Privacy

How we handle your roll-up

RollupBandit is built so the organiser stays in control of their roll-up's data. This page sets out, in plain language, what we collect, why, and what we don't.

Roll-up and round data

Member rosters, round configurations, scores, prize allocations, handicap movements and round history are stored on the organiser's device. This data is the roll-up's, not ours.

If the organiser turns on sharing for a roll-up, a published copy of its results is stored by RollupBandit so approved followers can view it. That is optional and explained under Sharing with followers below. Nothing is uploaded just because a roll-up exists in the app.

RollupBandit does not collect or hold roll-up prize money in-app. Pot collection and payouts are settled offline by the organiser, the way they always have been.

Personal information

Golfer names, handicaps and qualifying-round counters are entered by the organiser to run the roll-up. They are visible only to the organiser using the app on their device, unless the organiser chooses to share the roll-up with followers (see below).

RollupBandit does not require accounts or sign-in.

Diagnostics

Where crash reports or diagnostic logs are collected, they cover technical issues only - device model, OS version, the path through the app at the point of failure. They never include scores, names or any roll-up content.

Subscriptions

RollupBandit Premium is an auto-renewable subscription. The payment itself is processed by Apple via the App Store on iPhone and by Google via Google Play on Android. We never see card details.

To know whether a device is currently subscribed, RollupBandit uses RevenueCat as its subscription receipt processor. RevenueCat receives an anonymous app-user identifier (generated by the device, not linked to any roll-up data or personal information you have entered into the app) and the current subscription state for that identifier. That's how we unlock the premium features you've paid for without holding your billing information ourselves.

The Support ID shown inside Settings is the same anonymous identifier. Quoting it when you contact us lets us help you with a subscription question without needing you to create an account.

If an organiser uses roll-up sharing, our service checks the same subscription state with RevenueCat to confirm Premium before publishing. This is a read-only check; it adds no new billing information.

Anonymous app analytics

RollupBandit uses PostHog to collect anonymous product analytics from the mobile app. This helps us understand how the app is used, improve features, fix issues, and understand which premium features are useful to organisers.

The analytics we collect may include app events such as opening the app, creating a roll-up, creating or completing a round, using share/export, viewing premium features, starting an upgrade flow, completing or restoring a purchase, platform, app version, build number, and subscription status.

We do not send golfer names, roll-up names, tournament names, exact scores, exact payouts, backup contents, free-text notes, or personal golf data to analytics.

We do not use this analytics data for third-party advertising, and we do not use it to track you across other companies' apps or websites.

You can turn anonymous analytics off at any time in the app - open Settings and toggle "Anonymous analytics" under Privacy.

What we don't do

Sharing and exports

Recap and round share packs are generated on-device and handed to the platform's standard share sheet. Where the recap goes after that - WhatsApp, email, Messages - is decided entirely by the organiser at the moment of share.

Sharing with followers

An organiser can turn on sharing for a roll-up so the group can follow along in RollupBandit. This is off by default, applies only to the roll-ups the organiser shares, and every follower needs the organiser's approval before they can see anything.

When sharing is on, RollupBandit stores the published view of that roll-up on our service: golfer names, completed results and history, published handicaps, stats, seasons and honours, resolved prize and payout amounts, and any competitions the organiser chooses to include. Live scoring, drafts, entry-fee collection tracking and organiser-only settings are never uploaded.

Sharing and following use a device identifier and credential created by the app to authenticate requests and manage access. No account, email address or password is created, and the identifier stays on that device - it does not travel with backups.

When someone asks to follow a roll-up, they type a short name so the organiser can recognise the request. That name is kept only while the request is waiting and is removed once the organiser decides. The organiser may also link an approved follower to a golfer in the roll-up so their results are highlighted for them; the organiser can change or remove that link.

Our sharing service runs on Cloudflare. The databases and storage that hold shared roll-up data are configured with Cloudflare's European Union jurisdiction restriction, which keeps that stored data within the EU. Requests to and from the service may pass through Cloudflare's wider global network on the way.

Stopping sharing and removing followers

The organiser can remove any follower at any time; their access ends at their next refresh. The organiser can also stop sharing entirely, which ends all follower access and deletes the roll-up's published data from active storage. A small amount of operational record (such as the fact that a device once requested access) is kept where it is needed to run the service securely. Anything a follower's device has already downloaded and displayed cannot be remotely erased from their device, just as a shared WhatsApp recap cannot be unsent.

Notifications

Notifications are optional and off until you switch them on inside the app. If you do, RollupBandit uses Firebase Cloud Messaging (a Google service) to deliver them, which involves a Firebase-generated installation identifier for your app installation. Notifications are short signals - for example that a new result is ready or an access request has arrived - and never contain scores, prize amounts or golfer names beyond the roll-up's own name. We do not use Firebase Analytics.

Your rights

Because roll-up data lives on the organiser's device, deleting the app or removing a roll-up removes the data. For roll-ups that have never been shared, we hold no central copy of round content to delete on request. For a shared roll-up, the published copy is deleted from active storage when the organiser stops sharing.

For any privacy questions or requests, reach out to support@rollupbandit.com.

Updates to this page

This page is revised when the way RollupBandit handles data changes. The substantive position - the organiser's device is home, and anything stored by RollupBandit is there only because the organiser chose to share it - is not expected to change.