OpenYardage is a free community project. We do not sell any data and we run no advertising. We count reach without cookies and without any identifier in your browser, in totals and not per person (section 2). This policy states in full which data arises and where it goes.
Mikail Ege
Karlsruher Straße 2a, 10711 Berlin
Email: info@openyardage.com
A data protection officer has not been appointed, because the statutory conditions for that are not met here.
The site can be viewed without an account. In doing so, our hosting provider processes technically necessary connection data, in particular the IP address, the time, the address requested and details about the browser. Without this transmission a web page cannot technically be delivered.
Legal basis: legitimate interest in the secure and stable operation of the service, Article 6(1)(f) GDPR.
We count how often which pages are viewed, using the service Umami (Umami Software, Inc., San Francisco, USA; the data is stored on servers in the EU). Transmitted are the address viewed without query parameters and without the part after the hash, the page you came from, browser, operating system, device class and country. Added to that are thirty-four events, listed one by one here:
What you type into the search field of the club page is not transmitted.
In addition, the counter measures the loading behaviour of the page in your browser (Core Web Vitals: how quickly the largest content appears, how long the page takes to react to an input, and how much it shifts while loading). These are measurements of the device, not statements about you.
Two attributes are attached to the anonymous session: the chosen language and whether you are signed in (yes or no). No identifier that could join sessions or devices into one person is assigned.
Within the app we transmit a simplified page identifier instead of the address, for example "/app/course/erin-hills" for a course view or "/app/book" for a book; it contains no book ID, no username and no search term.
Your IP address is not stored by the provider; it only feeds a daily changing checksum that groups views of the same day and cannot be traced back to you.
No cookie is set and nothing is stored in your browser, which is why we do not ask for consent. If your browser sends the "Do Not Track" setting, the service counts nothing.
Legal basis: legitimate interest in knowing how the service is used, Article 6(1)(f) GDPR. You can object to the counting at any time, most simply via "Do Not Track" or an ad blocker; the service then works unchanged.
An account only comes into being if you actively sign in with Google. In doing so we receive from Google a user identifier, the display name you have stored there and your email address. We do not receive a password.
Legal basis: performance of the user relationship, Article 6(1)(b) GDPR.
| Data | Purpose | Visibility |
|---|---|---|
| Yardage books Title, description, notes per hole, clubs, drawings, optionally your handicap |
Core of the application | You decide per book: private or public. Public books are visible to everyone, including the username and handicap. |
| Shot distances (“bag”) | Range rings in the diagram | Stay private and are never shared with others. |
| Rounds Strokes per hole, the course and the time |
The scorecard you keep on the course | Stay private and are never shared with others. Stored only if you are signed in and click “keep round”; otherwise they stay in your browser. |
| Today’s pins The course, the day and two measurements in metres per hole; your user identifier forms part of the entry’s name |
Showing others where the pin is today | Public. Anyone can read them, without an account, including your user identifier. They are displayed only on the day they were set for. |
| Pin sets and pin diary Named sets of pin positions, a weekly plan for them, and for each day which position was in play on which hole |
Planning pins and looking back at which part of the green was used recently | Part of the book. Visible to everyone if the book is public, including the username. |
| Error reports Category, free text, the course and hole concerned, the coordinates of the course, program and data version |
Finding and fixing data errors | Not public. Visible to the controller. For processing, every report is transferred without your user identifier into a non-public repository at GitHub, see section 5. |
Operation, sign-in and data storage run through Google Firebase. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A data processing agreement is in place. The database is fixed to European servers (region eur3). Access from the United States by Google LLC cannot be ruled out technically; the transfer is based on the standard contractual clauses and the adequacy decision on the EU-US Data Privacy Framework.
