Privacy Policy
Effective 14 July 2026 · Version 1.0
Golfio F&B (“Golfio”, “we”, “us”) is a tee-sheet-driven Food & Beverage operations service for golf clubs, available at golfiofb.com. It is operated by Conor Mac Aogain, a sole trader established in Ireland, trading as Golfio F&B. Contact: conor@golfiofb.com.
This policy explains what personal data we handle, why, where it is stored, and the rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection (FADP), whichever applies to you.
1. Data we collect
Account data (Golfio as controller)
- Email address and password (stored as a salted hash by our auth provider — we never see or store the plain password).
- Club name you choose at signup.
- Subscription and billing status. Card details are collected and stored by Stripe, never by us — we hold only a customer reference and subscription state.
- Basic technical logs (IP address, request metadata) kept for security and rate-limiting.
Club operational data (Golfio as processor for the club)
- Uploaded tee sheets and the data extracted from them: golfer or society names, tee times, group sizes, dates.
- Staff records the club enters: names, roles, availability, working preferences, and (optionally) hourly pay rates.
- Rosters, events, compliance jobs, and manager-logged daily cover counts.
Photo uploads of printed tee sheets are processed in your browser (the text-recognition library runs client-side); the photo itself is not transmitted to or stored on our servers — only the extracted tee-time data is saved with the rest of your club state.
2. Why we process it (legal bases)
- To provide the service — account management, storing your club state, generating rosters and reports (performance of a contract, Art. 6(1)(b) GDPR).
- Billing — subscription payments via Stripe (contract, and legal obligation for tax/accounting records, Art. 6(1)(c)).
- Security — authentication, rate-limiting, abuse prevention (legitimate interests, Art. 6(1)(f)).
- For tee-sheet and staff data we process only on the club’s documented instructions — i.e. the features the club actively uses. We never sell personal data, use it for advertising, or train models on it.
3. Where your data lives
Application data is stored with Supabase on infrastructure located in Zurich, Switzerland. Switzerland benefits from a European Commission adequacy decision, so storing EU/UK personal data there is lawful without additional safeguards. Requests to the site are served by Vercel’s edge network, and payments are handled by Stripe; where those providers process data outside the EEA/UK, transfers are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses in our agreements with them.
4. Sub-processors
| Provider | Purpose | Location / safeguard |
|---|---|---|
| Supabase | Database, authentication | Hosted in Zurich, Switzerland (EU adequacy) |
| Stripe | Payments and billing | EU/US — EU-US Data Privacy Framework, SCCs |
| Vercel | Application hosting and delivery | Global edge — EU-US Data Privacy Framework, SCCs |
5. Cookies
We use strictly necessary cookies only: the authentication session cookie that keeps you signed in, and cookies Stripe sets during checkout for payment and fraud prevention. We do not use analytics, advertising, or tracking cookies, which is why there is no consent banner. If that ever changes, this policy will be updated and consent asked first.
6. Retention
- Account and club data: kept while the account is active.
- On account deletion (email us, or ask via your club’s admin): live data is deleted promptly and residual copies in encrypted backups expire on a rolling basis within 30 days.
- Billing records: kept as long as Irish tax law requires (currently 6 years).
7. Your rights
You can ask us for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or restrict certain processing. Email conor@golfiofb.com — we respond within one month. If a golfer’s request concerns tee-sheet data, we will refer it to the club (the controller) and assist the club in answering it.
You can also complain to a supervisory authority: in Ireland the Data Protection Commission; in the UK the ICO; in Switzerland the FDPIC; or your local authority elsewhere in the EU.
8. Security
All traffic is encrypted in transit (TLS) and data is encrypted at rest. Every database row is isolated per account with row-level security; application servers verify identity on every request, and writes are validated against a strict schema. Passwords are hashed by our auth provider. See the DPA for the fuller technical-measures list.
9. Changes
We will post any material change here and update the version and date above. If a change significantly affects how club data is processed, account holders will be notified by email first.