Elenie Marine

Privacy Policy

Version 1.3 · Effective 2026-09-10 · changed: trip log, providers, retention
The short version: we collect what the service needs to work and nothing else. Your live GPS position never leaves your device; trips you choose to keep are saved to your account. We run no advertising and no cross-site trackers; the one measurement tool we use is Cloudflare Web Analytics, described in section 4. We never sell your information. Card details go to Stripe, never to us.

1. Who we are

Elenie Marine ("we", "us") operates eleniemarine.com and its business, events, and operations portals from California, USA. Questions and requests about this policy: [email protected].

2. What we collect, and where it comes from

Things you give us directly:

Things generated by your use of the service:

Things collected automatically:

Your GPS position: live navigation runs on your device — the app never sends your live position to our servers. The one exception is the trip log: when you finish a run and choose to keep it, the app saves a simplified track of that trip (up to 400 points, with speed) to your account so you can see it under Log. You can decline to keep any trip and delete any saved trip at any time; kept trips are deleted with your account.

3. Why we collect it

One purpose per category — we do not reuse your data for unrelated purposes.

4. What we do not do

If any of this ever changes, this policy will change first, and we will tell you before it takes effect.

5. Who receives data

Service providers who process data on our instructions, to run the service:

Beyond that: content you post publicly (reviews, waterway reports, event results, business listings) is visible to other users of the service — that is its purpose. We may disclose information if the law requires it, and if the business is ever sold or merged, user data would transfer with it under this policy's protections.

6. Cookies and signals

We use two first-party mechanisms, both strictly necessary to keep you signed in, and one bot check:

That is the complete list. There are no analytics cookies, no advertising cookies, and no third-party cookies of any kind — which is why you don't see a cookie banner here.

Do Not Track and Global Privacy Control: we do not track you across other websites, for anyone, regardless of whether your browser sends these signals. There is nothing to opt out of; browsers sending GPC are honored by default because the behavior it opts out of does not exist here.

7. How long we keep things

Deleted data leaves our backups on a fixed schedule rather than being edited out: daily backups are kept 35 days, a monthly archive up to 400 days, and photo backups 60 days. Backups are encrypted to a key held offline, locked against editing, and used only to recover from data loss — never to restore a deleted account.

8. Your choices and rights

We extend these to every user, in every state, voluntarily — not only where a law requires it:

We verify requests through your account sign-in (including two-step verification) — we will never ask you to email us a photo of your ID. We aim to answer any emailed request within 30 days. If we decline a request, we will say why, and you can ask us to take a second look.

9. Security

All traffic is encrypted in transit. Passwords are stored only as hashes. Two-step sign-in is available to everyone and required for privileged accounts. Access to data is role-based and enforced on our servers, sensitive administrative actions require re-verification and are recorded in an append-only log, and card data is isolated to Stripe entirely. No system is perfectly secure and we do not promise otherwise — but minimizing what we collect in the first place is the biggest protection we can give you.

10. Children and teens

Accounts are for people 13 and older; members aged 13–17 use the service with a parent or guardian's permission (Terms, section 2). The service is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13 — if we learn we have, we delete the account and its data. We collect no birthdate and treat every member to the same minimal-collection standard; there is no advertising targeting of anyone, minors included.

Protections that apply to every member matter most for teens, so to state them plainly: your position is never attached to what you post in Community; waterway reports carry your approximate position (rounded to about 100 m), as the report sheet says, and trips you keep store their track in your own log; there is no private messaging on the platform; and the content standard is family-safe everywhere — see the Community Rules.

Minors' deletion rights: California residents under 18 may remove content they posted (delete any of your own posts or comments in the app, or the whole account under Me → Security) — and we will help on request at [email protected]. Event organizers may enter participant names (for example, race results) that include minors — organizers are responsible for having the right to do so, and a parent or guardian can ask us to remove a minor's name from displayed results at the same address.

11. Changes to this policy

When we make a material change, we will announce it with an in-app notification (and by email where appropriate) before it takes effect, and this page will always state its version and effective date. Prior versions are archived and available on request.