Privacy Policy
Last updated: 14 September 2026 · Version 3.0
This policy explains what personal data we process when you use BookrGo, for what purpose and on what legal basis, who we share it with and how you can exercise your rights.
1. Data Controller
The data controller for your personal data is Carlos Bernal, an individual operating the BookrGo service (hereinafter "we" or "the Service"), based in Spain for data processing purposes. You can contact us at [email protected] for any queries related to the protection of your data.
2. Data We Collect
We collect the following personal data:
- Account data: name, email address and password (stored in bcrypt-hashed form).
- Location data: approximate geographic coordinates (latitude and longitude), provided voluntarily to display nearby courts.
- Payment data: managed entirely by Stripe. We do not store card numbers or full banking details; we only retain Stripe transaction identifiers.
- Push notification tokens: device identifiers for sending notifications via Firebase Cloud Messaging.
- Usage data: bookings made, group, club and tournament membership, ELO history.
- Billing data: when a venue issues invoices through BookrGo (Verifactu), we process on the venue's behalf the tax details required (name or company name, tax ID and address) of the venue and of the invoice recipients and, if the venue has enabled submission, we send them to the Spanish Tax Agency under the Verifactu system.
3. Legal Basis for Processing
We process your data on the basis of:
- Contractual performance (Art. 6(1)(b) GDPR): necessary to provide the booking service, manage your account and process payments.
- Consent (Art. 6(1)(a) GDPR): for sending push notifications and using location data.
- Legitimate interest (Art. 6(1)(f) GDPR): for service security, fraud prevention and product improvement.
4. Purpose of Processing
We use your data to:
- Create and manage your user account.
- Enable the booking of sports courts and group management.
- Process payments and subscriptions through Stripe.
- Send notifications about your bookings, groups and tournaments.
- Show courts near your location.
- Calculate and maintain the ELO ranking in tournaments.
5. Third Parties and Processors
We share data with the following providers, strictly to provide the service:
- Stripe (stripe.com): payment processing. Stripe acts as an independent data controller for payment data.
- Firebase / Google Cloud (firebase.google.com): push notification delivery.
- Resend (resend.com): transactional email sending.
- Cloudflare (cloudflare.com): CDN, DDoS protection and DNS.
- Hetzner (hetzner.com): server hosting (location: Falkenstein, Germany, EU).
- Sentry (sentry.io): error and performance monitoring for technical diagnostics of the service.
- Awin (awin.com): affiliate network that manages outbound affiliate links and click attribution when you choose to follow one of those links.
We do not sell, rent or share your personal data with third parties for marketing purposes.
6. International Data Transfers
Our servers are located in the European Union (Germany). Some of our providers (Stripe, Firebase, Cloudflare, Sentry) may process data outside the EEA. In these cases, transfers are carried out under standard contractual clauses approved by the European Commission or other transfer mechanisms recognised by the GDPR.
7. Data Retention
We retain your personal data for as long as your account remains active. If you request account deletion, your personal data will be anonymised and associated records will be permanently deleted after a 30-day retention period (soft delete). Payment data is retained in accordance with applicable tax and legal obligations.
8. Your Rights
Under the GDPR, you have the right to:
- Access: obtain a copy of your personal data (available under Account > Export data).
- Rectification: correct inaccurate data from your profile.
- Erasure: delete your account and associated data (available under Account > Delete account).
- Portability: receive your data in structured JSON format.
- Restriction of processing: request the restriction of how your data is used.
- Objection: object to processing based on legitimate interest.
- Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
To exercise these rights, contact [email protected].
9. Cookies, local storage, analytics and advertising
BookrGo uses a strictly necessary session cookie for authentication of the administration panel. This cookie is HttpOnly, Secure and SameSite=Strict, and does not require consent under Article 22.2 of the LSSI.
The mobile and web application uses device local storage (SharedPreferences / localStorage) to save the authentication token, language and theme preferences, and consent preferences.
Our own measurement: we measure anonymous, aggregated traffic. Most of it is computed on our server, storing nothing on your device. To tell whether our pages get repeat visits we also store a first-party measurement identifier (bg_vid): a random number carrying no data about you, kept in your browser for at most 13 months, never leaving our domain, never shared with third parties and never linked to your account. It is used only for aggregated statistics about this site — never to profile you or personalise what you see — which is why it falls under the audience-measurement exemption. You can delete it at any time by clearing your browser storage.
