Privacy Policy — golfactive.eu
1. The short version
The Golf Active app has no accounts, no server holding player data, and collects nothing about your game. Your GPS position, scorecard, club distances and settings are created and stay exclusively in your phone's memory — they are never sent to us and we cannot access them. The only data we hold are the hosting provider's technical logs and the content of your message if you write to us.
This summary does not replace the rest of the document.
2. Controller and contact details
| Controller | SELKANO KANIEWSKI SP.J. |
| Address | ul. Poznańska 11, 78-100 Kołobrzeg, Poland |
| Company number (KRS) | 0001217985 |
| Tax number (NIP / EU VAT) | 6711870431 / PL6711870431 |
| Statistical number (REGON) | 54376777000000 |
| hello@golfactive.eu | |
| Website | https://golfactive.eu |
We have not appointed a Data Protection Officer: none of the conditions in Article 37(1) GDPR applies — we are not a public authority, we do not monitor individuals on a large scale, and we do not process special category data on a large scale. For all data protection matters write to hello@golfactive.eu.
We are established in the European Union, so no representative under Article 27 GDPR is required.
3. Our role, and what we do not do
3.1. We act as a controller
We are the controller for: operating the golfactive.eu website, handling correspondence addressed to us, commercial relationships with golf clubs, and the security of our infrastructure.
3.2. We are not a processor of player data on behalf of a club
In the standard configuration of the service we process no personal data of players on behalf of a golf club, because no such data ever reaches us. The app runs in the player's browser and sends nothing back to a server. There is therefore no subject matter for processing under Article 28 GDPR as regards player data.
Should we ever launch a module that changes this (for example a club operator panel or server-side statistics), the data processing agreement concluded with the club takes effect and this Policy will be updated before such a module goes live.
3.3. What we do not do — a closed list
- ❌ no user accounts, no registration,
- ❌ no GPS position collected or stored on a server,
- ❌ no analytics, visitor statistics or tracking tools,
- ❌ no advertising and no profiling,
- ❌ no selling or sharing of data with marketing companies,
- ❌ no social media plugins, Google Maps, external fonts or embedded videos.
4. The golfactive.eu website
4.1. Hosting logs
The website is static. It has no forms, no login and no third-party scripts. Every request nevertheless causes connection data to be processed technically by the hosting provider — as with any website.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Delivering the website, maintaining security and preventing abuse (including volumetric attacks) | IP address, date and time of request, resource requested, response code, browser type and version, operating system, referrer | Article 6(1)(f) GDPR — our legitimate interest in delivering and securing the website | up to 30 days in the provider's logs; aggregated non-identifying data indefinitely |
Balancing test (Article 6(1)(f) GDPR): delivering the page content is impossible without processing the IP address; the data are not combined with other datasets nor used to evaluate anyone; the retention period is short. We consider that the interests and rights of the visitor are not overriding. Documentation of this assessment is available on request.
4.2. E-mail contact
There is no contact form on the website — e-mail is the only channel.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Answering enquiries, correspondence, preparing quotations | e-mail address, name, club name, position, telephone and anything else you include | Article 6(1)(b) GDPR where it concerns concluding or performing a contract; Article 6(1)(f) GDPR (responding to an enquiry) otherwise | 12 months from the last message; where a contract is concluded — as set out in section 7 |
Please do not send us special category data (Article 9 GDPR) or identity documents by e-mail. There is never a reason to do so.
4.3. No cookies
The golfactive.eu website sets no cookies and uses no browser storage. That is why there is no consent banner — there is nothing to consent to. Details: Cookie and Local Storage Policy.
5. The Golf Active application
The app is built so that data protection is settled by architecture rather than by policy wording: no server exists for player data to reach.
5.1. GPS position
The app uses your phone's GPS receiver to calculate distances to the green and to hazards. Your browser will ask for permission to access your location; you may refuse and still use the map, losing only the distances measured from your own position.
The position is processed exclusively in your device's working memory. It is not sent to us or to anyone else, is not written to your phone's storage, and disappears when you close the browser tab. We never receive it in any form, aggregated or otherwise.
You can withdraw the permission at any time in your browser settings (padlock icon next to the address → permissions → location).
5.2. Data stored on your phone
The app writes four sets of information to browser local storage (localStorage):
| Key | Contents | Why |
|---|---|---|
golf-active:prefs |
selected tee, pin position, theme, units (metres/yards), language, basemap and arc visibility, screen wake lock | so the app looks the way you left it |
golf-active:round |
current round: playing handicap, tee, hole scores | so a flat battery on the 16th does not erase your round |
golf-active:history |
the last 25 completed rounds (summary) | history and statistics |
golf-active:clubs |
13 clubs with calculated average distances | club suggestion |
In addition, the offline cache (Service Worker) holds course geometry, application files, viewed facility photos and downloaded basemap tiles.
These are not personal data processed by us — we have no access to them, cannot read them, and do not even know they exist. They sit on your device, under your control.
