PRIVACY POLICY
Last updated: August 27, 2026
Birdied is a trading name of Scott M Limited, registered in England and Wales, company no. 15793247. Registered office: 87 North Rd, Poole BH14 0LT.
1. Information we collect
We collect information you provide directly: email address, display name, and profile photo (via Google OAuth). We also collect usage data including rounds played, course reviews, and social interactions within the app.
When you ask for golf courses near you on the Atlas, we use your approximate device location for that request only. Coordinates leave your device solely as rounded parameters on the nearby-courses request (about 100 metre precision). We never store them - not in your account, not in our database, and not in analytics. We do not track your location continuously, do not use background location, and do not use location for advertising or tracking.
2. How we use your information
Your information is used to: (a) provide and maintain the Service; (b) personalise your experience; (c) display your activity to friends on the social feed; (d) improve the Service; (e) communicate with you about updates and features; (f) when you request it, find golf courses near your current location on the Atlas.
3. Information sharing
Your display name, avatar, rounds, and reviews are visible to your friends on Birdied. We do not sell your personal information to third parties. We may share usage and analytics data with the third-party providers listed in section 7.
4. Data storage and security
Your data is stored securely on our servers. Passwords are hashed using bcrypt and are never stored in plain text.
5. Cookies and authentication
We use secure HTTP-only cookies and JWT tokens for authentication. These are essential for the Service to function and cannot be disabled.
6. Your rights
You have the right to: (a) access your personal data; (b) update or correct your information; (c) delete your account and all associated data; (d) export your data. You can delete your account at any time from the Profile tab.
7. Third-party services
We rely on a small number of third-party providers to run and improve Birdied. Each acts as a data processor on our behalf, under its own privacy policy. We do not sell your personal information to any of them.
Google (sign-in). We use Google OAuth for authentication. When you sign in with Google, we receive only your basic profile information - name, email address, and avatar - and Google's own privacy policy governs the data they collect.
Resend (email delivery). We use Resend to send you account and service email - for example verifying your address, resetting your password, confirming a waitlist request, and letting you know when your place is ready. Resend acts as our processor for these messages: to deliver the mail it receives the recipient address, the subject, and the message itself. Our email is sent from noreply@birdied.app, and Resend's own privacy policy governs the data it handles on our behalf.
PostHog (product analytics). We use PostHog to understand how Birdied is used and to diagnose errors. PostHog is hosted in the European Union and is the processor. In the browser, analytics, session-replay, and error reports go to birdied.app (a first-party path we proxy to PostHog); they do not go to a PostHog domain from your browser. As you move through the app, PostHog receives the address of each page you view, the page or site you arrived from, and any marketing-campaign tags in the link you followed. It also receives a record of certain in-app actions - for example logging a round, writing a review, sharing a course, joining the waitlist, or sending an invitation - along with a session identifier. PostHog also receives your interactions with the interface - such as clicks and taps, and where on the page they happen - to help us understand which parts of Birdied are used. On the web we also record a session replay of the page (how it was used), including for visitors who are not signed in. Text typed into form fields is masked before it is stored. Console-log and performance timing data may be included with that replay. When something goes wrong, PostHog also receives the technical details of the error. When you are signed in, we send PostHog your account identifier, your email address, and your display name (when you have one) as properties of your analytics person, so this activity can be attributed to you. When you join the waitlist, we send the email address you submitted the same way, along with the waitlist status and whether you joined through the form or through Google. If you start a waitlist request and leave without submitting an email, the attempt is recorded without contact details.
What leaves the app, and what we remove first. Before any page address or referrer is sent to PostHog, our app passes it through a single filter. That filter:
removes everything in the address after a “?” except a short list of marketing-campaign tags - so a secret token carried in a link, such as the token in a password-reset or email-verification email, or an invitation token, is stripped out and never sent;
replaces identifying parts of an address, such as an invitation token in the path, with a neutral placeholder; and
discards the part of an address after a “#”, which the app uses to carry sign-in tokens.
This filter removes credentials from the addresses we send; it does not stop the addresses themselves from being sent. Which pages you visit, and where you arrived from, still leave the app and are processed by PostHog as described above. Location coordinates on a nearby-courses request are stripped from diagnostic reports. Product analytics may record that you used near-me (for example a distance band, result count, or permission outcome) but never the coordinates themselves.
8. Children's privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app. Your continued use of the Service constitutes acceptance of the updated policy.
10. Contact
Questions about this policy: write to us from the contact page.
Birdied
Course data © OpenStreetMap contributors, available under the Open Database License.
Birdied is a trading name of Scott M Limited, registered in England and Wales, company no. 15793247. Registered office: 87 North Rd, Poole BH14 0LT.