Hagolf

Legal

Privacy policy

Last updated: 1 October 2026

In short. Hagolf keeps what it needs to score golf with other people: your account, your rounds, your leagues and the people you play with. It shows no ads, runs no analytics or tracking, and sells nothing to anybody. You can download everything or delete your account from inside the app at any time.

1. Who is responsible

The controller for the personal data processed through Hagolf (the app at app.hagolf.app and this website) is:

Hagworks, a sole proprietorship (eenmanszaak) owned by Maurits van ’t Hag
The Netherlands
Chamber of Commerce (KvK): Hagworks is being registered with the KvK. The registration number and business address will be listed here as soon as it is.
Email: privacy@hagolf.app

Hagworks has not appointed a data protection officer; questions about privacy go to the address above, and are answered by the owner.

2. What we keep, why, and on what basis

We only collect what the app needs to work. We never ask for your date of birth, address or phone number.

WhatWhyLegal basis (GDPR)
Account: the email address and name from the Google account you sign in with, the name and handle you choose, your handicap index, whether men’s or women’s course ratings apply to you, and your settings (who may find you, initials on shared boards)To sign you in, to show you to the people you play with, and to work out your handicap strokes. Your email address is used to sign you in and to reach you about your account; it is never shown to other users.Contract (art. 6(1)(b))
Your golf: rounds you score or are scored into, hole by hole, the optional extras you switch on (putts, fairways, penalties, bunkers), courses you add, leagues and league membershipsThis is the service: keeping score, leaderboards, leagues and statistics, on every phone you use.Contract
Change history: for every change to a card, what it was, what it became, when, and which account and device made itCards are shared records that everybody on them may correct, so the history shows who changed what.Contract; legitimate interest in fair, correctable records (art. 6(1)(f))
Friends and sharing: friend requests, friends, people you block, cards you share, invitation links, and the updates in your inboxTo let you find, invite and share with people, and to tell you what is new.Contract
Push notifications: the push address your phone’s browser gives us, only if you switch notifications onTo wake your phone when something new arrives. The push carries no content at all.Consent (art. 6(1)(a)); switch it off at any time in the app or in your phone’s settings
Sign-in sessions: when each session started and was last used, when it expires, a device identifier and the browser’s user agent; passkeys if you register one (a public key only)To keep you signed in, let you sign out everywhere, and detect a stolen session.Contract; legitimate interest in security
Abuse protection: short-lived counters per IP address and per email address for sign-in attempts and scorecard scans, and a monthly count of your scansTo stop the sign-in and scan services being abused, and to apply fair-use limits to scanning.Legitimate interest in security and in keeping costs in check
Scorecard photos you choose to scan, with the course’s par and the names of players you already play withTo read the scores off the card and match rows to the right players. The photo is passed to the reading service and not stored by us.Contract (you ask for it)
Course search: the club name, town or country you type, or your approximate location if you ask for clubs nearbyTo look the club up in a course database. Your location is used for that search only and not stored.Contract (you ask for it)
Purchases: what you bought, the amount, the currency, the date and the payment provider’s referenceTo give you what you bought on every phone, and to keep the records tax law requires.Contract; legal obligation (art. 6(1)(c))
Email to us: what you write to support or privacy, and our repliesTo help you.Legitimate interest in answering you

We do not use your data for advertising, profiling or automated decisions, and we do not sell or rent it to anyone.

3. People you add to a card

When you add a player who is not on Hagolf, you store their name, men’s or women’s ratings and handicap index in your address book, and their scores on the cards you keep. That is ordinary for a scorecard, but it means we hold data about people who have not signed up. We do this on the basis of our and your legitimate interest in keeping a complete scorecard. Please only add people who would expect to be on the card.

If that person later joins Hagolf, they can claim their card and see it. Anyone who appears in Hagolf without an account can ask us at privacy@hagolf.app to see what we hold about them, or to have their name removed.