Reach measurement (section 2) runs through Umami Software, Inc., 28 Geary Street, Suite 650, San Francisco, California, USA. A data processing agreement with the EU standard contractual clauses is in place; the provider in turn uses Amazon Web Services, Cloudflare and Vercel (USA) and Hetzner (Germany). The EU region is selected for openyardage.com, so the counting data is stored on servers in the EU; access from the United States by the provider cannot be ruled out technically and is based on the standard contractual clauses. Only the details named in section 2 are transmitted, no persistent IP address and no identifier.
With each of these requests your IP address is transmitted to the respective provider. That cannot be avoided technically, but it can be limited: the services marked “only when needed” are not contacted until you actually use the function in question.
Which of the nine warning services is queried depends on the coordinates of the course you are looking at: either via the country code of the course in our catalogue, or, when no catalogue course is nearby, via a bounding box around the service area. The coordinates may also come from a yardage book or from a link somebody sent you. That is why the "When" column names the coordinates and not the course: it is the coordinates that select the service.
| Service | What for | Location | When |
|---|---|---|---|
| Google gstatic.com, googleapis.com, firebaseapp.com | Program libraries, sign-in, database, map tiles | USA / IRELAND | always |
| Open-Meteo api.open-meteo.com | Weather and elevation at the course | EU | on course pages |
| National Weather Service api.weather.gov | Official severe weather warnings at the course | USA | for coordinates in the USA |
| Deutscher Wetterdienst maps.dwd.de | Official severe weather warnings at the course. By its own statement the DWD stores the IP address for up to 7 days in order to secure server operation | GERMANY | for coordinates in Germany |
| Instituto Nacional de Meteorologia apiprevmet3.inmet.gov.br | Official severe weather warnings at the course | BRAZIL | for coordinates in Brazil |
| Environment and Climate Change Canada api.weather.gc.ca | Official severe weather warnings at the course | CANADA | for coordinates in Canada |
| India Meteorological Department cap-sources.s3.amazonaws.com | Official severe weather warnings at the course. The service publishes them through an Amazon Web Services store | INDIA / USA | for coordinates in India |
| GeoSphere Austria warnungen.zamg.at | Official severe weather warnings at the course | AUSTRIA | for coordinates in Austria |
| MET Norway api.met.no | Official severe weather warnings at the course | NORWAY | for coordinates in Norway |
| SMHI opendata-download-warnings.smhi.se | Official severe weather warnings at the course | SWEDEN | for coordinates in Sweden |
| Japan Meteorological Agency www.jma.go.jp | Official severe weather warnings at the course. The service does not resolve the point, so the browser also fetches the municipal boundaries | JAPAN | for coordinates in Japan |
| OpenStreetMap nominatim.openstreetmap.org | Search for courses outside our catalogue, resolving a typed place name into coordinates | EU | only when needed |
| State surveying twelve official services of the German federal states and the Dutch service PDOK (service.pdok.nl) | official aerial imagery | GERMANY / NETHERLANDS | only when needed |
| Esri server.arcgisonline.com | Aerial imagery outside the official coverage | USA | only when needed |
| FairwayMapper, OpenStreetMap | Link for mapping the course | EU | only on clicking |
| Discord | Link to our community server (questions, feedback) | USA | only on clicking |
| Umami cloud.umami.is, gateway.umami.is | Counting page views without cookies (section 2) | EU (provider USA) | on all pages except the legal texts (imprint, privacy, terms); never with "Do Not Track" |
To the services in this table we transmit no details about your person, no identifiers and no contents of your books. Transmitted are only the technical details necessary for the request as well as the respective map section or your search term.
