Introduction
Salty Sanctum (“Company,” “we,” “us”) operates a web-based community platform for freediving enthusiasts at saltysanctum.com, with a companion iOS application in development (collectively, the “Platform”). This Privacy Policy describes how we collect, use, disclose, store, and protect your personal information when you use the Platform and all related services (the “Services”).
By accessing the Services, you consent to the practices in this Policy. This Policy is part of our Terms of Service.
We comply with the California Consumer Privacy Act (CCPA/CPRA), General Data Protection Regulation (GDPR) where applicable, and CAN-SPAM Act.
Information We Collect
2a. Information You Provide Directly
- Account information: Email, password, name, profile details (display name, bio, avatar, certification level, home region)
- Private information: Phone number, date of birth, medical notes, emergency contacts, shipping addresses. These are accessible only by you and encrypted at rest where appropriate.
- Preferences: Privacy settings, notification preferences, display preferences (units, time format)
- Community profiles: Buddy profile (experience, availability, interests), instructor profile (bio, specialties, rates), business applications
- User-generated content: Posts, comments, event details, marketplace listings, reviews, photos, chat messages, dive site contributions
- Social connections: Friend/buddy connections, follows, block lists
- Certifications: Certification details, evidence photos (for staff verification)
- Gear sizes: The wetsuit size you wear per brand, your fin foot-pocket size, and any mask or fin fit notes you choose to save. You give these so a listing can tell you when a seller stated the same size you saved. They are visible only to you, they are never shown to another user or attached to anything you list, and you can delete them at any time.
- Payments: Transaction details and payment identifiers. Card numbers are processed by Stripe and never stored on our servers.
- Waivers: Digital acknowledgements with timestamps, IP address, and user agent for audit integrity
2b. Information Collected Automatically
- Device and access data: IP address, user agent, authentication method, used for security auditing, rate limiting, and fraud prevention
- Location: Coarse location when you opt in, used for nearby dive sites, buddy discovery, and event proximity
- Analytics: Page views and feature usage events via PostHog, used to improve the Platform. We do not use Google Analytics or ad-network analytics.
- Product usage signals (first-party): We collect pseudonymous, privacy-clean usage signals that the product itself acts on, such as what people search for (including the search term), which areas of the map are browsed (as coarse 20 to 40 kilometer grid cells, never a precise or continuous location trail), which screens are viewed, and which features are opened. These are tied to a rotating session identifier and, when you are signed in, your account. They carry no free-form personal information by design, are stored on our own systems (not sold or shared), and are processed under our legitimate interest in improving the Platform. You can turn this off any time with the “Share usage analytics” toggle in Privacy Settings; the do-not-collect list below still applies whether it is on or off. We never instrument safety or emergency flows beyond simple counts, and we never record keystrokes, message content, or who views whose profile.
- Error data: Error traces and performance data via Sentry, with all user text, inputs, and media masked
- Push notification tokens: Device tokens via Firebase Cloud Messaging when you opt into push notifications
- Bot prevention: CAPTCHA challenge data via Cloudflare Turnstile on sign-up, sign-in, and password reset, with no persistent tracking
- Cookies: Essential authentication cookies for session management
2c. Information from Third Parties
- Google/Apple OAuth: Email, name, and profile photo (Google only) when you choose social sign-in
- Stripe: Transaction confirmations, payment status, refund status
2d. Information We Do NOT Collect
- We do not collect health data (beyond optional medical notes you provide)
- We do not collect biometric data
- We do not collect body measurements such as height or weight.
- We do not use advertising tracking pixels or ad-network analytics
- We do not sell your personal information
How We Use Your Information
- Provide Services: Authenticate accounts, display profiles, facilitate events, marketplace, chat, buddy matching, process payments, send notifications
- Safety: Enable check-ins, broadcast safety alerts, store emergency contacts for user-initiated sharing
- Security: Rate limiting, login auditing, fraud prevention, content moderation, bot detection
- Communication: Transactional and service emails. All non-essential emails can be opted out via Settings or one-click unsubscribe.
- Platform improvement: Error tracking (Sentry), product analytics (PostHog), aggregated usage patterns
- Legal compliance: Respond to legal requests, enforce Terms of Service
- CRM sync (optional): When enabled by administrators, email, name, and certification level may be synced to our CRM for onboarding communications. Off by default.
We do not sell, rent, or share your personal information for third-party advertising or marketing.
