# Privacy Policy



**Effective date:** [23/04/2026]

**Last updated:** [23/04/2026]



This Privacy Policy explains how Nines Golf ("Nines", "we", "our", or "us") collects, uses, and protects information when you use the Nines mobile application (the "App") and the website at nines-golf.com (the "Site").



If you have any questions about this policy, contact us at **ollie@nines-golf.com**.



## 1. Who we are



Nines Golf is the data controller for personal information processed through the App and Site. We are based in the United Kingdom.



## 2. Information we collect



We only collect information needed to run the Nines golf league. Specifically:



**Account information** (when you sign up):

- Email address

- Password (stored as a secure hash; we never see or store it in plain text)

- Display name



**League and play information** (as you use the App):

- Your golf handicap and internal "Nines Cap" rating

- The season and league you belong to

- Tee-time bookings you make

- Golf rounds you play, including date, course, and hole-by-hole scores (strokes, Stableford points, and hole results such as par, birdie, etc.)

- When you act as scorekeeper for another player, a record linking your account to the rounds you scored

- When another player validates your round, a record of that validation



**Technical information** (automatically, when you use the App or Site):

- Basic device and session information generated by our authentication provider (such as session tokens) to keep you logged in securely

- Standard server logs (IP address, timestamps, request URLs) retained for a short period for security and diagnostics



### What we do NOT collect



- We do **not** collect your location.

- We do **not** access your camera, photos, microphone, or contacts.

- We do **not** collect payment or financial information.

- We do **not** use advertising identifiers or run third-party advertising.

- We do **not** use analytics or tracking SDKs to profile you.



## 3. How we use your information



We use the information above only to:



- Create and manage your account and keep you signed in

- Let you book tee times, record scores, and view league standings

- Calculate your handicap, Stableford points, and Nines Cap

- Show league members (other authenticated users of your league) the scoreboards, schedules, and basic profile details (name, handicap) needed for the league to function

- Maintain the security and integrity of the service

- Communicate with you about the service when necessary (for example, to respond to a support request you send us)



We do not sell your personal information, and we do not share it for cross-context behavioural advertising.



## 4. Legal bases for processing (UK GDPR)



We rely on the following legal bases under the UK GDPR:



- **Contract**: to provide the App and league features you signed up for.

- **Legitimate interests**: to keep the service secure, prevent abuse, and improve the product.

- **Consent**: where you give us consent (for example, for any optional feature we introduce that requires it). You can withdraw consent at any time.



## 5. Who we share information with



We share personal information only with the following categories of service providers, who process it on our behalf under contract:



- **Supabase** (database, authentication, and realtime infrastructure) — [supabase.com/privacy](https://supabase.com/privacy)

- **Expo** (mobile app build, deployment, and over-the-air updates) — [expo.dev/privacy](https://expo.dev/privacy)

- **Framer** (hosting of nines-golf.com) — [framer.com/legal/privacy-policy](https://www.framer.com/legal/privacy-policy)

- **Google Workspace** (our business email) — [policies.google.com/privacy](https://policies.google.com/privacy)



We may also disclose information if required to do so by law, or to protect the rights, property, or safety of Nines, our users, or others.



Other authenticated members of your Nines league will be able to see your display name, handicap, tee-time bookings, and scores within the League — this is how the league itself works.



## 6. International transfers



Our service providers may process data outside the United Kingdom (for example, in the European Union or the United States). Where this happens, transfers are protected by the safeguards required under UK GDPR, such as Standard Contractual Clauses or adequacy decisions.



## 7. How long we keep your information



- **Account and profile data**: kept for as long as your account is active.

- **Rounds and scores**: kept for as long as your account is active, so the league's historical standings remain accurate. You can ask us to remove or anonymise your historical scores (see Section 9).

- **Server logs**: typically retained for up to 30 days.



When you delete your account, we delete or anonymise your personal information within 30 days, except where we are required to retain it by law.



## 8. Security



We use industry-standard measures to protect your information, including:



- Encrypted connections (HTTPS/TLS) for all traffic

- Passwords stored only as secure hashes

- Row-level security policies so each user can only modify their own data

- Access controls limiting who at Nines can view personal information



No system is perfectly secure, but we work to keep your data safe and will notify you of any breach affecting your personal information as required by law.



## 9. Your rights



Under the UK GDPR you have the right to:



- **Access** the personal information we hold about you

- **Correct** inaccurate information

- **Delete** your account and personal information ("right to erasure")

- **Restrict** or **object** to certain processing

- **Port** your information to another service

- **Withdraw consent** at any time, where processing is based on consent

- **Complain** to the UK Information Commissioner's Office (ICO) at [ico.org.uk](https://ico.org.uk)



To exercise any of these rights, email **ollie@nines-golf.com**. We aim to respond within 30 days.



## 10. Children



Nines is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us and we will delete it.



## 11. Changes to this policy



We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. If the changes are significant, we'll let you know in the App or by email.



## 12. Contact



Questions, requests, or complaints about this policy or your personal information:



**Email:** ollie@nines-golf.com

**Website:** https://nines-golf.com