Privacy Policy
Version françaiseLast updated: 14 September 2026
Draft dated 14 September 2026, pending review by a lawyer. Items in square brackets [TO CONFIRM] / [TO BE SET] must be validated before publication.
This policy describes how GolfSpec ([TO CONFIRM: company name], "GolfSpec", "we") processes personal data in connection with the GolfSpec Pro service, available at golfspecpro.app and through the iOS app. It supplements the Terms of Use, the Terms of Sale and the Data Processing Agreement (DPA).
1. Two distinct roles
GolfSpec acts in two capacities:
- Data controller (part A) for the data of customer shops and their staff: account creation and management, subscription billing, support, security, backups and monitoring of the Service.
- Data processor (part B) for the data of end customers (golfers) entered by each shop: GolfSpec processes them only on the shop's instructions; the shop is the controller and the point of contact for its customers' rights. GolfSpec's commitments to the shop are set out in the DPA.
2. Controller and contact
[TO CONFIRM: company name], [TO CONFIRM: legal form], [TO CONFIRM: registered office], [TO CONFIRM: company registration number]. Contact for personal-data matters: contact@golfspecpro.app [TO CONFIRM: dedicated address]. Data Protection Officer: [TO CONFIRM: whether a DPO is appointed].
A. GolfSpec as data controller
Data we process on our own behalf:
- Staff accounts: email, name, password (hashed), role (administrator, manager, fitter), language, assigned site, date notifications were last viewed.
- Shop account: company name, contact details, VAT number, branding (logo, colour, texts), currency, time zone; Stripe customer and subscription identifiers (never a card number), subscription status, date and version of acceptance of the Terms, deletion request.
- Subscription billing: handled by Stripe (card, invoices); we keep only identifiers and statuses.
- Support and contact: name, email, phone and message sent through the contact form or by email.
- Security: IP address used as a rate-limiting key (login, sign-up, forgotten password, magic link, booking), kept for at most 15 minutes; technical logs; error reports (Sentry).
- Notifications: push-notification subscription (browser or iOS) if the User enables it.
Purposes and legal bases:
- Providing the Service, managing accounts and authentication, billing the subscription — performance of the contract (Art. 6(1)(b) GDPR).
- Ensuring security (rate limiting, brute-force protection, error monitoring), backing up and restoring the database, improving the Service — legitimate interest (Art. 6(1)(f)).
- Keeping billing documents — legal obligation (Art. 6(1)(c)) [TO CONFIRM: accounting retention period].
- Sending Service-related emails (confirmation, password reset, alerts, invoices) — performance of the contract. No marketing-campaign feature is in service to date.
B. GolfSpec as processor for the shops
The shop decides which data it enters. Depending on the features used, the Service may host, on its behalf:
- Identity and golf profile: surname, first name, email, phone, the shop's CRM identifiers, home club, handicap index, handedness, playing frequency, fitter's free-text notes.
- Fitting: body measurements (height, wrist-to-floor, arm length), swing speeds, level, goals, fitting interview (current bag, feel, priorities and, where relevant, physical constraints declared by the customer), recommendations, quotes, discounts, order status, customer's handwritten signature.
- Ball-striking data: launch-monitor data per club (speeds, angles, spin, distances, dispersion, up to 100 shots), TrackMan reports imported by link.
- Workshop and after-sales: repair tickets (registered or walk-in customer), description, before/after and step photos, customer signature, event log; after-sales claims to suppliers (product, proof of purchase, photos, correspondence); supplier sales contacts.
- Messaging and portal: customer–fitter conversations, attachments, AI drafts, portal access tokens, portal push subscription.
- Appointments: online bookings (surname, first name, email, phone), appointments, no-shows, cancellation token.
- Shop payments (Stripe Connect): amount, type (payment, deposit, pre-authorisation), status, Stripe identifier, date of acceptance of the shop's terms and IP address declared on that occasion; manual payments (cheque or bank-transfer reference).
- Satisfaction: rating, free-text comments, click-through to the Google review.
- Emails sent to customers: recipient, subject, delivery status.
These data are processed solely to perform the features chosen by the shop (fittings and documents, portal, messaging, appointments, payments, workshop and after-sales, reminders configured by the shop, AI analyses). The shop determines the legal basis towards its customers; GolfSpec does not use these data for its own purposes or for advertising.
3. Artificial intelligence
The Service uses Google's Gemini model (currently gemini-2.5-flash) for four features, triggered by the shop:
- structured analysis of a fitting (suggested recommendations);
- session assistant (answer to a free-text question from the fitter during the fitting);
- drafting of a fitting summary for the customer;
- draft replies in the messaging module (feature the shop can enable or disable).
Data sent to the model — analysis, assistant and summary: handicap index, speeds, height, wrist-to-floor, arm length, handedness, level, playing frequency, goals, interview answers (including any physical constraints and free-text comments), per-club measurements, quote items, fitter's notes, home club, the shop's name and instructions, catalogue and product sheets; messaging drafts: the last eight messages of the conversation, and the fitting's notes, statuses and items.
The customer's surname, first name, email and phone are not included in the prompts; they may however appear in free-text fields (notes, comments, messages), which are sent as they are. The exact content sent is kept with the result in the fitting record, for traceability [TO BE SET: retention period].
