Privacy Policy

Last updated:  08/05/2026

Introduction

This Privacy Policy explains how Canopy Systems LLC ("we", "us", or "our") collects, uses, shares, and protects personal information about you when you visit or interact with https://canopy.cx/ (our "website") or use our services.

We are committed to protecting your personal information and being transparent about how we process it. This policy describes the types of information we collect, how we use it, the circumstances in which it may be shared, and the rights you may have regarding your information.

If you have any questions about this Privacy Policy or our data practices, you can contact us using the details in the Contact Us section below.

Last updated: 08/05/2026

Information We Collect

We may collect the following categories of information about you.

Information you provide directly

This includes information you provide when you:

This information may include your name, email address, postal address, phone number, payment information, and any other information you choose to provide.

Information collected automatically

When you visit our website, we automatically collect certain technical and usage information. This may include:

  • Device and browser information
  • Usage data / browsing activity
  • Cookies and tracking identifiers

This information helps us understand how our website is used and allows us to improve our services. Some of this information may be collected through cookies and similar technologies.

For more details, please see our Cookie Policy.

Special Category Data

We do not intentionally collect special category data — such as information about health, biometric identifiers, racial or ethnic origin, religious beliefs, or sexual orientation. Please do not submit this type of information through our website or services.

How We Use Your Information

We use the information we collect for the following purposes:

  • Providing and maintaining the service
  • Analytics and product improvement

Lawful Bases for Processing

Consent

We may process personal data where you have given clear consent for us to do so for a specific purpose, such as receiving marketing communications or the use of non-essential cookies.

You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Contract Performance

We may process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This may include processing information to create accounts, deliver services, or process transactions.

Legal Obligation

We may process personal data where necessary to comply with legal obligations that apply to us. For example, we may be required to retain certain financial records for tax, accounting, or regulatory purposes.

Legitimate Interests

We may process personal data where it is necessary for our legitimate interests or those of a third party, provided that those interests are not overridden by your rights and interests.

Our legitimate interests may include operating and improving our services, maintaining website security, preventing fraud, and analysing how our services are used.

You have the right to object to processing based on legitimate interests in certain circumstances. See our Privacy Rights for more information.

Cookies and Tracking Technologies

We use cookies and similar technologies to operate our website, analyse usage, and support certain functionality.

Some cookies are necessary for the website to function, while others may be used for analytics, performance monitoring, or advertising purposes.

For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, or reporting obligations.

When determining retention periods, we consider factors such as the nature and sensitivity of the information, the purposes for which it was collected, and applicable legal requirements.

Where personal data is processed on the basis of consent, we retain the data until consent is withdrawn or the data is no longer required for the purpose for which it was collected.

In practice, this means we retain your data for 2 years.

When personal information is no longer required, we will securely delete or anonymise it.

Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, alteration, or disclosure.

While we take reasonable steps to protect your information, no system or transmission of data over the internet can be guaranteed to be completely secure.

Your Privacy Rights

Depending on your location, you may have rights regarding your personal information, such as the right to access, correct, delete, or restrict the use of your data.

For detailed information about your rights and how to exercise them, please see our Privacy Rights.

Do Not Sell or Share My Personal Information

Certain sharing of personal data with advertising or analytics partners may be considered a "sale" or "sharing" under some US privacy laws.

Residents of California may have the right to opt out of the sale or sharing of personal information or limit the use of sensitive personal information.

To exercise these rights, please contact us using the details below.

Changes to This Policy

We may update this Privacy Policy from time to time.

The Last Updated date at the top of this policy shows when it was last revised.

Contact Us

If you have questions about this Privacy Policy or our data practices, you may contact us at:

Company Legal Name: Canopy Systems LLC

Registered Address: 542 Rutile Dr, Ponte Vedra Beach, Florida 32082, United States

Contact Email: legal@canopy.cx

Company Phone Number: +1 11111111111

Data Controller

For the purposes of the EU GDPR and UK GDPR, Canopy Systems LLC is the data controller responsible for your personal data.

If you are located in the UK or the EEA and believe your rights have been violated, you have the right to lodge a complaint with your local data protection authority.

In the UK, the supervisory authority is the Information Commissioner's Office (ICO) at ico.org.uk.

