Privacy Policy

Updated 3 September 2026

1. Data Controller

XenGolf Oy
Business ID: 3599871-2
Email: info@xengolf.fi

2. Contact for Data Protection Matters

Requests and questions about data protection: info@xengolf.fi. We respond within one month at the latest.

3. Scope of This Policy and Our Roles

This policy covers the following XenGolf Oy services:

  • Website www.xengolf.fi and the newsletter (section 4).
  • Impact service: the player web app at app.xengolf.fi, the Impact Golf mobile app (iOS, Android and Apple Watch) and the golf club administration view (sections 5–6).

Roles. XenGolf is the data controller for the website, the newsletter and the player's own Impact account. When a golf club uses Impact to manage competitions, start lists, its member register, membership applications and payments, the club is the controller and XenGolf is the processor. That processing is governed by a data processing agreement with the club, whose annex is the list of sub-processors.

4. Website and Newsletter

  • Newsletter: email address. Basis: consent (GDPR Art. 6(1)(a)).
  • Contact and demo requests: name, club, email address and message. Form data is forwarded to XenGolf's internal Slack channel, from which sales gets in touch. Basis: legitimate interest (responding to your request).
  • Analytics: Google Analytics 4 only with cookie consent: cookie identifiers, IP address (anonymised), browser and device data, pages visited. Basis: consent.
  • Server logs: content delivery network (CloudFront) logs contain the IP address, browser data and requested page. Daily visitor counts are derived from them without cookies. Basis: legitimate interest (security and operation of the site).
  • Embedded video: the intro video on the home page is loaded from Vimeo's servers and your browser's IP address is transmitted to Vimeo. The embed is set to Do Not Track mode and Vimeo sets no cookies.
  • Fonts and libraries: Google Fonts and the jsDelivr content delivery network receive your browser's IP address when fonts and the cookie banner library are loaded.

5. Impact Service: Player Data

We process the following data when you use Impact as a player in the web app or the mobile app:

  • Account: email address, username, password hash, language, home club, last login. Basis: contract.
  • Profile: first and last name, date of birth, handicap index, profile picture. Basis: contract.
  • Finnish Golf ID / eBirdie: the person identifier, membership data and handicap from the Finnish Golf Union's eBirdie register, fetched after you link your account. Linking is done with a code emailed to you or with your Golf ID credentials, which are used only for authentication and are not stored. Basis: contract.
  • Game data: rounds, hole-by-hole strokes, statistics, competition results and handicap history. Handicap rounds are submitted to eBirdie only when you choose to. Basis: contract.
  • Wellbeing data (Apple Watch): steps and walking distance recorded during a round, shown in the round summary and stored with the round. The round is also saved to the device's Health app under Apple's control. Basis: consent (HealthKit permission).
  • Friends and societies: friend relationships and requests (by email or QR code), player societies, reactions and comments. Basis: contract.
  • Competitions and payments: registrations, groups and tee times, and entry fees via Paytrail Oyj. Paytrail receives your name, email, phone number and the payment amount. XenGolf does not process or store card details. Basis: contract; for payments, statutory accounting obligations.
  • Google and Apple sign-in: the provider's user identifier and, on first sign-in, your email and name. Basis: contract (the sign-in method you choose).
  • Emails: messages we send (verifications, password resets, competition notices, results) are stored in a delivery log with recipient, subject and content. Basis: contract and legitimate interest (proof of delivery).
  • Feedback: free-form feedback, optional screenshots, device and browser data. Basis: consent.
  • Location: the mobile app may request device location to show nearby courses and the distance to the green. Location is processed on the device only and is not sent to XenGolf or third parties. The web app's weather view fetches weather for the course coordinates from Open-Meteo directly from your browser, so your IP address is transmitted to Open-Meteo. Basis: consent (location permission), legitimate interest (weather).
  • Push notifications: when push notifications are enabled we store the device installation identifier and Firebase Cloud Messaging token. The Android app includes the Google Firebase library, which transmits the app installation identifier to Google. Basis: contract.
  • Camera and photos, biometric lock: for taking a profile picture, scanning QR codes and optionally locking the app. Biometric authentication happens in the operating system; no biometric data is provided to XenGolf. Basis: consent.
  • Technical and usage data: IP address, browser and device data, app version, request logs and usage events (for example round saved, registration made) with user and club identifiers. The web app additionally collects page loads, errors and performance with AWS CloudWatch RUM, keyed by user identifier. Basis: legitimate interest (operation, security and development of the service).

6. Impact Service: Data Processed on Behalf of Golf Clubs

In the club administration view XenGolf processes the following data on the club's behalf. The club is the controller, and the club's own privacy notice describes the processing in more detail.

