1. Who we are
KOVA LABS PTE. LTD. (UEN 202621376C), registered at Marina Bay Financial Centre, 10 Marina Boulevard, #39-000, Singapore 018983, is responsible for the personal information described in this Policy. Our Data Protection Officer can be contacted at privacy@theturfapp.com or through https://theturfapp.com/support.html.
2. Scope of this Policy
This Policy applies to Turf’s website, public map, support and place-submission forms, mobile applications, account features, and related services. It does not govern third-party websites, maps, applications, or services that we link to but do not control.
3. Information we collect
The public website map can be browsed without an account. If you create an app account or use account features, we may collect your email address, authentication identifiers, username, display name, avatar, profile photos, profile visibility, home area, saved places, friends and requests, blocks, direct and spot-chat messages, online or offline availability, verified-spot sharing status, play history, reports, reviews, ratings, captions, uploaded photos, and places you submit. Turf also retains place-search queries and place-request records linked to your account, including the request type, country code where provided, and time. We use these records to enforce service limits, investigate failures, and prevent abuse. Video uploads are currently disabled; existing video content may remain subject to the retention rules below. With permission, the app checks device location while Turf is open to provide nearby results, keep your own map character positioned, determine whether you are at a verified Turf spot, verify reviews and check-ins, join spot chat, or submit a place. Approximate location can show that you are live at a selected verified spot; Precise Location is required to post, check in, submit a spot, or enter spot chat. Coordinates used for a server location check are transmitted securely for that check but are not retained in the verification record; Turf retains a short-lived proof containing the target spot, distance, accuracy level, and verification time. We do not show friends your precise coordinates: when spot sharing is on, we disclose only the verified Turf spot you are currently at. Support requests may include your name, reply email, category, subject, message, and optional screenshot. If you join the website waitlist, we collect your email address, launch-update consent, and related request metadata so we can send the updates you requested. When configured, Sentry receives restricted JavaScript error diagnostics: a generic error label, event identifier and timestamp, application environment, and numeric source line and column numbers. Turf removes the original error message, source paths, user details, request context, device context, and breadcrumbs from these error events before sending them. Sentry native crash reporting is disabled. Sentry and our other infrastructure providers still receive the IP address and ordinary technical information needed to handle network requests. Our infrastructure and security providers may also process IP address, device and browser information, request timestamps, and diagnostic or security logs.
4. How we collect information
We collect information directly from you when you create or update an account, use social or location features, upload content, submit or review a place, report content, or contact Support. We obtain public place facts and facility media from public authorities, public directories, community submissions, and third-party map listings, and record limited technical information through hosting, database, security, and map-tile requests.
5. Why we use information
We use information to operate and secure the service; display and maintain public sports-location listings; review, verify, correct, or reject submissions; respond to support and privacy requests; diagnose errors; prevent spam, fraud, abuse, and security incidents; understand service performance; comply with legal obligations; and establish, exercise, or defend legal claims. We will not use personal information for an incompatible purpose without providing any notice or obtaining any consent required by law.
6. Consent and permitted purposes
We collect, use, and disclose personal information with your consent, as needed to provide features you request, for legitimate operational and security purposes that a reasonable person would consider appropriate, and where required or permitted by law. Spot location sharing is off until you turn it on and grant device location permission. You can turn it off in Turf settings or withdraw device permission in system settings. Turning it off stops your active spot status and also prevents you from seeing friends at spots. Withdrawal does not affect processing already carried out lawfully and may prevent the affected feature from working.
7. When we share information
We use Supabase for authentication, database, storage, and server functions; Cloudflare for bot protection, authentication email delivery, secure app-request and diagnostic routing, and web infrastructure; Sentry for the restricted error diagnostics described above; and Expo Application Services for app builds. Apple processes Sign in with Apple requests when you choose that sign-in method. The mobile map uses Apple MapKit on iOS and the Google Maps SDK on Android. These map providers receive technical requests; the Google Maps SDK can also collect a pseudonymous SDK identifier, device and SDK metadata, crash metrics, IP address, and map interaction information. CARTO serves map tiles based on OpenStreetMap data; tile requests reveal the map area being viewed to CARTO. Apple Maps or Google Maps handles directions you choose to open. Google Places processes place-search text and relevant map coordinates through our server. The website loads fonts from Google Fonts and map software from unpkg, which receive ordinary browser requests including IP address. FormSubmit delivers public place-submission details and generic support notifications by email; those support notifications do not include your name, email address, message, or screenshot. These providers process information only as needed to provide their services under their own terms and privacy commitments. We may also disclose information to professional advisers, authorities when legally required, or a successor in a merger, financing, reorganisation, or sale. Usernames and avatars are visible to other users. The six-photo profile grid is visible to everyone for a public profile and only to mutual friends for a private profile. Online or offline availability is visible only to accepted mutual friends. Your verified Turf spot is visible only to accepted mutual friends who have also enabled spot sharing, only while you are at that spot and Turf is open. Direct messages, friend requests, blocks, saved places, and private account history are not made public.
