Privacy Policy
Last updated · August 2, 2026
Triangle Centre Court (“we”, “us”, or “our”) operates the Triangle Centre Court court-booking platform in Bula, General Santos City, South Cotabato, Philippines. For purposes of Republic Act No. 10173, or the Philippine Data Privacy Act of 2012, we act as the personal information controller for the personal data described in this notice.
This Privacy Policy explains what we process when you visit the website, create or use an account, reserve a court, join open play, contact us, or submit a payment for verification. It also explains your rights and how to exercise them.
Personal data we collect
- Account and identity data — your first and last name, email address, optional phone number, account role and status, email-verification status, your declarations that you are at least 18 and reside in General Santos City, the Terms and Privacy Policy versions presented at registration and the server-recorded date and time of acceptance or acknowledgment, and a securely hashed form of your password. We do not collect your birth date or street address for these eligibility declarations, and we do not store your password in readable form.
- Google sign-in data — if you choose Google sign-in, we receive your name, email address, Google account identifier, and email-verification status. Google does not provide us with reliable city-of-residence information. We do not receive or store your Google password.
- Booking and participation data — reserved court, game, date and time, open-play party, queue, match and attendance activity, booking notes, status, invoice-verification activity, cancellations, no-shows, and related venue records.
- Payment data — payment method, amount, charges, transaction reference, status, review result, tax-document number when recorded, and the proof-of-payment image you choose to upload. We do not ask for or store your MPIN, OTP, online-banking password, or other payment-account login credentials.
- Communications — messages and contact details you send through our contact channels, and transactional messages relating to your account, bookings, payments, or support requests.
- Technical, security, and attribution data — IP address or a hash derived from it, browser and device user agent, request and error information, visitor identifier, referral and landing-page details, and first- and last-touch campaign identifiers. We use this information for security, troubleshooting, fraud prevention, and measuring how bookings reach us.
We normally collect personal data directly from you. We may also receive it from Google when you use Google sign-in, from venue staff who create or manage a booking, or from a person arranging a booking or open-play party for you. If you give us another person’s information, you must be authorized to do so and must tell that person about this Privacy Policy.
Only upload the payment transaction we need
Your proof image must show only the specific transaction used to pay for the booking or group of bookings shown at checkout. Crop or redact your wallet balance, unrelated transactions, and unnecessary account details. Keep the amount, recipient, date and time, transaction status, and reference number visible so staff can verify the payment.
Never upload your MPIN, OTP, password, recovery code, login screen, complete transaction history, or any other credential. If another person’s data appears in the proof, make sure you have authority to share it. We may ask you to submit a new, minimized image if the proof is incomplete or contains unrelated personal data.
Purposes and lawful bases
- To perform or prepare for our contract with you — create and authenticate your account, hold and manage a slot, process a booking or open-play entry, verify eligibility declarations and legal-document acceptance, verify payment, provide confirmations, and respond to service requests.
- To comply with legal obligations — maintain records required by tax, accounting, consumer-protection, data-protection, and other applicable laws; respond to lawful orders; and handle legal claims.
- For legitimate interests — secure and troubleshoot the service, prevent fraud and abuse, maintain audit trails, manage venue operations, understand booking attribution, and protect customers, staff, and the business, provided those interests do not override your rights and freedoms.
- With consent where the law requires it — for an optional feature or processing activity that is not covered by another lawful basis. You may withdraw that consent without affecting processing that was lawful before withdrawal.
If required information is not provided, we may be unable to create an account, verify a payment, complete a booking, or provide the requested service. Optional fields are identified where collected.
Automated processing and staff review
Booking holds automatically expire at the deadline shown at checkout. The platform may temporarily suspend regular-booking creation after three unpaid holds expire within the applicable look-back period. This restriction does not prevent sign-in or participation in Open Play. Authorized venue staff can review the underlying booking records. Uploaded payment proofs are reviewed by authorized venue staff, not approved solely by an automated system.
Cookies and similar technologies
- Authentication and security cookies keep you signed in and help protect account sessions. The authentication cookie is HttpOnly and normally expires after 24 hours.
