ScubaTrail — Privacy Policy
Version 1.0 · Effective date: 2026-07-27
Data controller (dataansvarlig): JH Compliance v/ Jan Hjelvang, CVR 21733296, Denmark
Contact: info@jh-compliance.dk · +45 52 50 30 20
Supervisory authority: Datatilsynet (Danish Data Protection Agency)
1. Who we are
ScubaTrail is a personal dive log plus an open database of dive sites, dive centers and
marine species, available on web and mobile. It is operated by JH Compliance v/ Jan
Hjelvang (CVR 21733296), Denmark, the data controller. This policy explains what personal
data we process, why, on what legal basis, and the rights you have. We operate under the EU
GDPR and Danish data protection law, and follow an EU-data-sovereignty principle: data is
hosted in the EU and we do not use US advertising or analytics trackers.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account | Email, display name, password (stored only as an argon2 hash — never in clear text), certifications, profile | You |
| Dive log (pseudonymous personal data) | Dives, dates, depth/duration, sites, gas, buddies, ratings, notes, dive-computer profiles, gear | You / your dive computer (via Bluetooth) |
| Photos | Dive photos and avatar. GPS/EXIF metadata is stripped and images are re-encoded on upload; stored in EU object storage | You |
| Marine observations | Species you tag on your dives | You |
| Payment | Subscription status, plan, Stripe customer/subscription IDs. Card details are handled solely by Stripe and never reach ScubaTrail servers | You / Stripe |
| Community | Forum posts, reactions (only where you choose to participate) | You |
| Technical / security | IP address (for rate-limiting and abuse prevention), an essential session cookie (httpOnly, Secure, SameSite=Strict) | Automatic |
We do not use advertising, we do not sell personal data, and we do not embed
third-party tracking. Species photos are self-hosted, so your browser is not exposed to
external image hosts.
3. Why we use it & legal basis (GDPR Art. 6)
| Processing | Legal basis |
|---|---|
| Providing your personal log and account (pseudonymous, linked to your account) | Contract — Art. 6(1)(b) |
| Aggregated, pseudonymous platform statistics (e.g. counts, superlatives — never your name) | Legitimate interest — Art. 6(1)(f) (LIA on file; right to object applies) |
| Publishing a dive, profile or forum post you mark public | Consent — via the is_public action + your chosen display name |
| Security, rate-limiting, fraud/abuse prevention (IP) | Legitimate interest — Art. 6(1)(f) |
| Processing payments and keeping accounting records | Contract — Art. 6(1)(b) + legal obligation — Art. 6(1)© |
| Anonymous dive-site contributions | Not personal data (GDPR Recital 26) — stored with no user link; see §11 |
4. Sharing & processors
We share personal data only with processors (“databehandlere”) acting on our documented
instructions under a data processing agreement (DPA):
| Processor | Role | Location |
|---|---|---|
| Hetzner | Infrastructure, database and object-storage hosting | Germany (EU) |
| Mailjet | Transactional email (account/verification) | EU |
| Simply.com | Domain registration & DNS | Denmark (EU) |
| Stripe | Payment processing (checkout, subscriptions, card data) | EU/US (see §5) |
We never sell your data or share it for advertising.
App stores (Apple). When you download the iOS app, Apple processes your App Store / Apple
ID data as an independent controller under Apple’s own Privacy Policy
— Apple is not our processor. Because subscriptions are sold on the web (not via in-app
purchase), we do not route any payment through Apple. If we later enable push notifications,
Apple’s Push Notification service (APNs) would act as a processor for delivering those messages,
and we will update this policy accordingly.
5. International transfers
Our core processing stays within the EU/EEA (Hetzner in Germany, Mailjet in the EU, Simply.com
in Denmark). Where a processor (Stripe) may transfer data outside the EEA, it is covered by EU
Standard Contractual Clauses and/or an applicable adequacy decision.
6. Retention
We keep account and dive-log data while your account is active. On deletion (see §7) we
remove it, subject to short rotation windows for encrypted backups and any accounting
records we are legally required to keep. Aggregated/anonymous data is not linked to you
and is retained indefinitely.
7. Your rights
You have the right to access, rectify, erase, restrict, port, and object to processing,
and to withdraw consent. In particular:
- Access & portability: export your own data in a machine-readable format (in-app: Account → Export).
- Erasure (“right to be forgotten”): delete your account and log (in-app: Account → Delete account). Your confirmed species observations are either deleted or anonymised (with no re-identification) so the shared site database is not corrupted; the applicable policy is documented.
- Object (Art. 21): opt out of having your dives counted in platform statistics.
- Withdraw consent: make public dives/profile private again at any time.
To exercise any right, use the in-app controls or email info@jh-compliance.dk. You may
also lodge a complaint with Datatilsynet (www.datatilsynet.dk).
8. Security
We protect your data with: TLS/HTTPS everywhere (HSTS enabled), certificate pinning in the
mobile app, argon2 password hashing, httpOnly/Secure/SameSite session cookies, EXIF/GPS
stripping and re-encoding of uploaded images, rate-limiting, least-privilege database roles,
and encryption of data at rest on our EU hosting. No method is 100% secure, but we work to
industry standards.
9. Cookies
We use a single strictly necessary session cookie to keep you logged in. We do not
use analytics, advertising or cross-site tracking cookies, so no cookie-consent banner is
required for tracking purposes.
10. Public content
Dives, profile fields or forum posts you choose to make public are visible to others under
your chosen display name. Remember a dive log can reveal travel patterns — you control what
is public per item.
11. Anonymous dive-site contributions
When you add or enrich a dive site, that contribution is stored anonymously (source='user',
no user or batch reference) and may be published under the ODbL. Because there is no link back
to you, it is not personal data and cannot be individually withdrawn (GDPR Recital 26). Your
personal dive log is separate and remains private/yours.
12. Children
ScubaTrail is not directed at children under 13 (the age of digital consent in Denmark) and we
do not knowingly collect their data.
13. Changes
We will post changes here with a new version and effective date and, for material changes,
notify you in-app or by email.
14. App Store “App Privacy” summary
For Apple’s privacy labels, the data we use is limited to: account (email, name), user content
(dives, photos with location stripped, forum posts), and purchases (via Stripe), plus
diagnostics/identifiers used only for app functionality and security — not for tracking
across apps or for advertising.
15. Language
This policy is written in English, which is the authoritative and binding version. We may
provide translations (e.g. Danish) for convenience; in case of conflict, the English version
prevails — without prejudice to mandatory local rights, which apply regardless of language.
16. Contact
JH Compliance v/ Jan Hjelvang · CVR 21733296 · info@jh-compliance.dk · +45 52 50 30 20 · Denmark