How We Share Your Information
4a. With Your Consent or Direction
- Public content (profiles, posts, events, listings) visible based on your privacy settings
- Emergency contacts shared only when you explicitly initiate (e.g., safety check-in)
- Location shared only when opted in and only with friends
4b. Service Providers
We use the following third-party services to operate the Platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase (US) | Authentication, database, file storage, real-time chat | All account data, uploaded files, chat messages |
| Vercel (US) | Application hosting | All HTTP traffic routes through Vercel |
| Stripe (US) | Payment processing | Email, name, phone (where provided), billing address, tax id (where a business buyer supplies one), payment amounts |
| Google (US) | OAuth sign-in, push notifications (Firebase Cloud Messaging) | OAuth tokens (sign-in); device push tokens, notification content (FCM) |
| Apple (US) | OAuth sign-in | OAuth token exchange |
| Resend (US) | Transactional email delivery | Email address, email content |
| Shippo (US) | Shipping labels and tracking | Names, street addresses, parcel dimensions |
| Mapbox (US) | Interactive maps, geocoding | Latitude/longitude queries, anonymous map telemetry |
| Sentry (US) | Error monitoring | Error traces (all user text/inputs/media masked) |
| PostHog (US) | Product analytics | Page views, feature usage events, anonymized user identifiers |
| Upstash (US) | Rate limiting | IP addresses, user identifiers (for rate-limit counters only) |
| Cloudflare (US) | Bot prevention (Turnstile CAPTCHA) | IP address, browser challenge signals |
| Go High Level (US) | CRM sync (when enabled) | Email, name |
| Open-Meteo (EU) | Marine weather data for dive sites | Latitude/longitude queries only (no user data) |
| NOAA CO-OPS (US) | Tide predictions for dive sites | Latitude/longitude queries only (no user data) |
4c. Moderation and Administration
Authorized staff (moderators, admins) may access:
- Public profile information for user management
- Reported content for review and moderation decisions
- Business applications for approval/rejection
- Certification evidence for verification
- Safety incidents for response coordination
All admin actions are logged in an audit trail.
Staff cannot access: your password, private profile data (phone, DOB, medical notes), emergency contact details, shipping addresses, or payment card information. These restrictions are enforced through database-level access policies and application-level controls.
4d. Legal and Safety
We may disclose information when required by law, to protect rights or safety, respond to legal process, or in connection with a business transfer (merger, acquisition).
4e. Aggregated Data
We may share anonymized, aggregated data (e.g., popular dive sites, platform statistics) that cannot identify individuals.
Data Security
- Encryption: Sensitive data (emergency contacts, shipping addresses) is encrypted at rest using industry-standard methods. All data is encrypted in transit.
- Password security: Passwords are securely hashed; we never store plaintext passwords
- MFA support: Optional two-factor authentication with hashed backup codes
- Access control: Database-level access policies ensure users can only access their own private data
- Security headers: Content Security Policy, HSTS, and related protections
- Audit logging: Login events and all administrative actions are logged
No system is completely secure. You are responsible for maintaining your account security. Report suspected breaches immediately to security@saltysanctum.com.
Your Rights and Choices
6a. All Users
- Privacy controls: Adjust profile visibility, location sharing, DM permissions, activity status in Settings > Privacy
- Notification preferences: Opt out of email categories or globally in Settings > Notifications. Every email includes a one-click unsubscribe link.
- App permissions: Manage location and notification permissions via your browser settings
- Account data: View and edit your profile, certifications, addresses, and emergency contacts in Settings
6b. California Residents (CCPA/CPRA)
- Right to know what personal information is collected and how it's used
- Right to delete personal information (subject to legal exceptions)
- Right to opt out of “sales” of personal information (we do not sell your personal information)
- Right to non-discrimination for exercising your rights
6c. EU/UK Residents (GDPR)
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure / right to be forgotten (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Right to withdraw consent
Lawful bases for processing: consent (location, optional features), contract performance (account, transactions), legitimate interests (security, platform improvement).
6d. Account Deletion
You can request deletion of your account at any time through your Security Settings. Your account is deactivated immediately, and the request stays reversible for 30 days. After 30 days the account is permanently purged, including removal from third-party services. Section 7 describes what deactivation means, what is destroyed at the purge, and what survives it.
6e. Data Export
You can request a complete export of your personal data at any time through your Security Settings. The export includes your profile information, events, posts, marketplace activity, certifications, and related data in a machine-readable format.
