WAVESSO PRIVACY POLICY

Effective date: 24 August 2026

1. Introduction

This Privacy Policy explains how personal data is processed in connection with Wavesso, a web-based application available at https://wavesso.com.

Wavesso is a digital service designed to help users analyse surfing conditions, monitor surf spots and plan surfing trips.

This Policy applies to both Free Plan and Paid Plan users.

2. Data Controller

The controller of your personal data is:

Jacek Knaur Analityka
ul. Topazowa 27
62-081 Baranowo
Poland
Polish Tax Identification Number (NIP): 7792579722
email: [email protected]
phone: +48 572 848 969

referred to as “Wavesso”, “we”, “us”, “our” or the “Controller”.

For privacy-related matters, contact [email protected].

3. Personal data we process

3.1. Account data

When you create or use an Account, we may process:

Passwords are handled through Supabase Auth. Wavesso does not store your password in plain text.

3.2. Google Sign-In

You may create an Account or sign in using Google.

When you do this, we receive information required to authenticate you, including your email address and an identifier associated with your Google account. Depending on the OAuth scopes enabled, Google may also technically provide basic profile information.

We do not receive your Google Account password.

4. Surfing preferences

Wavesso stores information associated with your Account that is required to personalise results and monitor conditions, including:

We use this information to adapt Forecast results and alerts to your settings.

Wavesso does not retain a history of your searches or planned trips.

5. Address and location information

5.1. No automatic location tracking

Wavesso does not access your device's live location in the background or through browser geolocation functionality and does not track your movements.

5.2. Address or location entered by the User

You may voluntarily enter an address, city, town or other approximate location to use as a starting point for a calculation, for example when calculating distances to Surf Spots, airports or other locations.

The location:

Wavesso uses the Geoapify EU API to geocode locations entered by Users and is configured to use Geoapify's European API endpoint. The location query may be transmitted to Geoapify to the extent necessary to convert it into geographic coordinates.

Depending on how the request is technically sent, Geoapify may also process technical request metadata such as an IP address or HTTP headers. Wavesso does not use this information for advertising or marketing profiling.

Wavesso may use Google Maps for displaying maps or other mapping functionality; however, geocoding of locations entered by Users is performed through the Geoapify EU API and not through Google Maps.

6. Surf forecasts

Wavesso uses data sources including:

To obtain a Forecast, Wavesso may send information required for the request, such as Surf Spot coordinates, requested time period and Forecast parameters.

We do not intentionally send these Forecast providers your email address, username, Wavesso Account ID or payment information for the purpose of generating a Forecast.

A location entered by the User is not sent to Forecast providers unless it corresponds to geographic coordinates required to perform a calculation or Forecast expressly requested by the User.

7. Service emails and alerts

Wavesso may send emails required to provide the Service, including:

We use Zoho Mail for email communications.

Daily Surf Spot alerts are a feature of Wavesso and are not an advertising newsletter.

Wavesso does not currently send marketing newsletters or promotional email campaigns.

8. Payments and Stripe

Paid Plan payments are processed using Stripe Checkout.

When making a payment, you may provide Stripe with information including:

Wavesso does not receive or store your full payment card number.

Our Supabase database may store:

Stripe may act as an independent controller for certain processing, including fraud prevention, security and compliance with financial or regulatory obligations.

9. Technical information and logs

Wavesso does not use an IP address as a standard profile field in its core application database.

Our infrastructure providers may, however, automatically process connection and request information including:

Supabase Auth maintains authentication event logs, such as Account creation, login, logout, password reset, email verification and token refresh.

Technical information is used to provide the Service, diagnose errors, protect Accounts and infrastructure, prevent abuse, detect unauthorised access and maintain Service stability. We do not use it for behavioural advertising.

10. Purposes and legal bases under the GDPR

Where the EU GDPR applies:

Purpose Legal basis
creating and maintaining your Account performance of a contract or pre-contractual steps at your request – Art. 6(1)(b) GDPR
authentication and login performance of a contract – Art. 6(1)(b)
storing surfing preferences and monitored Surf Spots performance of a contract – Art. 6(1)(b)
personalising results performance of a contract – Art. 6(1)(b)
temporarily processing and geocoding a location entered by you performance of a contract or action at your request – Art. 6(1)(b)
sending requested Surf Spot alerts performance of a contract – Art. 6(1)(b)
managing Subscriptions and payments performance of a contract – Art. 6(1)(b)
accounting and tax records compliance with a legal obligation – Art. 6(1)(c)
security, abuse prevention and technical logging legitimate interests – Art. 6(1)(f)
error investigation and Service stability legitimate interests – Art. 6(1)(f)
responding to requests and complaints contract, legal obligation or legitimate interest depending on the request
establishing, exercising or defending legal claims legitimate interests – Art. 6(1)(f)
complying with applicable law Art. 6(1)(c)
future optional technologies that legally require consent consent – Art. 6(1)(a)

Equivalent legal bases are relied upon where the UK GDPR applies.

