Zhira Golf logo Zhira Golf
Global Maxima LLC

Privacy Policy

Effective October 3, 2026 · Supersedes the version effective August 14, 2026

This Privacy Policy explains how Global Maxima LLC, doing business as Zhira Golf ("Zhira Golf," "Zhira," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information through our websites, early access program, web and mobile applications, chat and voice concierge, booking and payment tools, email, and APIs (the "Services"). It also explains your rights under US state privacy laws, EU/EEA and UK data protection law, Canada's PIPEDA, and South Africa's Protection of Personal Information Act ("POPIA").

Summary and notice at collection

  • Early access today: we collect your email address (and optional name, trip type, and destinations), plus limited security and anonymous page-activity data. We do not collect phone numbers, and this site uses no cookies.
  • At platform launch: we will also handle account, trip, booking, payment-token, chat, and (where you use voice features) call data, as described below.
  • We do not sell your personal information and do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months.
  • Zhira never stores full card numbers. Payment details go directly to our payment processor.
  • You can access, correct, delete, or export your data and opt out of communications at privacy@zhiragolf.com.

1. Who is responsible for your data

Global Maxima LLC (a Minnesota limited liability company, 1250 Wayzata Boulevard East, STE 1, Wayzata, MN 55391, USA) is the data controller (and the "responsible party" under POPIA) for personal data collected through the Services. For reservations arranged with golf courses, resorts, airlines, and other suppliers ("Providers"), each Provider is an independent controller of the guest and player records it keeps. Contact our privacy office at privacy@zhiragolf.com or by mail at Global Maxima LLC, Attn: Privacy Office, at the address above. Where required by law we will appoint a representative in the EU/UK, and their details will be published here.

2. Information we collect

Depending on how you use the Services, we collect the following categories.

  • Contact and identity data: email address (required for early access), optional name, and, for platform accounts, sign-in identifiers from Google, Apple, or email and password through our authentication provider.
  • Trip and preference data: destinations, dates, tee-time windows, player counts, skill or pace preferences, lodging, flight and transport preferences, accessibility or dietary requests you choose to share, and the type of traveler you are (for example, solo golfer or group organizer).
  • Booking data: course and Provider names, confirmation numbers, changes and cancellations, and related messages.
  • Group data: names and contact details of people an organizer invites. Organizers must have permission to share this information, and invitees can ask us to stop contacting them.
  • Payment-related data: payment tokens, card brand and last four digits, billing postal code, amounts, receipts, and refund or dispute records. Full card numbers, security codes, and wallet credentials go directly to Stripe (and Google Pay or Apple Pay) and never touch our servers.
  • Communications: chat messages and transcripts, support emails, and early access inquiries. Where you use voice features, or where our automated assistant places a call to a Provider on your behalf, we may process audio, call metadata, and transcripts. Calls may be recorded or transcribed only with notice and in accordance with applicable consent laws, and our assistant identifies itself as an automated agent.
  • Location data: your country (detected from your connection), your home metro or destinations that you type in, and, in the mobile app, precise location only if you grant permission and only to provide features you request.
  • Technical and security data: a keyed hash of your IP address (not the address itself) used for rate limiting, user agent, timestamps, error and security logs, and Cloudflare Turnstile bot-check signals and tokens.
  • Site activity: anonymous on-page interaction events and, if you sign up, a short summary of your activity. See section 6.
  • Consent and compliance records: email verification time, notice and terms versions accepted, communication preferences, and rights requests.

Sources. We collect information from you, from people who invite you to a group trip, from Providers and booking systems you ask us to work with, from payment processors, and from your device and browser. We do not intentionally collect sensitive personal information (such as health, precise government ID, or biometric data). If you voluntarily share an accessibility or medical need so we can arrange suitable accommodations, we treat it as sensitive and use it only for that purpose.