4. Who sees what

5. Who we work with

We use a small number of service providers. Each processes data only to provide its part of the service, under a data processing agreement or its own terms as an independent controller where noted.

ProviderWhat forData involvedWhere
Cloudflare, Inc.Hosting of the app and this website, the database, nightly backups, and protection against attacksEverything stored by the app; IP addresses of visitorsGlobal network; database in the EU where available; US company
Google (Google Ireland Ltd / Google LLC)Sign-in with GoogleGoogle confirms who you are and tells us your name and email addressEU and US
Anthropic, PBCReading scores from scorecard photos you choose to scanThe photo, the course’s par, and the names of players you already play withUS
golfapi.ioCourse database lookupYour search terms, and your approximate location if you search for clubs nearby. No account data.Location not yet confirmed. Searches are sent by our server, so golfapi.io never sees your IP address or account.
Resend, Inc.Sign-in emails, only where sign-in by email code is offeredYour email address and the sign-in emailUS
Stripe Payments Europe, Ltd.Payments in the shop, once it takes paymentsYour payment details and email address, which you give to Stripe directly. We never see your card number. Stripe is an independent controller for its own legal duties, such as fraud prevention.Ireland; Stripe group in the US
Push services of your phone’s browser (Apple, Google or Mozilla)Delivering notifications, if you switch them onA wake-up message with no content, sent to your phone’s push addressDepends on your phone; mostly US

6. Data outside the EU

Some of these providers are based in the United States. Where personal data goes outside the European Economic Area, we rely on the EU–US Data Privacy Framework for providers certified under it, and otherwise on the European Commission’s standard contractual clauses. You can ask us for a copy of the safeguards that apply.

7. How long we keep it

DataKept for
Your account, rounds, leagues, friends and address bookUntil you delete them or your account
Change history of cardsAs long as the card exists; entries made by an erased account no longer point to a person
Sign-in sessions90 days from last use, then they expire
Invitation linksUp to 30 days
Updates in your inboxAbout 90 days
Push addressesUntil you switch notifications off, sign out everywhere, or the push service reports the address as gone
Abuse-protection countersThe current hour (sign-in and scan attempts) or month (scan count)
Scorecard photosNot stored by us; the reading service handles them under its own retention terms
Purchase records7 years, as Dutch tax law requires, also after you delete your account
BackupsPoint-in-time recovery for 30 days, and nightly copies for 90 days. Deleted data disappears from backups when they roll over.
Email to supportUp to two years after the conversation ends

8. Security

All traffic is encrypted (HTTPS), and the database is encrypted at rest by Cloudflare. Sign-in tokens and links are stored only as hashes, there are no passwords to steal, and a reused session token ends every session that came from it.

Hagolf is not end-to-end encrypted, and cannot be: a shared leaderboard is worked out from shared data on our server. We keep the risk small by keeping little: no addresses, no birth dates, no phone numbers, no payment details.

9. Your rights

Under the GDPR (in Dutch: AVG) you have the right to:

For anything you cannot do in the app, write to privacy@hagolf.app. We answer within one month, and may ask you to write from the email address of your account so we know it is you.

If you think we handle your data wrongly, please tell us first. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in the EU country where you live.

10. Cookies and storage on your phone

This website (hagolf.app) sets no cookies and uses no analytics, trackers or third-party scripts. The fonts are served from our own domain.

The app (app.hagolf.app) uses:

The app uses no advertising or tracking cookies. Signing out ends the session on that phone; the copy on the phone stays until you clear the app’s or site’s data in your browser settings.

11. Children

Hagolf is meant for people aged 16 and over to sign up by themselves. Younger golfers can appear on a card kept by a parent, coach or another adult. If you believe a child under 16 has an account without consent from a parent, write to us and we will delete it.

12. Changes to this policy

When we change this policy, we update the date at the top. If a change matters for how your data is used, the app tells you before you continue. The version inside the app is a shorter summary of this one; where they differ, this page is the complete version.