Privacy Policy
Effective Date: July 24, 2026
Owned & Operated by: JMartin Digital Apps LLC
Contact: [email protected]
Website: perch-golf.com
1. Introduction
This Privacy Policy explains how JMartin Digital Apps LLC (“we,” “us,” “our”) collects, uses, and protects information in connection with Perch (the “App”), a golf app for iOS devices. Perch is a single-player app that provides on-course distance measurements (rangefinding), maps, and weather information. It has no social features, no leaderboards, no sharing, and no user-generated content shared with other users.
We built Perch with privacy as a priority. We do not sell or rent your personal information, we do not use advertising SDKs or serve ads, and we do not track you across other companies’ apps or websites. The App is provided on an “AS IS” basis.
By downloading, accessing, or using Perch, you agree to the practices described in this Policy. If you do not agree, please do not use the App.
2. Information We Collect
We practice data minimization and collect only what is needed to operate the App, manage your subscription, and keep the service secure.
2.1 Account Information — Sign in with Apple (sole authentication method)
We use Sign in with Apple as the only way to create and access an account. Through it we receive:
- Your Apple user identifier (a unique ID assigned by Apple);
- An email address — either your real address or an Apple Private Relay address if you choose to hide your email; and
- Optionally, the name you choose to share.
We do not receive your Apple password or any Apple account credentials.
2.2 Subscription Information — RevenueCat
Subscriptions are sold through the Apple App Store. We use RevenueCat, Inc. to manage subscription status, validate purchase receipts, and provide subscription analytics. Through RevenueCat we process:
- An anonymous app user identifier;
- Purchase/transaction data (product purchased, purchase and renewal dates, subscription status); and
- Receipt validation data.
RevenueCat acts as our data processor. It stores data on Amazon Web Services in the United States and maintains SOC 2 Type II and ISO 27001 compliance, with controls audited annually by an independent CPA firm. We never receive or store your payment card details — all billing is handled by Apple.
2.3 Onboarding Analytics — Mixpanel (one-time only)
We use Mixpanel, Inc. to understand and improve our onboarding flow only. Mixpanel analytics are limited to onboarding and are not used for ongoing behavioral tracking. Data processed may include:
- Device model, operating system version, and App version;
- A Mixpanel-generated device identifier (this is not the Apple IDFA);
- Coarse, IP-derived approximate location (e.g., country/region). We do not retain IP addresses.
Mixpanel processes this data as our data processor. We do not use Mixpanel to build advertising profiles. You can have this data removed by deleting your account or contacting us. (EEA/UK users: see Section 8.3 regarding consent for analytics.)
2.4 Backend Data — Supabase
We use Supabase, Inc. for authentication and database services. Supabase stores:
- Your account information;
- Session and authentication tokens; and
- App data associated with your account (e.g., your settings and preferences).
Supabase hosts this data on servers in the United States and acts as our data processor.
2.5 Location Data
With your permission, the App uses your device’s precise GPS location to (a) calculate distances to points on the golf course (rangefinding) and (b) retrieve local weather for your location. This location processing happens on your device and in real time. We do NOT transmit your precise location to our servers, and we do NOT store it on our backend. See Section 3 for full details, including how to disable it.
2.6 Information We Do NOT Collect
To be clear about our limits, we do not:
- Collect the Apple IDFA (Identifier for Advertisers) or use it for tracking;
- Store a history of which courses you played, your rounds, or any location history on our servers;
- Access your contacts, photos, microphone, or health data;
- Track your browsing or activity across other apps or websites;
- Collect financial account or payment card information (Apple handles billing);
- Use any advertising SDKs or serve advertisements; or
- Sell or “share” your personal information for cross-context behavioral advertising (as those terms are defined under US state privacy laws).
3. Location, Rangefinding, Maps & Weather
Precise location (GPS). When you grant location permission, the App uses your precise GPS location on your device to measure distances to course features and to fetch local weather. This is processed on-device and in real time. Your precise location is not sent to or stored on our servers and is not linked to your account on our backend.
You control location access. Location is optional and can be turned off at any time in iOS Settings → Privacy & Security → Location Services → Perch, or when the App first requests permission. If you disable location, rangefinding and location-based weather will not function, but the rest of the App remains usable.
