Privacy policy
What Kourtiva collects, why, who sees it, and how to get rid of it.
Last updated 8 August 2026
The short version. We collect what is needed to book a court and let a venue run its business: your account details, your bookings and payments, and — only if you turn it on — fitness data from a wearable. We do not sell it, and we do not use it for advertising. You can delete your account at any time from kourtiva.com/delete-account.
1. Who we are
Kourtiva operates the Kourtiva platform: this website, the venue dashboard, the mobile apps and the integration API. We are based in Dubai, United Arab Emirates.
For data you enter into the platform as a player, we are the controller. Where a sports complex uses Kourtiva to manage its own members and bookings, that venue is the controller of its records and we act as its processor. If you want a venue's own records about you changed or removed, contact the venue; we will help them do it.
Privacy questions go to privacy@kourtiva.com.
2. What we collect
Account details
Your name, email address, password (stored only as a bcrypt hash — we cannot read it), and optionally a phone number, profile photo, short bio, skill level and favourite sports. Venue accounts also carry a company name and contact person.
Bookings and attendance
Which court you booked, when, who you invited, and whether you checked in. Scanning the QR code at a venue records a timestamped entry against that booking. Venues can see this for their own courts.
Location
The mobile app asks for your location so it can sort venues by how far away they are. This is used on your device to order the list and is not stored on our servers or attached to your profile. Declining the permission means the list is not distance-sorted; everything else still works.
Payments
Card details are handled by our payment processor and never reach our servers. We keep the record of what was paid, when, and for which booking, along with the resulting invoice.
Health and fitness data
If you connect a wearable, the app can record heart rate, step count, calories burned, distance, speed, cadence, power, and derived fatigue, performance and injury-risk scores against a playing session.
This is health data and we treat it as a special category. It is collected only with your explicit consent, only while you have the feature switched on, and it is used solely to show you your own performance. It is never sold, never used for advertising, and not shared with venues or insurers. Withdraw consent at any time by disconnecting the wearable in the app; deleting your account destroys this data outright rather than anonymising it.
Teams and messages
Teams you join, and messages you send in team chat. Other members of that team can read them.
Technical and security records
Server logs of requests, and an activity log of significant actions — who changed what and when. Where a venue uses the integration API, each call is logged with its method, path, status, duration and the token used. These exist to investigate abuse and security incidents.
3. Why we are allowed to use it
| Data | Purpose | Lawful basis |
|---|---|---|
| Account details | Create and secure your account | Performance of a contract |
| Bookings, check-ins | Reserve a court and let you in | Performance of a contract |
| Payments, invoices | Take payment; meet tax obligations | Contract; legal obligation |
| Location | Sort venues by distance | Consent (device permission) |
| Health and fitness | Show you your own performance | Explicit consent |
| Security and audit logs | Detect abuse; investigate incidents | Legitimate interests |
4. Who else sees it
- The venue you book with — your name, contact details and that booking, so they know who is arriving. They cannot see your bookings at other venues.
- Venue staff — only for the venues they are assigned to, and only what their role permits.
- Our payment processor — to take the payment.
- Our hosting and email providers — as processors, under contract, acting only on our instructions.
- Authorities — where the law actually requires it.
We do not sell personal data, and we do not share it with advertisers or data brokers. There is no advertising network embedded in the apps or this site.
5. Where it is held
Data is hosted on Amazon Web Services in the eu-central-1 (Frankfurt, Germany) region. If you are in the UAE, your data is therefore transferred to and stored in the European Economic Area, which applies data-protection standards at least equivalent to those you would expect at home.
6. How long we keep it
| Record | Kept for |
|---|---|
| Account details | Until you delete the account |
| Health and fitness data | Until you disconnect the wearable or delete the account — then destroyed |
| Bookings and check-ins | Anonymised when you delete the account |
| Invoices and payments | Retained as long as tax law requires, with your identifiers removed |
| Security and audit logs | Retained for security purposes, with your identifiers removed |
Financial records outlive account deletion because we are legally required to keep them. We strip them of anything identifying you first — see what deletion actually does.
7. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or withdraw a consent you previously gave. Most of this is available in the app under Profile; for anything else, email privacy@kourtiva.com and we will respond within 30 days.
Withdrawing consent does not undo what was lawful beforehand, and we may keep the minimum needed to meet a legal obligation.
8. Security
- Traffic is encrypted in transit with TLS; plain HTTP is refused, not merely redirected.
- Passwords are bcrypt hashes. Nobody at Kourtiva can read yours.
- API tokens are stored as SHA-256 hashes and are scoped to specific abilities.
- Databases and stored files are encrypted at rest and are not reachable from the internet.
- Staff access is scoped to assigned venues and revocable immediately.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you and the relevant regulator as required by law.
9. Children
Kourtiva is not intended for children under 13, and we do not knowingly collect their data. Where a venue enrols a minor in a coaching programme, the venue is responsible for obtaining parental consent. Tell us if you believe a child has created an account and we will remove it.
10. Cookies
This website uses a session cookie to keep you signed in and a CSRF cookie to protect forms. Your theme preference is kept in your browser's local storage. There are no analytics, tracking or advertising cookies, so there is no consent banner to click through.
11. Changes
If we change this policy materially we will update the date at the top and, for significant changes, notify you in the app or by email before they take effect.
12. Contact
privacy@kourtiva.com
Kourtiva, Dubai, United Arab Emirates
Want your account gone?
You can request deletion yourself — no need to email anyone.
Delete your account