We process error reports where the work on OpenYardage happens anyway: in a non-public repository at GitHub. Every report is filed there as an item and is readable only for people with access to that repository. The provider is GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA, represented in the European Union by GitHub B.V., Prins Bernhardplein 200, 1097 JB Amsterdam, Netherlands. The item is filed by a function running at Google Cloud in region europe-west1, that is at the processor already named at the top of this section; no further provider is added for this.
| Transmitted | Not transmitted |
|---|---|
| Category and free text of the report, name and identifier of the course concerned, the hole reported, the coordinates of the course, program and data version, the time and an internal identifier of the report. | Your user identifier. Nor your user name, your email address or your display name. Who reported stays in our database and does not travel along. |
Legal basis: legitimate interest in finding and fixing data errors and in processing them with the same tools this project is built with, Article 6(1)(f) GDPR. The transfer to the United States is based on the standard contractual clauses (Implementing Decision 2021/914) and the adequacy decision on the EU-US Data Privacy Framework, which GitHub has joined.
We use no cookies for advertising or measurement purposes. Stored are exclusively technically necessary details: the sign-in session, so that you stay signed in, as well as settings such as language, unit of measurement and the map view last chosen. These details remain on your device and can be deleted through the browser settings.
Added to this are the links of the five golf courses you opened most recently. They stand on the start page as a way back. They too remain on your device, are not transmitted to us and can be deleted through the browser settings.
If you keep a scorecard, the strokes you enter are likewise stored on your device, together with the course and the time. Only this way is a round you have started still there after you lock the screen and after a restart of the browser. The five most recent rounds are stored; the oldest one drops out as soon as a sixth is added. They too remain on your device, are not transmitted to us and can be deleted through the browser settings, and individually through “discard round” in the scorecard itself. Only if you are signed in and click “keep round” is a round additionally stored with us; section 4 applies then.
While you edit a book, your browser keeps the most recent state as a draft on your device. Only this way is the work still there after a crash, an empty battery or after you swipe the app away. The draft holds the same content that saving would transmit to us, together with your user ID and the time. Only ever one draft is kept; the next one overwrites it. It remains on your device and is not transmitted to us. It is deleted when you save, and likewise if you open the book again and decline the question about restoring it, and through the browser settings. It is offered only to the account it was created with.
If you were signed in, your browser also remembers that a sign-in existed. This is a single note without your name and without your identifier. It serves the display alone: on reload the page therefore does not briefly show the view for visitors who are not signed in, before the sign-in has been checked. It does not decide about your rights; what you are allowed to change is checked by our server in every case. It is deleted when you sign out.
In the course search there is the button “nearby”. Only when you click this button does your browser ask you for permission to determine your location. Without this click that does not happen, in particular not when the page is opened. If you grant permission, your location is used exclusively in your browser, in order to sort the list of golf courses by distance. It is not transmitted to us and not to third parties, is not stored and is not used again after the page is reloaded. If you decline, the list stays unchanged; you can continue searching at any time without this function.
On the first visit no language is stored yet. The page then reads the language setting of your browser in order to show the interface straight away in a language that you can presumably read. Your browser sends this detail along to every server with every page request anyway; with us it is neither stored nor passed on and serves only as the default setting. A language is stored only once you select one yourself. You can change the selection at any time at the top of the page.
This copy is only made if you ask for it. In the full-screen mode of a round there is a button “Save offline” for that. Only then does your browser store the application itself (program files, style sheets, font and logo) together with the hole and green data of that one course, around 145 kilobytes. Content is not part of it, so neither books nor notes, and no identifier of yours either; the copy holds nothing that could link two visits. It remains on your device, is not transmitted to us and can be deleted in the same place with “Remove”, and through the browser settings. Without that button press we store nothing for this.
You have the right of access, to rectification, to erasure, to restriction of processing, to data portability and to object to processing that is based on a legitimate interest. A request to the email address given above is sufficient.
In addition you can lodge a complaint with a supervisory authority. The competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59 to 61, 10555 Berlin.
No automated decision-making and no profiling takes place. The handicap entry serves solely for other users to classify books and is not evaluated.
The service is not directed at children under 16 years of age. For younger users the consent of the holders of parental responsibility is required.
If we add functions that bring new processing of data with them, we adapt this policy. Authoritative is the German version retrievable here at the time.