Privacy Policy
Privacy Policy
v0.5 · effective 2026-06-15Plain-language summary
Court Tabs is a friend-group app for booking sports courts and splitting the cost fairly. We collect your name, public @handle, login email, the payment email you want people who owe/are owed money to see, your phone number, and optional details (bio, pronouns, preferred name, avatar). We record your clubs, sessions you join, reservations, and payment records — but we do NOT process money or touch your card details. Settlement happens directly between people via Interac e-Transfer (Venmo and PayPal are planned). Other members of clubs you share can see your public profile; when you owe or are owed money, the other person sees your payment email and method. We use a small number of service providers to run the app — they process data for us, and we do NOT sell your data. We keep most records indefinitely so historical sessions and payments stay accurate for disputes. Deleting your account anonymizes your profile rather than erasing every row. Our app database is stored in Canada; some of our service providers process data in the United States, which means a cross-border transfer.
Effective date: 2026-06-15. Version: this policy is versioned alongside the application; see "Changes to this policy."
1. Who we are (the organization responsible for your information)
Court Tabs is a friend-group court-booking and fair-cost-splitting Progressive Web App (PWA). You create or join clubs, propose and sign up for sports sessions (such as pickleball and tennis), and the app helps split costs fairly after the game.
The organization responsible for your personal information (the "data controller" under GDPR terminology, or the "organization" under PIPEDA) is:
- Legal entity: Mocato Inc.
- Mailing address: Suite 1400 - 18 King Street East, Toronto, Ontario M5C 1C4, Canada
- Governing province / jurisdiction: Ontario
- Privacy contact email: privacyofficer@mocato.com
- Privacy officer / contact person: Privacy Officer
Under PIPEDA (and Québec Law 25), we are required to designate a person accountable for our privacy compliance. That person is the Privacy Officer, reachable at privacyofficer@mocato.com.
In this policy, "we," "us," "our," and "Court Tabs" mean the entity above. "You" means a user of the app.
2. What information we collect
We collect the following, mirroring exactly what the app stores. Optional fields are marked.
Account and profile
- Full name
- Public @-handle
- Notification/login email — used for sign-in and notifications; handled by our authentication provider
- Payment email — the email you want shown to people who pay you or whom you pay
- Phone number (required to create an account) — see section 3 for how we use it
- Profile bio (optional)
- Pronouns (optional)
- Preferred name (optional)
- Avatar image (optional), stored in a private storage bucket
- Payment method preference (Interac, Venmo, or PayPal)
- Payment email verification status (a timestamp recording when you confirmed, via a link we email to your payment address, that the address is yours; cleared automatically if you change the address)
Security / sign-in credentials
- WebAuthn credentials for biometric unlock: credential ID, COSE public key, signature counter, device label, and last-used timestamp. We store only public-key material and a counter; no biometric data and no private key ever leaves your device.
Login sessions and device information When you sign in, we record one entry per sign-in session so that you — and our admins, for account security — can see where your account is being used. Each entry may include:
- When you signed in and when you were last active
- Your IP address and the approximate location it maps to (country, region, and city). This is a coarse, network-level estimate — not precise GPS, and we never ask for or store your device's exact location.
- Your device type, operating system, and browser, including their versions, as reported by your browser's user-agent, and whether you are using the installed app or a browser tab
- Your screen size, pixel ratio, and your device's time zone We use this only for account security and to power the "where you're signed in" view, so you (or an admin helping you) can recognize and sign out of devices you don't recognize. We do not use it for advertising or tracking you across other sites. See "How long we keep your information" for retention.
Clubs, sessions, and bookings
- Club memberships (club, role, status, join/request timestamps, who approved you)
- Session participation (session, start/end time, status, your cost share)
- Reservations (court label, start/end time, actual cost, confirmation number)
- Reservation/booking proof attachments (booking confirmation images or PDFs)
- Household membership (household, billing contact, status, invite/accept timestamps)
- Handovers (the user a responsibility is transferred from/to, status, timestamp)
Payments (records only — we do not process money; see "Payments")
- Payment records (payer, payee, amount, status, claimed/confirmed timestamps, note)
- Payment proof attachments (e-transfer screenshots or receipts, image or PDF)
- Payment coverage tracking (a list of which users a given payment covers)
Notifications
- Browser push subscriptions (push endpoint, subscription keys, user-agent, last-used timestamp) — only if you opt in to push notifications
- Notification preferences (which non-payment notification categories you've muted, per channel — email or push). Payment notifications cannot be muted; see "How we use your information."
Feedback and product diagnostics
- Feedback submissions (type, message body, status, our admin reply, and any attachments such as screenshots)
- "Journey" breadcrumbs attached to a feedback submission: a short, in-memory list (maximum 30 events) of route paths you visited and the visible labels of buttons/links you clicked, plus the current URL, your viewport size, and your user-agent. These breadcrumbs never capture text you typed or the contents of form fields — only navigation paths and clickable-element labels. They are recorded only to help an admin understand what happened right before you submitted feedback.
Administrative / operational data
- Account flags: admin flag, account active status
- Audit logs (the actor, action, target type, target ID, and metadata for administrative actions)
- Exception/error logs (for debugging)
Facility and club configuration (not personal information, but stored alongside it)
- Facility/venue data (name, address, courts, cancellation window)
- Club info (name, slug, sport, default venue, default rate, visibility, join mode)
We do not knowingly collect more than the above. See "Cookies, local storage, and similar technologies" for client-side data.
3. How we use your information
We use the information above to:
- Create and operate your account and let you sign in (including optional biometric unlock via WebAuthn)
- Let you create/join clubs and households, propose sessions, and sign up
- Record reservations and split session costs fairly among participants
- Record peer-to-peer payment status (pending, claimed, confirmed) and let payers and payees attach proof of payment
- Show the right payment email and method to the specific person who owes you or whom you owe, so a transfer can be completed
- Send transactional emails (for example: payment due, payment confirmed, you've joined a session, an admin replied to your feedback) via our email provider
- Send browser push notifications for high-priority events (payment reminders, session changes) if you opt in
- Use your phone number to contact you about your account and your activity, and — where you've been told and the feature is available — to send transactional text messages (SMS): session and payment reminders, and identity-verification or sign-in codes. We do not use your number for marketing, and we do not sell or share it. Text messages are sent through our SMS provider, Twilio. You can opt out of non-essential reminder texts by replying STOP; verification and security codes may continue while your account is active.
- Handle feedback you submit and reply to you
- Keep audit and error logs for security, debugging, dispute resolution, and compliance
- Operate, secure, maintain, and improve the Service (including diagnosing problems and understanding how features are used)
- Protect the Service and our users (fraud prevention, abuse handling, security)
We do not use your information for third-party advertising, and we do not sell your information.
4. Legal basis and consent
Under PIPEDA, we rely primarily on your consent, which may be express (for example, opting in to push notifications, or choosing to attach a payment screenshot) or implied by your voluntary use of a feature whose purpose is obvious (for example, joining a session necessarily shares your participation with that session's roster). We collect, use, and disclose personal information only for purposes a reasonable person would consider appropriate in the circumstances.
You can withdraw consent at any time (subject to legal and contractual limits) by adjusting settings, declining/disabling push, or contacting us at privacyofficer@mocato.com. Withdrawing consent for core features may mean you can no longer use those features.
6. Where your information is stored and cross-border transfers
Court Tabs is hosted on Vercel, and our application data is stored with Supabase (database, authentication, and file storage). Transactional email is sent through Resend.
These providers commonly process and store data on servers located outside Canada, including in the United States. The exact region of our database and storage is: Canada and the United States. When your information is stored or processed in another country, it may be accessible to authorities in that country under that country's laws.
7. How we protect your information
We use a number of safeguards, including:
- Row-Level Security (RLS) is enabled on every application database table, defaulting to deny access unless a policy explicitly allows it.
- Profile visibility is enforced in the database: a user can see another user's profile only if both share an active club membership.
- Avatars, proofs, and feedback files live in private storage buckets with no public read access. They are reached only through short-lived signed links (valid for one hour) generated by our server. This is designed to prevent one user from accessing another user's files.
- Your payment email is exposed only to the assigned counterparty of a specific payment, after the payment is locked — never on your public profile.
- Your notification email, phone number, and admin flag are hidden from public profiles. Your notification email is visible only to you (in your own account view) and to admins reviewing feedback you submitted; your phone number is not exposed by any public interface.
- Biometric unlock (WebAuthn) stores only a public key and a signature counter on our servers. No private key and no biometric data ever leave your device.
- Uploaded files are validated on the server (file type sniffing, magic-number checks, and size limits); invalid files are rejected.
- Passwords are managed entirely by our authentication provider, which hashes them; we never see or store your raw password. Sign-in sessions use secure, http-only cookies.
- Administrative actions are recorded in audit logs.
No system is perfectly secure. We cannot guarantee absolute security, but we work to protect your information using the measures above.
8. How long we keep your information (retention)
We keep most records for as long as needed to operate the service and resolve disputes. Specifically:
- Profiles: kept indefinitely. Deleting your account anonymizes your profile rather than removing the row, so historical payments, sessions, and participations stay consistent (see "Your rights").
- Sessions and reservations: retained indefinitely.
- Payments: retained indefinitely, so past settlement history is available for dispute resolution.
- Feedback (including attached journey breadcrumbs): 90 days.
- WebAuthn credentials: retained until you remove the device or delete your account.
- Push subscriptions: stale subscriptions (those the push service reports as gone) are deleted automatically; others are retained until you unsubscribe.
- Audit logs and error/exception logs: 90 days.
- Login sessions (IP, approximate location, device/browser): up to 180 days from your last activity on that session, after which the record is deleted automatically. They are also deleted when you delete or deactivate your account.
- Files in storage (avatars, proofs, feedback images): deleted on a best-effort basis when the related profile is deleted or the attachment is removed; otherwise retained indefinitely.
- Authentication logs (email verification, password-reset tokens): managed by our authentication provider; their retention is governed by that provider.
9. Your rights and choices
Access and correction (PIPEDA). You have the right to ask what personal information we hold about you, to access it, and to request corrections. You can view and edit much of your profile (name, handle, payment email, payment method, bio, pronouns, preferred name, avatar) directly in the app. For anything else, contact us at privacyofficer@mocato.com.
Deletion and what it actually does. You can delete your account in the app. Be aware of exactly what happens, because we do not erase every record:
- Your profile is anonymized in place: your handle becomes a non-identifying value, your full name becomes "Deleted user," your notification email becomes a non-deliverable placeholder, your payment email is emptied, and your phone, avatar, bio, and pronouns are cleared. Your account is marked inactive.
- The profile row itself is kept so that historical payments, sessions, and participations that reference you remain valid. In other words, deletion anonymizes rather than fully erases.
- Your stored avatar file is deleted on a best-effort basis.
- Your sign-in (authentication) account is deleted on a best-effort basis; even if that step fails, the anonymized profile prevents you from signing in.
- You are signed out.
Because records such as past payments and session participation are retained (in anonymized form) for dispute resolution and data integrity, a deletion request will not necessarily remove every trace of your past activity. If you want us to attempt fuller erasure where lawful, contact privacyofficer@mocato.com and we will handle it manually to the extent feasible.
Withdrawing consent. You can disable push notifications, decline optional fields, or contact us to withdraw consent. Some features cannot work without certain data.
Québec Law 25 rights. If you are in Québec, you may have additional rights, including the right to de-indexing/cessation of dissemination in certain cases, the right to data portability, and the right to be informed about and to contest automated decisions.
GDPR rights. If GDPR applies to you, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.
We will respond to verified requests within the timeframes required by applicable law. We may need to verify your identity before acting on a request.
10. Children and age
Court Tabs is intended for adults arranging and paying for shared court bookings. It is not directed to children. We do not knowingly collect personal information from children below the applicable age of consent in your jurisdiction. A minimum age of 19 years or older is required to use Court Tabs. If you believe a child has provided us personal information, contact privacyofficer@mocato.com and we will take appropriate steps.
12. Payments — important clarification
Court Tabs records payments; it does not process them. We store payment records (payer, payee, amount, status, notes, and proof attachments), but we do NOT charge cards, hold funds, or move money. Settlement is peer-to-peer: you send money directly to the other person using Interac e-Transfer (live, Canada-focused); Venmo and PayPal are planned. We never collect or store card or bank-account numbers, and we do not integrate a payment processor. The payment email and method you provide are used so the other party to a specific payment can send or receive the transfer outside our app.
13. If there is a privacy breach
If a confidentiality incident or breach of security safeguards creates a real risk of significant harm, we will report it and notify affected individuals as required by PIPEDA (breach-of-security-safeguards reporting to the Office of the Privacy Commissioner of Canada) and, for Québec, maintain a confidentiality-incident register and notify the Commission d'accès à l'information and affected individuals as required by Law 25.
14. Changes to this policy
We may update this policy from time to time. This policy is versioned together with the app. When we make a material change, we will update the effective date and version and, where appropriate, notify you in the app and/or by email, and ask you to re-accept where the law requires renewed consent. Your continued use of Court Tabs after an update takes effect means you accept the updated policy, except where renewed consent is required.
15. How to contact us or make a complaint
Questions, access/correction requests, or complaints: contact our privacy contact at privacyofficer@mocato.com, or write to Mocato Inc. at Suite 1400 - 18 King Street East, Toronto, Ontario M5C 1C4, Canada.
We will acknowledge and respond to your concern. If you are not satisfied with our response, you may contact a privacy regulator:
- Canada (federal, PIPEDA): Office of the Privacy Commissioner of Canada (OPC) — www.priv.gc.ca; toll-free 1-800-282-1376.
- Québec (Law 25): Commission d'accès à l'information du Québec (CAI) — www.cai.gouv.qc.ca.
- Other provinces/countries: your local data protection or privacy authority, where applicable. EU/UK users may contact their national supervisory authority.