Privacy Notice
Draft — not yet finalised
The passages marked TO BE CONFIRMED below are facts about the business that have not yet been supplied. They have deliberately been left blank rather than filled with a plausible guess. Until they are completed, treat this notice as a description of how the booking system works, not as a final legal statement.
- The registered legal entity name and company registration number (UEN) that operates Golf Anytime.
- The Data Protection Officer’s name or title, email address and business contact number — Singapore’s PDPA requires a DPO to be designated and their business contact information made available.
- How long each kind of record is actually kept, and what happens at the end of that period.
- Which email service delivers confirmations, access codes and reminders.
- Who hosts the application and database, and in which country the data is stored.
- Whether card payments are live at launch, and through which provider.
- Whether Malaysia’s PDPA 2010 applies in addition to Singapore’s (see the note in this file).
Who we are
Golf Anytime operates the indoor golf simulator facility at 785E Woodlands Rise, #01-09, Singapore 735785, and this booking website. The organisation responsible for your personal data is TO BE CONFIRMED — the registered legal entity name and UEN of the company operating Golf Anytime.
You can reach us on +65 6100 1824 or at hello@anytimegolf.sg.
What personal data we collect
We collect only what the booking and the door need. There is no advertising network, no analytics tracker and no third-party script on this site.
- Your contact details — full name, email address and mobile number. You give these when you book a bay, and again if you create a member account.
- Your booking records — the dates, times and bay you booked, how long for, the party size, your booking reference, what you paid, and any cancellation or reschedule.
- Your membership records — the credit packages you bought, credits used and remaining, expiry dates, and any refund.
- Your account credentials — if you set a password, we store only a one-way cryptographic hash of it (argon2id). We never store, and cannot recover, the password itself.
- Google sign-in data — if you choose “Continue with Google”, we receive from Google the account identifier and the name and email address on that account. We never receive your Google password.
- Sign-in session data — for each signed-in session we record the IP address and browser user-agent it was created from, and when it was created, last used and expires. This is what lets us end a session that is being misused.
- Audit records — actions taken on your record by our staff, including who viewed or re-sent a door access code, with the time, the IP address and the browser used. This exists so that access to a door code can be accounted for.
- Your acceptance of our terms — which version of the Terms & Conditions you accepted, and when.
- Messages we send you — the confirmation, access-code, reminder, verification and password-reset emails, the address they went to, and whether delivery succeeded or failed.
We do not ask for, and have no use for, your NRIC, FIN, passport number, date of birth or any other identification number. Please do not send them to us.
Why we collect it
- To take, confirm, change and cancel your booking.
- To send you the door access code for your session. The code is sent by email only and is never shown in a browser, so that it is not left behind in browser history, a screenshot or a shared device.
- To send you a reminder before your session starts.
- To sell, track and expire membership credits, and to process refunds.
- To let you sign in, stay signed in, and recover your account.
- To keep the facility and its customers secure — detecting misuse of a door code, investigating a complaint or an incident, and preventing fraud and abuse of the booking system.
- To answer your enquiries and handle disputes about a booking or a charge.
- To meet our legal, accounting and tax obligations.
We do not sell your personal data, and we do not send marketing or promotional messages. Every email and message described above is part of delivering a booking you made. If that ever changes we will ask for your consent first, and for calls and text messages to Singapore numbers we would check the national Do Not Call Registry as the law requires.
Consent, and how to withdraw it
By making a booking or creating an account you consent to us collecting and using your personal data for the purposes above. You can withdraw that consent at any time by contacting us — see “Contacting us about your data” below.
Withdrawing consent has a practical consequence we would rather you knew in advance than discovered afterwards: we cannot send you a door access code, a confirmation or a reminder, so we cannot deliver a booking. Withdrawal does not undo anything we have already lawfully done, and it does not oblige us to delete records we are required to keep for legal, accounting or dispute-handling reasons.
Who we share it with
We disclose personal data only to the service providers that make the booking work, and only the minimum each one needs. We do not sell or rent it to anyone.
