Privacy Policy
How Grip collects, uses and protects your personal data.
Last updated · August 2026
This policy explains what personal data Grip collects, why we collect it, who we share it with and what rights you have. It applies to the Grip mobile application and this website. Grip operates in the United Kingdom and European Union, and this policy is written to meet UK GDPR and EU GDPR requirements.
Grip is the data controller for the personal data described here. For any question about this policy, or to exercise your rights, contact [email protected].
1. Data we collect
When you register for and use the Grip app, we collect:
- Account and profile data — name, email address, date of birth, gender, profile photograph, handicap, home course and playing preferences.
- Activity data — the general location region you set, your availability, messages and conversations, friend connections, saved calendar events and tee-time activity.
- Technical data — device type, operating system, app version and diagnostic information collected when an error occurs.
- Notification data — your notification settings and device push tokens.
Where you sign in with Apple or Google, we receive your name and email address from that provider. We do not receive your password.
2. Why we process it, and our lawful basis
Under UK and EU GDPR we must have a lawful basis for processing your data. Ours are as follows:
- To provide the service — creating your account, matching you with playing partners, messaging, courses, trips and notifications. Basis: performance of our contract with you.
- To keep the community safe — reviewing reports, moderating content and enforcing our Community Guidelines. Basis: our legitimate interest in a safe service, and our legal obligations.
- To improve the app — analysing which features are used and where errors occur. Basis: our legitimate interest in improving the service.
- Location — showing you nearby golfers and venues. Basis: your consent, which you may withdraw at any time in your device settings.
- To meet legal obligations — responding to lawful requests and retaining records where required. Basis: legal obligation.
We do not sell your personal data, and we do not use it to make automated decisions producing legal or similarly significant effects.
3. The Grip website
Before launch, this website allows you to join a waitlist by submitting your email address. We use it solely to notify you when Grip becomes available, on the basis of your consent. You may ask us to remove it at any time at [email protected].
4. Who your data is shared with
Other Grip users see the profile fields you choose to display — typically your first name, handicap and general area. Your precise location is never shown to other users. We also use the following processors, each bound by contract to process data only on our instructions:
- Supabase — database, authentication and file storage (EU/US servers).
- Firebase Cloud Messaging — delivers push notifications.
- Expo — app builds and over-the-air updates.
- Sentry — crash and error reporting. Receives diagnostic data when something goes wrong, which may include your user ID, device model, OS version and the screen you were on.
- Mixpanel — product analytics. Receives usage events such as screens viewed, features used and searches performed, linked to your user ID, so we can see how Grip is used and improve it (EU servers).
- Resend — email delivery. When you report another member, the report is emailed to our safety team so we can act on it quickly. That email contains the report reason and the user IDs and display names of the member reported and the member reporting.
We do not sell your personal data, and no processor is permitted to use it for its own purposes. We may also disclose data where required by law, to protect the rights or safety of our users or the public, or in connection with a merger or acquisition, in which case we will notify you.
5. Your rights
Under UK and EU GDPR you have the right to:
- Access a copy of the personal data we hold about you
- Have inaccurate or incomplete data corrected
- Have your data erased, including by deleting your account
- Restrict how we process your data
- Receive your data in a portable, machine-readable format
- Object to processing carried out on the basis of our legitimate interests
- Withdraw consent at any time where our processing relies on it
To exercise any of these rights, contact [email protected]. We will respond within 30 days. You can delete your account directly in the app; see our account deletion page.
You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). In the European Union it is the Data Protection Authority for your member state.
6. Retention
We retain your data for as long as your account remains active. When you delete your account, your personal data — including your profile, your photograph and any images you have uploaded — is deleted permanently and cannot be recovered. We retain only those limited records we are required to keep by law, such as safety reports where applicable. Messages you have sent may remain visible to their recipients, attributed to a deleted user. Waitlist email addresses are retained until launch, or until you ask us to remove them.
7. Where your data is stored
Your data is held on Supabase servers within the European Union. Certain processors, including Firebase Cloud Messaging and Expo, may process data outside the UK and EU. Where this occurs, the transfer is covered by an adequacy decision or by Standard Contractual Clauses approved for UK and EU transfers.
8. Security
We apply technical and organisational measures appropriate to the risk. Data is encrypted in transit and at rest. Access is enforced at database level by row-level security, so your records are reachable only by you and, where a feature requires it, by the users you have shared them with. Authentication tokens are stored in your device's secure keychain. No system is entirely secure, but where a breach is likely to result in a risk to your rights and freedoms we will notify you and the relevant supervisory authority within 72 hours.
9. Data stored on your device
Grip does not use advertising or tracking cookies. The app stores a small amount of data locally on your device: your authentication token, your app preferences and cached content for performance. This is cleared when you sign out or uninstall the app.
10. Children
Grip is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we hold data relating to a person under 18, contact [email protected] and we will delete it promptly.
11. Changes to this policy
We may update this policy from time to time. We will revise the date shown above and, where a change is material, notify you within the app.
12. Contact
Privacy enquiries and data rights requests: [email protected]. General support: [email protected].