Apple Maps / MapKit. The App uses Apple MapKit to display maps. When maps are shown, Apple processes the data needed to serve map tiles and related content. Apple states that Apple Maps is “designed from the ground up to protect your privacy” and that Apple does not collect personal data associated with your Maps usage, associating map activity with rotating, random identifiers rather than your Apple Account. We do not receive your Maps usage data. Apple’s handling of this data is governed by Apple’s Privacy Policy and the Apple Maps & Privacy notice.
Apple WeatherKit / Apple Weather. Weather information is provided by Apple WeatherKit. If you allow location access, your location is sent to Apple to return a relevant forecast; this is governed by Apple’s privacy policy and the Apple Weather & Privacy notice, and Apple states such information “is not linked to your identity.” We do not receive the raw location Apple uses to generate weather. Weather data is provided by Apple Weather and its data sources (including national meteorological agencies); attribution and the list of data sources are available via the in-App weather attribution link.
4. How We Use Information
We use the information described above to:
- Authenticate you and maintain your account (Sign in with Apple, Supabase);
- Provide and operate core features — rangefinding, maps, and weather;
- Manage your subscription and validate purchases (RevenueCat/Apple);
- Improve our onboarding experience (Mixpanel, onboarding only);
- Maintain security, prevent fraud and abuse, and protect the integrity of the App; and
- Comply with legal obligations and enforce our terms.
We do not use your information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
5. Third-Party Service Providers
We rely on the following providers, each acting as a data processor under contractual data-protection terms (including data processing agreements). We disclose only what is necessary for each provider’s function.
| Provider | Role | Data | Location | Privacy Policy |
|---|---|---|---|---|
| Apple | Authentication, in-app purchases/billing, MapKit, WeatherKit | Apple ID/email, purchase/billing, map & weather requests | Global (Apple-operated) | apple.com/legal/privacy |
| Supabase, Inc. | Auth & database backend | Account info, tokens, app data | United States | supabase.com/privacy |
| RevenueCat, Inc. | Subscription management & receipt validation | Anonymous app user ID, transaction/receipt data | United States (AWS) | revenuecat.com/privacy |
| Mixpanel, Inc. | Onboarding analytics (one-time) | Device/app info, Mixpanel device ID, coarse location | United States (or EU region) | mixpanel.com/legal/privacy-policy |
We do not sell your data to, or share it with, any third party for their own marketing.
6. Data Retention
- Account and app data (Supabase): retained while your account is active.
- Onboarding analytics (Mixpanel): retained for a maximum of one (1) year, after which it is automatically deleted.
- Subscription data (RevenueCat): retained while your subscription/account is active, and as required for financial recordkeeping and dispute resolution.
- Location data: not retained — processed on-device in real time and never stored on our servers.
When you delete your account, we delete or anonymize your personal data as described in Section 7, ordinarily within 10 days, except where longer retention is required by law.
7. Data Deletion
You can delete your account and associated data at any time:
- In-app: use the Delete Account option in the App’s settings; or
- By email: contact us at [email protected] from the email associated with your account.
Cancel your subscription first. Deleting your account does not automatically cancel an active Apple subscription. Please cancel through Settings → [your name] → Subscriptions on your device, or at apps.apple.com/account/subscriptions, before deleting your account.
Upon deletion we will:
- Remove your account and app data from Supabase;
- Remove your associated onboarding analytics from Mixpanel;
- Delete your subscription records from RevenueCat (subject to legally required financial retention); and
- Revoke your Sign in with Apple token via Apple’s token revocation REST API.
Deletion is ordinarily processed within 10 days.
8. Your Privacy Rights
We honor privacy rights regardless of where you live. To exercise any right, contact [email protected]. We may need to verify your identity before responding.
8.1 California (CCPA/CPRA)
California residents have the rights to know/access, delete, correct, and to limit the use and disclosure of sensitive personal information, and the right to non-discrimination for exercising these rights.
We do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months. Accordingly, while we honor opt-out preference signals such as Global Privacy Control (GPC), we already do not sell or share data.
Sensitive personal information: Precise geolocation is “sensitive personal information” under the CCPA/CPRA — defined as data locating a consumer within a 1,850-foot radius (Cal. Civ. Code §1798.140). We use precise location only on your device to provide the rangefinding and weather features you request, we do not store it, and we do not use it to infer characteristics about you. You may withdraw location access at any time in iOS Settings.
