Privacy Policy

Last Updated: May 22, 2025

Fore Advantage Golf ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and services (collectively, the "Service"), accessible via foreadvantagegolf.com. The Service is designed to help users monitor and receive notifications for available golf course tee times based on their specified filters. It does not facilitate direct bookings. Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.

1. Information We Collect

We may collect information about you in a variety of ways. The information we may collect via the Service includes:

a. Personal Data:

Personally identifiable information that you voluntarily provide to us when you register for an account, make a booking, or otherwise interact with the Service. This includes:

b. Account Information:

Your email address and unique user ID (sub). We use Google Sign-In, so we do not store your password.

c. Profile Data:

While not explicitly detailed as mandatory, we may collect information you voluntarily provide, such as your name or preferences, if you choose to add it to your profile.

d. Notification Filter Data:

Information related to your tee time search preferences, such as desired golf courses, dates, times, number of players, etc., used to provide notifications.

e. Notification Preferences:

Your choices for receiving notifications (e.g., email, Telegram), including your email address or Telegram identifier, and the status of these notifications (enabled, verified, primary).

f. Favorites:

Information about courses or filter preferences you save as favorites.

Derivative Data (Automatically Collected Information):

Information our servers automatically collect when you access the Service, such as:

  • Session Data: We use NextAuth.js which utilizes JWT tokens and session cookies for authentication and session management.
  • API Requests: Logs of your API usage, including the requests made, error messages, and status codes. This is standard operational data.
  • Timestamps: We log timestamps for various activities like data fetches, bookings, and notification dispatches for operational and analytical purposes.
  • Search History: Your search queries and the results you view to improve your experience and for analytical purposes.

c. Financial Data:

All payment information for any Service subscriptions is processed by Stripe. We do not directly collect or store your full payment card information. We collect and store your Stripe customer ID and information about your payment status and subscription details as provided by Stripe to manage your account and any subscriptions.

d. Data from Third Parties:

  • ForeUp: We fetch live tee time data from ForeUp. We do not send your personal data to ForeUp. Our queries to ForeUp are for course schedules and availability based on your search criteria.

2. How We Use Your Information

Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the Service to:

  • Create and manage your account.
  • Process any subscriptions and deliver the notification services.
  • Send you notifications about potential tee time availability based on your filters and preferences.
  • Display your saved favorites and search/filter history.
  • Monitor and analyze usage and trends to improve your experience with the Service.
  • Prevent fraudulent transactions, monitor against theft, and protect against criminal activity related to Service subscriptions.
  • Respond to your customer service requests.
  • Comply with legal and regulatory requirements.
  • Operate and maintain the Service, including caching tee time data (polled from ForeUp) for performance of the notification service.
  • Administer your account and provide you with customer support, including processing account deletion requests.

3. Disclosure of Your Information

We may share information we have collected about you in certain situations. Your information may be disclosed as follows:

a. By Law or to Protect Rights:

If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation.

b. Third-Party Service Providers:

We may share your information with third parties that perform services for us or on our behalf, including:

  • Payment Processing: Stripe, for processing payments for any Service subscriptions. (User email, user ID, and payment details are sent to Stripe).
  • Authentication: Google Sign-In (via NextAuth.js) for user authentication.
  • Notification Delivery: Providers for email (SES), Telegram, and SMS (SES) for delivering notifications. (User identifiers and notification content are shared).
  • Tee Time Data: ForeUp for fetching live tee time data. (No personal user data is sent to ForeUp).

These third parties are obligated to protect your information and are typically bound by their own privacy policies.

c. Business Transfers:

We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

d. With Your Consent:

We may disclose your personal information for any other purpose with your consent.

We do not sell your personal information to third parties.

4. Data Storage and Security

a. Data Storage:

Your personal data, notifications, favorites, and tee time cache are stored in DynamoDB, hosted on AWS. Payment and subscription data (except for references like Stripe customer ID) are stored by Stripe.

b. Security Measures:

We use administrative, technical, and physical security measures to help protect your personal information. These include:

  • Authentication: Secure authentication via NextAuth.js using JWTs and secure cookies (in production).
  • Authorization: Requiring authentication for all sensitive API routes.
  • Data Encryption: While not explicitly stated for all data at rest in DynamoDB, industry best practices are followed (e.g., HTTPS for data in transit).

While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.

5. Data Retention

We will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

  • User Data (Account Information, Profile, Favorites, Notification Filters, Notification Preferences, Search History): Retained until you delete your account. Upon account deletion, this data (including associated billing information references in our system for any subscriptions) is removed.
  • Tee Time Cache Data: Stored in DynamoDB with a Time-to-Live (TTL) and automatically expires after 30 minutes. This cache is based on data polled from ForeUp.
  • Payment Data (for Subscriptions): Retained by Stripe as required by their policies and legal obligations. We retain references (like Stripe Customer ID) as long as your account is active or as needed for financial reconciliation of subscriptions.

6. Your Rights and Controls

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right to Access: You can access most of your personal data through your user dashboard and via API (if applicable). You can also request a copy of the personal data we hold about you.
  • Right to Correction (Rectification): You can correct or update your account information through your settings. For other corrections, please contact us.
  • Right to Deletion (Erasure): You can delete your account through the user dashboard or by contacting us. This will trigger the deletion of your personal data from our systems, subject to our data retention policies (e.g., legal obligations).
  • Right to Manage Notifications: You can manage your notification methods (email, Telegram, etc.) and preferences through your account settings.
  • Right to Object or Restrict Processing: In certain circumstances, you may have the right to object to or request the restriction of the processing of your personal data.
  • Right to Data Portability: You may have the right to receive your personal data in a structured, commonly used, and machine-readable format.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within a reasonable timeframe and in accordance with applicable law.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to operate and personalize the Service.

  • Session Cookies: NextAuth.js uses session cookies (JWT-based) for authentication and to maintain your session. These are essential for the Service to function.
  • Other Cookies/Tracking: Currently, we do not explicitly mention the use of analytics or tracking cookies for advertising purposes. If this changes, this policy will be updated. [Consider if you use any analytics like Google Analytics, Vercel Analytics, etc., and update accordingly.]

You can typically remove or reject cookies via your browser settings. Please note that if you disable cookies, some features of the Service may not function properly.

8. Children's Privacy

The Service is not intended for use by children under the age of 13 (or a higher age threshold where applicable by local law, e.g., 16 in the EEA/UK). We do not knowingly collect personal information from children under this age. If we learn that we have collected personal information from a child under the relevant age without parental consent, we will take steps to delete that information as soon as possible. If you believe we might have any information from or about a child under the relevant age, please contact us at [email protected].

9. International Data Transfers

Your information, including personal data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including personal data, to the United States and process it there (as DynamoDB is hosted on AWS, and development is likely US-based).

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your personal data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us: