Privacy Policy

Last updated 2026-09-12
01

1. Introduction

This Privacy Policy describes how we handle personal information in connection with the "GolScore" service (hereinafter "the Service").

02

2. Information We Collect and Process

Depending on the features you use, we collect and process the information below. Please exclude other people’s personal information that is unnecessary for processing from images and notes.

DataCollection MethodStoragePurpose
Email addressGoogle sign-in, email registration or user inputSupabase AuthAuthentication, contact and email delivery
Account nameGoogle sign-in, email registration or user inputSupabase AuthDisplay name
Scores, course names, notes, goals, club settings and AI resultsUser inputIndexedDB + SupabaseService delivery
Card and payment informationStripeCard data is processed by Stripe (not stored in our database)Billing
Subscription and purchase history, generated reports (PDF)Payment results and report generationSupabase (DB / Storage)Delivering one-time products and re-downloads
Push notification tokenService WorkerSupabasePush notifications
Errors, operation context, performance and request logsAutomatic collectionSentry / VercelError monitoring and service improvement
Scorecard and shot-record imagesUpload for image recognitionSent through our server to Google Gemini (images are not saved in our database or Storage)Reading scores and shot details
Location (latitude and longitude)Weather lookup with location permissionSent through our server to WeatherAPI.comWeather autofill and nearby course suggestions
Page URLs, interaction events, device/browser information and cookie identifiers; first and last articles read before signup, viewing times and signup start timeAutomatic collectionGoogle Analytics 4 and Vercel. Pre-signup article history is retained in your browser for up to 90 days; signup records are linked to your member ID in Supabase until account deletionUsage and page performance analysis; counting registrations and current paid members by article. We do not infer cross-device history or past members’ sources
Support messages, reply address, delivery preferences and delivery recordsInquiries, email and preference changesEmail services, operator mailbox and Supabase (preferences/delivery records)Support replies and delivery management
Hashed IP/email addresses and submission timesAutomatic collectionSupabasePreventing repeated submissions and abuse
03

3. Purpose of Use

  1. Providing, operating, and improving the Service
  2. Managing and authenticating user accounts
  3. Processing payments for paid plans
  4. Responding to inquiries
  5. Ensuring service stability (error monitoring)
  6. Creating anonymized statistical data (such as calculating benchmark metrics, using aggregated data that cannot identify individuals)
  7. Providing AI analysis, image recognition and weather information
  8. Sending registration guidance, round summaries and other email or push notifications, and managing opt-outs
04

4. External Services and Data Transfers

We use the following external services. Transfers occur when you browse pages, sign in, purchase, use features or exchange email, and when we create backups. Links on the service names explain the providers’ data handling practices.

  • Stripe — Processes card information, email addresses and customer, purchase and subscription identifiers for payments and billing. Card numbers are entered on Stripe’s pages and are not stored in our database.
  • Supabase — Processes registration details, rounds, notes, settings, subscriptions, purchases, PDFs and delivery preferences for authentication, synchronization and storage. Google also processes authentication information when you sign in with Google.
  • Sentry — Receives errors, diagnostic codes, URLs, operation/request context and device information for troubleshooting and performance monitoring. Diagnostics may include account identifiers.
  • Google Gemini API — Receives information needed for AI analysis or image recognition, such as score statistics, course names, goals, club information, round/hole notes and uploaded images. We use the paid API, whose ordinary inputs and outputs are not used to improve Google’s products. The provider may nevertheless retain them temporarily for abuse prevention and other stated purposes.
  • Google Analytics 4 — Receives cookie and similar identifiers, page URLs, interaction events such as registration, recording and purchases, and device/browser information. We use GA4 to analyze service usage.
  • Vercel / Speed Insights — Processes IP addresses, request URLs and connection information to host the site and APIs and investigate failures. Speed Insights receives page performance, URLs and device/browser/country information to help improve performance.
  • Resend — Processes recipients, reply addresses, subjects, message bodies (including inquiries and round summaries) and delivery results to send email.
  • WeatherAPI.com — Receives latitude and longitude rounded to four decimal places from our server during weather lookups. Weather requests do not include your email address or account ID.
  • ImprovMX / Google Gmail — ImprovMX and Google Gmail process senders, recipients, subjects, message bodies and attachments to forward, receive and respond to support email.
  • GitHub — GitHub Actions retrieves and encrypts user data and authentication-account mapping information for recovery backups. The private decryption key is not stored on GitHub.