The output is a decision-support tool: it is reviewed and validated by the fitter before any use. Use is capped (analyses per day per shop, per-minute limits). [TO CONFIRM: applicable Google terms — processing region, prompt retention, no use for model training]
4. Sub-processors and data location
We use the following providers:
- Vercel Inc. — application hosting, server functions and scheduled jobs, executed in the London region (lhr1, United Kingdom); Vercel Blob — files (workshop photos, attachments, after-sales receipts, PDF cache) [TO CONFIRM: file-storage region].
- Neon Inc. — PostgreSQL database, AWS region eu-west-2 (London, United Kingdom).
- Upstash — rate-limiting Redis (temporary keys: IP address or email, expiring within 15 minutes); United States.
- Resend Inc. — transactional email delivery and delivery-status feedback [TO CONFIRM: region].
- Stripe — SaaS subscription and, through Stripe Connect, the shop's payments [TO CONFIRM: Stripe entity and region].
- Google (Gemini) — artificial-intelligence features (section 3) [TO CONFIRM: region].
- Apple (APNs) and Web Push services (Google, Mozilla, Apple) — delivery of push notifications (subscription tokens only).
- Sentry — collection of technical errors (server and browser) [TO CONFIRM: region and personal-data scrubbing].
- GitHub (Microsoft) — daily encrypted (AES-256) database backups, kept for 30 days (90 days for the monthly backup), and continuous integration; United States.
- cron-job.org — uptime monitoring; Better Stack — heartbeat monitoring [TO CONFIRM: activation]. No personal data in either case.
- TrackMan — when a report is imported by link, the Service reads that report (which contains the player's name) from TrackMan's servers.
- Shopify or another CRM — synchronisation of customer records if the shop enables the integration; encrypted credentials (AES-256-GCM).
Production data (application, database, files) are hosted in the United Kingdom, a country covered by an adequacy decision of the European Commission. Providers established in the United States (Upstash, GitHub and, depending on their processing region, Resend, Stripe, Google, Sentry) operate under the EU–US Data Privacy Framework or standard contractual clauses [TO CONFIRM: transfer mechanism verified for each provider]. We never sell or rent any data.
5. Cookies and local storage
The Service uses only cookies and storage strictly necessary for its operation, exempt from consent (Article 82 of the French Data Protection Act); no banner is therefore displayed:
- Session cookie (professional area): authentication, encrypted, HttpOnly, 30 days.
- portal_session (customer portal): customer session after a magic link, 24 hours.
- activeSiteId: site selected in the multi-site interface, 1 year.
- Local storage: golfspec-theme (theme), push-dismissed (notification banner), golfspec-offline-queue-v1 (queue of actions entered while offline).
No audience-measurement, advertising or behavioural-tracking tool is used; no third-party script is loaded in the pages and fonts are self-hosted.
6. Emails
Emails sent (confirmations, portal access links, quotes, reminders, alerts) contain neither an open-tracking pixel nor click-tracking links; we receive only the delivery statuses (sent, delivered, bounced, complained, failed) to diagnose failures.
7. Retention periods
- Shop account and entered data: for the duration of the subscription or trial, then 30 days after the deletion request (cancellable), before permanent deletion from production [TO BE SET: fate of inactive accounts with no deletion request].
- Encrypted backups: 30 days (90 days for the backup taken on the 1st of the month); point-in-time database restore: 6 hours.
- Subscription billing documents: kept by Stripe [TO CONFIRM: 10-year accounting retention and interplay with account deletion].
- Rate-limiting keys (IP, email): at most 15 minutes.
- Tokens: portal magic link 15 min; portal token 90 days; password reset 15 min; professional session 30 days; booking cancellation token [TO BE SET: no expiry to date].
- Technical logs: retention period of the hosting platform [TO BE SET]; Sentry error reports [TO BE SET].
- Email log (recipient, subject, status): [TO BE SET: no automatic purge to date].
- Content sent to the AI model, IP address of acceptance of the shop's terms (Stripe Connect), workshop event log and archived tickets: kept with the account [TO BE SET: specific periods].
The shop sets the retention period for its customers' data (inactive customers, old fittings); it has the JSON export and the assistance provided for in the DPA.
8. Security
- Encryption of communications (HTTPS/TLS) and of the database connection (SSL).
- Hashed passwords (bcrypt), minimum length, brute-force protection (10 attempts per 15 minutes) and non-enumeration of accounts.
- Rate limiting on sensitive endpoints (login, sign-up, exports, sending, AI).
- Per-shop data isolation enforced at database level (composite keys) and tested; role- and site-based access control.
- Third-party integration credentials encrypted (AES-256-GCM); no card data stored; Stripe Connect limited to the account identifier.
- Daily encrypted backups and quarterly restoration test; error monitoring and alerts.
- Signed, replay-protected webhooks; controlled uploads (allowed types, 10 MB maximum).
- Files stored on Vercel Blob and reachable through unguessable URLs [TO CONFIRM: file-access policy — security decision pending].
9. Your rights
Shop staff and managers (part A): you have the rights of access, rectification, erasure, portability, objection and restriction, and the right to set post-mortem directives. In practice, the administrator can export the account's data in JSON format, correct the shop's and users' information and request deletion of the account (effective after 30 days). For any other request: contact@golfspecpro.app [TO CONFIRM: address]. We reply within one month.
Shops' end customers (part B): send your request to the shop that carried out your fitting, which is the controller and which GolfSpec assists under the DPA. If you contact us directly, we forward your request to the shop concerned.
You may lodge a complaint with the French supervisory authority, the CNIL: www.cnil.fr.
10. Changes
This policy may evolve with the Service. Shops are informed by email of any substantial change at least 15 days before it takes effect; the update date appears at the top of the document.