Data Processing

Last updated September 24, 2026 · version 2026-09-24.1

1. What this page covers

This page describes the kinds of third-party processors OpenCourt uses to run the platform, what personal data each one touches, and why. We name the role rather than the vendor so this page stays accurate when a provider changes; the current list is available on request. It supplements our Privacy Policy. Read that first for the full picture of what we collect and your rights over it.

2. Our processors

Authentication, database and file storage— Accounts and the application database

Account sign-in and the primary database that holds profiles, bookings and posts. Uploaded images (profile photos, court photos) are kept in the same provider's file storage.

Payment gateway— Checkout for bookings

Handles card, GCash, Maya and QR Ph payments. Card and e-wallet credentials are entered on the gateway's own checkout page; OpenCourt receives only a payment reference and status.

Transactional email— Confirmations, cancellations, replies

Sends booking confirmations, cancellation notices and support replies. Receives the recipient's email address and the content of that specific email.

Hosting and infrastructure— Serving the website

Serves the website and its server functions, and processes request logs (IP address, request path) for operating and securing the platform, including its web application firewall, which rate-limits floods of requests per IP address.

Sign in with Google— Optional sign-in method

Only if you choose "Continue with Google": Google shares your name, email address and profile photo with us to create or sign in to your account.

Inbound email forwarding and support mailbox— Mail sent to our @opencourt.ph addresses

Email sent to help@ and privacy@ is forwarded to our support mailbox. The forwarding service sees the sender address and message in transit; nothing is stored beyond delivery logs.

Product analytics and session replay— Understanding how the app is used

Records which pages are opened and where a booking is abandoned, plus replays of sessions with every input masked. Cookieless: nothing is stored in your browser, and Do Not Track is honoured. Signed-in usage is tied to your user id.

Error monitoring— Fixing crashes

Receives a report when the app throws an error: the stack trace, the page, browser and OS, and your user id if you were signed in. So we can fix it. No form contents or payment data.

Bot check on the contact form and signup— Abuse prevention

A challenge confirms the contact form and account signup are submitted by a person. It processes the browser's IP address and device signals for that check only and does not track you across sites.

3. Pasalo is off-platform

Pasalo (booking transfer) payments are made directly between buyer and seller (GCash, Maya, bank transfer, or cash). OpenCourt never receives or processes that payment; we only store the buyer and seller’s own account details as entered by them, shown to each other to complete the handoff.

We process personal data through these providers to perform our contract with you (running your bookings and account), to comply with legal obligations (payment and tax records), and on the basis of our legitimate interest in operating a secure, working platform.

5. Cross-border processing

Some processors above operate infrastructure outside the Philippines. Each is bound by its own data-protection and security commitments, and we select providers that meet the standard required under the Data Privacy Act of 2012 for data shared outside the country.

6. Contact

Questions about a specific processor, the current vendor behind a role, or how your data flows through the platform: help@opencourt.ph. Requests under the Data Privacy Act (access, correction, erasure, objection) go to our Data Protection Officer at privacy@opencourt.ph.