A note for this deployment
Badminton Court Control Panel is self-hosted software. This policy describes the application’s built-in behavior. The operator of this deployment is responsible for its hosting logs, backups, configuration, legal basis, contact details, and any additional processing.
Deployment details
- Operator
- badminton.holey.cc
- Primary data region
- zh-TW
01
Scope and responsibility
This policy applies to this deployment of Badminton Court Control Panel and its built-in website features.
The person or organization operating this deployment determines why and how information is processed. Because the software is self-hosted, hosting providers, reverse proxies, backups, custom changes, and operational practices may add processing that is not visible to the application.
02
Information the application handles
The application handles only the information needed to run accounts, publish court events, accept registrations, protect access, and deliver optional notifications.
- Requests and security: validated IP address, request time, country signals supplied by supported proxies or an optional local GeoIP database, failed-attempt counters, lockout times, and derived attempt identifiers. A User-Agent is reduced to iOS, Android, Mobile, or Web for successful join/leave history; the complete User-Agent and device fingerprints are not stored by the application.
- Accounts: username, password hash, role and account status, creation time, optional avatar, saved hall locations, last successful sign-in time, and last successful sign-in IP address. Plain-text account passwords are not stored.
- Court events: organizer identity, event and group names, date and time, venue and coordinates, court ID, capacity, reserved-player nicknames, levels, prices, shuttlecock information, remarks, status, roll-call/clearing state, and uploaded photos or videos.
- Public registration: nickname, participant PIN hash, confirmed or waiting status, join time, roll-call/clearing state, and successful join/leave history. History contains nickname, action, time, validated IP address, and broad device category. Plain-text participant PINs are not stored.
- Push notifications: the selected court, browser push-service endpoint, encryption keys, language, and creation/update times after a visitor explicitly opts in.
- Contact messages: the name supplied by the visitor, optional reply contact, subject, message, interface language, submission time, and administrator read status.
03
What is public and what administrators can see
Court links are public. Event details, organizer name, uploaded event media, confirmed and waiting nicknames, and join/leave nicknames with timestamps can be viewed without signing in.
Reserved-player nicknames are public only when the organizer enables that setting. Administrators can see join/leave IP addresses and broad device categories, account sign-in information, and other controls needed to operate the service. Organizers and administrators can manage event and participant records within their permissions.
Administrator CSV exports contain event configuration, public URLs, creator and lifecycle information, counts, reserved nicknames, and media counts. They exclude active participant names, participant PINs, join/leave history, IP addresses, and device information.
Contact messages and optional reply details are visible only to administrator and super-administrator accounts through the protected message inbox.
04
Why information is used
- Create and authenticate accounts, enforce roles, and manage profiles.
- Publish, discover, share, duplicate, archive, and administer court events.
- Process registration, waiting-list promotion, leaving, roll call, and payment-clearing status.
- Prevent repeated credential guessing, investigate operational problems, and protect the service.
- Deliver court-specific notifications requested by the browser user.
- Receive and respond to support requests, track whether administrators have reviewed them, and optionally alert administrators to new messages.
- Select a language, generate social-sharing previews, and maintain the visitor’s chosen interface preferences.
05
Cookies and browser storage
- A signed session cookie supports sign-in state, role checks, and CSRF protection. Production operators should transmit it only over HTTPS.
- The court_lang cookie remembers the selected interface language for up to one year.
- Local storage remembers theme and palette choices and whether the first-visit introduction prompt has been handled.
- When notifications are enabled, the browser and its push service retain a push subscription. Turning notifications off removes this court’s server-side mapping.
- The built-in application does not include advertising or analytics trackers. A deployment operator may add services outside the application and must disclose them separately.
06
External services
Some features contact other providers, which process technical information under their own terms and privacy policies.
- Google Fonts is requested by website pages. Google Maps links are available for venue searches, and Google Maps JavaScript/Places loads on the event form when the operator configures an API key.
- Cloudflare Turnstile loads on signup, sign-in, and contact-message forms and receives verification information when both Turnstile keys are configured.
- Opt-in Web Push sends encrypted notification payloads through the push service selected by the visitor’s browser, such as Apple, Google, Microsoft, or Mozilla.
- When an administrator enables contact-message notifications, the submitted name, reply contact, subject, message, time, and inbox link are sent to the configured Discord webhook and/or Telegram bot chat. A failed delivery does not remove the message from this website’s database.
- When a court link is shared, the chosen social or messaging platform may request its public metadata and generated preview image.
- Following any external link sends the request directly to that external website.
07
Retention and deletion
- Account data remains until the account is deleted or an administrator deletes an eligible archived account. Member self-deletion removes the account, avatar, and saved locations, but already-published courts and their displayed creator label remain online without an owner.
- Leaving a court removes the active participant record. Successful join/leave history remains until the court itself is deleted.
- Archiving or expiration does not delete a court. Deleting a court removes its participants, reserved members, media records and files, participation history, push mappings, and generated social-preview cache.
- Turning off push notifications removes the matching court subscription mapping. Endpoints rejected as expired by a push service are removed automatically.
- Successful authentication clears the matching failed-attempt record; administrators can reset member sign-in retries. Other security records remain as needed to enforce current lockouts.
- Contact messages remain in the deployment database until the operator removes them according to its support and retention practices or handles an applicable deletion request.
- Hosting logs and backups are controlled by the deployment operator and may follow different retention and deletion schedules.
08
Security
The application uses password hashing, role and ownership checks, CSRF protection, optional Turnstile verification, upload validation, randomized stored filenames, rate limits, and scoped access to reduce risk. Sensitive push endpoints, Discord webhook URLs, and Telegram bot tokens are not displayed publicly or written to application logs.
No system is completely secure. The deployment operator is responsible for HTTPS, strong secrets, access controls, updates, backups, proxy configuration, and incident response.
09
Your choices and requests
- Members can change their password and avatar, delete saved locations, and permanently delete an eligible member account after password confirmation.
- Organizers can correct or delete courts they own. Public participants can leave an editable court using their nickname and PIN.
- Visitors can decline or disable push notifications, change language and appearance preferences, and clear this site’s cookies or local storage in their browser.
- A contact message requires a name, subject, and message. Reply contact is optional, but administrators may be unable to respond without it. Visitors may use a separately published contact method instead of the stored form.
- Required information is necessary for the related feature: without account credentials a person cannot create or sign in to an account; without a nickname and PIN a person cannot join or leave a court. Optional profile, venue-saving, media, reserved-nickname, reply-contact, and notification features may be left unused.
- Contact the deployment operator to request access, correction, deletion, restriction, or other rights available under applicable law. Some information may need to remain for security, record integrity, legal obligations, or because published court data is no longer attached to a deleted member account.
10
Changes and contact
This policy may be updated when the application or deployment practices change. The latest revision date appears at the top of this page.
Questions and privacy requests should be sent to the operator of this deployment using the contact method shown below.