Privacy Policy
Last updated: July 26, 2026
1. Who we are
The data controller for your personal data is Carlos Bernal, an individual operating the BookrGo sports court booking platform, based in Spain. You can contact us at [email protected].
2. What data we collect
We collect the following personal data when you use our service:
- Account information: name, email address, and encrypted password.
- Booking history: records of court reservations you make or participate in.
- Device tokens: for sending push notifications (only with your consent).
- Location data: approximate location used to find nearby courts (only when you grant permission).
- Usage data: interactions within the app to improve the service (analytics).
- Payment data: processed securely by Stripe; we never store card details.
3. How we use your data
We use your personal data to:
- Provide and maintain the court booking service.
- Send relevant notifications about your bookings, matches, and communities.
- Improve and personalize your experience within the app.
- Process payments for subscriptions.
- Ensure the security and integrity of the platform.
4. Legal basis for processing
We process your data under the following legal bases:
- Consent: for push notifications, location access, and analytics cookies.
- Contract performance: to provide the booking service you signed up for.
- Legitimate interest: to improve the platform, prevent fraud, and ensure security.
5. Data sharing
We share your data only with the following third-party processors, strictly to provide the service:
- Stripe: payment processing (PCI DSS compliant).
- Firebase (Google): push notifications, analytics, and crash reporting.
- Resend: transactional email delivery.
- Google AdSense: third-party advertising on our public web pages. Google and its partners may use cookies to serve and measure ads.
- Affiliate networks (Awin): some links to sports gear are affiliate links; we may earn a commission, at no extra cost to you.
We do not sell, rent, or trade your personal data to third parties.
6. Data retention
We retain your personal data for as long as your account is active. If you delete your account, your data is soft-deleted and permanently removed after 30 days. You may request immediate deletion by contacting us.
7. Your rights
Under the GDPR and applicable data protection laws, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Deletion: request deletion of your data ("right to be forgotten").
- Data export: download your data in a portable format.
- Object: object to data processing based on legitimate interest.
- Withdraw consent: at any time, without affecting prior processing.
You can exercise these rights from the app (Account > Settings) or by emailing [email protected].
8. Cookies
We also measure anonymous, aggregated traffic server-side, without cookies or identifiers stored on your device, under our legitimate interest; this measurement needs no consent. In addition we use the following types of cookies:
- Essential: authentication tokens required for the service to function.
- Analytics: with your consent, to understand usage patterns (Google Analytics, loaded client-side only after you accept).
- Advertising: with your consent, third parties including Google (AdSense) and its partners use cookies to serve ads based on your prior visits to this and other websites. You can opt out of personalised advertising in Google Ads Settings or at aboutads.info.
9. Children
BookrGo is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Data security
We implement industry-standard security measures to protect your data:
- All communications over HTTPS/TLS encryption.
- Passwords hashed with bcrypt (never stored in plain text).
- Authentication via JWT tokens with expiration.
- Rate limiting and brute-force protection.
- Regular security reviews.
11. International transfers
Your data is stored on servers in the European Union (Hetzner, Germany). We do not transfer your data outside the EU except through third-party processors (Stripe, Firebase, Resend) that comply with EU data transfer regulations and maintain adequate safeguards.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app or email. Continued use of the service after changes constitutes acceptance of the updated policy.
13. Contact
If you have any questions about this Privacy Policy or how we handle your data, please contact us at [email protected].
14. Automated court access control (smart locks)
When a venue enables automated access control on a court, confirming your booking generates a temporary credential (a code or digital permit) that lets you enter through the relevant door during your slot's time window, and we record which door was opened for you and when. This record also serves as the venue's access audit trail.
What we process: the booking the access corresponds to, the door and venue, the validity time window, the credential's status (issued, delivered, revoked) and, if the lock provider requires it, the code itself. We do not use fingerprints, facial recognition, or any other biometric data: the providers we support work with codes or digital permits.
Why we process it: to deliver what you booked (letting you into the court) and, based on the venue's legitimate interest, so it can resolve incidents or disputes about who accessed its facilities and when. We do not ask for your consent for this because it is an inseparable part of booking a court with automated access — just as we do not ask for consent to process your booking payment.
Who processes this data: depending on the venue and the specific use, both the venue (for the management and security of its own facility) and BookrGo (to deliver your credential and operate the system) may act as controllers for different purposes over this same record. We are finalizing in writing the exact allocation of responsibilities with venues; you can ask us for details at [email protected].
How long we keep it: between 90 and 365 days depending on the venue's plan; an automated job purges these records once that period elapses.
Your rights: you can request access to or erasure of this record just like the rest of your data (see the "Your Rights" section of this policy), by writing to [email protected].
15. California & U.S. State Privacy Rights (CCPA/CPRA)
This section is being finalized with U.S. legal counsel ahead of our U.S. launch and may change. It supplements the rest of this policy for residents of California and other U.S. states with comparable privacy laws.
Categories of personal information we collect. In the past 12 months we may have collected the following categories: identifiers (such as name and email address); internet or other electronic network activity (such as app and site usage); approximate geolocation (only when you grant permission); commercial information (such as bookings you make within a community); and inferences drawn from the above. We do not use sensitive personal information to infer characteristics about you.
Your rights. Subject to legal limits and identity verification, you have the right to:
- Know / access: request the categories and specific pieces of personal information we have collected about you.
- Delete: request deletion of personal information we collected from you.
- Correct: request correction of inaccurate personal information.
- Opt out of the "sale" or "sharing" of your personal information (see below).
- Non-discrimination: we will not discriminate against you for exercising these rights.
Do Not Sell or Share My Personal Information. We do not sell your personal information for money. However, when advertising cookies are used on our public web pages (for example, Google AdSense), this may qualify as a "sale" or "sharing" for cross-context behavioral advertising under the CCPA/CPRA. You can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer. We also honor the Global Privacy Control (GPC) browser signal automatically: when GPC is enabled we treat it as a valid opt-out and do not enable advertising cookies. Communities on paid plans do not see advertising.
How to exercise your rights. Use the privacy controls in the app and on our website, or email [email protected]. We aim to respond within 45 days, with one possible 45-day extension where permitted by law. You may use an authorized agent to submit a request on your behalf; we may ask you to verify your identity before acting.