Where processing is based on consent, you may withdraw consent at any time.

11. Service providers and recipients

Supabase

Supabase provides authentication, Account management, PostgreSQL database services and authentication/technical logs. Wavesso's primary Supabase project data is hosted in London, United Kingdom (eu-west-2). We do not currently use Supabase Storage for user-uploaded files.

Cloudflare

Cloudflare provides infrastructure services including hosting/edge functionality, DNS, routing, security and abuse protection, and may process technical connection information.

Render

Render hosts parts of the Wavesso backend/API and may process application logs and request information.

Zoho Mail

Zoho Mail is used for Account-related email, password resets, Surf Spot alerts and support communications.

Stripe

Stripe provides payment processing and Stripe Checkout.

Google

Google is used as a Google Sign-In provider and may be used for map display functionality. Geocoding of locations entered by Users is not performed by Google Maps.

Geoapify

Geoapify (KEPTAGO LTD) is used to geocode locations entered by Users. Wavesso uses the European Geoapify EU API endpoint (api-eu.geoapify.com). Geoapify may receive the location query and technical metadata necessary to process the API request.

Open-Meteo and Copernicus Marine

These services provide meteorological and oceanographic information used by Wavesso.

Other recipients

We may also disclose personal data where necessary to professional advisers, accounting providers, public authorities or courts where legally required, or an acquiring entity in connection with a lawful reorganisation or business transfer.

We do not sell our user database or Users' personal data.

12. International data transfers

Some Wavesso providers operate globally, which means personal data may be processed outside the European Economic Area.

Wavesso's primary Supabase database is currently located in London, United Kingdom.

Geocoding of locations entered by Users is performed using the Geoapify EU API. Wavesso is configured to use Geoapify's European endpoint. According to Geoapify's current Data Processing Agreement, API requests made through this endpoint are processed within EU infrastructure.

Where data is transferred to a country covered by an adequacy decision, we may rely on that decision. For other transfers, safeguards may include European Commission Standard Contractual Clauses, relevant UK transfer mechanisms and, for eligible recipients, the EU-U.S. Data Privacy Framework.

13. Data retention

Account information

Your email address, username, Plan, surfing preferences and monitored Surf Spots are generally retained while your Account remains active. After a valid deletion request, information is deleted or anonymised unless retention is legally required.

Location entered for calculations

A location entered for a calculation is not stored in the Wavesso database and is not retained as location history. Geoapify may process and retain request data under its own processing and retention terms.

Payment and accounting records

Transaction records required for tax, accounting, payment or legal-claims purposes are retained for the applicable statutory period.

Technical and security logs

Logs directly under our control are retained only as long as reasonably required for diagnostics and security and normally for no more than 90 days, unless longer retention is necessary for a security incident, legal claim or legal obligation.

Support communications

Support communications may be retained for as long as necessary to resolve the matter and for an appropriate claims period thereafter.

Backups

After Account deletion, certain information may remain temporarily in secured backups. Our intended maximum backup lifecycle is 30 days, after which deleted information should be overwritten or removed in the ordinary backup cycle unless continued retention is legally required.

14. Account deletion

Wavesso does not currently provide self-service Account deletion within the application.

You may request deletion by emailing [email protected].

We may ask for information reasonably necessary to verify that the request is made by the Account holder. Deletion does not require us to erase information we must retain for tax, accounting, legal, fraud-prevention, dispute or claims purposes.

15. Data access and export

You may request access to or an export of your personal data by contacting [email protected]. We may verify your identity before processing the request.

Where the GDPR or UK GDPR right to data portability applies, qualifying data will be provided in a structured, commonly used and machine-readable format as required by law.

16. Cookies and browser storage

Wavesso does not currently use:

We do not conduct behavioural advertising profiling.

Wavesso may use cookies, local storage or similar technologies where technically necessary to maintain your session, authenticate you, protect against abuse, retain necessary application state or maintain security.

