Privacy policy
1. Who we are
Looper is a golf caddie web app. The data controller for the personal data described here is the operator named in the footer (“we”, “us”). If you want the controller’s registered details in writing, ask on the support page and we will send them.
This policy covers the Looper website and the Looper app. It is written to be read, not to be survived, so if something here is unclear that is our fault and we will fix the wording if you tell us.
2. What we collect
- Your email address. Given when you create an account or ask for a sign‑in link. Used to identify your account, to send you the sign‑in link, and to send you the small number of messages an account requires — a receipt, a warning before a price change, a notice that your subscription is ending.
- Your passkey public key. Created when you register Face ID, Touch ID, Windows Hello or a security key. It is a public key and a credential identifier. We never hold your fingerprint, your face, or any biometric data; those never leave your own device.
- Your golf settings. Units, George’s speaking speed, your handicap if you enter one, and your carry distances per club if you enter them.
- Your saved courses and rounds. The courses you have saved, and the rounds you have chosen to save, including scores and shots you recorded.
- Your location while the app is open. See section 3, which is the part most people actually care about.
- Basic technical data. Server logs containing the request, the time and an IP address, kept short‑term for security and debugging.
We do not buy personal data about you from anyone, we do not sell it to anyone, and there is no advertising in Looper, so there is no advertising profile to build.
3. Your location
Looper needs to know where you are standing to tell you how far it is. Your device’s GPS position is read only while a round is open in the app, and only after your browser has asked you and you have said yes.
Positions are processed on your device wherever possible, and sent to our server only to compute a distance or a caddie call. We do not write your positions to a location history, and we do not store a track of your walk, unless you explicitly save a round — in which case the shot positions you saved are stored with that round, on your account, because that is what makes round stats work.
Close the round and Looper stops reading your position. Deleting a saved round deletes the positions in it.
4. George’s voice
George is a synthetic voice. His lines are generated from text on our server and cached as audio files so they play instantly and work without a signal. That cache is keyed to the hole and the number, not to you.
Looper does not listen to you. There is no microphone permission, no voice input and no recording of anything you or your playing partners say.
5. Course contributions are public
When you tag or correct a hole on a public course — a tee position, a green centre, a bunker edge, a carry number — that geometry becomes part of the public course record and is served to other golfers who play there. That is the whole point of it.
Contributed geometry is not published with your name or email attached. Course geometry you import under a licence that is personal to you is marked private to your account and is never served to another account.
6. Payment
Stripe processes all payments. Your card number, expiry and security code go to Stripe and never touch our servers — we never see them and cannot store them. We hold the Stripe customer and subscription identifiers, your tier, and whether the subscription is active, so the app knows what to unlock. Stripe’s own privacy notice governs what Stripe does with your payment data as a controller in its own right.
7. Analytics and cookies
We use a self‑hosted, cookieless analytics tool (Umami) to count page views and a handful of product events — a caddie call, a sign‑up, a checkout started. It sets no cookies, records no cross‑site identifier, and does not follow you anywhere else on the internet.
The only cookies Looper sets are the ones that make it work: a signed session cookie so you stay logged in, and a short‑lived cookie during sign‑in. They are strictly necessary, so there is no consent banner to click away.
8. Lawful basis
- Contract — your account, your settings, your location while you use the app, your subscription. We cannot give you a caddie without them.
- Legitimate interests — keeping the service up and secure, and counting anonymous usage so we know which features are worth building.
- Legal obligation — keeping transaction records for tax and accounting.
9. How long we keep it
- Account data — while your account exists, and then removed within 30 days of you deleting it.
- Saved rounds — until you delete the round or the account.
- Server logs — 30 days.
- Analytics events — retained in aggregate; they contain no name, email or account identifier.
- Payment and invoice records — six years, because UK tax law says so, and held in the smallest form that satisfies it.
10. Deleting your account
You can delete your Looper account yourself, from your account page, without emailing anyone and without waiting for us to reply. It is a button, it asks you once to confirm, and then it is done.
Deletion removes your email address, your passkeys, your settings, your carry distances, your saved courses and your saved rounds within 30 days, including from backups as those backups age out. Public course geometry you contributed stays, because other golfers are using it and nothing in it identifies you. Invoice records are kept for the statutory period in section 9 and nothing else.
11. Your rights
Under the UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another service in a portable format. Ask on the support page from the address on your account. We will answer within one month.
If you think we have handled your data badly, tell us first — and if we do not put it right you can complain to the Information Commissioner’s Office at ico.org.uk.
12. Where the data sits
Looper runs on servers in Europe. Some of the services we depend on — payment, transactional email — may process data outside the UK; where they do, the transfer is covered by the UK’s approved safeguards, such as the International Data Transfer Addendum to the standard contractual clauses.
13. Changes and contact
If we change this policy in a way that matters we will say so on this page and, for anything significant, email account holders before it takes effect. Older versions are available on request.
Everything goes through the support page, which a person reads.
that is genuinely all of it