- Categories of personal information we collect: identifiers (Apple user ID, email); commercial information (subscription/transaction data); internet/device activity (device and app info, onboarding analytics); geolocation (precise, on-device only, not stored); and Sign in with Apple data.
- Sources: directly from you and your device, and from Apple (authentication and purchases).
- Business purposes: authentication, providing app features, subscription management, onboarding improvement, and security.
- Third parties/recipients: our processors listed in Section 5.
- Response time: we respond within 45 days of a verifiable request, extendable once by an additional 45 days (90 days total) where reasonably necessary, as permitted by law.
8.2 Other US State Privacy Laws
If you reside in a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Maryland, Minnesota, Tennessee, Indiana, Kentucky, and Rhode Island — you may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising, sell personal data, or engage in profiling that produces legal or similarly significant effects. Several of these laws (for example, Connecticut) require opt-in consent to process precise geolocation (defined within a 1,750-foot radius in most of these states); we obtain your permission through the iOS location prompt and use precise location only on-device for the features you request. Where a law provides an appeal process for a denied request, you may appeal by contacting [email protected], and you may contact your state Attorney General if you have concerns.
8.3 European Economic Area (EEA), United Kingdom, and Switzerland (GDPR, UK GDPR, Swiss FADP)
Controller. The data controller is JMartin Digital Apps LLC, United States, contactable at [email protected].
EU / UK Representative. We have not appointed a representative in the European Union under Article 27 GDPR or in the United Kingdom. You may contact us directly at [email protected] on any issue related to our processing of your personal data.
Legal bases for processing. We rely on:
- Performance of a contract (Art. 6(1)(b)) — to create/authenticate your account, provide the App’s features, and manage your subscription;
- Legitimate interests (Art. 6(1)(f)) — to keep the App secure and prevent fraud and abuse; and
- Consent (Art. 6(1)(a)) — for location access (granted via the iOS permission prompt) and, where required, for onboarding analytics. You may withdraw consent at any time (by disabling location in iOS Settings, or via your in-app analytics choice) without affecting the lawfulness of prior processing.
Analytics and the ePrivacy Directive. For users in the EEA and UK, we request your consent before Mixpanel analytics are enabled, and you may decline without losing access to the App’s features.
Your rights. You have the rights to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority — in the EEA, your local Data Protection Authority; in the UK, the Information Commissioner’s Office (ICO) at ico.org.uk; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
International data transfers. Our servers and certain processors are in the United States. We rely on the following safeguards for transfers of personal data out of the EEA, UK, and Switzerland:
- Mixpanel, Inc. is certified under the EU-US Data Privacy Framework, its UK Extension, and the Swiss-US Data Privacy Framework, providing an adequate basis for transfers to Mixpanel.
- Supabase, Inc. and RevenueCat, Inc. are not DPF-certified; transfers to them are protected by the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum/IDTA, and equivalent Swiss safeguards, supported by transfer impact assessments where applicable.
- Apple processes data for authentication, purchases, maps, and weather under its own published data-transfer framework and privacy policy.
You may request a copy of the relevant safeguards by contacting [email protected].
Retention is described in Section 6. No Data Protection Officer is legally required for our processing, and none has been appointed; you may direct all inquiries to [email protected].
8.4 Other International Jurisdictions
We extend comparable rights — typically to be informed, to access, to correct, and to withdraw consent or request deletion — to users in the jurisdictions below, in accordance with local law. To exercise any right, contact [email protected].