Legal basis for accessing device storage: Article 5(3) of Directive 2002/58/EC (ePrivacy), as implemented in the Member State concerned — in Poland, Article 398 of the Electronic Communications Law of 12 July 2024. The storage is strictly necessary to provide a service explicitly requested by the user: without it there is no offline mode and no round recording, and those are precisely the functions people open this app for. That is why we neither ask for consent nor display a banner.
How to delete it: clear site data in your browser settings (Chrome: ⋮ → Settings → Privacy → Site settings; Safari: Settings → Safari → Advanced → Website Data), and if you added the app to your home screen, delete it like any other app. Everything disappears immediately and irreversibly, without any involvement on our part.
5.3. OpenStreetMap basemap — the only data leaving your device
The map is drawn over tiles served by the OpenStreetMap Foundation. Fetching a tile is an ordinary HTTP request in which your browser passes that server your IP address, request headers and the tile coordinates — and therefore, indirectly, the approximate area you are viewing, to tile precision rather than to your position.
| Recipient | OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom |
| Its role | separate controller — not our processor |
| Our role | controller in respect of the decision to embed the basemap and the resulting disclosure of the IP address |
| Legal basis | Article 6(1)(f) GDPR — legitimate interest in displaying a legible terrain map |
| Their policy | https://osmfoundation.org/wiki/Privacy_Policy |
How to avoid it: the app settings include a switch that turns the OpenStreetMap basemap off. What remains is the course drawing on a plain background — full navigation functionality with no connection to any external server whatsoever. Previously downloaded tiles continue to work from cache.
Transfers to the United Kingdom rely on the European Commission's adequacy decision for the UK (Article 45 GDPR). Should that decision cease to apply, we will rely on standard contractual clauses or offer clubs a basemap served from within the EEA.
5.4. Verify our network traffic yourself
Apart from downloading the app itself and the basemap tiles, the app makes no other network requests of its own accord. You can check this yourself: the "Network" tab in your browser's developer tools will show only the club's domain and tile.openstreetmap.org. We encourage you to verify — it is quicker than taking our word for it.
5.5. Links you click yourself
A facility card (restaurant, driving range, hire shop) offers three buttons that lead out of the app: call, directions and website. These are ordinary links — until you press one, nothing happens and no data goes anywhere.
| Button | What happens when you press it |
|---|---|
| Call | your phone opens its dialler with the facility's number; nothing reaches us |
| Directions | Google Maps opens in a new tab with the selected facility's coordinates as the destination. Google then receives your IP address and those coordinates — from that point Google's privacy policy applies, not ours |
| Website | the page published by the club opens; that site's policy applies |
If you would rather not send anything to Google, simply do not use the "directions" button — every navigation feature inside the app (distances, map, shot planning) works without it.
Exporting your scorecard. The card is drawn as an image in your phone's memory and is not sent anywhere. When you tap "share", your phone opens its own system share sheet — you decide who receives the image and through which app, and from that moment that app's terms apply. "Download" saves the file locally and "copy" places the result on your clipboard. We take no part in any of this and never learn that it happened.
6. Recipients
We do not sell or share data for marketing purposes. The list of recipients is short:
| Recipient | Role | What it receives | Region |
|---|---|---|---|
| Cloudflare, Inc. (101 Townsend St, San Francisco, USA) | processor — hosting (Cloudflare Pages), CDN, attack protection | connection data: IP address, headers, requested resources | global edge network; standard contractual clauses and EU-US Data Privacy Framework certification |
| OpenStreetMap Foundation (Cambridge, UK) | separate controller — map tile server | IP address and headers of the tile request | United Kingdom — adequacy decision |
| E-mail provider | processor — hello@golfactive.eu mailbox | content and metadata of correspondence | EEA |
| Accountants and advisers | processor / separate controller | club billing data (never player data) | Poland |
| Public authorities | separate controller | only where required by law | Poland / EU |
The current list is published at golfactive.eu/subprocessors — see List of processors.
7. Retention periods
| Category | Period | Basis |
|---|---|---|
| Hosting logs | up to 30 days | provider's retention policy; Article 6(1)(f) GDPR |
| E-mail correspondence without a contract | 12 months from the last message | legitimate interest — ability to reconstruct a matter |
| Club contact and contract data | term of the contract + 6 years | limitation periods for claims |
| Accounting records | 5 years from the end of the tax year | Polish Tax Ordinance Art. 86 §1; Accounting Act Art. 74 |
| Personal data breach records | 5 years | Article 33(5) GDPR — documentation duty |
| Data on your phone | until you delete it | outside our control — we have no access |
8. Your rights
You have the right to:
- access and a copy of your data — Article 15 GDPR,
- rectification — Article 16 GDPR,
- erasure ("right to be forgotten") — Article 17 GDPR,
- restriction of processing — Article 18 GDPR,
- data portability — Article 20 GDPR (for data processed on the basis of contract or consent),
- object to processing based on legitimate interests — Article 21 GDPR,
- withdraw consent at any time — Article 7(3) GDPR, without affecting the lawfulness of processing before withdrawal.
