Plain-Language Summary Not a substitute for the full Policy below
We collect your name, email, and username when you register — nothing more is required.
We never store credit card, debit card, or any external payment details. No financial data leaves the platform.
Your information is shared with organization administrators only within the organizations you join.
This policy is governed by Canadian federal and Ontario provincial law, including PIPEDA.
1. Overview & Scope
This Privacy Policy ("Policy") describes how CourtUp.ca ("CourtUp.ca", "we", "us", or "our") collects, uses, discloses, and safeguards personal information in connection with the CourtUp.ca platform, including its website, mobile-optimized interface, and all related services (collectively, the "Platform").
This Policy applies to all users of the Platform, including individual members ("Users"), organization owners ("Owners"), organization managers ("Managers"), and platform administrators ("Admins").
CourtUp.ca complies with the Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, and, where applicable, provincial privacy legislation including the Personal Information Protection Act (PIPA) in British Columbia and Alberta, and Loi 25 in Québec.
By using the Platform, you consent to the practices described in this Policy. If you do not agree with this Policy, please do not use the Platform. This Policy is incorporated by reference into our Terms of Service.
2. Definitions
The following capitalized terms have the meanings set out below throughout this Policy:
| Term | Meaning |
|---|---|
| "Personal Information" | Any information about an identifiable individual, as defined in PIPEDA. |
| "Sensitive Information" | Information such as health or medical data, financial account numbers, government-issued identification numbers, biometric data, racial or ethnic origin, religious beliefs, and sexual orientation. CourtUp.ca does not collect Sensitive Information. |
| "User" | Any individual who accesses or uses the Platform, whether or not they have a registered account. |
| "Organization" | A sports club, league, association, or group registered on the Platform to manage events and members. |
| "Owner" | A User who created or has top-level administrative ownership of an Organization on the Platform. |
| "Manager" | A User who has been granted administrative management authority over an Organization by the Owner or a platform Admin. |
| "Membership Balance" | An in-platform prepaid credit balance, expressed in dollars, associated with a User's membership in a specific Organization. It is not linked to any external payment instrument. |
| "PIPEDA" | The Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, as amended from time to time. |
3. Information We Collect
3.1 Account Registration
When you create an account on the Platform, we collect the following information:
- Full name — used to identify you to organization administrators and on event attendee lists.
- Email address — used for account verification, sign-in, password reset, and platform notifications.
- Username (nickname) — an optional public handle displayed within your organizations and on event pages.
- Password (hashed) — your password is stored only as a one-way cryptographic hash (bcrypt). We cannot read or recover your plain-text password.
- Email verification status — whether your email address has been confirmed.
3.2 Optional Profile Information
After creating an account you may optionally complete your user profile. Optional fields include:
- Avatar / profile photo — a publicly visible image you upload.
- Biography — a short personal description.
- Sports ratings — your DUPR (Dynamic Universal Pickleball Rating) and GPN (Global Pickleball Network) rating numbers, if you choose to provide them.
- Gender — used optionally for registration export reports generated by organization managers.
- DUPR ID — an optional external identifier for cross-referencing sports rating platforms.
None of the above optional fields are required to use the Platform.
3.3 Organization & Membership Data
When you join an organization or are approved as a member, we record:
- Your membership status and role within the organization (User, Member, Manager, Owner).
- Your Membership Balance — an in-platform credit balance managed by the organization. This is a platform-internal accounting record, not a payment instrument.
- The date you joined and whether your membership is approved or pending.
3.4 Event Registration Data
When you register for an event, we record:
- Which events you have registered for and your registration status (REGISTERED, WAITLIST, or CANCELLED).
- The date and time of your registration.
- Any event fee charged to or refunded to your Membership Balance.
3.5 Transaction Records
We maintain a log of all Membership Balance transactions (DEPOSIT, CHARGE, REFUND, ADJUSTMENT) so that you and organization administrators can review financial activity within the Platform. These records do not include any external bank account numbers, credit card numbers, or other external payment instrument data.