3. How we use information and our legal bases

  • Provide the Services (find availability, request and manage reservations, coordinate trips, process payments, send confirmations and support). Basis: performing our contract with you.
  • Verify your email and send launch and early access communications. Basis: your consent and our legitimate interest in running the program; you can withdraw consent any time.
  • Secure the Services and prevent fraud and abuse (bot protection, rate limiting, duplicate-booking and chargeback prevention). Basis: legitimate interests and, for payments, legal obligations.
  • Improve the Services (understand which content and features help people, debug issues, evaluate and improve assistant quality using de-identified or access-controlled data). Basis: legitimate interests.
  • Comply with law and enforce our terms (tax and accounting records, regulatory requests, dispute resolution). Basis: legal obligation and legitimate interests.
  • Marketing. We email about Zhira only as described in section 12. We do not use ad-tech or sell data.

4. AI and automated processing

  • Our chat and voice concierge uses large language models and speech services hosted by cloud providers (see section 5) to understand requests and draft responses. Your messages and relevant trip details are sent to those providers to generate a response.
  • We do not use your personal data to train our own or third-party foundation models without your consent. Our provider arrangements are configured to limit use of your data to providing the service to us.
  • The assistant helps with requests but does not make legal or similarly significant decisions about you on a solely automated basis. A person on our team can review or complete bookings, and you can ask for human review of any outcome at privacy@zhiragolf.com.
  • Please do not share card numbers, passwords, or government identifiers in chat. We apply safeguards against prompt-injection and misuse, and we may filter or block messages that appear malicious.

5. Who we share information with

  • Providers and booking systems you ask us to work with (golf courses, resorts, tee-sheet and club-management systems, marketplaces, airlines, and lodging distributors): the details necessary to make, change, or cancel your reservation, such as name, contact details, date, player count, and preferences. They handle that data under their own privacy practices.
  • Group members: an organizer sees the names and booking status of invited participants, and participants see trip details the organizer shares.
  • Service providers (processors) that work on our behalf under contract, including: Cloudflare (hosting, edge security, D1 database, Turnstile bot protection); Postmark (transactional email); Stripe, Google Pay, and Apple Pay (payments); Google Cloud and Firebase (AI models, speech-to-text, authentication, and session storage); Twilio (voice calls); Supabase (database, in regional projects); and application hosting, logging, and customer-support tools. We require them to protect personal data and use it only for our purposes.
  • Legal and safety: authorities, courts, or others where required by law or to protect rights, safety, and the security of the Services.
  • Business transfers: a successor in a merger, acquisition, financing, or sale of assets, subject to this policy.
  • With your direction or consent, and in aggregated or de-identified form that cannot reasonably identify you.

We do not sell personal information and do not share it for cross-context behavioral advertising.

6. Cookies and site analytics

This early access site does not use cookies, local storage, device fingerprinting, or third-party analytics or advertising tools. To understand what makes visitors sign up, the page records anonymous interaction events (for example, "viewed the pricing calculator" or "played the demo video") using a random identifier that exists only in your browser's memory for the current page visit. This identifier is never linked to your email address or IP address. These events are kept for up to 13 months.

If you submit the sign-up form, a short summary of your activity on the page (the button you clicked, the sections you viewed, time on the page, and any campaign or referring website) is stored with your sign-up record so we can learn what leads people to join. If your browser sends a Do Not Track or Global Privacy Control signal, no analytics events or activity summary are recorded at all, and we treat the Global Privacy Control as a valid opt-out request.

The Services at launch will use strictly necessary cookies or similar storage (for example, to keep you signed in and secure your session). If we introduce non-essential cookies, we will ask for your consent through a consent tool first where the law requires it. Cloudflare Turnstile may use limited signals from your browser to tell humans from bots.

7. Data residency and international transfers

Early access sign-up data is stored in Cloudflare D1 in a single Cloudflare region. When the platform launches, account and booking data will be stored in a regional database matched to your region: United States (CCPA and other US state laws), European Union (GDPR), and South Africa (POPIA), with backups in a corresponding Google Cloud region. Some service providers and Providers process data in other countries, including the United States. Where personal data from the EEA, UK, or South Africa is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or contracts that satisfy POPIA section 72, and we assess the recipient's protections. You can request a copy of the safeguards at privacy@zhiragolf.com.

