Who is responsible
Court Companion is run by one person in the Netherlands rather than by a company. There is no legal form, no Chamber of Commerce registration and no VAT number, because there is no business to register. If that changes, this page changes with it.
That is the controller for everything described below, in the sense the General Data Protection Regulation gives the word. For anything to do with your data — a question, a request, a complaint — write to hello@courtcompanion.app. It reaches the one person who runs this. No postal address is published — the imprint says why, and how to ask for one.
No data protection officer has been appointed, and none is required. That obligation falls on public authorities and on organisations whose core activity is monitoring people on a large scale or handling special categories of data at scale. This is a tournament calendar, a trip planner and a shared-cost ledger, run by one person. If it ever stops being that, this line changes before the practice does.
What this notice covers
The Court Companion app on iOS and Android, the same app in a browser at courtcompanion.app, and the API behind both. That is the whole service. There is no separate marketing site, no second system holding a copy of anything, and no office network any of it passes through.
What we hold, and what it is for
- Your email address and your name
- So you can sign in, and so the players you travel with know who they are travelling with. Without these there is no account.
- Your home city, and its coordinates
- Used to work out how far a tournament is from you and to sort a list by that. When you set up your profile the app offers the city Cloudflare’s network guesses from your connection; it is stored only if you accept that or type a city yourself, and you can change or clear it afterwards.
- The tournaments you follow and the entries you make
- Which events you are going to, and the partner you entered with. Your partner sees the entry, because it is as much theirs as yours.
- Your trips, and everything in them
- Flights, stays, stops and dates. Anyone you invite to a trip sees the trip.
- Messages you send other players
- Kept so a conversation is still there when you come back to it. We do not read them; we can, which is why a message you report can be looked at.
- Expenses, splits and settlements
- What a trip cost, who paid, and who still owes whom. Visible to the other members of that shared-cost group and to nobody else.
- Payment handles — an IBAN, a Pix key, a UPI id, a PayPal, bunq or Revolut name
- Shown to the other members of a shared-cost group so they can pay you back directly. Shown to no one else, and used by us for nothing.
- An IPIN licence number, if you add one
- Optional. It lets a partner enter the two of you in a tournament. Only players you have partnered with or entered alongside can see it, and you can see that list and revoke any of it.
- An avatar, if you upload one
- Stored as a file in our own object storage and served from there.
- Push notification tokens and your notification preferences
- The token identifies a device, not a person, and exists so a notification can reach the right phone.
- Error reports
- When something crashes, the stack trace and what the app was doing. Deliberately stripped of who it happened to — see below.
The legal ground for each of those
- Performing our contract with you (Article 6(1)(b)) covers your account, your entries, your trips, your messages and the shared-cost ledger. They are the service; without them there is nothing to use.
- Your consent (Article 6(1)(a)) covers your home location, your IPIN and push notifications. Each is offered, none is required, and withdrawing any of them is a switch in the app rather than a request to us.
- Our legitimate interests (Article 6(1)(f)) cover keeping the service standing up, preventing abuse of it, and fixing what crashes. We have weighed that against your interests by holding as little as the job allows: the error reports carry no identity, and the usage counts carry nothing that points at a person.
Cookies, and the banner you will not see
One cookie. It is called better-auth.session_token — prefixed __Secure- in production — it lasts 30 days, it is httpOnly so no script can read it, and it is SameSite=Lax so another site cannot make your browser send it. It carries your session and nothing else.
It is strictly necessary in the sense Article 5(3) of the ePrivacy Directive means — Article 11.7a of the Dutch Telecommunications Act, the Telecommunicatiewet — because it does nothing but deliver the thing you asked for, which is being signed in. A cookie like that needs no consent. So there is no consent banner on this service, because there is nothing to ask you about.
There is no analytics cookie, no advertising cookie and no consent cookie. There is no third-party script anywhere in the app, no tag manager, and no content delivery network in front of it. The two typefaces the app uses are bundled inside it, so no font is fetched from Google or anyone else. Map tiles are served from our own storage rather than from a tile provider, which means the part of the world you are looking at never leaves this service.