3.6 OAuth Sign-in Data
If you choose to sign in using a third-party OAuth provider (such as Google, Facebook, or WeChat), we receive from that provider only the information needed to create or link your Platform account, typically your name and email address. We do not receive your password or payment information from these providers. Your use of third-party sign-in services is also subject to those providers' own privacy policies.
3.7 Technical & Log Data
Like most web services, our servers automatically record standard technical information when you use the Platform, including your IP address, browser type, operating system, referring URL, pages visited, and timestamps. This data is used for security monitoring, debugging, and aggregate analytics. We do not use it to build individual marketing profiles.
4. What We Do Not Collect
CourtUp.ca is a community sports coordination platform. We have deliberately designed the Platform to avoid collecting information that is not necessary for its operation. The following categories of information are never collected, stored, or processed by CourtUp.ca:
- Health or medical information (e.g., medical conditions, prescriptions, health insurance numbers)
- Government-issued identification (e.g., SIN, passport number, driver's licence)
- Biometric data (e.g., fingerprints, facial recognition data, retinal scans)
- Racial or ethnic origin
- Religious or political beliefs
- Sexual orientation or gender identity (beyond what you optionally self-disclose in your profile)
- Home address or precise geolocation
- Phone numbers
5. How We Use Your Information
We use the information we collect for the following purposes only:
5.1 Operating the Platform
- Creating and maintaining your account and profile.
- Authenticating your identity when you sign in.
- Processing and managing event registrations, waitlists, and cancellations.
- Tracking Membership Balance transactions within the Platform.
- Displaying your name, nickname, and sports ratings on event attendee lists visible to other members of shared organizations.
5.2 Communications
- Sending you transactional emails such as account verification, password reset links, and event registration confirmations.
- Notifying you of changes to events you have registered for (e.g., cancellation or time changes communicated by the organization).
- Notifying you if you have been promoted from a waitlist to a registered status.
- Sending platform and policy update notices where required by law.
We do not send unsolicited marketing emails. You will only receive email communications that are directly related to your use of the Platform.
5.3 Security & Abuse Prevention
- Detecting and preventing fraudulent account activity, unauthorized access, and abuse of the Platform.
- Enforcing rate limits on sign-in attempts to protect accounts from brute-force attacks.
- Investigating reports of conduct that violates our Terms of Service.
5.4 Platform Improvement
- Aggregated, anonymized analytics to understand how the Platform is used and to improve its features and performance.
- Debugging and resolving technical errors.
7. Organizations, Owners & Managers
7.1 Data Access by Role
The Platform implements a role-based access model. The level of member data accessible to organization personnel is determined by their role:
| Role | Data Access Scope |
|---|---|
| Platform Admin | Full access to all organization and user data on the Platform for administrative, security, and support purposes. |
| Owner | Full access to member data, Membership Balances, transactions, and event registrations within their own organization(s). |
| Manager | Full access to member data, Membership Balances, transactions, and event registrations within the organization(s) they manage. Cannot access data from other organizations. |
| Member / User | Access to their own profile, Membership Balance, and registration history only. Can view the names and ratings of fellow members on shared event attendee lists. |
7.2 Organization Responsibilities
Organization Owners and Managers who access member personal information through the Platform act as independent data controllers for their own administrative activities. They are individually responsible for:
- Using member information only for legitimate organization management purposes;
- Complying with applicable Canadian privacy legislation (PIPEDA, PIPA, Loi 25) in respect of any personal information they access;
- Not sharing, exporting, or retaining member data beyond what is necessary for managing the organization; and
- Responding to member requests for access or correction of their information within their organization.
7.3 Export of Registration Data
Owners and Managers may export event registration lists (in CSV or TXT format) for operational purposes such as attendance tracking. These exports may include member names, nicknames, sports ratings, gender (if provided), and registration status. Exported data must be handled in accordance with this Policy and applicable law.
9. Security of Your Information
CourtUp.ca takes reasonable technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, and destruction. These measures include, but are not limited to:
- TLS/HTTPS encryption on all data transmitted between your browser and our servers.