6f. Exercising Your Rights
You can exercise your deletion and data export rights directly through self-service tools in your Security Settings. For any other privacy requests, contact privacy@saltysanctum.com. We verify identity before processing and respond within 30 days (GDPR) or 45 days (CCPA).
Data Retention
We retain your personal data for as long as your account is active and as needed to provide the Services.
7a. Deleting Your Account: the 30-Day Window
When you request deletion, your account is deactivated immediately. Your profile stops appearing to other members and to search, and the account can no longer post, sell, or message. Nothing is destroyed at this point.
The request then stays reversible for 30 days. You can cancel it at any time in that window from your Security Settings, and full access is restored. After 30 days the account is permanently purged, and cancellation is no longer possible.
An administrator removing an account puts it on this same 30-day lifecycle. Only a documented legal or underage case is purged immediately, and each such purge is recorded in our administrative action log with the reason for it.
If your account is subject to an active legal hold, for example a pending safety investigation or a report under our NCII removal policy, it is not purged while that hold is in place. The hold supersedes the 30-day clock, and the purge resumes only once the hold is released.
7b. What Happens at the Purge
Not every record is treated the same way, and the differences are deliberate.
Permanently deleted. Feed posts and feed comments you authored, your profile data, your private profile information, avatars and uploaded photos, saved items, follows, bookmarks, reactions, notifications, login audit rows, first-party analytics events, and your Stripe customer and CRM contact records.
Kept as anonymized tombstones. Some records live inside another member's conversation or contribution history, so destroying them would damage that person's record rather than protect yours. For these the record survives, every reference to you is removed, and you are shown as “Deleted user”: direct and community messages, marketplace reviews, dive-site contributions and other community-submitted site content, blog posts, conversation records, and event announcements.
Retained under a named legal basis. These survive with the reference to you removed, or held for the stated retention window where the law requires the underlying record to remain identifiable:
- Commerce records: payment, order, refund, and dispute records, retained as required by tax and financial regulations.
- Waiver records: signed waiver documents and waiver signatures, retained for legal audit and liability defence.
- Safety and abuse records: safety incident reports and chat and abuse reports, retained for safety purposes and for the establishment or defence of legal claims (GDPR Art. 17(3)(b) and (e)).
Also retained after the purge:
- Anonymized records: We may retain anonymized records of account actions (such as order counts and event attendance), with all personally identifiable information removed.
- Audit logs: Login audit logs are retained for 12 months. Administrative action logs are retained indefinitely.
- Third-party logs: Error logs (Sentry) and server-side application logs are retained per each provider's retention policy.
- Product usage signals: First-party usage signals are kept on a short, class-based schedule and then deleted automatically: search terms for 180 days; screen, feature, and content views for 90 days; and raw map-browsing events for 30 days (only the coarse, anonymous grid-cell totals are kept longer). If you delete your account, your raw usage signals are deleted; only anonymous, aggregate totals that identify no one remain.
Cookies and Tracking
See our Cookie Policy for details. In summary:
- We use essential cookies for authentication
- We use Sentry for error monitoring (with full masking of user content)
- We use PostHog for product analytics. PostHog may set a first-party cookie to distinguish unique visitors. No data is shared with ad networks.
- Mapbox collects anonymous map usage telemetry
- Cloudflare Turnstile is used for bot prevention on authentication forms. It does not use persistent tracking.
- We do not use advertising or social media tracking cookies
Intimate Imagery Shared Without Consent
If intimate imagery of you has been published on Salty Sanctum without your consent, you can request its removal through our removal request form, with no account required. We remove valid requests within 48 hours of receipt. The name and email address you give us on that form are used only to handle the request, confirm the outcome, and evidence that we met our legal obligation; they are visible only to our moderation team and are never disclosed to the person who published the material.
Children's Privacy
The Services are intended for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If we discover that a user is under 18, we will promptly delete their account and associated data. If you believe a minor has provided personal information, contact us at privacy@saltysanctum.com.
International Data Transfers
Your data is primarily processed and stored in the United States through our service providers. For transfers from the EU/UK, we rely on Standard Contractual Clauses and adequacy decisions where available.
Changes to This Policy
We may update this Policy periodically. Material changes will be communicated via email and/or a prominent notice on the Platform. The “Last Updated” date at the top indicates the most recent revision. Continued use after changes constitutes acceptance.
Contact
- Privacy inquiries: privacy@saltysanctum.com
- General support: support@saltysanctum.com
- Mailing address: Being finalized. Until it is published here, written correspondence should go to legal@saltysanctum.com.
