Privacy Policy
Last updated: July 2026
Track Golf lets you photograph a paper golf scorecard, reads the scores, and tracks your stats and an unofficial handicap. This page explains what we collect, how it is used, and the choices you have. Your data is private to your account by default.
What we collect
- Your email, to sign you in (and your name from Google if you use Google sign-in). Authentication is handled by Supabase.
- Rounds you save: scores, dates, courses, notes, and the stats and unofficial handicap derived from them.
- Course details from the rounds you save — the course name, and each hole's par, stroke index and distance. These go into a library shared with other players, without your scores or anything else about you. See “The shared course library” below.
- Scorecard photos you upload while scanning: kept with the in-progress scan (a “draft”) until you save or discard it, and with the saved round afterwards.
- Scan activity: a timestamp per scan attempt, used only to rate- limit the paid reading service and prevent abuse.
- Usage analytics: how the app is used, pages and stats views you open, and buttons you tap, to understand what works and improve the product. We do not record your screen, and we never capture the text you type. See “Cookies and analytics” below.
How scorecard photos are handled
When you scan a card, the image is sent to Google's Gemini API to read the numbers, and stored with your in-progress draft so you can resume the review on another device. When you save the round, the card photos are kept with it in your private account, so you can always check the saved scores against the original card. They are deleted when you delete the round or your account. Abandoned drafts (and their photos) are automatically deleted after 7 days.
A scorecard can show other players' names and scores. We store only what is on the card, within your private account, and do not share it. Please don't upload cards containing information other people wouldn't want recorded.
The shared course library
Track Golf keeps one shared library of golf courses: the course's name and, for each set of tees, the par, stroke index and distance of every hole, plus the course rating and slope. It comes from a golf course data provider and from rounds players log at courses the provider doesn't list. It exists so that a course is spelled one way for everyone, and so that in future a scanned card can be checked against the layout it claims.
When you save a round, the course details on it are added to this shared library. Your scores are not. Nothing about you, your round, your dates or your notes goes into it — only facts about the golf course, which are not personal information. Other players see the course; they do not see that you played it.
We keep a private record of which account reported which layout, so we can weigh a course's details against other cards from the same course and undo a bad entry. That record is visible only to you and to us, and it is deleted with your account. The course details themselves stay in the library, because by then they are simply facts about a golf course.
Friends
You can connect with other players as friends. A connection is always mutual: someone opens your invite link, and it only takes effect once you have both agreed. Nobody can add you without your answer, and nobody can find you by searching for your email address — the invite link is the only way in, and it works only if you send it to them.
Friends see the name you choose in Settings, and for each round you save: the course, the date, the tees, and the scores on the card. Your email address is never shown to them, and neither are your notes, your shot-by-shot details, or your scanned card photos. You can turn off sharing entirely in Settings without removing anyone, and either of you can end a friendship at any time — after which neither can see the other's rounds, including through links opened earlier.
Who we share it with
We use a small number of service providers to run the app:
- Google (Gemini API) to read scorecard images.
- Supabase for the database and authentication.
- Google for optional Google sign-in.
- A golf course data provider for course, tee, and rating lookups.
- PostHog for privacy-conscious product analytics (how the app is used).
We do not sell your data or use it for advertising.
Cookies and analytics
We use cookies your browser needs to keep you signed in, plus analytics cookies (PostHog) that measure how the app is used, pages and stats views you open, and buttons you tap, so we can improve it. Analytics is configured conservatively: no screen recording, and the text you type (emails, scores) is never captured. If your browser sends a “Do Not Track” signal, we honor it and don't load analytics.
Retention
- In-progress scan drafts and their photos: deleted after 7 days, or when you save or discard the round.
- Saved rounds, their card photos, and settings: kept until you delete them or your account.
- Scan-activity timestamps: kept up to 30 days.
- Friend connections and pending requests: kept until either person ends them, or until an account is deleted. Declining a request deletes it outright — no record of the refusal is kept on either account.
- Shared course details (names, pars, stroke indexes, distances, ratings): kept indefinitely — they describe the course, not you. The private record of who reported a layout is deleted with your account.
Your choices
In Settings you can export your rounds and delete your account, set the name your friends see, and turn off sharing with friends. Deleting your account permanently removes your rounds, drafts, photos, settings, friend connections, and your login, along with the record of which course layouts you reported. Course details already in the shared library remain, as described above. To ask about your data, contact us below.
Security
Data is stored per account with row-level security, so you only ever see your own rounds. No system is perfectly secure, but we aim to protect your information and keep only what the app needs.
Contact
Questions about privacy? Email privacy@example.com.
See also our Terms of Service.