When you continue to an external service such as Stripe Checkout or Google Sign-In, that provider may use its own cookies and similar technologies.

If Wavesso introduces non-essential analytics, advertising or other technologies requiring consent in the future, we will implement an appropriate consent mechanism before activation where required by law.

17. Travel links

Wavesso uses its own airport database and does not retain a history of your selected airports, travel dates or destinations.

Wavesso may generate links to:

A generated link may contain parameters such as departure airport, destination or selected travel dates to pre-populate a search. Once you access an external service, its operator processes information under its own privacy policy.

Wavesso does not receive payment card or booking information you provide to those services unless we clearly inform you of a different integration in the future.

18. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure and destruction.

No Internet service can guarantee absolute security. You should protect your Account credentials and not share your password.

19. Automated decision-making

Wavesso may automatically compare Forecast parameters with your surfing preferences and highlight potentially suitable conditions.

We do not use your personal data for solely automated decisions producing legal effects or similarly significant effects concerning you.

20. Rights of individuals in the EEA

Where the GDPR applies, you may have rights including:

Requests may be submitted to [email protected].

Our principal supervisory authority in Poland is the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.

21. United Kingdom users

Where the UK GDPR applies, you may have corresponding rights including access, rectification, erasure, restriction, portability, objection, rights concerning certain automated decisions and the right to complain to the Information Commissioner's Office (ICO).

You may contact us first at [email protected].

22. United States state privacy rights

Your rights may depend on your state of residence and whether a particular state privacy statute applies to Wavesso.

Where required, you may have rights relating to information about categories of personal information processed, access, correction, deletion, obtaining a copy, opting out of certain processing and appealing a privacy-request decision.

Requests may be submitted to [email protected].

23. California privacy disclosures

Wavesso may collect the personal information described in this Policy, including email addresses, usernames and Account information.

Wavesso does not sell your personal information and does not share personal information for cross-context behavioural advertising.

We do not use your information to target advertising.

To the extent the California Consumer Privacy Act / California Privacy Rights Act applies to Wavesso, California residents may have applicable rights including rights to know, access, correct, delete, obtain copies of certain information, opt out of sale or sharing where such activities occur, and exercise their rights without unlawful discrimination.

Because Wavesso does not currently sell or share personal information for cross-context behavioural advertising, we do not currently provide a “Do Not Sell or Share My Personal Information” mechanism.

Wavesso does not currently engage in cross-site behavioural tracking for advertising. Because there is no single uniform technical standard for the traditional browser “Do Not Track” signal, enabling DNT does not change technically necessary Wavesso functionality. If a legally mandated privacy preference signal becomes applicable to processing introduced by Wavesso, we will recognise it to the extent required by law.

24. No sale of data or advertising

We do not currently:

25. Children's and minors' privacy

Wavesso is not restricted exclusively to adults. Individuals who have not reached the age of majority may use the Service subject to applicable legal requirements.

Where particular processing of a minor's personal data is based on consent and applicable law requires that consent to be given or authorised by a parent or legal guardian, Wavesso will require such authorisation to the extent required by law.

For Users in Poland and the EEA, where processing in connection with an information society service relies on consent, applicable law may require the consent to be given or authorised by a person holding parental responsibility where the User is below the relevant statutory age.

Additional verifiable parental consent requirements may apply to Users under 13 in the United States.

If Wavesso learns that personal information relating to a child has been collected without parental or guardian authorisation required by applicable law, we will take appropriate steps, which may include deleting that information.

A parent or legal guardian may contact [email protected] regarding personal data of a person under their care and may exercise applicable rights on that person's behalf where provided by law.

26. Sensitive personal data

Wavesso does not ask Users to provide special-category personal data such as health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or sex-life information, genetic data or biometric information used for unique identification.

Please avoid including such information in support communications unless genuinely necessary.

27. Changes to this Policy

We may update this Privacy Policy where new functionality is introduced, providers change, authentication methods change, analytics are introduced, payment functionality changes or applicable law changes.

The current version will be available at https://wavesso.com/privacy.

Where a change materially affects the way we process personal data, registered Users will receive appropriate notice where required by law.

28. Contact us

For privacy questions, Account deletion, data export or other privacy rights requests, contact:

Jacek Knaur Analityka
ul. Topazowa 27
62-081 Baranowo
Poland
Polish Tax Identification Number (NIP): 7792579722
email: [email protected]
phone: +48 572 848 969

Effective date: 24 August 2026