| Jurisdiction | Governing law | Notes |
|---|---|---|
| Australia | Privacy Act 1988 / Australian Privacy Principles (as amended 2024) | Rights of access and correction; complaints to the OAIC. Personal information includes device identifiers. |
| Brazil | LGPD (Law 13,709/2018) | Rights of access, correction, deletion, portability, and information about processing; complaints to the ANPD. Access requests answered within 15 days. |
| Canada | PIPEDA | Rights of access and correction; we obtain meaningful consent and delete account data upon account deletion. Complaints to the Office of the Privacy Commissioner. |
| Argentina | Personal Data Protection Act (Law 25,326) | Rights of access, rectification, and deletion; oversight by the Agency for Access to Public Information (AAIP). |
| Mexico | Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP, 2025) | ARCO rights (Access, Rectification, Cancellation, Opposition); express consent for sensitive data; oversight by the successor to INAI. |
| South Korea | PIPA | Explicit, informed consent; rights to access, correct, delete, and suspend processing; separate consent for sensitive data. A domestic representative may be required for large foreign operators. |
| Singapore | PDPA 2012 (as amended) | Consent/notification and purpose-limitation obligations; rights of access and correction; complaints to the PDPC. |
| Malaysia | PDPA 2010 (as amended 2024/2025) | Notice and consent (bilingual English/Bahasa Malaysia); rights of access, correction, and data portability; data-breach notification. |
| Philippines | Data Privacy Act 2012 | Rights to be informed, access, rectify, erase/block, and to data portability; complaints to the National Privacy Commission. |
| Thailand | PDPA (GDPR-modeled) | Consent required for processing; rights of access, rectification, erasure, portability, and objection. |
| Indonesia | PDP Law (Law No. 27 of 2022) | Rights of access, correction, deletion, and withdrawal of consent; controller obligations including breach notification. |
| Vietnam | Personal Data Protection Law (Law No. 91/2025/QH15) and PDPD | Consent-based processing with separate consents for specific activities; rights to access, correct, and delete. |
| Taiwan | Personal Data Protection Act | Notice at collection; rights of access, correction, and deletion; consent for collection and use. |
| South Africa | POPIA | Rights of access, correction, and deletion; complaints to the Information Regulator; breach notification obligations. |
| Saudi Arabia | PDPL (SDAIA) | Consent-based processing; rights of access, correction, and deletion; oversight by SDAIA. |
| United Arab Emirates | Federal Decree-Law No. 45 of 2021 (PDPL) | Rights of access, rectification, erasure, restriction, and portability (pending Executive Regulations). |
| Qatar | Law No. 13 of 2016 | Rights of access, rectification, and erasure; oversight by the National Cyber Security Agency / competent authority. |
| New Zealand | Privacy Act 2020 & Information Privacy Principles | Rights of access and correction; mandatory breach notification to the OPC and affected individuals where a breach causes serious harm. |
| Iceland, Norway | GDPR (EEA) | Governed by Section 8.3. |
| Switzerland | FADP | Governed by Section 8.3. |
9. Subscription and Auto-Renewal Terms
Perch offers a paid subscription billed through your Apple App Store account.
- Payment is charged to your Apple Account at confirmation of purchase.
- Subscriptions renew automatically unless auto-renewal is turned off at least 24 hours before the end of the current period.
- Your account is charged for renewal within 24 hours prior to the end of the current period.
- You can manage or cancel your subscription in Settings → [your name] → Subscriptions, or at apps.apple.com/account/subscriptions.
- Apple manages all billing; refunds are handled under Apple’s policies.
10. Children’s Privacy
Perch is a general-audience app and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children under 13. In the United States we comply with the Children’s Online Privacy Protection Act (COPPA); in the EEA/UK we observe the applicable digital-consent age (13–16 depending on the country) and the UK’s Age Appropriate Design Code. If we learn that we have collected personal information from a child under the applicable age without appropriate consent, we will delete it promptly. If you believe a child has provided us personal information, contact [email protected].
11. Security
We protect your information using industry-standard measures, including:
- Encryption in transit via HTTPS/TLS;
- Supabase Row-Level Security (RLS) to restrict data access to your own account;
- Sign in with Apple for secure, password-less authentication; and
- Reliance on processors that maintain recognized security certifications (SOC 2 Type II, ISO 27001).
No method of transmission or storage is 100% secure, but we work to protect your information and to respond appropriately to any security incident, including notifying you and regulators where required by applicable law.
12. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the Effective Date above and, where appropriate, provide additional notice in the App. Your continued use of the App after changes take effect constitutes acceptance of the updated Policy.
13. Consent
By using Perch, you consent to the collection and use of information as described in this Policy. Where your jurisdiction requires specific consent (for example, for location access or, in the EEA/UK, for analytics), we obtain that consent separately, and you may withdraw it at any time as described above.
14. Contact Us
For any privacy question, request, or complaint, contact: JMartin Digital Apps LLC — [email protected] — perch-golf.com
To protect your privacy, we may verify your identity before fulfilling a request. We aim to respond within 45 days (or the shorter period required by your local law), with the ability to extend once where reasonably necessary and permitted, and we will inform you of any extension.