Last updated: March 2026
Privacy Policy
This is our privacy policy in plain English. No legal waffle, just a clear explanation of what data we collect, why we collect it, how we use it, and what rights you have. We have tried to make this as readable as possible while still covering everything UK GDPR requires.
1. Who we are
Golf Match UK is a platform that helps golfers find courses, playing partners, and society days across the UK. We are the data controller for the personal data described in this policy.
2. What data we collect
We only collect what we actually need to run the service. Here is a full breakdown:
| Data type | What it is | Why we collect it | Lawful basis |
|---|---|---|---|
| Account data | Email, name, hashed password | To create and manage your account | Contract |
| Profile data | Postcode, handicap, playing times, bio, photo, phone | To match you with nearby golfers and relevant courses | Contract |
| Scores | Course, date, score, par, notes | To calculate your implied handicap and track progress | Contract |
| Messages | Match conversations between golfers | To facilitate communication between matched golfers | Contract |
| Availability | Dates, times, flexibility preferences | To find you a game when you are free | Contract |
| Contact form data | Name, email, message | To respond to your enquiry | Legitimate interest |
| Analytics | Anonymous page views, web vitals | To understand how the site is used and improve it | Legitimate interest |
| Marketing preferences | Opt-in to marketing emails | To send you updates about features and golf tips | Consent |
Your password is securely hashed via Supabase Auth. We never see or store it in plain text.
3. How we use your data
We use your data to:
- Let you sign in and manage your account
- Show you courses and golfers near you
- Match you with compatible playing partners based on your profile
- Send you notifications about matches, RSVPs, and deals (based on your preferences)
- Calculate and display your implied handicap from logged scores
- Reply to messages you send us through the contact form
- Understand how the site is being used so we can make it better
- Send you marketing emails, but only if you opted in
Things we do not do with your data:
- We do not sell your data to anyone
- We do not use your data for advertising
- We do not track you across other websites
- We do not share your data with data brokers
- We do not store payment information (we do not take payments at this time)
4. Lawful basis for processing
Under UK GDPR, we need a lawful basis for processing your personal data. Here is what applies to each activity:
| Activity | Lawful basis | Explanation |
|---|---|---|
| Account creation and management | Contract | Necessary to provide the service you signed up for |
| Profile and matchmaking | Contract | Core to delivering the matching service |
| Match notifications | Contract | Service delivery: telling you when we find a game |
| RSVP reminders | Contract | Service delivery: reminding you about upcoming events |
| Marketing emails | Consent | Only sent if you opted in. You can withdraw consent at any time via your preference centre |
| Analytics | Legitimate interest | Helps us improve the site. Data is anonymous and aggregated |
| Contact form enquiries | Legitimate interest | So we can respond to your message |
5. Data retention
We do not keep your data longer than we need to. Here are our retention periods:
| Data type | How long we keep it |
|---|---|
| Account data | Duration of your account + 30 days after deletion request |
| Messages | 12 months after last activity in the conversation |
| Scores | Duration of your account |
| Contact form submissions | 6 months after resolution |
| Analytics (raw data) | 90 days, then aggregated and anonymised |
| Inactive accounts | Deleted after 24 months of inactivity (we will warn you at 22 months) |
6. Automated decision-making and profiling
We use an automated matching algorithm to suggest compatible golfers based on your location, ability, availability, and preferences. This profiling helps us deliver the core matching service. No decisions with legal or similarly significant effects are made solely by automated means.
You can adjust what data feeds into matching via your preference centre. You also have the right to request human review of any automated decision by emailing us.
7. Third-party services
We use a small number of third-party services to run the site. We have data processing agreements (DPAs) in place where required.
| Service | What it does | Location | Safeguards |
|---|---|---|---|
| Supabase | Database and authentication | EU region | DPA in place |
| Vercel | Hosting and analytics | US | UK-US Data Bridge certified |
| Resend | Transactional email | US | UK-US Data Bridge certified |
| OpenFreeMap | Map tiles | n/a | No personal data transmitted |
We do not share your data with anyone else. If that ever changes, we will update this policy and let you know.
8. International transfers
Some of our service providers are based in the United States. Where your data is transferred outside the UK, we rely on the UK-US Data Bridge (the UK extension to the EU-US Data Privacy Framework) as the primary safeguard. As a backup, we also have Standard Contractual Clauses (SCCs) in place with these providers. Our primary database is hosted in the EU by Supabase.
9. Cookies and local storage
We keep things minimal here:
| Cookie / storage | Purpose | Type | Consent needed? |
|---|---|---|---|
| Auth session | Keeps you logged in | Strictly necessary | No |
| Cookie consent preference | Remembers your cookie choice | Strictly necessary | No |
| Vercel Analytics | Anonymous site usage | Analytics | Loaded after consent |
We do not use any advertising cookies, social media trackers, or third-party marketing tools.
10. Your rights
Under UK GDPR (Articles 15 to 22), you have the following rights over your personal data:
Right of access (Subject Access Request)
You can request a copy of all the personal data we hold about you. The easiest way is to use the "Download my data" button in your preference centre. You can also email us for a formal SAR.
Right to rectification
You can correct any information that is wrong or out of date. Most of this can be done directly on your profile page.
Right to erasure
You can delete your account and all associated data. Use the "Delete my account" option in your preference centre, or email us.
Right to restrict processing
You can ask us to limit how we use your data in certain circumstances. Email us and we will handle it.
Right to data portability
You can download a machine-readable copy of your data. Use the "Download my data" button in your preference centre to get a JSON export.
Right to object
You can object to processing based on legitimate interest. You can manage your notification preferences in the preference centre, or email us for anything else.
Rights related to automated decision-making
You can request human review of any automated decision. See section 6 above for details of how our matching algorithm works.
How to exercise your rights
For anything you cannot do yourself in-app, email us at hello@golf-match.co.uk. We will respond within one calendar month.
11. Children
Golf Match UK is for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, please contact us and we will remove it immediately.
12. Data security
We take reasonable steps to protect your data. All connections to our site use HTTPS encryption. Passwords are hashed using industry-standard algorithms via Supabase Auth. Access to our database is restricted to authorised systems and personnel. We regularly review our security practices and update them as needed.
No system is 100% secure. If you become aware of any security issue, please let us know immediately at hello@golf-match.co.uk.
13. Changes to this policy
If we make any meaningful changes to this policy, we will update the date at the top of this page. For significant changes that affect how your data is used, we will do our best to let you know directly (for example, by email if you have an account).
14. How to complain
We hope you never need to, but if you are unhappy with how we handle your data you have the right to complain to the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Live chat: ico.org.uk/global/contact-us/live-chat
We would appreciate the chance to sort things out first though. Drop us a line at hello@golf-match.co.uk and we will do our best to resolve it.
15. Contact
For anything privacy-related, or if you just have a question about how we use your data:
Golf Match UK, Kelvedon, Essex, England