RyderDie

Privacy Policy

Version 1.3 · Last updated September 1, 2026

RyderDie helps groups organize golf trips: building trips, entering scores, running game formats, and inviting players. This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have. We have written it to be honest about how a shared, multi-player scorecard works: because trip results are shared among a small group, data tied to one player can often be identified by the others, so we treat that data as personal even after a name is removed.

Who is responsible for your data

RyderDie ("RyderDie", "we", "us") operates this service at ryderdie.golf and is the controller of the personal data described here.

For any privacy question or to exercise your rights, contact us at privacy@ryderdie.golf.

Legal review pending: Before we open the service to users in the EU or UK, our registered legal entity, postal address, and (where required) an EU/UK representative under GDPR Article 27 will be confirmed with legal counsel and added here.

What we collect

We collect the following, most of it directly from you when you sign up and use the service:

  • Account details: your display name, email address, and password (stored only in hashed form by our authentication provider).
  • Golf profile: your handicap index and GHIN number, if you provide them.
  • Trip and scoring data: the trips, rounds, tee times, pairings, game formats, and hole-by-hole scores you create or that are entered for you.
  • Roster data others provide about you: if a trip organizer or one of their co-organizers invites you, they may enter your name, email, phone number, handicap, and GHIN so you can be added to a trip before you have an account.
  • Operational records: authentication logs kept by our provider (which include your IP address) and application logs that record which account made a change, used to run, secure, and debug the service.
  • Error reports and operational alerts: when something in RyderDie fails, our software sends an automatic diagnostic report so we can find and fix it, and it raises an alert when one of its automated operations - a payment, a subscription, a card dispute, or the deletion of an account - needs one of us to look at it. Not every alert is a fault. We strip out the personal details we can identify before these are sent; what they contain, and who receives them, is described under "Who we share it with".

Cookies

We use only strictly-necessary cookies to keep you signed in. We do not use advertising or third-party analytics cookies.

How we use your data and our legal bases

We use your data to provide and secure the service. Under the GDPR, each purpose has a legal basis:

  • To run trips, scoring, invites, and your account - performance of our contract with you (the core service cannot work without this data).
  • To keep the service secure, prevent abuse, and fix problems, including the automatic error reports described above - our legitimate interest in a safe, working product.
  • To run paid plans and to carry out an account deletion, including the operational alerts our software raises when one of those needs a person to look at it - performance of our contract with you for the paid plan, compliance with our legal obligations for a deletion request, and our legitimate interest in establishing and defending legal claims where a payment is disputed.
  • To preserve the integrity of other players' finalized results after you delete your account - our legitimate interest, using only a minimal pseudonymous record (see "How long we keep your data").
  • Any future optional features such as marketing or analytics would rely on your separate, opt-in consent, which you could withdraw at any time. We have no such features today.

Who we share it with

We share data with a small number of service providers who process it only on our instructions, and with the other members of any trip you take part in. We do not sell your personal data, and we do not share it for cross-context behavioral advertising.

  • Other trip members can see the data you contribute to a shared trip - your name, scores, and pairings for that trip.
  • If a trip organizer or one of their co-organizers turns on the public scoreboard for a trip, that board can display participants' names and their net and gross scores publicly - and because net and gross together reveal the strokes a player received, a viewer can work out their course handicap. Whether a trip's board is public is controlled by its organizer and any co-organizers they add.

Scroll sideways to see all columns.

Service providers (sub-processors)
ProviderWhat they do for usWhere
SupabaseDatabase, authentication, and hosting for your account and golf dataUnited States
VercelHosting and content delivery for the RyderDie web appUnited States
ResendSending transactional email, such as trip invitationsUnited States
StripeProcessing payments for paid plans, and sending payment receipts. Stripe receives your email address, the card details you enter directly with them - we never receive or store your card number - and identifiers for your account and the trip you are paying for, so the payment can be matched back to itUnited States
Sentry (Functional Software, Inc.)Error tracking and operational alerts: receiving the automatic diagnostic report our software sends when RyderDie fails, so we can find and fix the fault, and the alerts it raises when one of its automated operations - a payment, a subscription, a card dispute, or the deletion of an account - needs one of us to look at it. Not every alert is a fault: a dispute being opened, or refunded money arriving back, are ordinary events we have the app tell us about. Before a report or an alert is sent we remove email addresses, invitation and sign-in links wherever they appear, and your cookies, and we drop the body of anything you submitted to us. An alert leaves out the wording of the underlying error message, which a diagnostic report may still carry and which stays in our own logs; it also leaves out the identifier for your customer record with our payment provider and the reference to your checkout session, both of which our own erasure destroys, so a copy kept here would outlive that erasure. The payment, subscription and dispute references described below do remain, and our payment provider can resolve them in its own records. We do not send Sentry any advertising or usage-analytics data. What remains is technical: the error or alert and where in our code it came from, the RyderDie pages you moved through and the controls you pressed just before it, with any name shown on a control replaced by a placeholder, the requests the app made around the failure and the addresses they went to - which can include words you typed, such as a course search - the diagnostic lines logged around it, your browser type and language setting, and - where we have attached it - the random identifier for your account, which tells us that one person is affected without telling Sentry who they are. An alert about one of those operations also carries the reference numbers that identify what it concerns - the trip, the payment, the subscription, the dispute, the record, or the message our payment provider sent us - together with figures and dates describing it, such as an amount and currency, or a deadline we have to meet. An alert about one account deletion that failed carries the identifier of the request or account concerned, since that is what we are failing to erase. Diagnostic reports are sent both from your browser and from our servers; the operational alerts come from our servers only. The reports sent from your browser go to Sentry directly rather than through us, so their servers see the internet address your browser connects from, even though we do not put it in the reportUnited States

Legal review pending: Data-processing agreements (GDPR Article 28) and CCPA service-provider addenda with each provider above are being confirmed with counsel before any EU/UK launch.

