Last updated: 9 July 2026

Privacy Policy

This policy explains how Cuppacard Ltd (“we”, “us”, “our”), the company behind BookMyBays, collects, uses, and protects your personal data. We are committed to handling data responsibly and in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


1. Who We Are

Cuppacard Ltd is the data controller for personal data collected through the BookMyBays platform at bookmybays.com.

Cuppacard Ltd
Company number: 15636346 (registered in England and Wales)

If you are a Customer who has made a booking with a golf venue through BookMyBays, that Venue is also a data controller for your booking information. Please refer to the Venue's own privacy policy for details of how they use your data.

For any privacy-related queries, contact us at: [email protected]

2. Data We Collect

Venue account holders:

  • Name, email address, and phone number
  • Business name, address, and contact details
  • Billing information (processed and held by Stripe — we do not store card details)
  • Usage data: pages visited, features used, login times
  • Communications with our support team

Customers making bookings:

  • Name and email address
  • Phone number (if provided)
  • Booking details: date, time, bay, duration, and amount paid
  • Payment confirmation reference (not card details)

Gift card purchasers and recipients:

  • If you buy a gift card, we collect your name and email address (for the receipt) and, if you choose to send it to someone else, the recipient's name and email address
  • We use the recipient's details only to deliver the gift card and any redemption reminders

Website visitors:

  • Technical data such as IP address, browser type, and referring URL collected via analytics (see sections 5 and 9 for details of the analytics tools we use and how consent works)

3. How We Use Your Data

We use the data we collect to:

  • Create and manage your account
  • Process bookings and payments
  • Send booking confirmations and reminders
  • Provide customer support
  • Improve the Platform and fix technical issues
  • Measure whether our advertising leads to sign-ups
  • Send product updates and service communications (you can opt out of marketing emails at any time)
  • Comply with legal and regulatory obligations

4. Legal Basis for Processing

Under UK GDPR, we rely on the following legal bases:

  • Contract performance — creating and managing your account, processing bookings and payments, and sending booking confirmations and reminders
  • Legitimate interests — improving the Platform, providing customer support, preventing fraud, ensuring security, and sending service communications to existing account holders about similar services (you can opt out at any time)
  • Legal obligation — where we must retain data to comply with law (e.g. financial records)
  • Consent — for optional marketing communications and for analytics and advertising cookies, which you can withdraw at any time

5. Sharing Your Data

We do not sell your personal data. We share it only where necessary:

  • Stripe — to process payments securely. Stripe's privacy policy applies to data they hold.
  • Supabase — our database and authentication infrastructure provider.
  • Vercel — our hosting provider; your data may transit through their infrastructure.
  • PostHog — product analytics. Before you consent to analytics cookies, we collect only ephemeral, in-memory usage events with no cookies or persistent identifiers; after consent, we use cookies to measure how the Platform is used. We configure PostHog to mask on-page text and we do not use session recording.
  • Google (Google Ads) — we measure whether our advertising leads to sign-ups. If you have not consented to analytics cookies, Google receives only a cookieless, aggregated conversion signal (Google Consent Mode) and no advertising cookies are set; if you consent, cookie-based conversion measurement applies.
  • Amazon Web Services (SES) — sends booking confirmations, reminders, and account emails on our behalf.
  • Venues — Customer booking data is accessible to the Venue you booked with.
  • Legal authorities — where we are required to disclose data by law or court order.

All third-party providers are contractually required to handle data securely and only for the purposes we specify.

6. International Data Transfers

Some of the third-party providers we use (including Stripe, Supabase, Vercel, and Amazon Web Services) operate infrastructure outside the United Kingdom — typically within the European Economic Area (EEA) and the United States. This means your personal data may be transferred to, stored in, or accessed from countries outside the UK.

Where we transfer personal data to a country that has not been deemed by the UK Government to provide an adequate level of protection, we put in place appropriate safeguards as required by Article 46 of the UK GDPR, which include:

  • The UK Government's International Data Transfer Agreement (IDTA), or
  • The European Commission's Standard Contractual Clauses together with the UK Addendum issued by the Information Commissioner's Office.

You can request a copy of the relevant transfer mechanism by emailing [email protected].

7. Data Retention

We retain personal data for as long as necessary to provide the service and meet our legal obligations:

  • Venue account data — retained for the duration of your account plus 2 years after closure
  • Booking records — retained for 7 years for financial/legal compliance purposes
  • Marketing preferences — until you unsubscribe or withdraw consent
  • Website analytics — aggregated and anonymised after 26 months

If the Venue you booked with stops using BookMyBays, your booking data is returned to that Venue or deleted in accordance with our data processing commitments, except where we must retain it to comply with law.

8. Your Rights

Under UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — request deletion of your data where we no longer have a lawful reason to hold it
  • Restriction — ask us to pause processing in certain circumstances
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests or for direct marketing
  • Withdraw consent — where processing is based on consent, you can withdraw it at any time

To exercise any of these rights, email us at [email protected]. We will respond within one calendar month.

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Cookies and Similar Technologies

BookMyBays uses cookies and similar technologies (including browser localStorage) to keep you signed in, remember your preferences, and improve the Platform.

  • Essential cookies — required for authentication and session management. Cannot be disabled.
  • Preference storage — your theme preference (light/dark mode) and your cookie consent choice are stored in localStorage.
  • Analytics cookies (PostHog) — help us understand how the Platform is used. Before consent, no analytics cookies or persistent identifiers are set and only ephemeral in-memory events are collected; after consent, cookies are used.
  • Advertising measurement (Google Ads) — measures whether our advertising leads to sign-ups. Before consent, no advertising cookies are set and Google receives only a cookieless, aggregated conversion signal via Google Consent Mode; after consent, cookie-based measurement applies.
  • Booking funnel measurement — on a venue's booking page we record how far a booking attempt gets (times viewed, slot picked, details entered, booking completed) so the venue can see where customers drop out. This uses a random identifier held in your browser's sessionStorage for the duration of that one booking attempt, and it is cleared once you book. No cookies are set, no third party is involved, and the events carry no personal data — only the date you looked at, the session type, party size, and whether anything was available.

We do not set analytics or advertising cookies until you give consent via our cookie banner. You can change or withdraw your consent at any time by clearing your cookie preference and reloading the page, or via your browser settings. Disabling essential cookies will prevent you from signing in.

10. Automated Decision-Making

We do not use your personal data to make automated decisions that have legal or similarly significant effects on you.

11. Children

The Platform is not directed at children. Accounts and bookings may only be created by persons aged 18 or over; a parent or guardian must make any booking on behalf of a child. We do not knowingly collect personal data from children, and if we learn we have done so we will delete it. Venues are responsible for their own safeguarding obligations at their premises.

12. Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These include encrypted connections (HTTPS), access controls, and secure third-party infrastructure.

No system can be guaranteed to be completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO and, where required, affected individuals in accordance with our obligations under the UK GDPR.

If you suspect a security issue, please contact us immediately at [email protected].

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via the Platform. The “last updated” date at the top of this page indicates when it was last revised.


Also see our Terms of Service · Back to BookMyBays