- Attribution cookies store a random visitor identifier and, when applicable, campaign identifiers for up to 90 days so we can connect a booking to the source that led to it.
- Session storage prevents duplicate attribution events during the same browser session.
Google sign-in and the embedded Google map are provided by Google and may process information under Google’s own privacy terms when you use those features. You can block non-essential cookies using browser controls, although doing so may reduce attribution accuracy. Blocking authentication cookies will prevent account sign-in.
Who receives personal data
We do not sell personal data. We disclose it only as reasonably necessary to:
- authorized venue staff who administer bookings, payments, accounts, and support;
- players and visitors to a public open-play session view, which may show first names in queues, matches, and leaderboards; anonymous public views do not show player last names;
- contracted service providers for cloud hosting, database services, payment-proof file storage, email delivery, security, and technical support;
- Google, when you choose Google sign-in or use an embedded Google service;
- professional advisers, insurers, or a successor to the business when reasonably necessary and subject to appropriate confidentiality safeguards; and
- courts, regulators, law-enforcement bodies, or other persons when required by law or necessary to establish, exercise, or defend legal claims.
Some providers may process data outside the Philippines, depending on where their systems operate. When that occurs, we remain accountable for the data and require appropriate contractual, organizational, and technical safeguards designed to provide a comparable level of protection.
Retention
- Account profile data is retained while the account is active. After a verified closure request, we restrict access promptly and delete or anonymize profile data within 30 days, except for transaction records that must be retained by law or for a valid dispute or legal claim.
- Booking, payment, charge, and invoice metadata needed for tax and accounting is retained for five years from the deadline for the relevant return, or from a later filing date, and longer only when a lawful preservation requirement applies.
- A payment-proof image is automatically deleted 180 days after an approved or rejected payment is reviewed. An authorized administrator may place a documented accounting, dispute, or legal hold before deletion. Deleting the image does not delete the limited payment and accounting metadata described above.
- In-app notifications are automatically deleted after 30 days.
- Application audit logs are automatically deleted after 60 days.
- Attribution cookies expire after no more than 90 days.
- Backup copies are kept on a rolling schedule of no more than 90 days. Data deleted from the live service may remain inaccessible in a backup until that backup expires. If a backup must be restored for service continuity, applicable deletions are re-applied.
When a retention purpose ends, we delete, anonymize, or securely dispose of the data, subject to the backup cycle and any documented legal, accounting, or dispute hold. An account-deletion request therefore does not erase records that we must lawfully retain.
Your data-subject rights
Subject to the Data Privacy Act and its lawful exceptions, you have the right to be informed, object to processing, access your personal data, correct inaccurate data, request erasure or blocking, obtain data portability where applicable, withdraw consent where consent is the basis, claim damages for a violation, and file a complaint with the National Privacy Commission.
To exercise a right, contact us below and identify the account or record involved. We may take reasonable steps to verify your identity and authority before acting. If we cannot grant a request because of a contract, legal obligation, overriding legitimate interest, or legal claim, we will explain the applicable reason.
Security and incidents
We use reasonable organizational, physical, and technical safeguards appropriate to the risks, including access controls, restricted administrative access, password hashing, HttpOnly authentication cookies, temporary signed links for private payment proofs, audit logging, and secure transport in production. No system is completely secure. We investigate suspected incidents and notify affected people and the National Privacy Commission when notification is required by law.
Adults-only customer accounts
Customer accounts are limited to people who are at least 18 years old. We ask for an age-eligibility declaration instead of collecting a birth date. If we learn that a customer account belongs to a minor, we may restrict the account and delete or anonymize its personal data, except records we must retain by law or for a valid legal claim. A parent or guardian may contact our Data Protection Officer regarding a minor’s personal data.
Changes to this notice
We may update this Privacy Policy when our processing or legal obligations change. We will post the revised notice with a new “Last updated” date and provide additional notice before a material change when required.
Contact and privacy requests
The owner of Triangle Centre Court serves as our designated Data Protection Officer. Contact the owner/DPO at centrecourtgsc@gmail.com or 0918 948 3861. Our place of business is in Bula, General Santos City, South Cotabato, Philippines.