Where your data is processed

Our service providers process data in the United States. If you use RyderDie from outside the United States, your data will be transferred there.

Legal review pending: The transfer safeguard for EU/UK users - Standard Contractual Clauses or the EU-US Data Privacy Framework, plus a transfer impact assessment for each provider - is being finalized with counsel before we offer the service in the EU or UK, and will be described here.

How long we keep your data

While your account is active, we keep your data so the service works.

When you ask us to delete your account, we hold it for a 30-day grace period during which the deletion can be reversed. After that, we permanently erase your directly-identifying personal data - name, email, phone, GHIN, and password - from our live systems (our database and authentication provider), completing within one month of your request. Backups and logs are handled separately, as described below.

We keep only a minimal pseudonymous participation record - your past scores and the handicap that was frozen into each finalized round - so that the other players' finalized results and competition history are not corrupted. This record is no longer tied to your name, and we keep it under our legitimate interest in the integrity of shared results.

If your account is under an active dispute or fraud investigation when you ask to delete it, we may keep a minimal record for up to 90 days to resolve it.

Backup copies are held "beyond use" - never restored except for disaster recovery - and age out on our backup-retention schedule. Our application logs and our providers' authentication, email and error-tracking logs age out on their own retention schedules.

We also record the days on which you open an event and enter scores in it, for every event you take part in. While your account is active we keep that record as part of running the service.

When you delete your account we erase that record along with everything else - except for a PAID event that you ran yourself, where we keep your own record of it for up to 180 days and then delete it automatically. We keep that much whether or not a payment has been disputed, because a card dispute can arrive months after the charge and this is the evidence that the event was used. If a payment IS disputed we keep it for up to a further 180 days while the dispute is resolved, and no longer. What is kept contains no name, email, phone, GHIN or IP address - only an internal account reference, which event, and the dates - and we keep it under our legitimate interest in establishing and defending legal claims.

Legal review pending: Our legitimate-interest assessment for the retained pseudonymous record is being reviewed with counsel before any EU/UK launch.

Your rights

Depending on where you live, you have some or all of the following rights over your personal data.

  • Under the GDPR (EU/UK): access, correction, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent where we rely on it. You may also lodge a complaint with your local data-protection supervisory authority.
  • Under the CCPA/CPRA (California): to know and access the personal information we hold, to delete it, to correct it, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising these rights. We acknowledge requests within 10 business days and respond within the timeframe the law requires.

How to exercise your rights

You can delete your account yourself from your account page, which starts a 30-day grace period during which the deletion can be reversed. For any other request, email us at privacy@ryderdie.golf and we will handle it by hand. We may need to verify your identity before acting on a request.

California: categories of personal information

For California residents, this is the personal information we collect, its sources, and why we use it. We have not sold or shared personal information, and we do not use sensitive personal information beyond providing the service.

  • We do not collect precise geolocation, biometric data, or inferences used for profiling.

Scroll sideways to see all columns.

Personal information categories under the CCPA/CPRA
CategoryExamplesSourcePurpose
IdentifiersName, email addressYou; your trip organizer and any co-organizers they addAccount, trips, invites
Account credentialsPassword (stored hashed)YouAuthenticate you
Golf informationHandicap index, GHIN number, scoresYou; your trip organizer and any co-organizers they addScoring and game formats
Internet or network activityAuthentication logs, IP address, automatic error and alert reports, and the days on which you open an event and enter scores in itAutomatically from your use; and from our payment providerRunning the service, security, debugging, running paid plans and account deletions, and showing that a paid event was used if its payment is disputed
Contact details of inviteesEmail, phone numberYour trip organizer or a co-organizer they addSend trip invitations

If you were invited to a trip

You may appear on a trip roster before you ever create a RyderDie account, because a trip organizer, or a co-organizer they added to help run the trip, added you. In that case the source of your data is that organizer or co-organizer, and we hold the contact and golf details they entered so they can invite you and run the trip.

The rights above still apply. If you do not want to be listed, contact us at privacy@ryderdie.golf and we will remove your details.

Children

RyderDie is for adults. You must be 18 or older to use it, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has given us data, contact us and we will delete it.

How we protect your data

We protect your data with database row-level security, encryption in transit, and access controls that limit who and what can read each row. No online service can promise perfect security, but we design for least-privilege access by default.

Changes to this policy

We version this policy. When we make a material change, we will update the version and ask you to accept the new one. The version and date shown at the top reflect the policy currently in force.

Contact us

For any privacy question or to exercise your rights, email privacy@ryderdie.golf.