- Our email provider — receives your name and email address in order to deliver confirmations, access codes, reminders, verification links and password resets. TO BE CONFIRMED — the email service provider used, and the country it operates from
- Our payment provider — if you pay by card, you are taken to the provider’s own hosted payment page. Your card number is entered there and never reaches our servers; we receive only a payment reference and whether the payment succeeded. Where card payment is enabled the provider is Stripe, whose privacy policy governs what it does with the data you give it. TO BE CONFIRMED — whether card payments are live at launch and, if so, the provider in force and the link to its privacy policy
- Google — only if you use “Continue with Google”. The exchange is between you and Google; we receive the result.
- Our hosting provider — the application and database run on a single server operated on our behalf. The provider does not use your data for its own purposes. TO BE CONFIRMED — the hosting provider and the country the server and database are located in
- Professional advisers and the authorities — where we are legally required to disclose, or need to establish or defend a legal claim.
One further external check is worth naming for completeness: when you choose a password we test it against the Have I Been Pwned breached-password service. Only the first five characters of a one-way hash of the password are sent, so the service cannot learn your password, your identity or which account the check was for. No personal data leaves us in that request.
Where your data is held, and transfers overseas
Your booking and account records are stored in a single database run on our behalf at TO BE CONFIRMED — the hosting provider and country where the database is located. Some of the service providers above operate outside Singapore, which means your personal data may be transferred out of Singapore. Where that happens we require the recipient to protect the data to a standard comparable to the Personal Data Protection Act 2012.
How long we keep it
Singapore’s PDPA requires us to stop keeping personal data once it no longer serves the purpose it was collected for and there is no legal or business reason to retain it. We are not permitted to keep records indefinitely simply because keeping them is easier, and we do not intend to.
The actual periods are TO BE CONFIRMED — the retention period for each kind of record — bookings, member accounts, sign-in sessions, audit records and payment records — and what happens at the end of it (deletion or anonymisation). We have deliberately not published a number here that we could not stand behind.
What we can tell you today, because it is built into the system: a sign-in session has a fixed expiry and stops working at it, and email verification and password-reset links expire and can be used only once.
How we protect it
- The site is served over an encrypted connection.
- Passwords are stored only as argon2id hashes. Session tokens, door-code links and password-reset links are stored only as one-way hashes, so a copy of the database does not yield a working credential.
- Door access codes are sent by email and are never displayed in a browser. Every time a member of staff views or re-sends one, that is recorded against your booking.
- Staff access to customer records is restricted to the people who need it to run the facility, through a separate administration login.
If a data breach occurs that is likely to result in significant harm to you, or that affects a significant number of people, we will notify the Personal Data Protection Commission and affected individuals as the PDPA requires.
Your rights: access and correction
You have the right to ask us:
- for a copy of the personal data we hold about you, and how we have used or disclosed it in the past year;
- to correct anything that is wrong or out of date;
- to stop using your data, by withdrawing your consent.
If you have a member account, the fastest route is to sign in and open your profile, where you can update your name and mobile number yourself, and your bookings, which lists your booking history. To change the email address on your account, or for anything you cannot change there — including a guest booking made without an account — contact us using the details below.
We will respond to an access or correction request as soon as we reasonably can, and in any case within the time the PDPA allows. We may need to verify your identity first, and we may charge a reasonable fee for an access request, which we will tell you about before proceeding. If we cannot fulfil a request we will tell you why.
Cookies
This site sets one cookie, and only once you sign in: a session cookie that keeps you signed in. It holds a random token, not your name or email. Staff signing in to the administration console get an equivalent cookie, and a short-lived cookie is used during Google sign-in to protect that exchange and is discarded immediately afterwards.
There are no advertising cookies, no analytics cookies and no third-party tracking on this site. Clearing the session cookie in your browser signs you out.
Contacting us about your data
Please direct any question, access or correction request, or complaint about how we handle personal data to our Data Protection Officer:
TO BE CONFIRMED — the Data Protection Officer’s name or title, email address, business contact number and postal address
Until those details are published, contact us at hello@anytimegolf.sg or +65 6100 1824 and mark your message for the Data Protection Officer. If you are not satisfied with our response, you may raise the matter with the Personal Data Protection Commission of Singapore.
Changes to this notice
We will update this page when what we do with personal data changes. Where a change is significant we will tell you before it takes effect. Please check this page from time to time.