Privacy Policy
Last updated: March 2026
This privacy policy describes how TeeConnect (hereinafter "we", "our" or "TeeConnect") collects, uses, stores and protects your personal data when you use our mobile application and associated services (hereinafter "the Service").
This policy is written in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data ("GDPR"), as well as the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
1. Data controller
The controller of your personal data is:
- Name: TeeConnect
- Registered office: Belgium
- Email: contact@teeconnect.io
2. Data collected and purposes
We collect the following categories of data:
2.1. Registration and profile data
| Data | Purpose |
|---|---|
| Email address | Account creation and management, communications |
| First and last name | Identification between users |
| Golf handicap | Matching between players of compatible level |
| Country and region | Geographic search for partners and clubs |
| Business sector | Professional connections between golfers |
| Profile picture | Profile personalisation |
2.2. Usage data
| Data | Purpose |
|---|---|
| Chat messages | Communication between users |
| Round participation | Organisation and history of golf rounds |
| Preferences and matches | Improvement of partner suggestions |
2.3. Optional data
| Data | Purpose |
|---|---|
| Geolocation (optional) | Geolocated sponsor offers and content, search for nearby clubs |
Geolocation is only enabled with your explicit consent and can be disabled at any time in your device settings.
3. Legal basis for processing
In accordance with Article 6 of the GDPR, we process your data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): the processing of your registration, profile, chat and round participation data is necessary to deliver the service you accepted when creating your account.
- Consent (Art. 6(1)(a)): the collection of your geolocation relies on your prior consent, which you may withdraw at any time.
- Legitimate interest (Art. 6(1)(f)): improving our services and preventing abuse constitute a legitimate interest, with due regard to your fundamental rights.
- Legal obligation (Art. 6(1)(c)): certain processing may be necessary to meet our legal obligations (e.g. judicial requests).
4. Retention period
- Account data: retained for the entire duration of your use of the Service, then deleted within 30 days after the user deletes the account.
- Chat messages: retained for the duration of the conversation, then deleted within 30 days after either participant's account is deleted.
- Geolocation data: processed in real time and not stored permanently.
- Technical logs: retained for a maximum of 12 months for security and debugging purposes.
5. Sharing with third parties
We never sell your personal data. We share your data only with the following processors, strictly for the purpose of providing the Service:
| Processor | Role | Data location |
|---|---|---|
| Supabase Inc. | Database hosting, authentication, file storage | EU (Frankfurt, Germany — eu-central-1) |
| Google LLC | Authentication via Google OAuth (if chosen by the user) | EU (authentication data only) |
| Apple Inc. | Authentication via Apple Sign-In (if chosen by the user) | EU (authentication data only) |
Each processor is bound by a data processing agreement (DPA) compliant with Article 28 of the GDPR.
6. Data transfers outside the European Union
Your personal data is hosted exclusively within the European Union, on Supabase servers located in Frankfurt (Germany), region eu-central-1.
No data is transferred to third countries as part of the normal operation of the Service. Should such a transfer become necessary in the future, it would be covered by the appropriate safeguards provided for by the GDPR (standard contractual clauses, adequacy decision, etc.) and you would be informed beforehand.
7. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): obtain confirmation that your data is being processed and receive a copy of it.
- Right to rectification (Art. 16): correct inaccurate or incomplete data, directly from your profile or by contacting us.
- Right to erasure (Art. 17): request the deletion of your data. You can delete your account directly from the application.
- Right to data portability (Art. 20): receive your data in a structured, commonly used and machine-readable format.
- Right to object (Art. 21): object to the processing of your data based on our legitimate interest.
- Right to restriction of processing (Art. 18): request the restriction of processing in certain circumstances.
- Right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise your rights, contact us at contact@teeconnect.io. We will respond to your request within one month, in accordance with the GDPR.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (DPA): www.dataprotectionauthority.be
8. Cookies and similar technologies
The TeeConnect mobile application does not use cookies. As a native application, it uses neither third-party cookies nor advertising tracking technologies.
The teeconnect.io website may use cookies strictly necessary for its operation (e.g. remembering the chosen language). No tracking or analytics cookies are used.
9. Data security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure or destruction:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest (AES-256)
- Secure authentication (bcrypt password hashing)
- Row Level Security policies in the database
- Data access limited to what is strictly necessary (principle of least privilege)
- Hosting on certified infrastructure (Supabase/AWS, SOC 2 and ISO 27001 certifications)
10. Protection of minors
The Service is intended for people aged 16 or over. We do not knowingly collect data from people under 16. If we learn that a user is under 16, we will delete their account and data as soon as possible.
11. Changes to the privacy policy
We reserve the right to amend this privacy policy at any time. In the event of a substantial change, we will inform you by in-app notification or by email at least 30 days before the changes take effect.
The date of the last update appears at the top of this page. We invite you to consult it regularly.
12. Contact — Data protection officer
For any question about this privacy policy or the exercise of your rights, you can contact us:
- Email: contact@teeconnect.io
- Subject: "Data protection — [your request]"
We undertake to handle your request within one month of receiving it.