Who this applies to
The Service is operated by {{OWNER: registered legal name of the operating company}}, registered in {{OWNER: country / province of registration}} under registration number {{OWNER: company registration number / NTN}} (“we”, “us”, “our”). It is published to the app stores and this website under the name Courtivo, referred to below as “the Service”. “You” means the person using it.
This policy covers the mobile app, this website, and the venue dashboard. It applies both to customers who book courts and to venue staff who hold an account to manage a venue. Where the two differ, it says so.
What we collect
This list is the authoritative one.
The app stores’ data-disclosure forms are filled in from this page. If something is collected and is not listed here, this page is wrong and should be corrected rather than worked around.
Things you give us
- Your mobile number. This is how you sign in — we send a one-time code by SMS — and it is the main way your account is identified. You cannot use the app without one.
- Your name. Shown to a venue on a booking so their staff know who is arriving.
- An email address. Required for venue and administrator accounts. Optional for customers.
- Profile details you choose to add — a photo, your area, your favourite sport, your skill level.
- Business details, for venue accounts only: business name and tax registration number.
- What you write — messages to a venue, reviews, and anything you send to support.
Things the app produces as you use it
- Your bookings and payments — venue, court, sport, date, time, amounts, and the status of each.
- Check-in records — when your QR code was scanned at a venue.
- Push notification tokens, one per device you sign in on, so we can send you booking notifications.
- Device and session information — enough to keep you signed in, to sign you out everywhere if you ask, and to tell one of your devices from another.
- A security log of significant account actions.
Things we do not do
- We do not show advertising, we do not build advertising profiles, and we do not sell your data to anybody.
- This website runs no analytics and sets no tracking cookies — see the cookie notice. The app carries no analytics or attribution SDKs either; nothing measures you inside it.
- We do not collect your contacts, your calendar, or your browsing history.
Permissions the app asks for
Each of these is requested only at the point it is needed, and the app works with them declined — you will just lose that feature.
- Location. Used to show venues near you on the map and to sort search results by distance. Used while you have the app open. We do not track your location in the background.
- Camera. Used to scan a QR code at check-in, and to take a photo for a review or your profile. Nothing is recorded unless you take a picture.
- Photo library. Used only when you pick an existing image for a review or profile photo. We receive the images you choose, not your library.
- Notifications. Used for booking confirmations, reminders and messages from a venue.
What we use it for
- To sign you in and keep your account secure.
- To take a booking, collect payment for it, and get you checked in at the venue.
- To tell the venue who is arriving and when.
- To send you booking notifications and messages from a venue.
- To answer support requests and investigate payment problems.
- To detect and prevent fraud and abuse.
- To meet our tax, accounting and legal obligations.
We do not use your data to make decisions about you by automated means that produce legal or similarly significant effects.
Who else sees it
- The venue you book. They see your name, your booking, your check-in, and your messages to them. They do not see your other bookings, your payment details, or venues you have booked elsewhere.
- Our payment provider, {{OWNER: payment gateway name and legal entity}}, which processes the payment itself.
- Our SMS provider, {{OWNER: SMS / OTP provider name}}, which receives your mobile number in order to deliver your sign-in code.
- Apple and Google, whose push services carry notifications to your device.
- Our hosting and storage providers, {{OWNER: hosting, database and file-storage providers, and the countries they run in}}.
- Authorities, where we are legally required to disclose something.
We do not sell your personal data, and we do not share it for anyone else’s marketing.
Chat and reviews are not private
A conversation with a venue is read by that venue’s staff — often several people, not one named individual. Treat it as a business channel and do not send anything through it that you would not want the venue’s team to have.
Reviews are public. Your name and profile photo appear alongside what you write. Deleting your account does not automatically remove reviews you have already published — see what deletion actually does.
We may read a specific conversation when it is reported to us, or when we are investigating fraud, safety or a support issue.
Payment information
Payments are handled by our payment provider. Your full card number and bank credentials are entered with them and are not stored on our systems.
What we keep is the record of the transaction: the amount, the currency, the time, whether it succeeded, the provider’s reference, and enough of an identifier to recognise the instrument on a refund. That is what lets us trace a duplicate charge or pay money back.
How long we keep it
Booking and payment records are kept for {{OWNER: retention period for financial records, per tax and accounting rules}}, because we are required to be able to produce them.
Account details are kept while your account is open, and are erased when you close it, as described on the delete account page.
Other retention periods: {{OWNER: how long chat messages are kept}}, {{OWNER: how long the security log is kept}}, {{OWNER: how long support tickets are kept}}.
Your choices
- See or correct your details — most of it is editable in the app under your profile.
- Turn off notifications — in the app, or in your phone’s settings.
- Withdraw a permission — location, camera or photos, in your phone’s settings, at any time.
- Close your account — in the app, or through the web request route.
- Ask us a question about your data — see the contact page.
Pakistan does not currently have a general data protection statute in force. We are not claiming compliance with the GDPR, the CCPA, or any other foreign regime, because that would be an assertion we cannot stand behind. We handle your data to the standard described on this page. {{OWNER: whether to commit to a named external standard, and which — a decision for counsel}}
Children
The Service is not intended for children under {{OWNER: minimum age to hold an account}}, and accounts are not knowingly created for them. If you believe a child holds an account, tell us and we will close it.
How we protect it
- Traffic between the app and our servers is encrypted in transit.
- Sign-in is by one-time code, so there is no customer password to be stolen or reused.
- Signing out, or closing your account, invalidates existing sessions on every device.
- Access to production data is limited to staff who need it, and significant actions are logged.
No system is perfectly secure. If we discover a breach affecting your data we will tell you and the relevant authorities as required.
Changes to this policy
We will update this page when what we collect or how we use it changes, and the date at the top will change with it. Where a change is significant we will tell you in the app before it takes effect.
How to reach us
Questions about this policy, or about your data, go to {{OWNER: name or role of the person accountable for data protection}} — contact details are on the contact page.