Privacy policy

How ReadyCourt handles personal data, for venues who use the platform and for players who book through it.

Draft. This policy is a working document and has not yet been reviewed by a lawyer. Have it checked against the Data Privacy Act of 2012 (RA 10173) and your own practices before you rely on it commercially.

1. Who controls what

ReadyCourt is booking software licensed to sports venues. Two different relationships sit behind that, and they matter for your data:

  • The venue is the data controller for its own customers. When you book a court, the venue decides why your details are collected and what happens to them.
  • ReadyCourt is the data processor. We store and process that information on the venue's behalf, under their instructions, and we do not use it for our own purposes.
  • For the venue's own staff accounts, meaning the people who log in to run the venue, ReadyCourt is the controller.

If you booked a court and want your information changed or deleted, contact the venue first. They can action it directly, and we support them if needed.

2. What we collect

From players booking a court

  • Name
  • Email address, if provided, so we can send the tracking number and status updates
  • Mobile number, if provided
  • Party size, booking notes, and any add-ons selected
  • The booking itself: venue, court, date, time, amount, payment status

We do not collect or store card numbers, bank credentials or e-wallet logins. Payment happens directly between you and the venue, typically against a GCash or Maya QR code they display. We record only whether the venue has marked a booking as paid.

From venue staff

  • Name, email address and a hashed password
  • Two-factor authentication secret and recovery codes, if enabled
  • Venue configuration: courts, hours, pricing, branding, payment instructions, tax details

Automatically

  • Server logs (IP address, browser type, pages requested, timestamps), kept for security and troubleshooting
  • A session cookie, which is strictly necessary for logging in and for the booking flow to work

We do not run advertising trackers or third-party analytics profiling.

3. How it's used

  • To take, confirm, change and cancel court bookings
  • To send transactional email: booking received, confirmed, cancelled
  • To let a player check their booking status using a tracking number
  • To produce the venue's own sales and tax reports
  • To keep accounts secure and to investigate abuse

We do not sell personal data. We do not send marketing email to players. Any promotional contact comes from the venue, under their own consent.

4. Sharing

Personal data is disclosed only to:

  • The venue you booked with. They see your booking and contact details, because they have to.
  • Infrastructure providers. The platform runs on DigitalOcean servers located in Singapore. Email is delivered through a third-party mail provider.
  • Authorities, where we are legally required to disclose.

Data is stored outside the Philippines (Singapore) for latency reasons. Providers are bound by their own data-protection commitments.

5. Retention

  • Bookings are retained while the venue's account is active, since they form the venue's sales and tax records. Cancelled bookings are kept for the same reason.
  • Staff accounts are removed when a venue closes its account.
  • Server logs are kept for a short operational window and then rotated.

When a venue leaves the platform, its data is deleted or returned within a reasonable period, subject to any records the venue must keep for tax purposes.

6. Your rights

Under the Data Privacy Act of 2012, you have the right to:

  • Be informed about how your data is processed
  • Access the personal data held about you
  • Correct anything inaccurate
  • Object to processing, or withdraw consent
  • Request erasure or blocking, where grounds apply
  • Data portability
  • Lodge a complaint with the National Privacy Commission
  • Claim damages for unlawful processing

For booking data, raise these with the venue. For anything ReadyCourt controls directly, contact us below.

7. Security

  • Passwords are hashed with bcrypt and never stored in readable form
  • Optional two-factor authentication for every staff account
  • Rate limiting on login, two-factor, password reset and booking lookup
  • Venue data is scoped so one venue can never read another's records
  • Encrypted transport (HTTPS) on production domains

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected venues and, where required, the National Privacy Commission.

8. Contact

Questions about this policy, or a request about your data: support.readycourt@gmail.com.

We may update this policy as the product changes. The revision date below tells you when it last moved.

Last updated: 11 August 2026