Legal

Privacy Policy

What WakeSurf collects, why, who it is shared with and what you can ask us to do about it.

Last updated 2 September 2026.

1. Who is responsible for your data

The data controller for the personal data described here is the operator of the WakeSurf MAP platform (contact: info@wakesurfmap.com). Company registration details are available on request at info@wakesurfmap.com and will be published here.

For anything in this policy, write to info@wakesurfmap.com or use the contact page. No data protection officer has been appointed.

2. What we collect

We only hold what the product actually asks for. Grouped by where it comes from:

  • Account: your email address, display name, first and last name, and an avatar image if you upload one.
  • Rider profile, all optional: date of birth, country, phone number, the languages you speak, your preferred language, height in centimetres, weight in kilograms, riding level, years of wakesurf experience, preferred riding styles, whether you bring your own board and its brand, size and type, and free-text training notes.
  • Bookings: which location and coach, the date and time, the status of the booking, and any note you add for the club or coach.
  • Payments: the status of the payment and the identifiers Stripe gives us for the checkout session and the payment. Card numbers are entered on Stripe's own pages and never reach our servers.
  • Payout details, for coaches and clubs only: account holder name, IBAN or account number, bank name, bank country, a tax or registration identifier, and any note you add. Stored so that payouts can be made by bank transfer.
  • Messages you send to a coach through the platform, and reviews you publish.
  • Support: the contact form, support tickets, and the text you type into the AI concierge or the AI trip planner, including the reply generated for you.
  • Technical: the country and approximate coordinates your network provider attaches to the request, used to centre the map on your first visit. The code does not store them. Club pages also count visits: the count is made from a hash of your network address and browser that changes every day, cannot be turned back into either, and is kept only as a number per day - no cookie is set and no browsing profile exists.
  • Clients recorded by a coach or club: when a coach or club records a session for somebody who is not on the platform, they may store that person's name and one contact line (for example a phone number or email). See "Clients recorded outside the platform" below.

3. Why we use it

  • To create and run your account and let you sign in.
  • To take a booking, collect payment for it, and cancel or refund it.
  • To give the club or coach the information they need to prepare a safe, correctly set up session.
  • To send you booking notifications and answer your support requests.
  • To moderate reviews and listings, and to keep the platform free of fraud and abuse.
  • To meet accounting and tax obligations that apply to the operator.

4. The grounds we rely on

We rely on the grounds set out below.

  • Performance of a contract, for your account, your bookings and payment.
  • Legal obligation, for accounting and tax records.
  • Legitimate interests, for security, fraud prevention, support and improving the service.
  • Consent, where consent is the right ground, for example if optional analytics are ever introduced.

5. What a coach or club can see about you

When you book, the coach who is teaching you receives a fixed, limited set of profile fields. The list is enforced in the database query, not only in the interface.

A coach sees: your name, your preferred language, riding level, years of experience, preferred styles, height, weight, whether you have your own board and its brand, size and type, your training notes, and any note you attached to the booking.

A coach does not see: your email address, your phone number, your date of birth, your country, your full list of languages or your plan. Platform staff can see more where support or moderation requires it.

6. Clients recorded outside the platform

A coach or club can record a session for a client who has no account here - a name and one contact line, entered by them, so their calendar reflects reality. If that is you: the coach or club who entered your details is responsible for them, the platform stores them only so that their calendar works, they are visible to that coach or club and to platform administrators, and they are never used for marketing or shared further.

Your coach can also send you a one-off invitation email to join the platform; joining is optional and nothing changes if you ignore it. To have recorded details corrected or removed, ask your coach or club, or write to info@wakesurfmap.com.

7. Payments

Payments are processed by Stripe. You enter your card details on Stripe's checkout pages under Stripe's own privacy terms, and we receive back the payment status and Stripe's identifiers. We do not store card numbers.

When a booking is refunded, the money is returned to the card that paid, through Stripe.

8. Who we share data with

We use the following providers. Each receives only what it needs for its part of the service.

  • Supabase: the database, sign-in, file storage and the API behind the site. Our database is hosted in the European Union (AWS eu-west-1, Ireland).
  • Stripe: card payments, checkout and refunds.
  • Resend: transactional email, such as booking and support notifications. Email is only sent when the operator has switched it on.
  • Google Calendar: only for coaches who choose to connect a calendar. We store the connected Google account address and calendar identifier, and we read and write the calendar events for their sessions.
  • Mapbox: map tiles, search and geocoding. Your browser contacts Mapbox directly when a map is displayed.
  • OpenWeather: forecasts for a location. Only the location's coordinates are sent, never anything about you.
  • The Lovable AI gateway, which routes to Google and OpenAI models: the text you type into the AI trip planner or the support concierge, together with public location data, is sent for a reply. Do not type anything into those boxes you would not want processed by an AI provider.
  • Wikimedia Commons, Openverse and Mapillary: sources of location photography. No personal data is sent to them.
  • Public authorities, where the law requires it.

9. Where your data is processed

The providers listed above operate internationally, and several are established outside the European Economic Area. Personal data may therefore be transferred outside your country.

Our database is hosted in the European Union (AWS eu-west-1, Ireland); the application is served through a global edge network. Where a provider processes data outside the European Economic Area, the transfer relies on that provider's legal safeguards, such as the European Commission's standard contractual clauses.

10. Cookies and browser storage

The site uses a small number of strictly necessary cookies and two browser storage entries. There are no analytics, advertising or tracking cookies at the time of writing. The Cookie Policy lists every one of them by name.

11. How long we keep data

We keep your personal data for as long as your account is active, and afterwards for as long as the law requires (for example, accounting rules require transaction records to be kept for several years).

12. Your rights

Subject to the law that applies to you, you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything that is wrong, which you can also do yourself in your profile;
  • delete your account and the data attached to it, except records we must keep;
  • export your data in a portable format;
  • restrict or object to a particular use;
  • withdraw consent where the use was based on consent.

13. Complaints

If you think we have handled your data badly, tell us first through the contact page. You also have the right to complain to a supervisory authority: the data protection authority in your country of residence; the authority for the platform operator is the Data State Inspectorate of Latvia (Datu valsts inspekcija).

14. Children

The platform is not designed for children, and the minimum age for holding an account is 18. Where a minor rides, the booking is expected to be made and supervised by a parent or guardian.

15. Security

Access to the database is controlled by row level security rules, sign-in sessions are held in cookies that JavaScript cannot read, and payout bank details are masked everywhere except to the owner and to platform administrators. No system is perfectly secure, and we make no certification claim of any kind.

16. Changes to this policy

When this text is changed, the date at the top will change with it. If a change materially affects you, we will say so on the site.

17. Contact

Questions and requests: use the contact page, or write to info@wakesurfmap.com.