Privacy Policy
Last updated: June 11, 2026
Buddive exists to help divers find trustworthy buddies. That only works if you trust us with your data too. This policy explains what we collect, why, who can see it, and the controls you have. We do not sell your personal data — to anyone, ever.
1. Who we are
Buddive (“we,” “us”) operates buddive.com, a dive-buddy matching platform. We are the data controller for the personal data described here. Contact: support@buddive.com.
2. What we collect and why
- Account data. Your email address and sign-in records. We use magic-link email authentication, so your email is how you sign in. Used to operate your account, send sign-in links, and send service notifications.
- Waitlist emails. If you join the waitlist, we store your email to invite you when your destination opens. Used only for that purpose.
- Profile data. Name or display name, avatar and photos, bio, languages, dive style, interests, home location (optional), and similar fields you fill in. Used to show your profile to other divers so you can match.
- Dive certifications. Self-declared certification level, agency, and dive count; and, if you choose verification, certification card images or eCard screenshots and verification selfies. Used to display your credentials and run document checks.
- Trip, destination, and presence data. Trip cards (destination, dates), and presence check-ins at destinations. Used to surface you in destination feeds so divers who will be in the same place can find each other.
- Dive plans. Pre-dive plan agreements you sign with a matched buddy: max depth, turn pressure, buddy-check confirmations, planned dive time, and an emergency contact for each diver. Emergency contact details are personal data about a third party — only provide a contact who has agreed to be listed. Used to give both buddies a shared, timestamped plan record.
- Post-dive attestations. After a planned dive, each buddy answers binary behavior questions about the other (buddy check done, depth respected, etc.) and may add a free-text safety concern. This means other users submit data about you. Attestation answers are not shown to the rated diver individually; they are aggregated into a trust signal on your profile. Free-text safety concerns are visible only to moderators.
- Messages. Communications between matched buddies on the platform. Used to deliver your conversations; also reviewable by us when a conversation is reported, to investigate safety issues.
- Blocks, reports, and moderation records. Who you block, reports you file or that are filed about you, and our moderation decisions. Used to enforce our rules and keep the platform safe.
- Technical data. Standard logs (IP address, browser/device info, timestamps) from our hosting providers, push-notification subscriptions if you enable them, and — when error tracking is enabled — error reports that may include device and session context. Used to run, secure, and debug the Service.
We collect this data directly from you, from other users (e.g., attestations and reports about you), and automatically through your use of the Service. We do not collect data from data brokers and we do not run background checks.
3. Legal bases (GDPR)
Where the GDPR or similar laws apply, we process your data on these bases: contract (operating your account, matching, dive plans, messages), legitimate interests (platform safety, moderation, fraud prevention, debugging), consent (waitlist emails, push notifications, optional verification photos — you can withdraw consent at any time), and legal obligation (responding to valid legal process).
4. Who sees your data
- Other divers. Your profile (photos, certifications and verification badges, dive style, trust signal, trip cards, and destination presence) is visible to signed-in users so matching can work. Once you match with someone, they can also see your messages to them and any dive plan you co-sign — including the emergency contact you entered on that plan. Your email address is never shown to other users by us.
- Service providers (processors) who run infrastructure for us: Supabase (database, authentication, file storage), Vercel (web hosting), Resend (transactional email delivery), and Sentry (error tracking, when enabled). If we add identity-verification (e.g., a provider such as Stripe Identity) or hosted chat infrastructure, those vendors will process the relevant data under contract with us, and we will update this policy. All providers are bound to process data only on our instructions.
- Moderators. Our moderation reviews reports, free-text safety concerns, and — when reported — message threads.
- Legal and safety. We may disclose data when required by law or valid legal process, or when we believe in good faith it is necessary to prevent serious harm to a person (for example, cooperating with search-and-rescue or law enforcement after a dive incident).
- Business transfers. If Buddive is acquired or merged, your data may transfer to the successor, who must honor this policy or notify you of changes.
We do not sell or rent your personal data, and we do not share it with third parties for their own advertising.
5. Retention
We keep your data while your account is active. When you delete your account, your profile, photos, trips, presence check-ins, dive plans, attestations, and messages are deleted along with it. We may retain limited records longer where we have a legal or safety reason to — for example, moderation and incident records tied to safety reports, records needed to enforce bans, backup copies for a limited window, and aggregate data that no longer identifies you. Waitlist emails are kept until you join or ask to be removed.
6. Security
Data is encrypted in transit (TLS) and at rest with our hosting providers. Access to data in our database is restricted with row-level security so users can only read what the product intends them to see, and administrative access is limited to the operator. Sign-in uses magic links, so there is no password for anyone to steal — but that means your email inbox is the key to your account; protect it. No system is perfectly secure, and we cannot guarantee absolute security.
7. Your rights and controls
- Access and correction. You can view and edit your profile, trips, and plans in the app at any time. For data not editable in the app, email us.
- Export. You can request a copy of your personal data in a portable format by emailing support@buddive.com.
- Deletion. You can permanently delete your account yourself from your profile settings — no email required, no retention dark patterns. Deletion removes your account and associated data as described in Retention above.
- Consent withdrawal and objection. You can disable push notifications in your device settings, unsubscribe from the waitlist, and object to or restrict processing by contacting us.
- Complaints.If you are in the EU/EEA or UK, you may lodge a complaint with your supervisory authority. We’d appreciate the chance to address it first.
8. Cookies, local storage, and the PWA
We use cookies for one thing: keeping you signed in (Supabase authentication session cookies). We do not use advertising or cross-site tracking cookies. Buddive is an installable progressive web app: a service worker caches app assets on your device so the app loads fast and works on weak connections (common at dive destinations), and local storage may hold app preferences. Uninstalling the app or clearing site data in your browser removes these. Because essential cookies are the only cookies we use, you won’t see a cookie-consent banner.
9. Children
Buddive is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has an account, report it to support@buddive.com and we will remove it.
10. International transfers
Buddive serves divers traveling worldwide, and our infrastructure providers store and process data in the United States and other countries. Where data is transferred out of the EU/EEA, UK, or other regions with transfer rules, we rely on our providers’ safeguards such as Standard Contractual Clauses and, where applicable, Data Privacy Framework certifications.
11. US state privacy rights (CCPA/CPRA and similar)
If you live in California or another US state with a comprehensive privacy law, you have rights to know, access, correct, delete, and port your personal information, and the right not to be discriminated against for exercising them. We do not “sell” or “share” personal information as those terms are defined in the CCPA/CPRA, so there is nothing to opt out of. Exercise any of these rights in-app (edit/delete) or via support@buddive.com; we will verify requests using your account email.
12. Data breaches
If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law, and tell you plainly what happened, what data was involved, and what we are doing about it.
13. Changes to this policy
We will update this policy as the product evolves — for example, when chat or identity-verification vendors go live. Material changes will be announced through the Service or by email, and the “Last updated” date above will change. This policy works together with our Terms of Service.
14. Contact
Privacy questions, rights requests, or concerns: support@buddive.com.