Privacy policy
Last updated:
Effective date: 12 September 2026
Version: 1.0
This is a translation of the Hungarian original for convenience. Where the two differ, the Hungarian text governs.
1. The controller
The controller for the CourseForge mobile app and its website is:
- Name: Bába Gergely e.v. (sole trader)
- Registered and postal address: Béke utca 145, 2519 Piliscsév, Hungary
- Sole trader registration number: 58553789
- Tax number: 48261825131
- Data protection and support email: support@courseforge.hu
- Website: www.bagemedia.hu
(the “Controller” or “Provider”).
This policy covers the CourseForge mobile app (the “App”), the CourseForge website, and support correspondence relating to the App.
2. Summary
CourseForge is a data-minimising app that works primarily on the device:
- there is no CourseForge account and no mandatory registration;
- course designs created by the user stay, as a rule, on the user’s device;
- the Provider operates no cloud storage of its own for course designs;
- image, PDF and CourseForge files are created, imported and exported on the user’s device, at the user’s initiative;
- the Provider does not receive the user’s payment card details;
- in the Free version, the Google AdMob advertising service may process technical, device, advertising and usage data;
- to verify a Lifetime Pro purchase, RevenueCat processes purchase and technical data;
- if the user contacts support, the Provider processes the contact details given and the content of the message.
3. Locally stored course designs and files
3.1. Data processed
The App may store the course designs, settings and related data created by the user locally on the user’s device. These may include in particular:
- the arena dimensions and visual settings;
- the obstacles and other course elements placed;
- names, notes and other design data entered by the user;
- local app settings;
- imported and exported CourseForge, image or PDF files.
3.2. How and why
The App processes this data in order to provide the design, save, import and export functions. Course designs are not uploaded to any server of the Provider, and the Provider does not access their content in normal operation.
An operation performed locally and solely on the user’s device does not in every case amount to processing of personal data by the Provider. Even so, the Provider describes how local storage works, for transparency.
3.3. Retention and deletion
Locally stored designs and settings may remain on the device until the user deletes them in the App, clears the App’s data, removes the App, or the device storage is otherwise erased. It is advisable to make exported backups of important designs before removing the App.
3.4. Import, export and sharing
The user chooses the destination and the recipient of an exported file. If the user sends a file to email, a messaging app, cloud storage or another external service, that external provider is responsible for the subsequent processing under its own policy.
Where possible the App uses the system file picker and share sheet. If a feature requires permission to access device storage or the photo library, the App requests only the access that feature needs. The permission can be withdrawn in the device’s system settings; this may limit the import or save feature concerned.
4. Google AdMob advertising and consent management
4.1. The service
The Free version of CourseForge may display advertising through the Google Mobile Ads SDK / Google AdMob. Depending on the user’s location and the applicable terms, Google Ireland Limited and/or Google LLC may be involved in providing the service.
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Google privacy policy: https://policies.google.com/privacy
- Google advertising data: https://policies.google.com/technologies/ads
4.2. Possible categories of data
Depending on settings, device, region, permissions and the user’s consent choice, the Google Mobile Ads SDK may process in particular:
- the IP address and the approximate location estimated from it;
- device and app identifiers, such as an advertising ID or an app-scoped identifier;
- device type, operating system, language and technical characteristics;
- advertising data, such as the ad shown, impressions, clicks and other interactions;
- app usage events and user interactions;
- diagnostic, performance and non-user-linked crash data;
- the consent choice and related technical information.
Exactly what is processed depends on the version of the Google Mobile Ads SDK in use and on the advertising features enabled in CourseForge.
4.3. Purposes
Processing may serve to:
- select, display and measure advertising;
- show personalised advertising where the user has validly consented;
- show limited or non-personalised advertising;
- prevent advertising fraud, abuse and security incidents;
- measure and improve the performance of the advertising service;
- meet legal and consent requirements.
4.4. Legal basis
Where applicable data protection or electronic communications rules require it, the legal basis for personalised advertising, for accessing device data that is not strictly necessary, and for processing for tracking purposes is the user’s freely given consent under Article 6(1)(a) GDPR.
Certain processing relating to the security of the advertising system, fraud prevention and the lawful operation of the service may rest on the legitimate interests of the Provider or of Google under Article 6(1)(f) GDPR, or on compliance with a legal obligation under Article 6(1)(c) GDPR. Google’s own processing is also governed by the legal bases Google determines.
