This Privacy Policy explains what information Mini Golf Scorecards (“we”, “us”) collects, how we use it, and the choices you have. It applies to both venue admins and players who use the Service.
1. Information we collect
From venue admins: business name, contact email, billing email, address, phone, payment information (handled by Stripe), logo and brand assets, and configuration data such as courses and hole pars.
From players: game scorecards (player names, strokes, totals), optional email if a player wants their scorecard emailed or wants to look up past games, optional ratings, hole feedback, and review text. We also collect technical data including IP address, device type, and approximate location for bot protection and security. If you scan a QR code at a venue, we record the scan and the code identifier.
Cookies and similar technologies: we use cookies for authentication (venue admin sessions), bot protection (signed cookies that mark a player as having scanned a real venue QR), and to remember your verification when looking up past games. We do not use third-party advertising cookies.
2. How we use information
- To provide the Service: render scorecards, sync scores across players, deliver emails, and bill venues.
- To prevent abuse: GPS, QR-cookie, and puzzle challenges keep automated traffic from creating fake games.
- To improve the product: aggregate analytics about feature use, performance, and reliability.
- To communicate: transactional emails, billing notices, and important policy updates.
3. How information is shared
With venues, about their players: when a player enters an email at one of your courses, that email is made available to that venue along with consent flags and game history. It is shared only with the venue the player visited — not across venues.
With service providers: Stripe (payments), email/SMS delivery providers, hosting infrastructure, and Google (for the optional review-prompt link). These providers process data on our behalf and are bound by confidentiality and security obligations.
For legal reasons: we may disclose information when required by law, court order, or to protect rights, property, or safety.
We do not sell your personal information.
4. Data retention
Venue account data is retained while the account is active. After cancellation we retain data for 90 days to allow recovery, then delete or anonymize it. Game scorecards may be retained longer in de-identified form for analytics and product development. Billing records are retained for as long as required by tax and accounting law.
5. Your choices and rights
- Access and correction: venue admins can view and update their data from the dashboard. Players can email us to request access or deletion of their data.
- Email preferences: scorecard delivery is opt-in per game. Marketing emails sent by venues honor unsubscribe links.
- EU/UK users (GDPR): you have the right to access, correct, delete, port, and object to processing of your personal data. Our legal basis is contract performance for venue admins and legitimate interest / consent for players.
- California users (CCPA/CPRA): you may request disclosure of categories of personal information collected, request deletion, and opt out of any “sale” or “sharing” (we do not engage in either).
To exercise any right, email [email protected].
6. Security
We use industry-standard practices to protect data in transit (TLS) and at rest (encrypted database storage), apply role-based access controls internally, and review security periodically. No system is perfect — please report vulnerabilities to [email protected].
7. Children’s privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from children. If a parent or guardian believes their child has provided personal data, contact us and we will delete it.
8. International transfers
We are based in the United States. If you access the Service from outside the US, your information may be transferred to and processed in the US, where data-protection laws may differ from your country.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to venue admins or via the dashboard. The “Last updated” date above reflects the most recent revision.
10. Contact
Questions or requests about this policy? Email [email protected].