Privacy Policy for DiveConnect.io
Last Updated: July 10, 2026
1. Introduction
Welcome to Diveconnect.io (the "Platform"). This Privacy Policy explains how Dive Connect, LLC, a limited liability company based in St. Petersburg, Florida, USA ("we," "us," or "our"), collects, uses, shares, and protects information in relation to our website, our iOS and Android mobile applications, and related services (collectively, the "Service"). It applies to all visitors, users (divers booking services, "Users"), and dive providers ("Providers"). By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
A. Information you provide to us
- User account information: when you create an account, we collect your name, email address, phone number, and password.
- Profile & social content: information you add to your diver profile and content you post through community, buddy, review, and messaging features.
- Provider account information: for Providers, the account information above plus business name, physical address, and payout information (handled by our payment partner).
- Provider verification information: government-issued ID, diving certifications, business registration, and proof of insurance. Highly sensitive identity documents are collected and processed directly by our identity-verification partner (Stripe Identity) and are not stored on our servers.
- Payment information: your card details are provided directly to our payment processor (Stripe). We do not store full card numbers on our servers.
- Communications: information you provide when you contact us for support at admin@diveconnect.io.
B. Information we collect automatically
- Usage data: how you interact with the Service, such as pages or listings viewed, searches, and access times.
- Device & log data (including mobile): when you use our mobile apps or website we collect device identifiers, device model and operating system, app version, IP address, and diagnostic/crash logs.
- Push notifications: if you enable them in the mobile app, we process a push notification token to deliver booking, community, and account notifications. You can turn notifications off in your device settings.
- Location data: we may collect approximate location from your IP address, or — with your permission on mobile — more precise device location, to show nearby dive sites, Providers, and people, and to help determine applicable taxes.
- Camera & photo library (mobile): if you choose to upload photos, the app accesses your camera or photo library only for that purpose, with your permission.
- Cookies & similar technologies: see our Cookie Policy. You can control non-essential cookies through our consent banner and your browser.
3. How We Use Your Information
- To provide the Service: create accounts, facilitate Bookings between Users and Providers, enable community features, and process payments.
- To ensure safety and trust: verify the identity and qualifications of Providers and enforce our Community Standards.
- To communicate with you: send booking confirmations, updates, support responses, and administrative messages.
- For legal and tax compliance: meet our legal obligations, including tax reporting where required by law.
- To improve and market: understand and improve the Platform and, with your consent where required, send promotional messages.
4. How We Share Your Information
We do not sell your personal data. We share information in these limited circumstances:
- With Dive Providers: when you make a Booking, we share the information the Provider needs to deliver the service (such as your name and booking details).
- With our service providers (subprocessors): the vendors listed in Section 5 who process data on our behalf under contract.
- For legal reasons: where required by law or in response to valid requests by public authorities.
- In a business transfer: in connection with a merger, acquisition, or sale of assets, subject to this policy.
All the above categories exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.
5. Service Providers (Subprocessors)
We rely on the following categories of trusted third parties to operate the Service. Each is bound by contract to protect your information and use it only to provide services to us:
- Supabase — cloud database, authentication, and file storage hosting.
- Stripe — payment processing and payouts (Stripe Connect).
- Stripe Identity — Provider identity and document verification.
- Sentry — application error and performance monitoring (diagnostic data), used on a legitimate-interest basis to keep the Service secure and reliable. If you consent to analytics cookies, Sentry may also record masked session replays (text, form inputs, and media hidden).
- PostHog — product analytics (including click, repeated-click, and JavaScript-error events) and session replay with form inputs masked and page text masked on account pages, used only after you consent to analytics cookies. Separately, our servers send PostHog limited operational records of service events (for example, a booking being confirmed or a payment failing) that contain internal identifiers only — no contact or payment details — and are not used to build an analytics profile of you.
- Vercel — hosting, plus Web Analytics and Speed Insights (traffic and page-performance measurement) used only after you consent to analytics cookies.
- Email delivery provider — transactional and account email (SMTP).
- SMS provider — SMS notifications where you have opted in (see our SMS Policy).
- Mapping providers — Google Maps and/or Leaflet / OpenStreetMap to display maps and locations.
- Stormglass — marine weather and tide data for dive sites; we send dive-site coordinates, not your personal data.
- Anthropic — on-demand message translation. When you tap "Translate" on a chat message, the text of that message is sent to Anthropic's Claude API to produce the translation. This happens only when you request it, the translation is shown only to you, and under Anthropic's commercial API terms the content is not used to train its models. Translations are cached so each message is processed at most once per language.
6. International Data Transfers
Our Service is global and our company is based in the United States. Your personal information may be transferred to and maintained on servers located outside your state or country. If you are in the European Economic Area (EEA), UK, or Switzerland, we transfer data to the U.S. and to Providers in various locations using appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs).
7. Your Data Rights
- All users: you can access and update your account information through your profile settings, and you can request deletion of your account and associated data.
- EEA/UK (GDPR): you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing.
- California (CCPA/CPRA): you have the right to know what personal information is collected, to delete it, to correct it, and to opt out of any "sale" or "sharing." Dive Connect, LLC does not sell your personal information.
To exercise these rights, contact us at privacy@diveconnect.io. We will verify your identity before processing your request. For step-by-step instructions on deleting your account and data — in the app or by request — see Deleting Your Account.
8. Data Security & Retention
We use administrative, technical, and physical safeguards to protect your information, though no method of transmission or storage is completely secure. We retain personal data only as long as necessary for the purposes in this policy, to comply with legal obligations (such as tax and accounting records), to resolve disputes, and to enforce our agreements.
9. Children's Privacy
The Service is intended for adults 18 and older. We do not knowingly collect personal information from anyone under 18, and in any event not from children under 13 (consistent with the Children's Online Privacy Protection Act, COPPA). If you believe a minor has provided us personal information, contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the new policy on this page and update the "Last Updated" date above.
11. Contact Us
Dive Connect, LLC
7901 4TH ST N STE 27295
St Petersburg, FL 33702, USA
Privacy requests: privacy@diveconnect.io
General: admin@diveconnect.io