Privacy Policy
Last updated · July 23, 2026
Triangle Centre Court (“we”, “us”, or “our”) operates the Triangle Centre Court court-booking platform in Bula, General Santos City, South Cotabato, Philippines. For purposes of Republic Act No. 10173, or the Philippine Data Privacy Act of 2012, we act as the personal information controller for the personal data described in this notice.
This Privacy Policy explains what we process when you visit the website, create or use an account, reserve a court, join open play, contact us, or submit a payment for verification. It also explains your rights and how to exercise them.
Personal data we collect
- Account and identity data — your first and last name, email address, optional phone number, account role and status, email-verification status, and a securely hashed form of your password. We do not store your password in readable form.
- Google sign-in data — if you choose Google sign-in, we receive your name, email address, Google account identifier, and email-verification status. We do not receive or store your Google password.
- Booking and participation data — reserved court, game, date and time, open-play party, queue, match and attendance activity, booking notes, status, invoice-verification activity, cancellations, no-shows, and related venue records.
- Payment data — payment method, amount, charges, transaction reference, status, review result, tax-document number when recorded, and the proof-of-payment image you choose to upload. We do not ask for or store your MPIN, OTP, online-banking password, or other payment-account login credentials.
- Communications — messages and contact details you send through our contact channels, and transactional messages relating to your account, bookings, payments, or support requests.
- Technical, security, and attribution data — IP address or a hash derived from it, browser and device user agent, request and error information, visitor identifier, referral and landing-page details, and first- and last-touch campaign identifiers. We use this information for security, troubleshooting, fraud prevention, and measuring how bookings reach us.
- Account-integrity data — an internal trust score and its history, based on events such as approved or rejected payments, expired holds, cancellations, no-shows, open-play attendance, and authorized staff adjustments.
We normally collect personal data directly from you. We may also receive it from Google when you use Google sign-in, from venue staff who create or manage a booking, or from a person arranging a booking or open-play party for you. If you give us another person’s information, you must be authorized to do so and must tell that person about this Privacy Policy.
Only upload the payment transaction we need
Your proof image must show only the specific transaction used to pay for the booking or group of bookings shown at checkout. Crop or redact your wallet balance, unrelated transactions, and unnecessary account details. Keep the amount, recipient, date and time, transaction status, and reference number visible so staff can verify the payment.
Never upload your MPIN, OTP, password, recovery code, login screen, complete transaction history, or any other credential. If another person’s data appears in the proof, make sure you have authority to share it. We may ask you to submit a new, minimized image if the proof is incomplete or contains unrelated personal data.
Purposes and lawful bases
- To perform or prepare for our contract with you — create and authenticate your account, hold and manage a slot, process a booking or open-play entry, verify payment, provide confirmations, and respond to service requests.
- To comply with legal obligations — maintain records required by tax, accounting, consumer-protection, data-protection, and other applicable laws; respond to lawful orders; and handle legal claims.
- For legitimate interests — secure and troubleshoot the service, prevent fraud and abuse, maintain audit trails, manage venue operations, understand booking attribution, and protect customers, staff, and the business, provided those interests do not override your rights and freedoms.
- With consent where the law requires it — for an optional feature or processing activity that is not covered by another lawful basis. You may withdraw that consent without affecting processing that was lawful before withdrawal.
If required information is not provided, we may be unable to create an account, verify a payment, complete a booking, or provide the requested service. Optional fields are identified where collected.
Automated processing and staff review
Booking holds automatically expire at the deadline shown at checkout. The platform also automatically adjusts an internal trust score when specified booking and payment events occur; authorized staff can review its history and make documented adjustments. Staff can see the score when managing accounts, but it is not the sole basis for payment approval or for a legal or similarly significant decision. Uploaded payment proofs are reviewed by authorized venue staff, not approved solely by an automated system.
Cookies and similar technologies
- Authentication and security cookies keep you signed in and help protect account sessions. The authentication cookie is HttpOnly and normally expires after 24 hours.
- Attribution cookies store a random visitor identifier and, when applicable, campaign identifiers for up to 90 days so we can connect a booking to the source that led to it.
- Session storage prevents duplicate attribution events during the same browser session.
Google sign-in and the embedded Google map are provided by Google and may process information under Google’s own privacy terms when you use those features. You can block non-essential cookies using browser controls, although doing so may reduce attribution accuracy. Blocking authentication cookies will prevent account sign-in.
Who receives personal data
We do not sell personal data. We disclose it only as reasonably necessary to:
- authorized venue staff who administer bookings, payments, accounts, and support;
- contracted service providers for cloud hosting, database services, payment-proof file storage, email delivery, security, and technical support;
- Google, when you choose Google sign-in or use an embedded Google service;
- professional advisers, insurers, or a successor to the business when reasonably necessary and subject to appropriate confidentiality safeguards; and
- courts, regulators, law-enforcement bodies, or other persons when required by law or necessary to establish, exercise, or defend legal claims.
Some providers may process data outside the Philippines, depending on where their systems operate. When that occurs, we remain accountable for the data and require appropriate contractual, organizational, and technical safeguards designed to provide a comparable level of protection.
Retention
- Account records are retained while the account is active and afterward only for as long as needed for legal obligations, legitimate business records, disputes, or claims.
- Booking, payment, charge, and invoice records are retained for the applicable tax, accounting, consumer-dispute, and legal-claims periods.
- Payment-proof images are retained only while reasonably necessary to verify the payment, resolve disputes, satisfy applicable recordkeeping duties, or establish, exercise, or defend a claim. They should not contain unrelated financial data.
- In-app notifications are automatically deleted after 30 days.
- Application audit logs are automatically deleted after 60 days.
- Attribution cookies expire after no more than 90 days.
When a retention purpose ends, we delete, anonymize, or securely dispose of the data, subject to backup cycles and any lawful preservation requirement. An account-deletion request may therefore not erase records that we must lawfully retain.
Your data-subject rights
Subject to the Data Privacy Act and its lawful exceptions, you have the right to be informed, object to processing, access your personal data, correct inaccurate data, request erasure or blocking, obtain data portability where applicable, withdraw consent where consent is the basis, claim damages for a violation, and file a complaint with the National Privacy Commission.
To exercise a right, contact us below and identify the account or record involved. We may take reasonable steps to verify your identity and authority before acting. If we cannot grant a request because of a contract, legal obligation, overriding legitimate interest, or legal claim, we will explain the applicable reason.
Security and incidents
We use reasonable organizational, physical, and technical safeguards appropriate to the risks, including access controls, restricted administrative access, password hashing, HttpOnly authentication cookies, temporary signed links for private payment proofs, audit logging, and secure transport in production. No system is completely secure. We investigate suspected incidents and notify affected people and the National Privacy Commission when notification is required by law.
Children
A person under 18 should use the platform only with the involvement and authorization of a parent or legal guardian. A parent or guardian may contact us regarding a minor’s personal data.
Changes to this notice
We may update this Privacy Policy when our processing or legal obligations change. We will post the revised notice with a new “Last updated” date and provide additional notice before a material change when required.
Contact and privacy requests
Contact the Triangle Centre Court privacy representative at centrecourtgsc@gmail.com or 0918 948 3861. Our place of business is in Bula, General Santos City, South Cotabato, Philippines.