8. Retention

We keep personal data only as long as needed for the purposes above, and then delete or de-identify it. Typical periods are:

  • Early access records: until you ask us to delete them, you unsubscribe, or they are no longer needed for launch communications. Unverified requests may be deleted sooner.
  • Anonymous site activity events: up to 13 months.
  • Rate-limiting and security records: about 24 hours, and only as keyed hashes.
  • Booking, payment, and tax records: up to 7 years, or longer where law requires, to meet accounting, tax, and dispute obligations.
  • Chat transcripts and voice recordings: generally up to 12 months, unless needed longer for a dispute, fraud investigation, or legal obligation, or unless you ask us to delete them earlier where the law allows.
  • Backups roll off on a schedule and deleted data is removed from them in the ordinary course.

9. Security

We use technical and organizational safeguards appropriate to the data, including encryption in transit and at rest, strict access controls, keyed hashing of IP addresses, one-way hashing of email verification tokens (which expire after 48 hours), bot protection and rate limiting on sign-up, origin checks on our APIs, and tokenized payments handled by PCI-DSS Level 1 processors. No system is perfectly secure. If a breach affects your personal data, we will notify you and regulators as the law requires.

10. Your rights

Everyone. You can ask us to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent, as described in section 11. We will not discriminate or retaliate against you for exercising your rights.

United States (California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states). Depending on your state, you may have the right to know and access the personal information we hold; correct inaccuracies; delete; receive a portable copy; opt out of the sale or sharing of personal information, targeted advertising, and certain profiling (we do none of the first three); and limit use of sensitive information (we do not use it beyond what the law permits). You may use an authorized agent, and you may appeal our decision by replying to our response; if you are still unsatisfied, you may contact your state attorney general. California residents may also request information about disclosures for direct marketing under California's "Shine the Light" law (we make none).

European Economic Area and United Kingdom. You have the rights of access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests), the right to withdraw consent at any time without affecting earlier processing, and the right not to be subject to solely automated decisions with legal or similarly significant effects. You may lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office).

South Africa (POPIA). You may ask whether we hold your personal information, request access, correction, or deletion, and object to processing. You may complain to the Information Regulator (South Africa) at inforeg.org.za.

Canada (PIPEDA and provincial laws). You may request access to and correction of your personal information, withdraw consent subject to legal restrictions, and complain to the Office of the Privacy Commissioner of Canada or your provincial regulator.

11. How to exercise your rights

  • Email privacy@zhiragolf.com, or write to Global Maxima LLC, Attn: Privacy Office, 1250 Wayzata Boulevard East, STE 1, Wayzata, MN 55391, USA. Please tell us the email address you used and the right you want to exercise.
  • We may need to verify your identity (for example, by confirming your email address) before acting, and we will not ask for more information than necessary.
  • We respond within 45 days in the US (extendable once by 45 days where permitted), one month in the EEA/UK (extendable by two months for complex requests), and 30 days under POPIA, and we will explain any refusal.
  • Your browser's Do Not Track or Global Privacy Control signal is honored automatically on this site.

12. Communications choices

We send a verification email when you request early access and later email you about launch, features, and offers. Every marketing email has an unsubscribe link, and you can also write to privacy@zhiragolf.com. Service messages about your account or bookings will still be sent. We do not send text messages through the early access program; if we add text messaging, we will obtain your separate consent first and honor opt-out keywords.

13. Children

The Services are for adults aged 18 and older. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it. Organizers who book for minors in their group are responsible for having the authority to do so.

14. Changes and contact

We may update this policy as our practices or the law change. We will post the new version with an updated date and, for material changes, notify you by email where we have your address. Third-party sites and Providers have their own privacy practices that we do not control.

Questions or complaints: privacy@zhiragolf.com · Global Maxima LLC, Attn: Privacy Office, 1250 Wayzata Boulevard East, STE 1, Wayzata, MN 55391, USA. Your use of the Services is also subject to our Terms of Service.