Privacy Policy
1. Introduction
This Privacy Policy describes how we handle personal information in connection with the "GolScore" service (hereinafter "the Service").
2. Information We Collect and Process
Depending on the features you use, we collect and process the information below. Please exclude other people’s personal information that is unnecessary for processing from images and notes.
| Data | Collection Method | Storage | Purpose |
|---|---|---|---|
| Email address | Google sign-in, email registration or user input | Supabase Auth | Authentication, contact and email delivery |
| Account name | Google sign-in, email registration or user input | Supabase Auth | Display name |
| Scores, course names, notes, goals, club settings and AI results | User input | IndexedDB + Supabase | Service delivery |
| Card and payment information | Stripe | Card data is processed by Stripe (not stored in our database) | Billing |
| Subscription and purchase history, generated reports (PDF) | Payment results and report generation | Supabase (DB / Storage) | Delivering one-time products and re-downloads |
| Push notification token | Service Worker | Supabase | Push notifications |
| Errors, operation context, performance and request logs | Automatic collection | Sentry / Vercel | Error monitoring and service improvement |
| Scorecard and shot-record images | Upload for image recognition | Sent through our server to Google Gemini (images are not saved in our database or Storage) | Reading scores and shot details |
| Location (latitude and longitude) | Weather lookup with location permission | Sent through our server to WeatherAPI.com | Weather autofill and nearby course suggestions |
| Page URLs, interaction events, device/browser information and cookie identifiers; first and last articles read before signup, viewing times and signup start time | Automatic collection | Google Analytics 4 and Vercel. Pre-signup article history is retained in your browser for up to 90 days; signup records are linked to your member ID in Supabase until account deletion | Usage and page performance analysis; counting registrations and current paid members by article. We do not infer cross-device history or past members’ sources |
| Support messages, reply address, delivery preferences and delivery records | Inquiries, email and preference changes | Email services, operator mailbox and Supabase (preferences/delivery records) | Support replies and delivery management |
| Hashed IP/email addresses and submission times | Automatic collection | Supabase | Preventing repeated submissions and abuse |
3. Purpose of Use
- Providing, operating, and improving the Service
- Managing and authenticating user accounts
- Processing payments for paid plans
- Responding to inquiries
- Ensuring service stability (error monitoring)
- Creating anonymized statistical data (such as calculating benchmark metrics, using aggregated data that cannot identify individuals)
- Providing AI analysis, image recognition and weather information
- Sending registration guidance, round summaries and other email or push notifications, and managing opt-outs
4. External Services and Data Transfers
We use the following external services. Transfers occur when you browse pages, sign in, purchase, use features or exchange email, and when we create backups. Links on the service names explain the providers’ data handling practices.
- Stripe — Processes card information, email addresses and customer, purchase and subscription identifiers for payments and billing. Card numbers are entered on Stripe’s pages and are not stored in our database.
- Supabase — Processes registration details, rounds, notes, settings, subscriptions, purchases, PDFs and delivery preferences for authentication, synchronization and storage. Google also processes authentication information when you sign in with Google.
- Sentry — Receives errors, diagnostic codes, URLs, operation/request context and device information for troubleshooting and performance monitoring. Diagnostics may include account identifiers.
- Google Gemini API — Receives information needed for AI analysis or image recognition, such as score statistics, course names, goals, club information, round/hole notes and uploaded images. We use the paid API, whose ordinary inputs and outputs are not used to improve Google’s products. The provider may nevertheless retain them temporarily for abuse prevention and other stated purposes.
- Google Analytics 4 — Receives cookie and similar identifiers, page URLs, interaction events such as registration, recording and purchases, and device/browser information. We use GA4 to analyze service usage.
- Vercel / Speed Insights — Processes IP addresses, request URLs and connection information to host the site and APIs and investigate failures. Speed Insights receives page performance, URLs and device/browser/country information to help improve performance.
