Privacy at OpenTees

Clear about your data.
Careful with it.

This notice explains what personal information OpenTees uses, why we use it, who receives it and the choices you have.

Effective 24 August 2026

01

Built around your preferences

We use the details you provide to find and rank tee times that suit how you like to play.

02

Not a data marketplace

We do not sell your personal information. We share it only where needed to operate, protect and improve OpenTees.

03

You remain in control

You can update your preferences, unsubscribe from marketing and exercise your data-protection rights.

01

Overview and who is responsible

OpenTees recommends personalised golf tee-time opportunities. It is not a booking platform: when you choose to view or book a tee time, you are sent to the relevant golf course or third-party booking provider.

For UK data-protection law, the controller responsible for the personal information described in this notice is OpenTees Ltd.

Trading nameOpenTees

CompanyOpenTees Ltd, company number 17371624

Registered inEngland and Wales

Registered office71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Privacy emailhello@open-tees.com

02

Information we collect

Depending on how you use OpenTees, we may process:

  • Identity and contact information: your name, email address and information you provide when contacting us.
  • Location information: your postcode, chosen search area and travel radius. We use this to identify relevant courses; we do not need precise live GPS location for the current service.
  • Golf preferences: preferred courses, days, tee-time windows, budget, player count and other choices you submit.
  • Recommendation information: matches, scores, reasons and other inferences generated from your preferences and available tee times.
  • Course requests: requested course, email, location and any optional notes you submit.
  • Acquisition information: when you sign up, we automatically record the page you landed on, the website that referred you, and any campaign parameters (UTM values) present in the link you followed. If you arrived via a paid ad, we record which type of click-tracking parameter was present (for example, that it was a Google Ads click) — never the click identifier itself. Separately, if you choose to answer it, we record your own single answer to "How did you hear about OpenTees?" on the confirmation screen after you save your preferences. This is optional, and distinct from the automatic record above.
  • Usage and interaction information: recommendation and email interactions, links selected, outbound booking clicks, pages or features used, and timestamps.
  • Technical and security information: IP address, browser or device information, diagnostic records, request logs and security events generated when you use the website or service.
  • Communication and consent records: support messages, email delivery status, marketing choices, unsubscribe requests and evidence of consent where applicable. If you unsubscribe, you can optionally tell us why from a short list of reasons (or your own brief note) — this is entirely optional, is never required to unsubscribe, and we use it only to understand and improve the service.

We generally collect information directly from you and automatically through your use of OpenTees. Tee-time and course information comes from golf courses, booking providers and other sources used to provide the recommendation service.

OpenTees does not intentionally ask for special-category information such as health, biometric, religious or political information. Please do not provide it in free-text fields.

03

How and why we use information

PurposeInformationLawful basis
Set up and maintain your profile; monitor, rank and send tee-time recommendations.Contact, location, preferences, recommendation and delivery information.Taking steps at your request and performing our agreement to provide the service.
Respond to enquiries and requested course notifications.Contact, communication and course-request information.Performance of the service and our legitimate interest in responding and expanding coverage.
Operate, troubleshoot and secure OpenTees; prevent misuse and maintain reliability.Technical, security, account and usage information.Our legitimate interests in providing a secure and dependable service; legal obligation where applicable.
Understand service performance and improve recommendations and user experience.Usage, interaction and aggregated recommendation information.Our legitimate interests in improving OpenTees; consent where cookies or similar technologies legally require it.
Send optional news, product updates or promotions.Contact information and marketing choices.Your consent, or the limited PECR soft opt-in where its conditions genuinely apply.
Comply with law, establish or defend legal claims, and respond to regulators or authorities.Relevant information held by us.Legal obligation and our legitimate interests in protecting legal rights.

Where we rely on legitimate interests, we consider the benefit to OpenTees and its users, whether the processing is necessary, and its effect on your rights. You may object as explained below.

04

Personalised recommendations and profiling

OpenTees automatically compares live tee-time information with the preferences you provide. Factors may include location and distance, preferred courses, day, time, budget and player count. The service ranks available opportunities and may explain why a match was selected.

This is profiling because it evaluates your preferences to personalise recommendations. It does not decide whether you may play golf, set the provider’s price, complete a booking, or produce a legal or similarly significant decision about you. You decide whether to follow a link and any booking is governed by the course or booking provider.

You can change your profile and preferences or ask us about the information used for your recommendations by contacting us.

05

Recommendation emails and marketing

Emails needed to provide a service you request—such as tee-time recommendations, profile confirmations, security notices and a requested notification that a course is available—are service communications. You can stop recommendation emails by changing your preferences or using the unsubscribe facility provided.

We treat separate promotional newsletters, offers and product marketing as direct marketing. We send these only where PECR permits it, normally with your consent. Where we rely on the soft opt-in, we will have collected your details directly while discussing or providing our own similar service and offered a clear opt-out both then and in every marketing message.