What we count
One row is written when a screen is built. It contains, in full: the word screen_view, which screen it was, which platform asked for it, which language it was rendered in, and which version of the app asked — plus how many milliseconds it took and how many database queries it cost.
That is the whole row. There is no user id, no email address, no IP address and no session id in it, and nothing else is joined to it later. It can tell us that a screen is slow or that nobody opens it. It cannot be reassembled into one player’s path through the app, because the thing that would connect two rows to the same person is not written down.
Who else touches it
These are our processors: they act on our instructions and for no purpose of their own. Each is listed with what it actually receives, rather than with what it is capable of receiving.
- Cloudflare
- Hosts the whole service: the code, the databases, the files and the email that carries your sign-in code. Its network also supplies the rough location we offer you at sign-up, worked out from your connection rather than from your device.
- Sentry
- Receives error reports. Configured not to attach personal data to them — no email, no IP address, no request body — so a report says what broke and not who it broke for.
- Booking.com
- Receives, when you look for somewhere to stay: the coordinates of the destination, your dates, how many guests, and a currency. It does not receive your name, your email address or any identifier of you.
- AeroDataBox, through RapidAPI
- Receives a flight number and a date when you add a flight to a trip. Nothing else, and nothing about you.
- Firebase Cloud Messaging
- Would receive a device token and the text of a notification. It is not in use: the app currently ships a push service that does nothing, so no push notification is sent to anyone and nothing reaches Google. This entry is here so that switching it on is a change to this page and not a surprise.
- The European Central Bank
- Publishes the daily reference exchange rates we use to show a shared cost in your own currency. We fetch a public file; nothing is sent, so the ECB receives nothing about anyone.
Data leaving the European Economic Area
Some of the providers above sit outside the EEA, or are owned by a company that does. Rather than say so in general, here is which is which, and what each transfer rests on.
- Booking.com
- Amsterdam. Nothing leaves the EEA.
- The European Central Bank
- Frankfurt. Nothing leaves, and nothing about anyone is sent in the first place.
- Cloudflare
- A United States company running a global network. Covered by Cloudflare’s data processing addendum, which incorporates the European Commission’s standard contractual clauses. The databases behind this service are not pinned to one region, so assume the data they hold may be processed outside the EEA.
- Sentry
- United States. Covered by Sentry’s data processing addendum and the same standard contractual clauses. What travels is an error report with no email address, no IP address and no request body in it.
- AeroDataBox, through RapidAPI
- United States. Covered by RapidAPI’s terms and the same standard contractual clauses. What travels is a flight number and a date.
How long any of it is kept
- Your account and everything attached to it: for as long as the account exists.
- After you ask for your account to be deleted: removed within 30 days.
- Expenses in a shared-cost group outlive your account, because they are also other people’s records of what they paid. Your name is replaced in them.
- Error reports: at most 90 days, the longest Sentry keeps an error event on any of its plans, and less on the free one. They carry nothing that identifies you.
Your rights, and where they are in the app
The GDPR gives you the right to see what we hold, to correct it, to have it erased, to restrict or object to what we do with it, to take it elsewhere in a usable format, and to withdraw any consent you gave. Two of those are buttons rather than requests.
- Take a copy of everything
- The profile screen has an export. It is a single file containing everything this service holds about you, served from /api/profiles/me/export.
- Have it erased
- The profile screen has a delete. Your account stops working immediately and what we hold is removed within 30 days.
- Everything else
- Write to the address at the top of this page. We answer within a month, as the Regulation requires.
If you think we have got this wrong, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the authority where you live. You do not have to come to us first, although we would rather you did.
Children
Court Companion is for players aged 18 and over. You confirm your age when you sign in. We do not knowingly hold data about anyone younger; if you believe we do, write to the address above and it will be removed.
When this notice changes
The date at the top changes with it. Where a change affects what we do with data you have already given us, we will say so in the app rather than relying on you to come back and read this page.