1. Who is responsible
Cotabato Pickleball Courts is the independent operator responsible for the personal data described here. A formal operator identity and privacy contact should be confirmed before commercial launch; private residential details are not published on this site.
2. Information we handle
- Seller accounts: display name, email address, an optional salted password hash, account timestamps, and recorded policy acceptance.
- Social sign-in: Google or Facebook provider name, stable provider account ID, display name, and email when the provider supplies one. Google also indicates whether its email claim is verified. Provider access tokens are used transiently to retrieve identity and are not stored.
- Sessions and security: random session identifiers stored as one-way hashes, expiry dates, essential cookies, rate-limit records, and one-way request fingerprints derived from network and browser signals. Raw IP addresses and user-agent strings are not stored in application tables.
- Pasalo: venue, schedule, prices, optional court number and seller note, contact method and destination, status, posting-rule acceptance, aggregate counts, and moderation history.
- Reports: reason, optional note, reporter account when logged in, and a one-way reporter key used to prevent duplicate reports.
- Court submissions: submitter name, contact number, optional email, venue information, coordinates, public venue contacts, booking methods, and notes.
- Operational analytics: booking-link events and Pasalo views, shares, and contact clicks. These are first-party records and are not advertising profiles.
- Administrators: username, email, salted password hash, session records, and moderation actions.
The current application does not collect Pasalo payments, card details, private proof files, precise player location, provider passwords, provider friend lists, provider posts, or third-party advertising identifiers. Browser geolocation for nearby courts stays in the browser and is not submitted to the application.
3. Why we use it
We use this information to operate and secure accounts, publish and manage Pasalo, connect interested players to a seller's chosen channel, maintain the court directory, review submissions and reports, prevent abuse, measure feature use, troubleshoot, and respond to correction or privacy requests.
4. Public and private information
Pasalo venue, schedule, price, selected contact-method label, seller note, status, and activity counts may be public. The raw seller contact destination is returned only after the safety step. Seller email, internal user ID, session values, request fingerprints, report details, moderation metadata, and any future private proof file are not part of public listing output.
Court venue contacts are intended to be public. A submitter's verification name, personal contact number, and email remain available only to authorized administrators unless separately approved as venue contact information.
5. Cookies and analytics
The application uses essential, first-party HTTP-only cookies for account sessions and short-lived social-authentication state, PKCE, and onboarding. Seller sessions expire after 30 days and administrator sessions after 7 days unless ended earlier. Session tokens and pending onboarding tokens are stored in the database only as hashes.
First-party operational analytics do not use advertising cookies or third-party analytics SDKs. Social login uses browser redirects rather than embedded Google or Meta tracking SDKs. Because no non-essential tracking cookie was found in the current application, we do not show a general cookie-consent banner. This should be reassessed before adding advertising, behavioral analytics, or other non-essential tracking.
6. Service providers and external links
The application uses its deployment host and a configured PostgreSQL/Neon database provider to serve the site and store application data. Self-hosted map files and glyphs are delivered with the application. No email delivery, object-storage upload, advertising, or third-party analytics integration is currently implemented.
If you choose social sign-in, your browser is redirected to Google or Meta. The provider authenticates you and receives normal OAuth request metadata such as the app client ID, callback address, requested identity scopes, and ordinary network/browser request information. Cotabato Courts receives only the minimal identity data described above and never receives your Google or Facebook password. Google and Meta do not receive access to Pasalo content merely because you use social sign-in.
When you choose an external venue, booking, phone, Facebook, Messenger, Viber, WhatsApp, Telegram, or other link, you leave or invoke a third-party service. Your interaction with that service is governed by its own privacy practices. A link alone does not mean that service processes data for Cotabato Courts.
7. Retention
Account, Pasalo, submission, moderation, and analytics records currently remain until they are removed through administration or a justified privacy request. Sessions remain until logout, deletion, or expiry; expired session and rate-limit rows are not yet automatically purged. Hosting and database backups may persist according to provider schedules.
We do not promise immediate deletion where limited records are reasonably needed for security, fraud prevention, moderation integrity, legal obligations, or backups. A formal retention schedule and automated cleanup policy are production decisions still to be completed.
8. Your privacy rights and data deletion
Under applicable Philippine data-protection law, you may have rights to be informed, request access or correction, object to certain processing, request erasure or blocking where appropriate, obtain portable data where applicable, complain to the National Privacy Commission, and seek remedies provided by law. These rights can depend on the circumstances and lawful retention needs.
There is no instant account-deletion feature. To request access, correction, deletion, restriction, or deletion of data associated with Google or Facebook sign-in, contact us through the privacy-request path. Include the account email and the provider used; do not send passwords or OAuth tokens. We may need to verify your identity before acting.
9. Security and children
We use technical and organizational measures intended to protect personal data, including hashed passwords and sessions, access controls, origin checks, input validation, and rate limiting. No system can guarantee perfect security.
The service is not designed specifically for children. A minimum-age and parental-consent approach should receive Philippine legal review before the platform deliberately markets account features to minors.
10. Changes and contact
We may update this notice as the product or processing changes. The current version and effective date appear above. Privacy questions may be sent through the contact page.