4.5. Giving and withdrawing consent
In the European Economic Area, the United Kingdom, Switzerland and other regions that require consent, the App may use the Google User Messaging Platform (UMP) consent interface.
The user can change or withdraw an earlier choice in the App’s Settings. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. After consent is refused or withdrawn, limited or non-personalised advertising may still appear, where that can lawfully be provided in the region concerned.
On iOS, tracking across apps or websites may also require permission under Apple’s App Tracking Transparency. If the user does not grant it, the App is not permitted to use the advertising identifier protected by Apple for that purpose.
5. Lifetime Pro, Apple/Google purchases and RevenueCat
5.1. App store purchase
The one-off in-app purchase of Lifetime Pro is processed by the Apple App Store or Google Play billing system. As its own controller, the app store may process in particular:
- app store account data;
- payment and billing data;
- transaction data and purchase history;
- device, region, currency and security check data.
The Provider does not receive the user’s full payment card details or the app store account password. Apple’s and Google’s processing is governed by their own privacy policies:
- Apple privacy policy: https://www.apple.com/legal/privacy/
- Google privacy policy: https://policies.google.com/privacy
5.2. RevenueCat
To verify the validity of a purchase, to provide the Lifetime Pro entitlement and to support “Restore purchases”, the Provider uses the service of RevenueCat, Inc.:
- RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA
- Privacy policy: https://www.revenuecat.com/privacy
As the Provider’s processor, RevenueCat may process in particular:
- a random or app-specific anonymous user identifier;
- device type and operating system;
- the App and SDK version;
- a technical timestamp of the most recent use of the App;
- purchase history, product identifier, entitlement status and transaction information;
- the Apple purchase receipt or Google purchase token;
- currency and regional settings;
- technical data needed for purchase verification, fraud prevention and debugging.
CourseForge has no user accounts of its own, so as a rule no name, email address or other direct identifier created by the Provider is passed to RevenueCat. The Provider does not use RevenueCat customer attributes to transmit a name, email address, telephone number or other direct identifier, and does not link RevenueCat’s anonymous identifier to any user profile of its own.
5.3. Purpose and legal basis
The purposes of processing by RevenueCat are:
- verifying the purchase and activating the Pro entitlement;
- restoring an earlier purchase;
- preventing unauthorised access and purchase fraud;
- investigating the operation and faults of the purchase system;
- producing aggregated purchase reports.
The legal basis is performance of the contract and steps taken prior to purchase under Article 6(1)(b) GDPR; for billing, consumer protection and other mandatory records, compliance with a legal obligation under Article 6(1)(c) GDPR; and for fraud prevention and the security of the service, the Provider’s legitimate interests under Article 6(1)(f) GDPR.
6. Support, fault reports and data protection requests
6.1. Data processed
If the user contacts the Provider by email or another published channel, the Provider may process:
- the user’s name and email address;
- the content of the message and any data the user volunteers;
- the time of contact;
- for a fault report, technical data about the device, operating system and app version;
- for a purchase issue, the transaction or app store receipt identifier;
- the replies and the outcome of the matter.
Please do not send special category or unnecessary personal data that is not needed to resolve the matter.
6.2. Purpose, legal basis and retention
The purpose is to answer the question, provide support, fix a fault, investigate a complaint, handle a legal claim and fulfil data protection rights.
The legal basis is handling the contract at the data subject’s request under Article 6(1)(b) GDPR; for consumer complaints and other mandatory handling, compliance with a legal obligation under Article 6(1)(c) GDPR; and for general support, abuse prevention and legal claims, the Provider’s legitimate interests under Article 6(1)(f) GDPR.
General support correspondence is kept for at most 2 years after the matter is closed, unless further retention is needed to pursue a legal claim. Consumer complaints and the replies to them are kept for 3 years under Hungarian consumer protection rules. Accounting records are subject to the applicable mandatory retention period.
7. The CourseForge website
The CourseForge website is a simple, static presentation and legal information site. The Provider uses no Google Analytics, Meta Pixel, advertising or other marketing tracking code on it, and sets no cookies.
The web server may technically log the IP address, the time of the request, the resource opened, basic technical data about the browser and device, and the error code. The purpose of this logging is the security, operation and debugging of the website and the prevention of abuse. The legal basis is the Provider’s legitimate interests under Article 6(1)(f) GDPR.