8. International transfers
Our service providers may process information in countries other than the country where you live. Where required, we use contractual commitments and other safeguards recognised by applicable data-protection law and take reasonable steps to ensure transferred information receives an appropriate level of protection.
9. How long we keep information
Account information is retained while your account is active. Account-linked place-search and place-request records currently have no separate automatic expiry and are removed when your account is permanently deleted. If you use Delete account, the account is deactivated for 30 days; signing back in during that period restores the account and cancels deletion. After 30 days, the account and associated personal data are permanently deleted unless limited retention is required for security, legal, fraud-prevention, or dispute purposes. Expired location-verification proofs become eligible for scheduled deletion 24 hours after expiry; a later verification can clear your proofs that expired more than one hour earlier. Ordinary spot-chat messages become eligible for deletion after 30 days, except messages subject to an open moderation report, and spot-visit presence history after 90 days. Scheduled deletion runs periodically rather than immediately at the retention boundary. Public factual place information may remain after account deletion, but your identity and user-generated photos, videos, reviews, messages, and profile data are removed unless retention is legally required. Support and moderation records are retained only for as long as reasonably needed to resolve the request, enforce our rules, prevent repeated abuse, meet legal obligations, or handle a dispute.
10. Security
We use authentication, access controls, row-level database policies, encrypted network transport, restricted administrative credentials, storage rules, rate limits, bot protection, and account-level deletion controls designed to protect information. Access is limited according to operational need. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
11. Device storage, cookies, analytics, and diagnostics
The mobile app stores an authentication session in protected device storage, encrypted message and submission drafts with a key in protected device storage, and limited interface state so you can stay signed in and recover unfinished work. Drafts expire after 30 days and are cleared by the app when you sign out. The website may use essential browser storage and Cloudflare Turnstile data for security and form protection. Turf does not use advertising cookies, cross-site tracking, or a product-analytics SDK. Sentry sends the restricted JavaScript diagnostics described above when enabled and connectivity permits. Third-party map and infrastructure providers may receive ordinary technical requests under their own policies.
12. Children’s privacy
Turf is not directed to children under 13. We do not knowingly collect personal information from a child below that age. If you believe a child under 13 has provided personal information, contact us so we can review and delete it where appropriate.
13. Your privacy rights
Depending on where you live, you may request access, correction, deletion, restriction, portability, or information about how your personal information is used; object to certain processing; or withdraw consent. You can delete your Turf account directly in the app under Me → Settings → Delete account. Other requests can be submitted through https://theturfapp.com/support.html. We may verify your identity before completing a request. If your concern is unresolved, you may contact Singapore’s Personal Data Protection Commission at https://www.pdpc.gov.sg/complaints-and-reviews/report-a-personal-data-protection-concern or the authority that applies where you live.
14. Public content and third-party links
Place names, locations, categories, amenities, and public facility photos may be visible to anyone. Do not submit personal information, private facilities, people’s faces where consent is required, or content you do not have the right to share. Links to Google Maps and other third-party services are governed by those services’ own terms and privacy practices.
15. Changes to this Policy
We may update this Policy to reflect service, legal, or operational changes. We will post the revised version here and update the effective date. If a change materially affects how account information is handled, we will also provide notice in the app or by email when required.
16. Contact us
Questions, complaints, access or correction requests, and deletion requests may be submitted through https://theturfapp.com/support.html or sent to privacy@theturfapp.com. Postal correspondence may be sent to KOVA LABS PTE. LTD. at Marina Bay Financial Centre, 10 Marina Boulevard, #39-000, Singapore 018983.