You can object to direct marketing or withdraw marketing consent at any time by using the unsubscribe link or emailing us. We may retain the minimum information needed on a suppression list so we continue to respect your choice.

06

Cookies, similar technologies and measurement

The links you receive by email (to edit your preferences or answer the acquisition question) use a short-lived, signed access code carried in the page address rather than a cookie, and the core website does not need a cookie to work. Our hosting provider, Framer, runs its own basic site-analytics script on every page.

With your permission, we also use Google Analytics to understand how people use OpenTees and to improve the service. Google Analytics's own code is not loaded into the page at all until you actively accept it in the cookie banner shown on your first visit — it does not run, set a cookie, or send any measurement data before that. If you reject or ignore the banner, Google Analytics is never loaded. You can change your choice at any time using "Cookie settings" in the website footer or on our Cookie Policy, which lists every cookie we actually use, its provider, purpose and duration. Refusing analytics never prevents use of the core service.

07

Who receives your information

We may disclose information only as reasonably necessary to:

  • Supabase, which provides the database, file storage and server-side infrastructure that runs OpenTees. Golfer data is hosted in Supabase's UK (London) region.
  • Resend, which delivers our recommendation, profile and account emails on our behalf.
  • Framer, which hosts and publishes the OpenTees website, and provides its own basic site-analytics.
  • Google, via Google Analytics, only where you have consented to analytics cookies — see the cookies section above and our Cookie Policy.
  • professional advisers, insurers, auditors and contractors who need information to provide their services;
  • courts, regulators, law-enforcement bodies or public authorities where disclosure is required or legally permitted; and
  • a buyer, investor or successor if OpenTees is reorganised, financed, sold or transferred, subject to appropriate confidentiality and legal safeguards.

Service providers act under contractual restrictions and may use personal information only for agreed purposes. We do not sell personal information. We do not give golf courses or booking providers your OpenTees profile merely because you follow an outbound link. Those third parties collect information directly from you under their own privacy notices if you use their services.

08

International transfers

Supabase hosts golfer data in its UK (London) region. Framer and Google are based in the United States, and Google Analytics data (where you have consented to it) is processed by Google. Where this is a restricted transfer, we rely on the supplier's lawful transfer mechanism appropriate to the destination — this may include UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with supplementary safeguards where required.

You may contact us for more information about the safeguards relevant to your information.

09

How long we keep information

We keep your profile and preference information for as long as you have an active OpenTees profile, so we can keep matching and recommending tee times for you. If you unsubscribe or ask us to delete your information, we will delete or anonymise the personal information we hold, other than what we reasonably need to keep — for example, the minimum information needed on a suppression list to continue honouring your unsubscribe choice, evidence of consent where we may need to demonstrate compliance, or anything we must keep to meet a legal obligation, resolve a dispute, or investigate suspected fraud or misuse.

We do not currently operate an automated, age-based deletion schedule across every system. We review information manually and delete or anonymise it when we become aware it is no longer needed for the purpose it was collected for. We are working towards more automated retention controls over time; this notice will be updated to describe them accurately once they exist.

10

Security

We use proportionate technical and organisational measures designed to protect information against accidental or unlawful destruction, loss, alteration, disclosure or access. These include access controls, restricted administrative permissions, encrypted network connections, managed infrastructure, logging, backups and review of service-provider safeguards where appropriate.

No online service can guarantee absolute security. If a personal-data breach creates a risk to people, we will assess it and notify the ICO within the legally required period where notification is required. We will also notify affected individuals where the law requires it.

11

Your data-protection rights

Depending on the circumstances and lawful basis, you may have the right to:

  • be informed about how we use your information;
  • request access to personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information;
  • ask us to restrict how information is used;
  • receive information you provided in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing, including related profiling;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • raise concerns about automated processing or ask for information about recommendation profiling.

To exercise a right, email hello@open-tees.com. We may ask for information needed to verify your identity. We normally respond within one month, although the law permits extensions for complex or numerous requests. Rights are not absolute, and if an exemption applies we will explain it. Exercising a right is currently a manual process — email us and we will action your request directly; we do not yet offer a self-service account-deletion or data-export tool.

Complaining to the ICO

We would appreciate the opportunity to resolve your concern first. You also have the right to complain to the Information Commissioner’s Office.

ico.org.uk/make-a-complaint ↗

Telephone: 0303 123 1113

12

Children

OpenTees is not currently designed for children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has provided information to us, please contact us so we can investigate and delete it where appropriate. Golf courses and booking providers may apply their own age and supervision rules.

13

Changes and contact

We may update this notice when OpenTees, its suppliers or the law changes. The effective date at the top identifies the current version. If a change materially affects how we use existing information, we will provide an appropriate additional notice and seek consent where the law requires it.

Questions or requests should be sent to hello@open-tees.com.