DRAFT — pending legal review. This document is a working draft and has not yet been reviewed by counsel. It will be finalized before paid billing goes live.

Privacy Policy

Last updated: September 29, 2026

This Privacy Policy explains how Cudo Solutions LLC ("we", "us") collects, uses, and shares information when you use WhatUGet at whatuget.app (the "Service"). We do not sell your personal information.

1. Information we collect

  • Account data. Your email address and login credentials or sign-in tokens, managed through our authentication provider, Supabase.
  • Tournament data. Tournament names, courses, dates, teams, player names, handicaps, optional player emails, match schedules, scores, and stats entered by organizers, captains, and players.
  • Billing data. Subscription status and limited payment details (such as the card brand and last four digits) provided by Stripe. We never receive or store full card numbers.
  • Technical data. Basic log and device information (IP address, browser type, pages requested) collected by our hosting provider for security and reliability.

2. How we use information

  • To provide the Service: scoring, leaderboards, spectator views, PDFs, and stats;
  • To send transactional emails such as sign-in links and player invitations;
  • To process subscriptions and prevent fraud;
  • To generate optional AI match recaps and previews;
  • To provide support, keep the Service secure, and comply with law.

3. Service providers we share data with

We share data only with providers that help us run the Service:

  • Supabase — database and user authentication (account and tournament data).
  • Resend — delivery of transactional emails (recipient email address and message content).
  • Stripe — payment processing and the subscription Customer Portal. Card data is entered directly with Stripe and is never stored by us.
  • Google (Gemini API) — when AI recaps or previews are generated, relevant match and player data (such as player names, teams, handicaps, scores, and results) is sent to Google's Gemini API to produce the text.
  • Cloudflare — hosting, content delivery, and security for whatuget.app.

We may also disclose information if required by law, or in connection with a merger, sale, or transfer of the business.

4. Public tournament data

Tournament pages and spectator links are designed to be shared. Anyone with a tournament link can see team names, player names, and scores for that tournament. Organizers should only add information that participants are comfortable sharing.

5. Cookies and local storage

We use cookies and browser local storage that are necessary to keep you signed in, maintain your session, and store scores offline until they sync. We do not use third-party advertising cookies. Stripe may set its own cookies on its checkout and portal pages for fraud prevention.

6. Data retention and deletion

We keep account and tournament data for as long as your account is active, and after a subscription lapses so you can resubscribe without losing history. You can request access to, correction of, or deletion of your personal data at any time by emailing whatugetapp@proton.me. We will respond within 30 days. Some records (for example, payment records) may be retained where required by law. Players who were added to a tournament by an organizer can also contact us to have their name removed.

7. Security

We use industry-standard measures, including encrypted connections (HTTPS) and database access controls, to protect your information. No method of transmission or storage is 100% secure.

8. Children

The Service is not directed at children under 13, and we do not knowingly collect personal information from them without parental consent. If you believe a child has provided us data, contact us and we will delete it.

9. International users

The Service is operated from the United States and our providers may process data in the United States and other countries. Depending on where you live, you may have additional rights under local law (such as the GDPR or CCPA); contact us to exercise them.

10. Changes and contact

We may update this policy and will note the "Last updated" date above. Questions or requests: whatugetapp@proton.me. Company contact (Cudo Solutions LLC): jason@cudosolutions.com. See also our Terms of Service.