- Bcrypt password hashing — your password is never stored in readable form.
- Signed and encrypted session tokens (JWT) to prevent session tampering.
- Rate limiting on sign-in endpoints to prevent brute-force attacks.
- Role-based access controls ensuring users can only access data appropriate to their role.
- Containerized infrastructure with network isolation between application and database layers.
- Regular security reviews of application code and dependencies.
- Email obfuscation in public-facing documentation to reduce spam harvesting.
10. Data Retention
10.1 Active Accounts
We retain your personal information for as long as your account remains active or as needed to provide you with the Platform's services.
10.2 Account Deletion
If you request deletion of your account, we will delete or anonymize your personal information within a reasonable period, subject to the following exceptions:
- Information required to be retained by applicable Canadian law (e.g., financial transaction records required under tax law).
- Information necessary to resolve outstanding disputes or enforce our Terms of Service.
- Aggregated or anonymized data that no longer identifies you.
10.3 Transaction Records
Membership Balance transaction records (DEPOSIT, CHARGE, REFUND, ADJUSTMENT) may be retained for up to seven (7) years in accordance with standard Canadian financial record-keeping practices and applicable tax regulations, even after account deactivation. These records are internal accounting entries and do not include external payment data.
11. Your Privacy Rights
Under PIPEDA and applicable provincial privacy legislation, you have the following rights with respect to your personal information held by CourtUp.ca:
You may request a copy of the personal information we hold about you. We will respond within 30 days of receiving a written request.
You may update most of your profile information directly through the Platform's account settings. For other corrections, contact us and we will update your information promptly.
You may request deletion of your account and personal information, subject to our retention obligations described in Section 10.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent may limit your ability to use certain features of the Platform.
How to Exercise Your Rights
To submit a privacy request, please contact our Privacy contact at pr****y@c******.ca or through the Contact Us page at courtup.ca/contact. Please include your name and the email address associated with your account. We will respond within thirty (30) days and will not charge a fee for reasonable access requests.
12. Children's Privacy
The Platform is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. Users between the ages of 13 and 18 may use the Platform only with the express consent of a parent or legal guardian.
If you are a parent or guardian and believe your child under 13 has provided personal information to CourtUp.ca without your consent, please contact us at pr****y@c******.ca. We will take prompt steps to delete such information from our records.
Parents and guardians who consent on behalf of a minor between 13 and 18 accept the same obligations and responsibilities as the minor User under our Terms of Service and this Policy.
13. Third-Party Links & Services
The Platform may contain links to third-party websites or integrate third-party services (such as Google Maps for venue lookup, or OAuth providers for sign-in). These third parties have their own privacy policies, and CourtUp.ca is not responsible for their privacy practices.
We encourage you to review the privacy policies of any third-party services you interact with through the Platform. CourtUp.ca does not endorse or make any representations about third-party websites or services.
Third-party sign-in providers (Google, Facebook, WeChat) are governed by their respective privacy policies. When you sign in via OAuth, the information shared with CourtUp.ca is limited to what is described in Section 3.6.
14. Changes to This Policy
CourtUp.ca reserves the right to update this Privacy Policy at any time to reflect changes in our practices, the Platform, or applicable law. When we make material changes, we will:
- Update the "Effective Date" at the top of this page.
- Post a prominent notice on the Platform.
- Where required by applicable Canadian law, notify you by email to the address associated with your account.
Your continued use of the Platform after the updated Policy has been posted constitutes your acceptance of the revised Policy. If you do not agree to the updated Policy, please stop using the Platform and request account deletion as described in Section 11.
The most current version of this Policy will always be available at courtup.ca/privacy-policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please contact us through any of the following channels:
Ontario, Canada
Our commitment to you
CourtUp.ca is built to bring sports communities together. We take privacy seriously and are committed to handling your personal information with care, transparency, and respect. We collect only what is necessary, protect it with industry-standard measures, and never sell it. This Privacy Policy, together with our Terms of Service, constitutes the complete agreement between you and CourtUp.ca regarding the handling of your personal information.