If you are in the EEA, you may contact the data protection authority in your country of residence, place of work, or where the alleged infringement occurred.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

The "Last updated" date at the top shows when it was last revised.

Privacy & Policy

Last updated: July 20, 2026

This summary highlights the most important points about how Canopy Systems LLC ("Canopy," "we," "us," "our") handles personal information. It is not a substitute for the full policy below.

What Canopy does. Canopy provides a unified software platform for private, semi-private, and public clubs (golf, country, and racquet clubs), covering member and patron management, reservations and scheduling, point of sale, member billing and payments, event management, staff and operations management, member communications, mobile apps, and reporting.

Our two roles. For most data that clubs put into the platform — information about their members, guests, and staff — the club is the controller and Canopy is a processor acting on the club's instructions. That processing is governed by our DPA, not this policy. This Privacy Policy describes the personal information for which Canopy itself is the controller — for example, our website visitors, prospective customers, and the club personnel who administer a Canopy account.

  • We collect information you provide, information collected automatically (including, in our mobile apps, location data), and information from third parties.
  • We use it to provide and improve the platform, communicate with you, process billing, ensure security, and meet legal obligations.
  • We do not sell personal information. We share it only with service providers (subprocessors), affiliates, and as required by law.
  • Card payments are handled by Stripe; Canopy does not collect or store full card numbers.
  • Depending on where you live, you may have rights to access, correct, delete, or port your information.

Questions or requests? Contact legal@canopy.cx.

1. Scope and Our Role

This Privacy Policy explains how Canopy Systems LLC, a Florida limited liability company, collects, uses, and shares personal information when Canopy acts as a controller — meaning when Canopy determines the purposes and means of processing. It applies to our public websites, our sales and marketing activities, our communications with prospective and current customers, and the administration of customer accounts.

1.1 Where this policy does not apply: club (customer) data

Canopy's clients are clubs. When a club uses the platform, it uploads and generates data about its members, guests, and staff. For that data, the club is the controller and Canopy is a processor acting only on the club's documented instructions. Canopy's handling of that data is governed by the DPA between Canopy and the club, together with the club's own privacy notice — not by this Privacy Policy.

If you are a club member, guest, or staff member and want to access, correct, or delete information held about you in the platform, please contact your club directly.

1.2 Who this policy applies to

This policy works alongside our Cookie Policy, our DPA, and any product- or region-specific notices we publish. Where a specific notice conflicts with this policy, the specific notice controls for that context.

2. Who This Policy Applies To

How we handle your information depends on how you interact with Canopy. In this policy, "you" may mean:

  • Visitors — anyone who visits our websites without a Canopy account.
  • Prospects — representatives of clubs evaluating Canopy (demo requests, sales contact, marketing signups).
  • Customer personnel (administrators and authorized users) — club staff and managers who register for, configure, or administer a Canopy account on the club's behalf.
  • Members, guests, and other club end users — individuals whose data flows through the platform because a club uses Canopy. As explained in §1.1, this policy does not govern that data except for limited mobile-app data where Canopy acts as a controller.

3. Information We Collect

As a controller, we collect the following categories of personal information.

3.1 Information you provide to us

Category Examples
Account & identity Name, business email, phone number, job title, club affiliation, username, password.
Customer relationship Demo requests, sales correspondence, contract and onboarding details, support tickets, survey responses.
Billing contact data Billing name, business address, and billing contacts for the club account. (Cardholder data is handled by Stripe — see §6.)
Communications The content of emails, chats, and other messages you send to us.

3.2 Information we collect automatically

Category Examples
Usage data Pages and features viewed, actions taken, dates and times of access, referring pages.
Device & connection IP address, browser type, operating system, device identifiers, language settings.
Cookies & similar tech Identifiers and preferences set through cookies, pixels, and local storage (see Cookie Policy).
Mobile app data App version and device data from our mobile apps, and diagnostic or crash data where such features are enabled.
Location data (mobile only) Approximate or precise location collected through our mobile apps — e.g., to record a member's presence at a club or a staff member's clock-in/clock-out location, where enabled.

Where our mobile apps offer features that use location (for example, an optional staff clock-in feature), any precise geolocation collected is treated as sensitive under some laws. Where we collect it, we use it only for the specific purpose described above and not for any other purpose.

