This policy explains what data Looper collects, why, and your rights under UK GDPR and the Data Protection Act 2018. We are the data controller. Our lawful basis for processing is contract (to provide the service you sign up for) and, for analytics, legitimate interests.
Looper is a golf scoring and performance app operated by Looper Caddie Ltd (or its sole-trader equivalent), based in the United Kingdom. You can reach us at privacy@loopercaddie.com.
When you create an account we collect your name (display name you choose), email address, and handicap index. These are stored in our database (Supabase, EU region).
Every round you record — scores, putts, fairways in regulation, greens in regulation, course name, tee played, date — is stored in our database. This is the core purpose of the app.
If you upload an avatar, the image is stored in Supabase Storage (EU region). You can delete it at any time from the Players tab.
If you use the AI scorecard-scan feature, the photo you take is sent to our AI provider (Anthropic) for text extraction and then stored in Supabase Storage. Photos are not used to train AI models.
During a live round, the app uses your device's GPS to calculate distances to the front, middle, and back of the green. GPS coordinates are processed on-device in real time and are not stored in our database after your round ends. If you choose to pin green positions manually, those coordinates are stored with the course record for the benefit of all players on that course.
If you enable push notifications, your device's APNs token is stored in our database so we can send you notifications about group activity (e.g. a group-mate posting a round). You can revoke this at any time in your device settings.
We collect anonymous usage events (which screens you visit, which features you use) via PostHog, routed through the EU endpoint (eu.i.posthog.com). These events are not linked to your name or email — they use a randomly generated ID. We use this data to understand how the app is used and to prioritise improvements.
If the app crashes or encounters an error, a report is sent to Sentry containing technical details (the error message, the screen you were on, your device type). Your name may be included if you were signed in at the time, to help us reproduce the issue.
If you purchase a Looper Premium subscription, the transaction is handled by Apple's App Store and RevenueCat. We receive a record of your subscription status (active or inactive) but we never see your payment card details. Apple processes the payment; RevenueCat provides us with entitlement status only.
We share data with the following processors, all operating under appropriate data-protection agreements:
| Provider | Purpose | Data region |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| PostHog | Product analytics | EU (eu.i.posthog.com) |
| Sentry | Error tracking | EU |
| Anthropic | AI scorecard parsing, coaching reviews, practice plans | US (via our UK proxy) |
| RevenueCat | Subscription entitlement (when premium is active) | US |
| Apple APNs | Push notifications (iOS) | US |
| Netlify | Hosting and serverless function infrastructure | US / EU CDN |
| Resend | Transactional email (waitlist confirmations) | EU |
For transfers to US-based processors (Anthropic, RevenueCat, Apple, Netlify), we rely on Standard Contractual Clauses or the processor's own binding corporate rules.
We do not sell your data, use it for advertising, or share it with any party not listed above.
You have the right to:
To exercise any right, email privacy@loopercaddie.com. We will respond within 30 days. You can also delete your account and all rounds directly from the Players tab in the app.
If you are unhappy with how we handle your data you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
We keep your account data and rounds for as long as your account is active. If you delete your account, all personal data is removed within 30 days. Anonymised, aggregated analytics data (with no personal identifiers) may be retained indefinitely.
Looper is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has provided us with personal data, contact us at privacy@loopercaddie.com.
All data is transmitted over HTTPS. Our database uses row-level security — you can only access data within your own group. API keys are stored server-side only and never exposed to the browser. We conduct periodic security reviews.
If we make material changes we will update the "Last updated" date at the top of this page and, where required, notify you via the app or email. Continued use of Looper after a change constitutes acceptance of the updated policy.
Data controller: Looper Caddie Ltd
Email: privacy@loopercaddie.com