  • Competitions: participants' name, handicap, Golf ID, club, email, groups, tee times, results and payments.
  • Member register: club members' name, member number, membership status and handicap, fetched from the Finnish Golf Union's eBirdie register.
  • Membership applications: applicant's name, date of birth, gender, contact details and address, guardian details for minors, handicap and green card details, marketing and contact consents, the IP address at submission time and the accepted terms. The club's privacy notice is shown on the form. Decided applications are deleted 12 months after the decision.
  • Club messages: emails the club sends to participants and their delivery log.

7. Recipients and Sub-processors

The following sub-processors process personal data on our behalf. The current list with locations and transfer mechanisms: Sub-processors.

  • Amazon Web Services (data centre Stockholm, eu-north-1): hosting, database, files, logs and usage analytics.
  • Resend (USA): sending the service's emails.
  • Paytrail Oyj (Finland): payment services. As a payment institution Paytrail retains payment data for five years by law on its own behalf.
  • Slack (USA): internal notifications from forms and error and usage alerts.
  • Google: Google Analytics (with consent), the Firebase library in the Android app, Google Fonts.
  • GitHub, Tailscale and Anthropic: development and operations tools through which XenGolf's technical staff may process service data in a limited way for troubleshooting.

The following parties are independent controllers to whom data is transferred when you use the service: the Finnish Golf Union (eBirdie, Golf ID, handicaps and results), Google and Apple (sign-in, app stores, Apple Health). In addition, your browser directly calls the following third parties, which receive your IP address but to which XenGolf discloses no data stored in the service: Vimeo (intro video), jsDelivr and Google Fonts (website libraries and fonts) and Open-Meteo (weather in the web app).

Data is not sold or disclosed to third parties for marketing purposes. Data is disclosed to authorities only where required by law.

8. Transfers Outside the EU and EEA

Service data is stored in the EU (AWS, Stockholm). Some sub-processors operate in the United States (Resend, Slack, Google, Vimeo, GitHub, Anthropic), and the AWS content delivery network also uses edge locations in North America. Transfers rely on the EU-U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. Details per vendor: Sub-processors.

9. Retention Periods

  • Account and game data: for as long as the account exists. When you delete your account, it is closed and sessions, push devices and Apple sign-in are revoked immediately. Closed account data is deleted or anonymised in the clean-up run after the end of the golf season, except data that accounting law or the club's competition history requires to be kept.
  • Membership applications: 12 months from the decision.
  • Payment data: 6 years from the end of the financial year, as required by the Finnish Accounting Act.
  • Email delivery log: for the lifetime of the account.
  • Technical logs: application logs 14 days, load balancer logs 90 days, content delivery network logs 30–90 days, usage events up to 2 years.
  • Newsletter: until you unsubscribe.
  • Cookies: see section 12.

10. Data Subject Rights

Under the GDPR you have the right to:

  • Access: know what personal data we process about you.
  • Rectification: have inaccurate data corrected. You can edit your profile yourself in the app.
  • Erasure: delete your account in the app (Profile → Account settings → Delete account) or request deletion by email.
  • Restriction and objection: for processing based on legitimate interest.
  • Portability: receive the data you provided in a machine-readable format.
  • Withdraw consent: at any time. Unsubscribe from the newsletter via info@xengolf.fi, change cookie settings in , and manage app permissions (location, camera, Health, notifications) in your device settings. Apple sign-in can be revoked in device settings (Settings → [your name] → Sign-In & Security → Sign in with Apple → Impact Golf).
  • Lodge a complaint: with the Office of the Data Protection Ombudsman, tietosuoja.fi.

For data processed on behalf of a club (section 6), requests are directed to the club and we assist the club in fulfilling them.

11. Data Security

All connections are encrypted with HTTPS. The database and stored files are encrypted at rest. Passwords are stored only as hashes; session credentials are kept in httpOnly cookies (web) and in the device's encrypted keystore (mobile). The service is protected by a web application firewall (AWS WAF), and access to personal data is limited to staff who need it for their work. Club data is isolated between clubs.

12. Cookies and Similar Technologies

Website www.xengolf.fi

Cookie Purpose Type Duration
xengolf_ccCookie preferencesNecessary1 year
_gaGoogle Analytics user identifierAnalytics (consent)2 years
_gidGoogle Analytics session identifierAnalytics (consent)24 hours

Web app app.xengolf.fi

Cookie / storage Purpose Type Duration
Session cookies (httpOnly)Keeping you signed inNecessarySession / sign-in validity
cwr_s, cwr_uAWS CloudWatch RUM: session and user identifier for error and performance monitoringOperational monitoring30 min / 30 days
Browser local storageOffline scorecard storage and settingsNecessaryUntil cleared

Analytics cookies on the website are enabled only with your consent: .

13. Changes to This Policy

We may update this privacy policy. We will announce material changes on the website and in the app. Changes to the sub-processor list are notified to club customers in accordance with the data processing agreement.