3.3 Information from other sources

  • Clubs and their personnel (e.g., when an administrator adds another user).
  • Service providers and lead-enrichment or marketing providers.
  • Public sources and social media, where you have made information available.

4. How We Use Information And Our Legal Bases

We use personal information for the purposes below. Where the GDPR or similar laws apply, we rely on the lawful basis noted.

Purpose Lawful basis (GDPR)
Provide, operate, and secure our websites and accounts; authenticate users. Performance of a contract; legitimate interests.
Respond to inquiries, provide support, manage the customer relationship. Performance of a contract; legitimate interests.
Process billing and maintain transaction and account records. Performance of a contract; legal obligation.
Send service and administrative messages. Performance of a contract; legitimate interests.
Send marketing communications about Canopy. Consent (where required); otherwise legitimate interests.
Analyze and improve our products; develop new features. Legitimate interests (our website analytics is cookieless).
Detect, prevent, and investigate fraud, abuse, and security incidents. Legitimate interests; legal obligation.
Comply with law and enforce our agreements. Legal obligation; legitimate interests.

Where we rely on legitimate interests, we balance those interests against your rights. You may object as described in §11.

5. Artificial Intelligence Features

Canopy offers AI-assisted features, including an AI email builder, and is developing additional AI capabilities such as an AI document editor. When you use these features, the content you submit is processed to generate the requested output.

We may use service providers (AI model providers) to deliver these features, as listed in our sub-processor list. We do not use personal information that Canopy controls to train third-party or Canopy proprietary AI models without a lawful basis and, where required, your consent or the controlling club's instruction. Where Canopy processes club data through AI features, it does so as a processor under the club's DPA.

5.A Automated decision making and profiling

Canopy's AI features assist with drafting and content generation; they do not make decisions that produce legal or similarly significant effects about you without human involvement. We do not engage in automated decision-making or profiling that would be subject to GDPR Article 22 in a way that produces such effects without a lawful basis and appropriate safeguards. Where applicable law gives you the right not to be subject to a decision based solely on automated processing, you may exercise it as described in §11.

6. Payments And Financial Data

Card payments are processed by Stripe. Canopy uses Stripe Connect, Stripe's payments-for-platforms solution, so that clubs accept payments through their own Stripe connected accounts. Card details are entered directly into Stripe-hosted fields; Canopy does not collect, store, or transmit full cardholder data. Payments settle directly to each club's connected account; Canopy is not the payment processor and does not hold, receive, or route those funds. Stripe's handling of payment data is governed by Stripe's own privacy policy.

Canopy does store billing-adjacent financial records that are not cardholder data — e.g., transaction amounts and dates, purchase and order records, account and Club Cash balances, and limited payment metadata such as a payment token or the last four digits of a card. We treat this as personal information subject to this policy or, where it concerns club members, to the club's DPA.

7. Cookies And Similar Technologies

We use a small number of strictly-necessary first-party cookies to keep you signed in and keep our websites secure, and a cookieless analytics tool to understand site usage in aggregate. We do not use advertising or cross-site targeting cookies, and our public website does not display a cookie consent banner because it sets no non-essential tracking cookies. For details, see our Cookie Policy.

8. How And With Whom We Share Information

We do not sell personal information. We share it only as described here:

  • Service providers and sub-processors — vendors that host our infrastructure, deliver email, process payments, provide analytics, power AI features, and provide support tooling, acting on our instructions under contract.
  • Affiliates — entities under common control with Canopy.
  • Legal and safety — to comply with law, respond to lawful requests, enforce our terms, or protect rights, property, and safety.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets.
  • With your direction or consent.

8.1 Categories of service providers (sub processors)

We engage service providers that act as sub-processors on our instructions under contract. They fall into the following categories: cloud hosting and infrastructure; payment processing; transactional and marketing email; SMS and push notifications; AI-assisted features; product and website analytics; error and crash logging; maps and location services; file storage and content delivery; customer support; and data warehousing and business intelligence.

We maintain a current, named list of sub-processors — including each provider's purpose and location — and make it available to our customers on request and through their Data Processing Agreement, together with a mechanism to receive advance notice of changes. That list is kept consistent with DPA Schedule C.