- Resend — Processes recipients, reply addresses, subjects, message bodies (including inquiries and round summaries) and delivery results to send email.
- WeatherAPI.com — Receives latitude and longitude rounded to four decimal places from our server during weather lookups. Weather requests do not include your email address or account ID.
- ImprovMX / Google Gmail — ImprovMX and Google Gmail process senders, recipients, subjects, message bodies and attachments to forward, receive and respond to support email.
- GitHub — GitHub Actions retrieves and encrypts user data and authentication-account mapping information for recovery backups. The private decryption key is not stored on GitHub.
These providers and their subprocessors may process or store information outside Japan. Locations vary by service and are not limited to the United States. For example, Gemini inputs and outputs may be temporarily stored or cached in countries where Google or its agents maintain facilities. Please consult the linked provider policies and safeguards. On request, we will explain what we can verify about our use of these services.
5. Storage, Protection and Handling After Deletion
We use HTTPS for transmission and store accounts, rounds and other service data in Supabase. Scores are also stored in your browser’s IndexedDB. Account-linked data is generally retained while you use the account; we delete it from the operational database and delete purchased PDFs when processing your account deletion request.
Daily recovery backups are encrypted and retained on GitHub for 30 days. Data deleted from the service may remain in an earlier backup until its retention period expires. During recovery, we check deletion records to avoid reintroducing deleted accounts. Downloaded recovery copies are discarded after use.
In the app database, support submission tracking records, including anti-abuse hashes but excluding message bodies, become eligible for deletion more than 30 days after submission. Delivery history for welcome and post-round emails becomes eligible more than 180 days after sending. A daily overnight process removes eligible records in limited batches, so backlogs or failures may delay deletion. These periods do not apply uniformly to support messages in inboxes, payment records or other logs.
Payment and billing evidence, support correspondence and deletion records may be retained as needed for legal obligations, refunds, disputes or abuse prevention. We review the need for retention and delete information that is no longer needed. Provider-side retention and deletion also follow the providers’ policies. Aggregates that cannot be linked to individuals may remain.
Signing out from your profile removes scores, draft rounds, course notes, related caches and goal settings stored by this site in that browser. We ask for confirmation when there are potentially unsynchronized records, draft rounds or course notes. Scores already saved in the cloud remain. Account deletion alone does not erase data on each device, and signing out does not remove downloaded files or data in other browsers or devices. Save anything you need before clearing data in each browser or device.
6. User Rights
For access, correction, restriction of use, deletion or account closure, email support@golsco.app from your registered email address and describe your request. We verify identity in a way appropriate to the request, such as confirming a reply from that address. Do not send passwords or authentication codes. Tell us if you no longer have access to your registered address.
After verifying identity, we investigate as needed and respond without undue delay. If more time is needed or part of a request cannot be fulfilled, we explain why and provide an expected timeline. For account deletion, we also check subscription cancellation. Account deletion and subscription cancellation are separate processes.
support@golsco.app7. Cookies, Browser Storage and Your Choices
We primarily use localStorage for login state and preferences, and IndexedDB for scores. GA4 uses cookies and similar technologies to measure views and interactions. We also store the demo start time in localStorage to measure registrations within seven days of starting a demo. Speed Insights and Sentry transmit performance and diagnostic information when you browse. Section 4 lists recipients, data and purposes.
You can restrict or clear cookies and site data in your browser. Clearing site data may remove your login state and unsynchronized records. In supported browsers, Google’s opt-out add-on can disable GA4 measurement; it does not stop transfers to Sentry, Speed Insights or other services. You can deny or revoke location permission and enter weather manually. Email preferences can be changed in your profile or through unsubscribe links in emails.
8. Contact
For inquiries regarding the handling of personal information, please contact us at: Email: support@golsco.app
support@golsco.app9. Policy Changes
We may update this Policy as necessary. Significant changes will be notified through the Service. Updated content takes effect upon posting on this page.