Web analytics: on our public website we may enable Google Analytics with your consent; only then is it loaded in your browser.
Web advertising: some indexable public pages may show Google AdSense ads. Google and its partners may use cookies to serve and measure ads.
Mobile advertising: the mobile application may show Google AdMob ads to users without Premium. Before requesting personalised mobile ads, we ask for consent through Google UMP. Premium users do not see advertising.
Communications: notifications about your bookings, groups, matches and tournaments are part of the service (contractual performance). Promotional communications —by email or push notification— are only sent if you have given your marketing consent, which you can withdraw at any time from your profile without affecting your use of the service.
10. Security
We implement technical and organisational measures to protect your data:
- Passwords hashed with bcrypt (we do not store passwords in plain text).
- Authentication via JWT with short-lived tokens (15 minutes) and rotating refresh tokens.
- Encrypted communications via HTTPS/TLS on all connections.
- Protection against brute-force attacks with rate limiting and temporary account lockout.
- Administration panel protected with two-factor authentication (TOTP).
11. Minors
The Service is intended for persons aged 16 and over. We do not intentionally collect data from children under 16. If you are aware that a minor has provided personal data, please contact us to arrange its deletion.
12. Changes to This Policy
We reserve the right to modify this Privacy Policy. In the event of material changes, we will notify you through the application or by email. The date of the last update is indicated at the beginning of this document.
13. Contact and Complaints
For any queries about data protection, you can contact us at [email protected].
If you believe that the processing of your data is not appropriate, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
Related documents: Terms of Use, Acceptable Use, Venue Terms and Legal Notice.
14. Automated court access control (smart locks)
When a venue enables automated access control on a court, confirming your booking generates a temporary credential (a code or digital permit) that lets you enter through the relevant door during your slot's time window, and we record which door was opened for you and when. This record also serves as the venue's access audit trail.
What we process: the booking the access corresponds to, the door and venue, the validity time window, the credential's status (issued, delivered, revoked) and, if the lock provider requires it, the code itself. We do not use fingerprints, facial recognition, or any other biometric data: the providers we support work with codes or digital permits.
Why we process it: to deliver what you booked (letting you into the court) and, based on the venue's legitimate interest, so it can resolve incidents or disputes about who accessed its facilities and when. We do not ask for your consent for this because it is an inseparable part of booking a court with automated access — just as we do not ask for consent to process your booking payment.
Who processes this data: depending on the venue and the specific use, both the venue (for the management and security of its own facility) and BookrGo (to deliver your credential and operate the system) may act as controllers for different purposes over this same record. We are finalizing in writing the exact allocation of responsibilities with venues; you can ask us for details at [email protected].
How long we keep it: between 90 and 365 days depending on the venue's plan; an automated job purges these records once that period elapses.
Your rights: you can request access to or erasure of this record just like the rest of your data (see the "Your Rights" section of this policy), by writing to [email protected].
15. California & U.S. State Privacy Rights (CCPA/CPRA)
DRAFT: this section is being finalized with U.S. legal counsel ahead of our U.S. launch and may change. It supplements the rest of this policy for residents of California and other U.S. states with comparable privacy laws.
Categories of personal information we collect: identifiers (name and email address); internet or other electronic network activity (app and site usage); approximate geolocation (only when you grant permission); commercial information (bookings you make within a community); and inferences drawn from the above. We do not use sensitive personal information to infer characteristics about you.
Your rights (subject to legal limits and identity verification):
- Know / access the categories and specific pieces of personal information we have collected about you.
- Delete personal information we collected from you.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of your personal information.
- Non-discrimination for exercising these rights.
Do Not Sell or Share My Personal Information: we do not sell your personal information for money. However, when advertising cookies are used on our public web pages (for example, Google AdSense), this may qualify as a "sale" or "sharing" for cross-context behavioral advertising under the CCPA/CPRA. You can opt out using the "Do Not Sell or Share My Personal Information" link in our website footer. We also honor the Global Privacy Control (GPC) browser signal automatically: when GPC is enabled we treat it as a valid opt-out and do not enable advertising cookies. Premium users do not see advertising.
How to exercise your rights: use the privacy controls in the app and on our website, or email [email protected]. We aim to respond within 45 days, with one possible 45-day extension where permitted by law. You may use an authorized agent to submit a request on your behalf; we may ask you to verify your identity before acting.