These providers and their subprocessors may process or store information outside Japan. Locations vary by service and are not limited to the United States. For example, Gemini inputs and outputs may be temporarily stored or cached in countries where Google or its agents maintain facilities. Please consult the linked provider policies and safeguards. On request, we will explain what we can verify about our use of these services.

05

5. Storage, Protection and Handling After Deletion

We use HTTPS for transmission and store accounts, rounds and other service data in Supabase. Scores are also stored in your browser’s IndexedDB. Account-linked data is generally retained while you use the account; we delete it from the operational database and delete purchased PDFs when processing your account deletion request.

Daily recovery backups are encrypted and retained on GitHub for 30 days. Data deleted from the service may remain in an earlier backup until its retention period expires. During recovery, we check deletion records to avoid reintroducing deleted accounts. Downloaded recovery copies are discarded after use.

In the app database, support submission tracking records, including anti-abuse hashes but excluding message bodies, become eligible for deletion more than 30 days after submission. Delivery history for welcome and post-round emails becomes eligible more than 180 days after sending. A daily overnight process removes eligible records in limited batches, so backlogs or failures may delay deletion. These periods do not apply uniformly to support messages in inboxes, payment records or other logs.

Payment and billing evidence, support correspondence and deletion records may be retained as needed for legal obligations, refunds, disputes or abuse prevention. We review the need for retention and delete information that is no longer needed. Provider-side retention and deletion also follow the providers’ policies. Aggregates that cannot be linked to individuals may remain.

Signing out from your profile removes scores, draft rounds, course notes, related caches and goal settings stored by this site in that browser. We ask for confirmation when there are potentially unsynchronized records, draft rounds or course notes. Scores already saved in the cloud remain. Account deletion alone does not erase data on each device, and signing out does not remove downloaded files or data in other browsers or devices. Save anything you need before clearing data in each browser or device.

06

6. User Rights

For access, correction, restriction of use, deletion or account closure, email support@golsco.app from your registered email address and describe your request. We verify identity in a way appropriate to the request, such as confirming a reply from that address. Do not send passwords or authentication codes. Tell us if you no longer have access to your registered address.

After verifying identity, we investigate as needed and respond without undue delay. If more time is needed or part of a request cannot be fulfilled, we explain why and provide an expected timeline. For account deletion, we also check subscription cancellation. Account deletion and subscription cancellation are separate processes.

support@golsco.app
07

7. Cookies, Browser Storage and Your Choices

We primarily use localStorage for login state and preferences, and IndexedDB for scores. GA4 uses cookies and similar technologies to measure views and interactions. We also store the demo start time in localStorage to measure registrations within seven days of starting a demo. Speed Insights and Sentry transmit performance and diagnostic information when you browse. Section 4 lists recipients, data and purposes.

You can restrict or clear cookies and site data in your browser. Clearing site data may remove your login state and unsynchronized records. In supported browsers, Google’s opt-out add-on can disable GA4 measurement; it does not stop transfers to Sentry, Speed Insights or other services. You can deny or revoke location permission and enter weather manually. Email preferences can be changed in your profile or through unsubscribe links in emails.

About the Google Analytics opt-out add-on

08

8. Contact

For inquiries regarding the handling of personal information, please contact us at: Email: support@golsco.app

support@golsco.app
09

9. Policy Changes

We may update this Policy as necessary. Significant changes will be notified through the Service. Updated content takes effect upon posting on this page.