AMP Media

Golfaaja

Privacy

Last updated September 23, 2026. Golfaaja by AMP Media. Friends match play scoring. It is not the Beehive Open app. Events are PIN-gated. No ads.

Account

Create / host only — guests who join a match never need an account (name + playing handicap; optional Contact Info). Firebase Authentication owns credentials. We never see or store plaintext passwords.

  • Magic link — email one-time sign-in link via Firebase Auth.
  • Password — optional email + password. Hashed by Firebase / Google; we never see plaintext.
  • Passkey — WebAuthn / passkey when enabled in Firebase Auth (Identity Platform).
  • Authenticator OTP — TOTP authenticator app when Firebase MFA is enabled.
  • Phone / SMS — not collected for sign-in until SMS ships.

Profile on this device can store a default playing handicap for new matches only — editing it never rewrites handicaps or pops on live or finished scorecards. Password and passkey changes go through Firebase Authentication only; we never store plaintext passwords. Sign out clears the on-device resume pointer so the next person on a shared phone is not dropped into your last round.

We use your email to sign you in and reach you about the waitlist / invites. Account + matches you created: delete via anders@ampmedia.co · Data Deletion Request.

Waitlist ladder

Email, state, optional phone; invite-friend links (?ref=) so we know who invited whom; invite codes; scorecard photos you upload to help fill course cards (User Content). Not sold, not ads.

What we collect (events)

  • Event name, PIN, people (name, playing handicap, SI card, side if teams)
  • Rounds (course, tee, format, pops)
  • Tee times (date, time, who, course)
  • Scores once play starts
  • Chat messages

Guest signup

Hosts can share an unguessable signup link. Guests submit name and playing handicap (index) for that match only. Blank HCP = scratch. Optional email or phone for that match only. Connecting an account is optional. Contact Info for that match only — not the waitlist ladder, not sold, not ads. Entries sit pending until the host confirms; then they join the roster like anyone else. Link isn’t listable. Host (admin PIN) can edit or remove. Same delete path: anders@ampmedia.co · Data Deletion Request (name the match).

GPS

The hole map can show yards-to-pin when a pin location is in the Utah book. Location is opt-in: the browser or phone asks when you open GPS. We do not store your location. Missing pin means no yards-to-pin.

How it is stored

Each event is its own document in Google Firebase under a 4-digit PIN. Reads are PIN-gated. There is no public list of events. No ads.

Join PIN is scores, board, and chat (share it). Admin PIN edits people, rounds, and course (don’t share). Same AMP Media stub otherwise.

Chat

Chat (event room, plus team rooms if sides are on) is PIN-gated — only that event, not public. No Giphy this pass. Push still off.

Course interest

If a private course isn’t playable and you tap I want this course, we send your email and phone to that course only, with this consent, so they can see interest. Not sold, not ads. Delete: anders@ampmedia.co · Data Deletion Request.

Course scorecards

Courses can submit details and a scorecard photo at /submit-scorecard. Submissions include contact info and the image for review (User Content).

Delete

anders@ampmedia.co · Data Deletion Request (account + matches you created as host + waitlist + uploads). Say the event PIN if you have it.

App Store later

Contact Info · App Functionality (guest signup email/phone for that match; course interest to the named course). Not tracking.

Back