TRUST, BUILT INTO EVERY CONVERSATION

Privacy is a commitment.
Here is ours.

This policy explains how Golfpassc handles data when delivering authorized business messaging and management services, and how customers can control access and request deletion.

Effective date: September 17, 2026   ·   Last updated: September 17, 2026

Our promise, in plain language.

Data privacy is our priority. We use accessed data only to provide management functions to the corresponding authorized customer. We do not use it for advertising targeting, user profiling, or telemarketing. We do not sell or share it with any third-party entity.

01. Scope & responsibility

This Privacy Policy applies to Golfpassc’s website and its authorized business messaging and management services, including data accessed through Meta platforms where a customer grants the relevant permissions.

Golfpassc handles customer data for the management functions requested by that customer. The customer determines which business resources to authorize and the business purposes of its customer communications. We keep our use of accessed data within those authorized functions.

02. Data we access

The data accessed depends on the permissions granted and the functions the customer chooses to use. Relevant data may include:

  • Business resource information: identifiers and details of authorized business accounts, Pages, and messaging resources.
  • Conversation information: messages, attachments, conversation identifiers, timestamps, and delivery or response status needed to manage customer communications.
  • Corresponding customer information: platform identifiers, display names, and information a person provides in a conversation, where available within the granted permissions.
  • Authorization and workflow information: permission status, access credentials, response settings, routing instructions, and operational records required to perform the authorized functions.

We limit access to data relevant to the requested management functions and the authorization provided by the customer.

03. How data is used

All accessed data is used solely to provide the corresponding management functions to the customer who authorized access. These functions include organizing business conversations, delivering configured responses, supporting customer-service workflows, and coordinating authorized team follow-up.

We also use the information needed to maintain the authorization, operate those functions, and resolve service issues affecting that customer.

We do not use accessed data for advertising targeting, user profiling, or telemarketing. We do not repurpose one customer’s data for another customer’s activities or for unrelated commercial purposes.

04. No sale or third-party sharing

We do not sell or share accessed customer data with any third-party entity. We do not make it available to advertisers, data brokers, telemarketing businesses, or other organizations for their own use.

Data access remains limited to providing the corresponding customer’s authorized management functions.

05. Data retention & permanent deletion

We retain data only for as long as it is needed to deliver the customer’s authorized management functions.

When a customer revokes authorization, we immediately stop accessing their data. In accordance with Meta’s platform policies and the user’s requests, we permanently delete all related data from our systems.

Deletion applies to related customer information, conversation data, authorization credentials, and associated records held in our systems. We do not retain copies for advertising, profiling, telemarketing, resale, or other unrelated purposes.

We also honor user requests to delete relevant data in accordance with applicable platform requirements. Removing data from Golfpassc’s systems does not itself remove the original information held by the customer or the originating platform.

06. Your choices & deletion requests

To revoke authorization: open the permissions or business integration settings of the Meta account or business resource that granted access, locate the Golfpassc integration, and remove its access. The exact controls depend on the Meta product and authorization method used. Revocation triggers the access cessation and deletion commitments in Section 05.

To request deletion directly: use the existing service communication channel through which your business works with Golfpassc. Identify the relevant business resource or account and the data you want deleted so that we can locate the records and verify that the request is authorized. Do not provide passwords or access tokens.

If you communicated with a business that uses Golfpassc, you may also direct a deletion request to that business through the same channel you used to communicate with it. The business can identify the relevant conversation and instruct us to delete the associated data.

Customers may also use their existing Golfpassc service communication channel to ask questions about this policy or request access to, or correction of, relevant information.

07. Data protection

We are committed to protecting data against unauthorized access, use, alteration, disclosure, and loss. Our handling of customer data is governed by limited authorization, purpose-specific access, and the retention and deletion commitments described in this policy.

Customers should keep their own business account access secure and grant only the permissions required for the functions they intend to use.

08. Website privacy

The Golfpassc public website does not include advertising trackers, analytics scripts, or forms that collect personal information. Its page code does not set cookies or store information in your browser’s local storage.

When you visit the website, the hosting infrastructure may process technical request information, such as your IP address, requested page, and browser information, to deliver and protect the site. This technical website traffic is separate from customer data accessed through authorized business integrations.

09. Policy updates

We may update this policy to reflect changes to our services, data-handling practices, or applicable platform requirements. The current policy will remain available on this page, with the latest revision date shown above.