Privacy Policy
This Privacy Policy explains what information Tee Time Master ("we," "us") collects, how we use and share it, and your choices. It applies to our website and app.
1. Information we collect
- Account info: your email address and a hashed password.
- Course credentials: the login you provide for your own course account, stored encrypted and used only to book on your behalf.
- Payment info: processed by our payment provider (Stripe). We store a payment-method reference (e.g. card brand and last four digits), not your full card number.
- Contact info: phone number, if you enable SMS alerts.
- Usage & booking data: your Watches, matches, bookings, fees, and the fairness "why you won/lost" records.
- Referral & credit data: your referral code, the attribution between referring and referred accounts, conversion status, and credits granted, used, expired, or voided.
- Device, acquisition & log data: IP address, timestamps, basic request logs, campaign tags and advertising click identifiers, landing path, external referrer hostname, website/app surface, and coarse device class. We do not store the full referring or landing URL for acquisition attribution.
2. How we use your information
To provide and operate the Service (monitor and book tee times on your own account), process the per-booking service fee, send you notifications you've enabled, prevent abuse and enforce our fairness and anti-hoard rules, maintain our security and audit trail, administer customer referrals and credits, measure which campaigns lead to registrations and bookings, comply with law, and communicate with you about the Service.
3. How we share it
We do not sell your personal information. We share it only with service providers ("sub-processors") who help us run the Service, under contract and only as needed:
- Stripe: payments.
- Twilio: SMS notifications.
- SendGrid: email notifications.
- PostHog: product analytics (US) to understand how the Service is used.
- Meta: website conversion measurement (advertising pixel).
- Cloud hosting & a booking-egress provider: to run the app and reach course booking systems.
We may also disclose information if required by law or to protect our users, the Service, or a course.
4. Special handling of course credentials
Your course login is encrypted at rest, used only to act on your own account, and never sold or shared for any purpose other than operating the Service for you. Our logs keep only a non-reversible fingerprint of a credential, never the secret, password, or full card number. When you disconnect a course account, the stored credentials are deleted.
5. Data retention
We keep personal information for as long as your account is active or as needed to provide the Service. The first-party acquisition cookie expires after 90 days; the allowlisted acquisition snapshot linked to an account is retained with that account. Referral attribution and credit records are retained with the related account and our audit records. We then delete or de-identify information, except where we must retain records (for example, audit, tax, or dispute-resolution) as permitted or required by law.
6. Your rights & choices
Depending on where you live (including under GDPR and CCPA/CPRA), you may have rights to access, correct, delete, or port your information, and to opt out of certain processing. You can disconnect course accounts and delete your account at any time, and manage email/SMS preferences in your settings. To make a request, contact us (below).
7. Cookies
We use a small number of cookies/local storage that are necessary for the Service (such as keeping you signed in). We also use a 90-day first-party acquisition cookie shared between our website and app, privacy-conscious product analytics (PostHog), and a conversion-measurement pixel (Meta). These help us understand visits, registrations, and booking outcomes; we do not use them to sell your information. You can block these with your browser or an ad-blocker.
8. Security
We use encryption at rest for sensitive credentials, a hash-chained (tamper-evident) audit log, and access controls. No method of storage or transmission is 100% secure, but we work to protect your information.
9. Children
The Service is not directed to children under 18, and we do not knowingly collect their information.
10. Changes
We may update this Policy. We'll post the new version with an updated date and, for material changes, provide reasonable notice.
11. Contact
Privacy questions or requests? Contact us at team@teetimemaster.com.