- Hosting and CDN provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
- Privacy policy: https://www.cloudflare.com/privacypolicy/
The website uses Cloudflare Web Analytics to measure traffic. That service sets no cookies, writes nothing to browser storage for measurement, does not fingerprint the browser, and does not follow the visitor to other websites. The Provider sees aggregate figures: page views, referrers, country, browser family. The Provider cannot identify or single out an individual visitor from them. Legal basis: the Provider’s legitimate interest in knowing which pages are read, under Article 6(1)(f) GDPR. Because the measurement stores nothing on the visitor’s device, it requires no consent.
The website remembers the language choice in the browser’s localStorage, holding only the two-letter code of the chosen language (en or hu). This is a functional preference requested by the user, it stays on the device, and it is never sent to a server.
If the Provider later introduces a contact form, a newsletter or marketing tracking, this policy will be amended before the feature is switched on, and prior consent will be requested where required.
8. Retention summary
| Data | Typical retention |
|---|---|
| Local course designs and settings | On the user’s device until deleted, until app data is cleared, or until the App is removed |
| AdMob and advertising data | Under Google’s own retention rules; the Provider does not, as a rule, receive an individual copy |
| UMP consent status | Until the choice is changed, expires, or is requested again by the system, under Google’s technical rules |
| RevenueCat purchase and entitlement data | For as long as needed to verify and restore entitlements, perform the contract and meet mandatory legal claims |
| General support correspondence | At most 2 years from closure of the matter; longer where a legal claim is being resolved |
| Consumer complaint and reply | 3 years |
| Accounting records | Until the end of the applicable accounting and tax retention period |
| Website traffic measurement (Cloudflare Web Analytics) | Aggregate statistics under Cloudflare’s retention rules; no individual visitor profile is created |
The Provider deletes or anonymises personal data earlier where the purpose has ceased and no law or legal claim justifies further retention.
9. Transfers and processing outside the European Economic Area
Google, RevenueCat, Apple, the hosting/CDN provider and some of their sub-processors may also process data outside the European Economic Area, in particular in the United States.
Transfers may take place on an appropriate legal basis and with appropriate safeguards, in particular:
- under an adequacy decision of the European Commission, including — where applicable — the EU–US Data Privacy Framework;
- using the Standard Contractual Clauses adopted by the European Commission;
- under another safeguard recognised by Chapter V GDPR.
Current transfer and sub-processor information for each provider is set out in their own privacy, data processing and security documentation.
10. Security
The Provider applies technical and organisational measures proportionate to the risk of the processing, including in particular:
- data minimisation and account-free, local operation;
- transmission over encrypted HTTPS/TLS connections wherever data is transferred;
- use of the app stores’ secure payment systems;
- restricting and protecting provider-side access;
- keeping to supported SDK versions and security updates;
- avoiding unnecessary device permissions.
No electronic system can be considered entirely free of risk. The user is also responsible for protecting their device, installing system updates and backing up important course designs.
11. Supervisory authority and remedies
The user has the right to lodge a complaint with a data protection supervisory authority, in particular in the country of their habitual residence, place of work or the place of the alleged infringement.
In Hungary, the competent authority is:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) — the Hungarian National Authority for Data Protection and Freedom of Information
- Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary
- Postal address: 1363 Budapest, Pf. 9, Hungary
- Email: ugyfelszolgalat@naih.hu
- Telephone: +36 1 391 1400
- Website: https://www.naih.hu/
The possibility of complaining to the authority does not affect the user’s right to a judicial remedy.
12. Minors
CourseForge is a general-purpose tool for designing equestrian courses. It is not designed specifically for children under 13 and is not distributed as an app aimed at children. The Provider does not knowingly request a name, date of birth or contact details from children, and does not knowingly process data for personalised advertising in relation to children.
A minor may use the App in accordance with the law applicable to them and, where required, with the permission of a parent or legal guardian. If the Provider learns that it is processing a child’s personal data without an appropriate legal basis, it will take the necessary steps to delete the data or regularise the processing.
13. Automated decision-making and profiling
The Provider does not carry out solely automated decision-making that would produce legal effects concerning the user or similarly significantly affect them.
Where consent is given, Google’s advertising system may use an advertising profile based on interests and online activity to select personalised advertising. That consent can be withdrawn as described in section 4.5.
14. Changes to this policy
The Provider may amend this policy, in particular where the law changes, a new feature is introduced, an SDK or provider changes, or the processing itself changes. The version in force at any time is available with the effective date and version number above on the CourseForge website and can be opened from within the App.
In the event of a material change, the Provider will give separate notice in the App or by other appropriate means, and where the new processing requires consent, will request it before the processing begins.
Questions about this page: support@courseforge.hu · Impresszum