Privacy Policy
Version 2.1 · Last updated: October 7, 2026
1. Controller
The controller of your personal data is MetriQ Golf. To exercise your rights or ask questions, contact our Data Protection Officer (DPO):
2. Data We Collect
Scroll the table to see all columns. Use arrow keys with a keyboard.
| Category | Examples | Purpose |
|---|---|---|
| Account | Name, email, password (hashed), gender, sport category (Junior/Adult), role (athlete/coach) | Create and maintain your account |
| Golf data | Rounds, hole-by-hole shots, score, course, par, distances | Performance analysis and handicap |
| Training | Practice sessions, categories, duration, goals, sub-goals | Personalized recommendations |
| Location | GPS during round (on-course position) | Show distances and auto-identify course |
| Audio | Lesson recordings (only when you initiate) | AI lesson analysis with explicit consent |
| Device | Device ID, push token, timezone | Notifications and security |
| Usage | Features accessed in the app, technical errors and, with consent, website visits and interactions | Improve the app and website |
3. Legal Bases
- Contract performance — account and golf data needed to deliver the service
- Consent — audio recording of lessons, marketing emails (optional)
- Legitimate interest — account security, fraud prevention, product improvement
- Legal obligation — when required by law
4. How We Use Your Data
- Provide statistics, performance analysis and round history
- Generate training recommendations and personalized goals
- Calculate handicap and track progression over time
- Allow linked coaches to monitor athlete progress
- Send goal notifications and training reminders (with permission)
- Process subscription payments (via RevenueCat)
- Improve AI golf-analysis models
5. Sub-Processors
We share data with the following service providers, solely to operate MetriQ:
Scroll the table to see all columns. Use arrow keys with a keyboard.
| Company | Country | Purpose | Privacy Policy |
|---|---|---|---|
| Supabase Inc. | USA | Database and authentication | supabase.com/privacy |
| Railway Corp. | USA | Backend server hosting | railway.app/legal/privacy |
| OpenAI, L.L.C. | USA | AI analysis (insights, voice transcription) | openai.com/policies/privacy-policy |
| Anthropic, PBC | USA | AI analysis (coaching, advanced analysis) | anthropic.com/privacy |
| Groq, Inc. | USA | High-speed AI inference | groq.com/privacy-policy |
| Google LLC | USA | Maps, geocoding and consented website analytics | policies.google.com/privacy |
| Resend, Inc. | USA | Transactional email delivery | resend.com/privacy |
| RevenueCat, Inc. | USA | Subscription management | revenuecat.com/privacy |
We do not sell, rent, or monetize your data with advertisers or data brokers.
6. Your Rights
- Access — know what data we hold about you
- Correction — fix inaccurate or incomplete data
- Deletion — delete your account and all associated data (You → Delete Account)
- Portability — export your data in machine-readable format (You → My Data → Export)
- Opt-out of sale — we do not sell personal information; this right is inherently satisfied
- Revoke consent — withdraw consent at any time without prejudice to prior processing
7. California Residents — CCPA / CPRA
- Right to Know: You may request disclosure of personal information we collect, use, disclose, and sell/share.
- Right to Delete: You may request deletion of personal information we collected from you.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: MetriQ does not sell or share personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: We use sensitive PI only to provide the service.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To submit a California privacy request: privacidade@metriqgolf.com with subject line "CCPA Request — [type]".
8. Other US State Privacy Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with active privacy laws have rights similar to those described above. Contact us at the email below to exercise any of these rights.
9. Children (COPPA)
MetriQ is intended for users 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child has provided information without parental consent, contact us for immediate removal.
10. Data Retention
Scroll the table to see all columns. Use arrow keys with a keyboard.
| Data Type | Retention Period |
|---|---|
| Account and profile | Until deleted by user or 2 years after inactivity |
| Golf and training data | While the account is active |
| Security logs | 90 days |
| Transactional emails (Resend) | 30 days in Resend logs |
| AI processing data (OpenAI/Anthropic) | Per each vendor's policy (typically 0–30 days) |
11. Security
- HTTPS/TLS encryption on all endpoints
- Passwords stored as bcrypt hashes (never in plain text)
- Session tokens with expiration and revocation
- Database access restricted to authorized servers
- Daily automated database backups
- Periodic source code security audits
11a. Automated Decisions and AI
We use AI systems to generate performance analysis, training recommendations, and insights about your game. These are automated suggestions, not definitive decisions producing legal effects on you.
You have the right to request human review of decisions made solely on automated processing. Contact privacidade@metriqgolf.com.
11b. Cookies and Similar Technologies
The MetriQ app uses local storage for preferences, credentials and temporary data. On this website, Google Analytics 4 (Google LLC) runs only after you select “Accept analytics.” If you accept, analytics cookies such as _ga and _ga_* help measure visits and interactions so we can understand and improve the site. You can decline or withdraw your choice through “Cookie preferences” in the footer. Your choice is saved in your browser’s local storage. Analytics cookies are not required to browse the site.
- AsyncStorage: persistent storage of settings, preferences, and cache.
- SecureStore: encrypted storage of sensitive credentials (session tokens).
- HTTP Cache: temporary storage of API responses for offline support.
11c. Push Notifications
You control notifications in You → Notifications. The push token is stored only to deliver notifications you authorized and is removed when you log out or delete your account.
11d. Security Incident Notification
In case of a security incident affecting your personal data, we will notify you and competent authorities (ANPD in Brazil, US state authorities) as required by law, within 72 hours of discovery.
12. Changes to This Policy
We will notify you of material changes via in-app notification or email at least 15 days before the effective date. Continued use after the effective date constitutes acceptance.
Contact — DPO
Data Protection Officer: MetriQ Team
For privacy requests, use subject line: "Privacy Request — [type]"