How we look after your information
Last updated 29 September 2026 · Applies to theguestbook.golf, waitlist.theguestbook.golf and The Guest Book app
The Guest Book introduces golfers — members willing to host, golfers hoping to be hosted, and anyone in want of a fourth. Doing that properly means holding some of your personal information, and this page explains exactly what we hold, why, and what your rights are. We have tried to write it the way we write everything else: plainly.
1. Who we are
The Guest Book is operated by The Guest Book Ltd, a company registered in England and Wales under company number 17391490, whose registered office is Apartment 2303, 12 Bankside Boulevard, Salford, M3 7HZ, United Kingdom. We are the data controller for the information described here. For anything in this policy, contact hello@theguestbook.golf — that inbox is read by the founders, not a department.
2. What we collect, and why
How you sign in
You open an account with an email address and a password, and you sign in with the same two on any phone — which is what lets your card follow you from one device to the next. We confirm the address by emailing you a short code to type back into the app, and we use it afterwards to reach you about your own account and to let you set a new password if you forget one. Your password is stored only as a one-way hash: nobody here can read it, and we cannot tell you what it is. Lawful basis: performing our contract with you.
Anyone may join. A club or founder code is optional and adds something rather than opening the door: your club’s own code places you in that club’s room, vouched for by the club, and a founder code from the waitlist carries the offer that came with it. Without a code, everything else works exactly the same.
Your member card
- Name, home club, handicap, your one-line profile, ways to play, availability — this is your profile; it exists so other members can decide whether to play with you. Lawful basis: performing our contract with you.
- Photo (optional) — shown on your card if you add one.
- Gender (optional) — powers the “play with women / men” filter. It is never shown on your card. Lawful basis: your consent; leave it unanswered and everything still works.
Your date of birth
The Guest Book is for adults. We ask your date of birth once, at signup, to confirm you are 18 or over — and we store only the confirmation, not the date itself. Lawful basis: legal obligation and legitimate interest in keeping the service adult-only.
Age works on declaration: we rely on what you tell us, as our Terms explain, and a false declaration ends a membership. If you suspect a member is under 18, email hello@theguestbook.golf — reports are reviewed promptly, handled discreetly, and kept as safety records (see section 5). Where a report is upheld we remove the account and delete its data, and we will pass information to the authorities where the law requires or child safety demands it.
Your mobile number
We ask for a mobile number at signup and verify it by text. We use it to: (a) confirm you are a real, reachable person — one member, one number; (b) let a host or guest be reached if plans change on the day of a round; and (c) support the first-tee check-in safety feature. It is never shown on your card and never sold. Verification texts are sent through Twilio (see section 4). Lawful basis: performing our contract with you, and our legitimate interest in member safety.
Your location
If you allow it, we use your device’s approximate location to show golfers nearest you first. Location is only read when you grant the permission your browser or device asks for, and saying no leaves the app fully usable. Lawful basis: your consent, withdrawable at any time in your device settings.
Notifications
The iPhone app can send you notifications, and only if you turn them on. If you do, we store the device token Apple gives your iPhone against your card, so that we know where to send them, and the text of each notification passes through Apple’s push service to reach your phone. We send only the kinds you have switched on in My Card. The token is deleted when you turn notifications off on that phone, sign out, or delete your account. It is never used for advertising and never shared with anyone else. Lawful basis: your consent, withdrawable at any time in My Card or in your device settings.
What you do in the app
- Invitations and matches — who you invite and who invites you, so introductions can be made.
- Messages, posts, notes, reactions and vouches — the things you write, and any photo you attach to a post. An etiquette filter runs on-device; content that breaks the house rules is altered or refused before it is stored.
- Tee times, check-ins and scorecards — the golf you arrange and record, including no-shows, which may be noted against a profile as part of the safety features.
The waitlist
The waitlist form collects your first name, email address, location and (optionally) handicap and home club, so we can invite you when your card is ready and honour the waitlist offer. Lawful basis: taking steps at your request prior to entering a contract.
Payments
There are none. Membership is free, and the app takes no payments at all — we do not ask for a card, hold card details, or run any payment processing. There is no payment data for us to collect, and none is passed to anyone.
What we deliberately do not do
- No advertising trackers, no analytics profiles sold to anyone, no data brokers.
- Local storage on your device is used only to keep you signed in and remember your settings — the strictly necessary kind, which is why there is no cookie banner.
- We do not send marketing texts and we do not send marketing email. Your number is for verification and the day of your round. Your address is for signing in, confirming that the address is yours, resetting a password, and anything we have to tell you about your own account.
3. Who can see what
Your member card — name, photo, club, handicap, line, ways to play — is visible to other members; that is the point of the book. Your email address, mobile number, gender and date-of-birth confirmation are never visible to other members, and your password is not visible to anyone, ourselves included. Messages are visible only to the people in the conversation.
4. Who processes data for us
We use a small number of service providers, each bound by their own data-processing terms:
| Provider | What they do for us | Where |
|---|---|---|
| Supabase | Database and sign-in — all member data, including your email address and the one-way hash of your password | London, UK |
| Netlify | Website hosting and the waitlist form | US/global CDN, under standard safeguards |
| Twilio | Sending verification texts (your number, for delivery only) | US, under standard safeguards |
| Google Workspace | Our email — messages you send to hello@, and the confirmation and password-reset codes we send to you | UK/EU/US, under standard safeguards |
Where a provider processes data outside the UK, transfers rely on UK adequacy decisions or the UK International Data Transfer Addendum / Standard Contractual Clauses.
The club register — the names and locations of golf clubs — is built from OpenStreetMap data, © OpenStreetMap contributors, made available under the Open Database Licence.
5. How long we keep things
- Your account — for as long as you are a member. Your email address and the hash of your password are part of the account and go when it goes. You can delete it yourself in the app; ask us instead and we will do it within 30 days.
- The waitlist — until you become a member or ask to come off it.
- Messages and posts — while the accounts involved exist.
- Safety records (check-ins, reports) — up to 24 months, because their purpose is protecting members over time.
6. Your rights
Under UK data protection law you can ask us, at any time, to:
- show you the data we hold about you (access);
- correct anything wrong (rectification);
- delete your data (erasure — “take me out of the book”);
- hand it over in a portable format;
- restrict or object to particular processing;
- withdraw consent where consent is the basis (gender, location) — without affecting anything else.
Email hello@theguestbook.golf and we will respond within one month. If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk — though we would rather you told us first so we can put it right.
7. Security
Member data lives in a UK-hosted database protected by row-level security, so the database itself enforces who may read what. Connections are encrypted in transit. Passwords are never held in a form anyone can read — only as a one-way hash, which is why a forgotten password is reset rather than looked up. We take no payments, so there are no card details to store or to lose. No system is perfect; if a breach ever puts your data at risk we will tell you and the ICO as the law requires.
8. Changes
If this policy changes in any way that matters, we will say so in the app before the change takes effect — not bury it. The “last updated” date at the top always tells you the current version.