8.2 Third party services you connect

If your club connects a third-party integration (for example, an accounting tool or a calendar) and directs your data to that third party, that provider acts on your instructions, not ours. It is not a Canopy sub-processor, and your use of it is governed by that provider's terms — not this policy.

9. International Data Transfers

Canopy is based in the United States and may process information in the U.S. and other countries. Where we transfer personal information out of the EEA, UK, or Switzerland, we use a recognized transfer mechanism — typically the European Commission's Standard Contractual Clauses (and the UK Addendum) — with supplementary measures where needed.

10. Security And Retention

We maintain administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit, and monitoring. No system is perfectly secure.

We retain personal information for as long as needed to fulfill the purposes in this policy, including to provide the platform, comply with legal obligations, resolve disputes, and enforce agreements. When information is no longer needed, we delete or de-identify it.

11. Your Privacy Rights

Depending on where you live, you may have rights to: access, correct, delete, port, object to or restrict certain processing (including direct marketing), opt out of profiling or automated decisions that produce legal or similarly significant effects, and withdraw consent — without unlawful discrimination for exercising them.

To exercise these rights, contact legal@canopy.cx. We will verify your request and respond within the time required by law. You may also lodge a complaint with your local data protection authority.

Club members, guests, and staff: if your request concerns data held in the platform on a club's behalf, please contact your club, which controls that data.

12. Children

Our websites, sales activities, and account administration are directed to businesses and adults, and we do not knowingly collect personal information directly from children in our capacity as a controller.

Clubs may, however, enroll minor family members of their members (for example, junior members) as users of the club's account and mobile app. Where that occurs, the personal information of those minors is club data: the club is the controller and Canopy processes it solely as a processor on the club's documented instructions under the DPA. The club is responsible for providing any required notices and for obtaining verifiable parental or guardian consent where the law requires it, including under the U.S. Children's Online Privacy Protection Act (COPPA) and, in the EEA/UK, Article 8 of the GDPR. Requests about a minor's information held in the platform should be directed to the club. We support clubs with appropriate app-store age ratings and in-app consent touchpoints.

13. Changes to This Policy

We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice as required by law. Continued use after an update means you accept the revised policy.

14. How to Contact Us

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:

Canopy Systems LLC, Florida, United States

Email: legal@canopy.cx
‍
Mailing address: 542 Rutile Dr, Ponte Vedra Beach, FL 32082

Appendix A — United States State Privacy Disclosures

Supplements the policy for residents of U.S. states with comprehensive privacy laws (California, and states such as Virginia, Colorado, Connecticut, and others as they take effect).

A.1 California (CCPA/CPRA)

In the preceding 12 months, we have collected the categories in §3, from the sources in §3.3, for the purposes in §4, and disclosed them to the recipients in §8. We do not sell or share personal information as those terms are defined under California law, and we do not use or disclose sensitive personal information for purposes beyond those permitted by the CCPA.

Exercising rights; authorized agents. California residents may request access, deletion, and correction. You may use an authorized agent to submit a request on your behalf; we will require the agent to demonstrate authority (for example, written permission signed by you or a valid power of attorney) and may ask you to verify your own identity directly. We verify requests by matching the information you provide against information we hold; for certain requests we may require additional verification. We respond within the timeframes required by law and will not discriminate against you for exercising your rights.

Opt-out preference signals (Global Privacy Control). Where we engage in any activity that constitutes a "sale" or "share" under California law, we will treat a recognized opt-out preference signal, such as the Global Privacy Control (GPC), as a valid request to opt out for that browser or device, and we will provide a "Your Privacy Choices" link as required.

A.2 Other U.S. states

Residents of other states with applicable laws have comparable rights to access, correct, delete, and port, and to opt out of targeted advertising, sale, and certain profiling.

Contact legal@canopy.cx

Appendix B — EEA, UK, And Switzerland (GDPR)

Controller: Canopy Systems LLC.

Legal bases: see §4.

Your rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.

International transfers: see §9.

Retention: see §10.

Appendix C — Canada (PIPEDA)

We handle personal information in accordance with PIPEDA and applicable provincial laws. We obtain consent where required, limit collection to identified purposes, and provide access and correction rights. Contact legal@canopy.cx; you may also contact the Office of the Privacy Commissioner of Canada.