Sweden. For applicable data-protection law, including the EU General Data Protection Regulation (GDPR), Hampus Andersson is the controller of personal data processed directly for Golf Passport.

Privacy questions can be sent to hampusandersson.dev@gmail.com.

Short version: Golf Passport uses account data to provide your account, stores the golf-course activity you choose to save, and can use device location to find nearby courses. The app does not currently include advertising or an advertising SDK.

2. What data does Golf Passport process?

Account and profile data

Email address, authentication identifiers, display name, preferred language and, where you choose or an identity provider supplies it, profile/avatar information.

Golf activity you save

Courses marked as played, played dates, course ratings and optional rating notes or similar information you submit in the app.

Location

Coarse or precise device location when you grant location permission and use location-based course discovery. Location is used to identify courses near you; it is not used by Golf Passport for advertising.

Authentication provider data

If you choose Google Sign-In, Google and the authentication service exchange the information needed to authenticate you, such as provider identifiers and basic account information permitted by the sign-in flow.

Technical service data

Infrastructure providers may process ordinary technical information such as IP addresses, timestamps, request metadata and security logs as necessary to host, secure and deliver the app backend or website.

3. Why is this data used?

Golf Passport processes data to:

  • create, authenticate and maintain your Golf Passport account;
  • store and retrieve your profile and personal golf-course history;
  • save ratings and notes you choose to create;
  • show nearby courses when you request location-based discovery;
  • maintain course-rating aggregates and core app functionality;
  • prevent abuse, troubleshoot problems and keep the service secure; and
  • respond to support, privacy and account-deletion requests.

Depending on the processing involved, the legal basis may be the performance of the service you request, legitimate interests in operating and securing Golf Passport, compliance with legal obligations, or your consent where consent is required. Device location is only accessed after the relevant device permission is granted.

4. What is visible to other people?

The golf-course catalogue and aggregate course statistics are intended to be broadly available. Individual course-visit records, individual rating records and rating notes are designed as user-specific account data.

Certain profile information, such as a display name or avatar, may be available to other signed-in Golf Passport users where current or future social/profile features expose it. Do not put sensitive personal information in your display name, rating notes or other free-text fields.

5. Service providers and data sharing

Golf Passport does not sell your personal data. Personal data may be processed by service providers needed to run the app:

  • Supabase — authentication, database and backend infrastructure used by Golf Passport.
  • Google — only where you choose Google Sign-In or otherwise interact with a Google service used for authentication.
  • Cloudflare — hosting, delivery and security for this public Golf Passport website.

Data may also be disclosed where required by law, to protect users or the service, or as part of a legitimate business reorganisation where the recipient remains bound by applicable data-protection obligations.

6. International processing

Some service providers may process data outside Sweden or the European Economic Area. Where applicable, Golf Passport relies on the safeguards made available by those providers and required by applicable data-protection law.

7. Data retention

Account-linked data is generally retained while your Golf Passport account remains active and for as long as reasonably necessary to provide the service, resolve security or support issues, and meet legal obligations. When an account is deleted, associated user data is deleted or scheduled for deletion unless limited retention is legally required. Residual copies may remain temporarily in protected backups according to infrastructure-provider backup cycles.

8. Account and data deletion

You can request deletion of your Golf Passport account and its associated user data through the account deletion page. Where an in-app deletion control is available, you can also initiate deletion there.

Deleting your Golf Passport account does not delete an external Google account or other third-party identity-provider account.

9. Your rights

If GDPR or similar law applies to you, you may have rights to access, correct, delete or restrict processing of your personal data, object to certain processing, receive certain data in a portable format, and withdraw consent where processing relies on consent.

To exercise a privacy right, contact hampusandersson.dev@gmail.com. We may need to verify that the request relates to your account before acting on it. You may also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.

10. Children

Golf Passport is a general golf utility and is not designed specifically for children. If you believe a child has provided personal data in circumstances where consent or another legal basis is required, contact us so the matter can be reviewed.

11. Website privacy

This website does not intentionally use advertising cookies or a first-party analytics system. Its hosting and security infrastructure may still process standard request information needed to deliver and protect the site.

12. Security

Golf Passport uses reasonable technical and organisational measures intended to protect personal data, including authenticated access controls and backend row-level access policies for user-linked records. No system can guarantee absolute security.

13. Changes to this policy

This policy may be updated when Golf Passport features, service providers or legal requirements change. The current version will remain available at this URL and the “Last updated” date will be revised when material changes are made.

14. Contact

Golf Passport / Hampus Andersson
Sweden
Email: hampusandersson.dev@gmail.com