Privacy Policy
1. Who we are
Elenie Marine ("we", "us") operates eleniemarine.com and its business, events, and operations portals from California, USA. Questions and requests about this policy: [email protected].
2. What we collect, and where it comes from
Things you give us directly:
- Account details: email address, password (stored only as a cryptographic hash), display name, and — if you turn on two-step sign-in — an authenticator secret.
- Things you add: your boats, saved places and routes, trips and fuel fills you log, reviews you write, waterway reports you file (which can include a location), and event registrations.
- Photos you choose to upload: business listing photos, Community post photos, your profile photo, and photo evidence attached to waterway reports. Before a photo is stored we remove its hidden camera metadata — including any GPS position, device identifiers and timestamps embedded in the file. Listing, Community and profile photos are reachable by anyone with the link; report photos are private (visible only to our operations team while reviewing the report, never to other users).
- Community (optional — nothing is created until you open it): a short bio and home port, your posts and any photos attached to them, comments, reactions, saves, who you follow and who you block, and reports or appeals you file. Posts are shown to signed-in members by default; you can set your Community profile to public or private from your Community profile page.
- If you sign in with Google, we receive your Google email address and name.
- Business and event details, if you run one: organization name and listing information, team membership, and event content.
Things generated by your use of the service:
- Purchase records for paid placements: what was bought, the amount, the dates, and a Stripe checkout reference. Your card number, expiry, and security code go directly to Stripe and never touch our servers.
- Notifications we send you inside the app, and a security log of sensitive administrative actions.
Things collected automatically:
- Standard server logs: your IP address (and, at our network provider Cloudflare, your browser type), kept up to 90 days for security and debugging.
- Anonymous usage counts (for example, "a place was viewed"). These carry no account identifier — we can see that a feature was used, never who used it.
- Map tiles are loaded by your browser directly from MapTiler and CARTO (OpenStreetMap-based imagery). Like any online map they receive your IP address and which map tiles you are viewing — while the map follows your boat that approximates your position — but never your GPS fix or your account. Tiles you have already viewed or saved for offline use are served from your device.
Your GPS position: live navigation runs on your device — the app never sends your live position to our servers. The one exception is the trip log: when you finish a run and choose to keep it, the app saves a simplified track of that trip (up to 400 points, with speed) to your account so you can see it under Log. You can decline to keep any trip and delete any saved trip at any time; kept trips are deleted with your account.
3. Why we collect it
- To run the service: accounts, maps, saved data, events, business listings.
- Safety features: showing community waterway reports and hazards.
- Content safety: automated screening of new Community posts and comments, with a person making every decision.
- To process payments for paid placements, through Stripe.
- To send transactional email — sign-in links, receipts, event and security notices.
- Security and fraud prevention, and compliance with law.
One purpose per category — we do not reuse your data for unrelated purposes.
4. What we do not do
- We do not sell your personal information, and never have.
- We do not share it with advertisers or ad networks.
- We use one measurement tool, Cloudflare Web Analytics: a small script Cloudflare adds to our pages that sends your IP address, browser type, the page you are viewing, the page you came from and how quickly the page loaded to Cloudflare, so we can see how many people use the site and whether it loads well. It sets no cookie, does not identify you, and is not used to follow you across other sites. We run no advertising pixels, session recording, or fingerprinting.
- We do not buy data about you from anyone, and we are not a data broker.
- We do not build behavioral profiles or make automated decisions with legal effects about you.
If any of this ever changes, this policy will change first, and we will tell you before it takes effect.
5. Who receives data
Service providers who process data on our instructions, to run the service:
- Supabase — our database and sign-in infrastructure (this is where your account data lives).
- Stripe — payment processing. Stripe's handling of your card details is governed by Stripe's privacy policy.
- Cloudflare — network security and content delivery in front of our servers, Cloudflare Web Analytics (the cookieless page-view measurement described in section 4), including the Turnstile check on the sign-in page that tells humans from bots, and Cloudflare R2, which holds our encrypted backups.
- DigitalOcean — the servers the service runs on.
- Anthropic — when you post in Community, the text of your post or comment and any attached photos are sent to Anthropic's API to be screened for clearly unsafe content. The screen can only hold a post for a person to review; it never removes content or penalises an account on its own. It never receives your name, email or account.
- MapTiler and CARTO — map tiles (see section 2).
- Google — (a) Google Workspace delivers our sign-in codes and confirmation emails; (b) when you add or search for a place, the place name or search text and the map location you submit — never your account or IP — are sent to Google Places and Yelp to look up business details; (c) if you choose Continue with Google, Google knows you signed in here.
Beyond that: content you post publicly (reviews, waterway reports, event results, business listings) is visible to other users of the service — that is its purpose. We may disclose information if the law requires it, and if the business is ever sold or merged, user data would transfer with it under this policy's protections.
