Privacy policy
Last updated: 11 September 2026
1. Controller
The controller for the processing of personal data in connection with golfpal is Appitized GmbH, Wilhelmstr. 74, 38100 Braunschweig, Germany, represented by its Managing Director Pawel Artur Sas.
For data protection questions you can reach us at mail@golfpal.app.
We have not appointed a data protection officer, as the statutory conditions for doing so do not currently apply.
2. The roles of golfpal and the venues
golfpal is a platform through which operators of golf and leisure facilities („venues“) make their offerings bookable. We are the controller for providing and operating the platform.
Where a venue processes personal data in its own dashboard, for example managing its guests' bookings or sending promotions, we act as a processor on that venue's behalf. The venue is the controller for delivering the booked service on site.
3. What data we process
Account data: email address, name and, where provided, telephone number, plus the link to a venue if you work there as a member of staff.
Booking data: the resource booked, date and time, price, add-ons booked, booking notes, entries to tournaments and events, memberships, and vouchers bought and redeemed.
Payment data: amount, currency, payment status, payment method and our payment provider's references. Full card details never reach our systems; they are entered at and processed solely by the payment provider.
Communication data: messages you exchange with a venue through the chat, and emails you send us.
Technical data: IP address, time of access, address requested, volume of data transferred, and browser and operating system details. Technical error reports may also be generated when something fails.
4. Purposes and legal bases
We process your data to perform the usage agreement and to handle bookings and payments, including confirmations, reminders and cancellations, on the basis of Art. 6 (1) (b) GDPR.
We process data to meet legal obligations, in particular commercial and tax retention duties, on the basis of Art. 6 (1) (c) GDPR.
We process data for the security and stability of the platform, to prevent abuse and fraud, and for error analysis and further development, on the basis of our legitimate interest under Art. 6 (1) (f) GDPR.
We send notifications about a venue's promotions and offers only on the basis of your consent under Art. 6 (1) (a) GDPR. You can withdraw that consent at any time with effect for the future, at no disadvantage to you.
5. Signing in with a one-time code
To sign in to the booking area we send a one-time code to your email address. The code is stored only for as long as it is valid and is then rendered unusable. It is delivered through our email service provider.
6. Recipients and processors
Supabase, Inc., USA, provides the database, authentication and file storage. The data is held in the Frankfurt am Main data centre (region eu-central-1). A data processing agreement is in place.
Vercel Inc., USA, hosts and serves the web application. A data processing agreement is in place.
Stripe Payments Europe, Limited, Dublin, Ireland, handles payments. Stripe is an independent controller for payment processing and processes the data required for it under its own privacy terms.
Postmark, a service of ActiveCampaign, LLC, USA, sends our transactional emails such as booking confirmations and sign-in codes.
Sentry, Functional Software, Inc., USA, receives technical error reports. The service is only used where it is configured for the environment in question.
The venue you book with receives the data needed to deliver the booking, in particular your name, contact details and the booking details.
We do not pass your data on beyond this unless we are legally obliged to.
7. Transfers to third countries
Some of the providers listed above are based in the United States. Where personal data is transferred to a third country, we base the transfer on the European Commission's standard contractual clauses or on the provider's certification under the EU-US Data Privacy Framework.
8. Retention
We keep account data for as long as your account exists. After the account is deleted we remove the data unless a statutory retention duty prevents it.
Booking and payment data is subject to commercial and tax retention periods of up to ten years.
We delete technical error reports after 90 days at the latest. Sign-in codes expire within minutes.
9. Cookies and local storage
We use strictly necessary cookies only: one set to sign you in and keep your session alive, and one to remember your language choice.
We use no tracking, no advertising cookies and no third-party audience measurement. Consent under § 25 (1) TDDDG is therefore not required.
10. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).
You also have the right to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21 GDPR).
A message to mail@golfpal.app is enough to exercise any of these rights.
11. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Lower Saxony Data Protection Commissioner, Prinzenstraße 5, 30159 Hannover, Germany.
12. Changes to this privacy policy
We update this privacy policy when the platform or the legal situation changes. The version published on this page is the one that applies.