PURESURFERSLIVE SURF ATLAS

FOR THE LOVE OF IT / CALIFORNIA

Privacy policy

What PureSurfers collects, what stays in your browser, which services receive information, and how to make a privacy or account request.

Effective date: September 29, 2026 · Service: PureSurfers · Contact: contact@puresurfers.com

Your surf check should not require handing over your life story.

You can browse the map and read Surf Insights without an account. Some information is still processed when a website loads. This policy explains the core PureSurfers service, including optional accounts, favorites, alerts and email correspondence.

At a glance: Guest field notes and personal map edits stay in this browser unless you deliberately export or share them. Signed-in favorites and account alerts use Supabase. Hosting, map, email and notification services process data needed to deliver their features. Signing out does not delete an account or a local journal.

1. Information involved

Ordinary site visits

Our web host and security systems can record an IP address, date and time, requested URL and query string, response status, browser/device identification and referring page. We use access statistics and logs to understand usage, troubleshoot failures and protect the service. A server request is not automatically a unique person or a verified identity.

Information saved on your device

Guest favorites, field-journal notes, session records, saved plans, display choices and personal pin corrections use browser storage. The core application does not silently upload journal text or personal pin edits to your account. Other people using the same browser profile may be able to read these records. A journal export is readable by anyone who receives it.

Optional sign-in and account features

Requesting a sign-in code sends your email address, and a CAPTCHA response when enabled, to Supabase Auth. An unconfirmed sign-in request and associated security records may exist before you finish verification. After verification, account records can include your user ID, verified email, timestamps, favorite spot IDs, sync revisions and separate email-consent records. The browser stores session credentials to keep you signed in. We do not ask for your database password or your email-account password.

Optional alerts

Account alerts can store selected spots, thresholds, quiet hours, channel preferences, consent records, delivery history, account inbox entries and linked device details. Web Push subscriptions include a provider endpoint and encryption-key material. An older device-based watch, when used, is separate from the signed-in account. A notification may show a spot name on a lock screen, depending on your device settings.

Location and messages you choose to provide

A location-based control can request browser permission to help center the map. Regional forecast requests use catalogue sampling locations, not a continuous GPS track of you. Loading a map area still tells its tile provider which area is requested. Messages you email us include the address, text and attachments you choose to send. Do not include secrets or unnecessary sensitive information.

2. How the information is used

We use this information to display and maintain the atlas, verify sign-in, synchronize chosen favorites, operate requested alerts, remember settings, respond to correspondence and privacy requests, prevent abuse, investigate errors and understand service usage.

Login codes are service messages. They are not permission to send product updates. Product-update email preferences, alert email consent and browser notification permission are separate choices. Creating an account or sending feedback does not automatically opt you into all of them.

3. Who can receive information

The operator and authorized service administrators can access information needed to operate and support the service. It is not made public merely because you create an account. We use the following categories of service providers:

ServiceInformation and purpose
Bluehost / web hostingSite requests, access logs, files and operational data used to deliver and protect the website.
SupabaseSign-in requests, authentication/session information, cloud favorites, consent and account-alert data. Edge Functions may process alert delivery.
Email and browser push providersDelivery addresses or subscription endpoints and message-delivery information. Email providers process message content; Web Push uses encrypted payload delivery. These providers may retain their own logs.
Map tiles: Esri/ArcGIS, OpenStreetMap and CARTOThe map style you select determines which providers receive browser requests, including IP/network information and the tiles needed for the viewed area.
Open-Meteo, NOAA and other identified observation services; TomTom trafficRequests for regional data or tiles. Many are relayed through our server; some observation requests may go directly from your browser, depending on the feature. Direct requests expose ordinary network metadata to that provider.
jsDelivr and optional hCaptchaDelivery of account-support scripts, or anti-abuse challenges when configured. Direct requests may include IP/network and browser information; CAPTCHA processing also uses challenge information.
Camera viewers and other external linksFollowing a link visits another operator’s service, which applies its own practices. PureSurfers does not control that site or its cookies.

Some providers may recognize a browser across other sites or over time under their own policies. We do not control their independent practices. Information may be processed in the United States or other locations where a provider operates. We may disclose information when legally required, to protect rights or security, or with your specific direction; this is not permission to publish private field notes.

The core PureSurfers application is not configured to sell personal information or use it for cross-context behavioral advertising. It does not include an advertising pixel or ad-profile system. A new advertising, analytics or partner integration would require reviewing this notice and the relevant controls before activation.

4. Cookies, local storage and service workers

PureSurfers uses localStorage and sessionStorage for app preferences, guest records, authentication and temporary synchronization state. Its service worker can cache public app-shell files and deliver notifications you enable. Browser storage is not the same as an account backup. Blocking or clearing it can remove local notes and settings and sign you out.

The current core application does not add an advertising cookie. That does not mean every supporting service is cookie-free: hosting/security services, CAPTCHA, map providers and external pages may have their own cookies or storage. This page does not itself install optional analytics or request marketing consent.

Export important journal data before clearing anything. Signing out is safer on a shared device, but it is not a command to erase the browser’s guest journal. Use your browser’s site-data controls deliberately and keep exported files private.

5. California Do Not Track disclosures

The core application does not currently change its essential requests or storage behavior in response to the browser’s legacy Do Not Track signal. It is not configured for cross-site advertising profiles. Third-party services involved in loading a feature may collect information across services or over time, as described above.

Global Privacy Control is different from Do Not Track. No sale/sharing opt-out workflow is represented as active here because the core application is not configured for sale or cross-context behavioral advertising. That is not a promise to ignore rights or signals required by applicable law. A change to tracking or advertising would require the appropriate technical controls as well as an updated notice.

6. Retention and security

Local records remain until you remove them, clear browser storage or the browser removes them. Active account data is retained while the account is maintained and as needed to provide the requested features. Alert histories and operational caches are bounded separately; deleting a visible alert is not a request to erase every delivery log.

We handle verified deletion requests for active account records, subject to information that must be retained for security, legal obligations or resolving a dispute. Backup copies, provider logs, sent email and correspondence can persist separately and may expire on different schedules. We do not promise an exact deletion deadline for every processor or backup that has not been verified. Contact us for information about the records relevant to your request.

The service uses HTTPS and access controls, and server credentials are kept out of public client code. No system or transmission is guaranteed perfectly secure. Do not store passwords, financial details or other sensitive information in field notes, and do not send us sign-in codes or keys.

7. Your choices and requests

You may browse without signing in. Use My account for product-email preferences and sign-out. Use My alerts to change or pause account rules, stop alert email or remove a linked device. Your browser/operating system separately controls notification and location permission.

Account deletion is currently owner-assisted. Email contact@puresurfers.com to request access, a copy, correction or deletion, or to ask a privacy question. Write from the registered address when possible; we may need to verify control before acting. The rights and exceptions available to you depend on applicable law and your location.

An account deletion does not automatically clear local field notes, remove copies you exported, recall delivered messages or delete an independent legacy device watch. Tell us which records or devices are involved. We do not ask for your password to process a request.

8. Children

PureSurfers is a general-audience resource, not a service directed to children under 13. We do not knowingly seek their personal information. A parent or guardian who believes a child has supplied account information should contact us so we can investigate and arrange appropriate removal. Reading a guide is not a substitute for adult supervision or suitable instruction in the water.

9. Changes and contact

We will post revisions here and update the effective date. When a material change affects account information or requires consent, we will provide an appropriate additional notice or request. Check this page when choosing new optional features.

Responsible service: PureSurfers. Privacy contact: contact@puresurfers.com. See the contact page for request guidance.