6. Cookies and signals
We use two first-party mechanisms, both strictly necessary to keep you signed in, and one bot check:
__Host-helm_session— a sign-in cookie on the business/event/operations portals; HttpOnly and Secure; it lasts at most 8 hours (or until you sign out).- Local storage on eleniemarine.com holding your sign-in token, your preferences (theme, GPS setting), a trip in progress until you save or discard it, and map tiles and app files cached for offline use. None of this is sent to anyone.
- Cloudflare Turnstile — a bot check on sign-up and sign-in that runs in your browser and sends your IP address to Cloudflare to verify the result; it sets no tracking cookie.
That is the complete list. There are no analytics cookies, no advertising cookies, and no third-party cookies of any kind — which is why you don't see a cookie banner here.
Do Not Track and Global Privacy Control: we do not track you across other websites, for anyone, regardless of whether your browser sends these signals. There is nothing to opt out of; browsers sending GPC are honored by default because the behavior it opts out of does not exist here.
7. How long we keep things
- Your account and everything in it — for as long as you keep the account. Deleting your account removes your boats, saved places, routes, trips and fuel log, Community profile, posts, comments, reactions and follows immediately. We keep one record that the account existed and was deleted — your email address, account id, date and who requested it — so we can answer later questions and detect abuse; it is never shown to other users and is kept as described below.
- Reviews and waterway reports — safety information keeps its value, so when you delete your account the content may be kept but is disconnected from you (anonymized).
- Photos — follow what they belong to: listing photos until the business removes them (or we do, for moderation), report photos with the report (report photos are also deleted when you delete your account). Copies held by our content-delivery network or by browsers that already loaded a photo can persist after removal — up to 1 day for profile photos and up to a year for other photos.
- Community posts and comments you delete — their photos are removed at once; the text is cleared 30 days later.
- Notifications — kept 12 months.
- Purchase records — kept 7 years, as tax and accounting law requires.
- Server logs — kept up to 90 days for security and debugging.
- The security log — staff actions and a record of each account deletion — is append-only, kept for at least 3 years and reviewed for deletion by hand after that.
Deleted data leaves our backups on a fixed schedule rather than being edited out: daily backups are kept 35 days, a monthly archive up to 400 days, and photo backups 60 days. Backups are encrypted to a key held offline, locked against editing, and used only to recover from data loss — never to restore a deleted account.
8. Your choices and rights
We extend these to every user, in every state, voluntarily — not only where a law requires it:
- Access and correction — your profile, boats, saved places, routes, trips, reviews and Community posts are visible and editable in the app under Me; to change your sign-in email or withdraw a waterway report you filed, write to [email protected].
- Deletion — delete your account yourself: Me → Security → Delete my account. It works immediately and does not require contacting anyone. If you own a business listing or an event, transfer or close it first. (Purchase records and the security log are retained as described in section 7.)
- Export — download a copy of your data under Me → Security, or email us at [email protected].
- Marketing email — we currently send transactional email only. If we ever send marketing email, it will have a working unsubscribe link and we will honor it promptly.
We verify requests through your account sign-in (including two-step verification) — we will never ask you to email us a photo of your ID. We aim to answer any emailed request within 30 days. If we decline a request, we will say why, and you can ask us to take a second look.
9. Security
All traffic is encrypted in transit. Passwords are stored only as hashes. Two-step sign-in is available to everyone and required for privileged accounts. Access to data is role-based and enforced on our servers, sensitive administrative actions require re-verification and are recorded in an append-only log, and card data is isolated to Stripe entirely. No system is perfectly secure and we do not promise otherwise — but minimizing what we collect in the first place is the biggest protection we can give you.
10. Children and teens
Accounts are for people 13 and older; members aged 13–17 use the service with a parent or guardian's permission (Terms, section 2). The service is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13 — if we learn we have, we delete the account and its data. We collect no birthdate and treat every member to the same minimal-collection standard; there is no advertising targeting of anyone, minors included.
Protections that apply to every member matter most for teens, so to state them plainly: your position is never attached to what you post in Community; waterway reports carry your approximate position (rounded to about 100 m), as the report sheet says, and trips you keep store their track in your own log; there is no private messaging on the platform; and the content standard is family-safe everywhere — see the Community Rules.
Minors' deletion rights: California residents under 18 may remove content they posted (delete any of your own posts or comments in the app, or the whole account under Me → Security) — and we will help on request at [email protected]. Event organizers may enter participant names (for example, race results) that include minors — organizers are responsible for having the right to do so, and a parent or guardian can ask us to remove a minor's name from displayed results at the same address.
11. Changes to this policy
When we make a material change, we will announce it with an in-app notification (and by email where appropriate) before it takes effect, and this page will always state its version and effective date. Prior versions are archived and available on request.