Privacy notice

What Court Companion knows about you, why it knows it, who else sees it, and how to take it back.

Last updated 22 September 2026

Who is responsible

Court Companion is run by one person in the Netherlands rather than by a company. There is no legal form, no Chamber of Commerce registration and no VAT number, because there is no business to register. If that changes, this page changes with it.

That is the controller for everything described below, in the sense the General Data Protection Regulation gives the word. For anything to do with your data — a question, a request, a complaint — write to hello@courtcompanion.app. It reaches the one person who runs this. No postal address is published — the imprint says why, and how to ask for one.

No data protection officer has been appointed, and none is required. That obligation falls on public authorities and on organisations whose core activity is monitoring people on a large scale or handling special categories of data at scale. This is a tournament calendar, a trip planner and a shared-cost ledger, run by one person. If it ever stops being that, this line changes before the practice does.

What this notice covers

The Court Companion app on iOS and Android, the same app in a browser at courtcompanion.app, and the API behind both. That is the whole service. There is no separate marketing site, no second system holding a copy of anything, and no office network any of it passes through.

What we hold, and what it is for

Your email address and your name
So you can sign in, and so the players you travel with know who they are travelling with. Without these there is no account.
Your home city, and its coordinates
Used to work out how far a tournament is from you and to sort a list by that. When you set up your profile the app offers the city Cloudflare’s network guesses from your connection; it is stored only if you accept that or type a city yourself, and you can change or clear it afterwards.
The tournaments you follow and the entries you make
Which events you are going to, and the partner you entered with. Your partner sees the entry, because it is as much theirs as yours.
Your trips, and everything in them
Flights, stays, stops and dates. Anyone you invite to a trip sees the trip.
Messages you send other players
Kept so a conversation is still there when you come back to it. We do not read them; we can, which is why a message you report can be looked at.
Expenses, splits and settlements
What a trip cost, who paid, and who still owes whom. Visible to the other members of that shared-cost group and to nobody else.
Payment handles — an IBAN, a Pix key, a UPI id, a PayPal, bunq or Revolut name
Shown to the other members of a shared-cost group so they can pay you back directly. Shown to no one else, and used by us for nothing.
An IPIN licence number, if you add one
Optional. It lets a partner enter the two of you in a tournament. Only players you have partnered with or entered alongside can see it, and you can see that list and revoke any of it.
An avatar, if you upload one
Stored as a file in our own object storage and served from there.
Push notification tokens and your notification preferences
The token identifies a device, not a person, and exists so a notification can reach the right phone.
Error reports
When something crashes, the stack trace and what the app was doing. Deliberately stripped of who it happened to — see below.

The legal ground for each of those

Cookies, and the banner you will not see

One cookie. It is called better-auth.session_token — prefixed __Secure- in production — it lasts 30 days, it is httpOnly so no script can read it, and it is SameSite=Lax so another site cannot make your browser send it. It carries your session and nothing else.

It is strictly necessary in the sense Article 5(3) of the ePrivacy Directive means — Article 11.7a of the Dutch Telecommunications Act, the Telecommunicatiewet — because it does nothing but deliver the thing you asked for, which is being signed in. A cookie like that needs no consent. So there is no consent banner on this service, because there is nothing to ask you about.

There is no analytics cookie, no advertising cookie and no consent cookie. There is no third-party script anywhere in the app, no tag manager, and no content delivery network in front of it. The two typefaces the app uses are bundled inside it, so no font is fetched from Google or anyone else. Map tiles are served from our own storage rather than from a tile provider, which means the part of the world you are looking at never leaves this service.

What we count

One row is written when a screen is built. It contains, in full: the word screen_view, which screen it was, which platform asked for it, which language it was rendered in, and which version of the app asked — plus how many milliseconds it took and how many database queries it cost.

That is the whole row. There is no user id, no email address, no IP address and no session id in it, and nothing else is joined to it later. It can tell us that a screen is slow or that nobody opens it. It cannot be reassembled into one player’s path through the app, because the thing that would connect two rows to the same person is not written down.

Who else touches it

These are our processors: they act on our instructions and for no purpose of their own. Each is listed with what it actually receives, rather than with what it is capable of receiving.

Cloudflare
Hosts the whole service: the code, the databases, the files and the email that carries your sign-in code. Its network also supplies the rough location we offer you at sign-up, worked out from your connection rather than from your device.
Sentry
Receives error reports. Configured not to attach personal data to them — no email, no IP address, no request body — so a report says what broke and not who it broke for.
Booking.com
Receives, when you look for somewhere to stay: the coordinates of the destination, your dates, how many guests, and a currency. It does not receive your name, your email address or any identifier of you.
AeroDataBox, through RapidAPI
Receives a flight number and a date when you add a flight to a trip. Nothing else, and nothing about you.
Firebase Cloud Messaging
Would receive a device token and the text of a notification. It is not in use: the app currently ships a push service that does nothing, so no push notification is sent to anyone and nothing reaches Google. This entry is here so that switching it on is a change to this page and not a surprise.
The European Central Bank
Publishes the daily reference exchange rates we use to show a shared cost in your own currency. We fetch a public file; nothing is sent, so the ECB receives nothing about anyone.

Data leaving the European Economic Area

Some of the providers above sit outside the EEA, or are owned by a company that does. Rather than say so in general, here is which is which, and what each transfer rests on.

Booking.com
Amsterdam. Nothing leaves the EEA.
The European Central Bank
Frankfurt. Nothing leaves, and nothing about anyone is sent in the first place.
Cloudflare
A United States company running a global network. Covered by Cloudflare’s data processing addendum, which incorporates the European Commission’s standard contractual clauses. The databases behind this service are not pinned to one region, so assume the data they hold may be processed outside the EEA.
Sentry
United States. Covered by Sentry’s data processing addendum and the same standard contractual clauses. What travels is an error report with no email address, no IP address and no request body in it.
AeroDataBox, through RapidAPI
United States. Covered by RapidAPI’s terms and the same standard contractual clauses. What travels is a flight number and a date.

How long any of it is kept

Your rights, and where they are in the app

The GDPR gives you the right to see what we hold, to correct it, to have it erased, to restrict or object to what we do with it, to take it elsewhere in a usable format, and to withdraw any consent you gave. Two of those are buttons rather than requests.

Take a copy of everything
The profile screen has an export. It is a single file containing everything this service holds about you, served from /api/profiles/me/export.
Have it erased
The profile screen has a delete. Your account stops working immediately and what we hold is removed within 30 days.
Everything else
Write to the address at the top of this page. We answer within a month, as the Regulation requires.

If you think we have got this wrong, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the authority where you live. You do not have to come to us first, although we would rather you did.

Children

Court Companion is for players aged 18 and over. You confirm your age when you sign in. We do not knowingly hold data about anyone younger; if you believe we do, write to the address above and it will be removed.

When this notice changes

The date at the top changes with it. Where a change affects what we do with data you have already given us, we will say so in the app rather than relying on you to come back and read this page.