Send your request to hello@golfactive.eu. We reply without undue delay and within one month of receipt; for particularly complex matters this may be extended by two further months, of which we will inform you within the first month (Article 12(3) GDPR). Exercising your rights is free of charge.
A practical note: if your request concerns round data, clubs or settings in the app, you do not need to contact us — and we could not act on it. Those data are on your phone only and you delete them yourself as described in section 5.2. This is not evasion: we physically do not hold them.
9. Complaints to a supervisory authority
You may lodge a complaint with a supervisory authority — in the country of your habitual residence, place of work, or place of the alleged infringement (Article 77 GDPR). Our lead authority is the Polish DPA, but you may also approach your own:
| Country | Authority | Website |
|---|---|---|
| Poland | Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw | uodo.gov.pl |
| Ireland | Data Protection Commission (DPC), 6 Pembroke Row, Dublin 2 | dataprotection.ie |
| United Kingdom | Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF | ico.org.uk |
| Germany | BfDI or the competent state authority | bfdi.bund.de |
| France | CNIL | cnil.fr |
| Spain | AEPD | aepd.es |
| Italy | Garante per la protezione dei dati personali | garanteprivacy.it |
| Sweden | Integritetsskyddsmyndigheten (IMY) | imy.se |
| Denmark | Datatilsynet | datatilsynet.dk |
| Netherlands | Autoriteit Persoonsgegevens | autoriteitpersoonsgegevens.nl |
10. Users in the United Kingdom
Where we offer the service to individuals in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply alongside the EU GDPR, and the Privacy and Electronic Communications Regulations 2003 (PECR), regulation 6, applies to device storage in place of the ePrivacy provisions cited above. The analysis is identical: the storage described in section 5.2 is strictly necessary for a service requested by the user, so no consent is required.
The competent authority for UK users is the ICO (details above), and UK users retain all rights listed in section 8 under the equivalent provisions of the UK GDPR.
Before we begin offering the service to clubs established in the United Kingdom, we will assess and, where required, appoint a UK representative under Article 27 UK GDPR and publish their details in this Policy.
11. Users in Ireland
For users in Ireland the EU GDPR applies together with the Data Protection Act 2018 and the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336/2011), regulation 5 of which implements Article 5(3) ePrivacy. Complaints may be lodged with the Data Protection Commission.
12. International transfers
Data stay within the European Economic Area as a rule. There are two exceptions, both described above:
- Cloudflare, Inc. — global edge network. Safeguards: standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 and certification under the EU-US Data Privacy Framework.
- OpenStreetMap Foundation — United Kingdom. Safeguard: the European Commission's adequacy decision (Article 45 GDPR).
A copy or description of the safeguards is available on request to hello@golfactive.eu.
13. Security
We apply technical and organisational measures appropriate to the risk (Article 32 GDPR). For this service the most effective one is minimisation at source — data we never collect cannot be breached. Beyond that:
- encrypted connections only, HTTPS/TLS 1.2+, enforced at hosting level,
- security headers:
X-Content-Type-Options,Referrer-Policy: strict-origin-when-cross-origin,X-Frame-Options, and a restrictivePermissions-Policydisabling location, camera, microphone and payment access on the website, - no third-party scripts, no ad networks, no external fonts, no social plugins,
- two-factor authentication on all infrastructure provider accounts,
- a personal data breach procedure with notification to the supervisory authority within 72 hours (Article 33 GDPR).
14. No profiling, no automated decisions
We take no decisions based solely on automated processing, including profiling, producing legal effects or similarly significantly affecting anyone (Article 22 GDPR). We carry out no marketing profiling of any kind.
The club suggestion in the app is calculated from your own measurements on your own phone and is not a decision within the meaning of Article 22 GDPR — it is a calculator, not an assessment of a person.
15. Children
The app is not directed exclusively at children, but golf is played by minors too. Since we collect no personal data from users of the app and rely on no consent, Article 8 GDPR (conditions applicable to a child's consent for information society services) does not apply here. A child can use the app exactly as safely as an adult — with exactly the same effect on their data, namely none.
16. Changes to this Policy
We may amend this Policy, in particular when the service, an infrastructure provider or the law changes. The current version is always available at golfactive.eu/privacy-policy with its effective date and version number.
Where a change is material — and we treat as material in particular any start of collecting player data, launch of analytics, or addition of a new recipient — we will announce it 14 days in advance prominently on the website and in the app, not merely by replacing a file.
17. Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-08-04 | Document created for golfactive.eu |
_This is a translation of the Polish original. In the event of discrepancy, and without prejudice to mandatory consumer protection rules of your country of residence, the Polish version prevails._
_SELKANO KANIEWSKI SP.J., Kołobrzeg, 4 August 2026_