MyNextDive

MyNextDive · Legal

Privacy Policy

Last updated: 14 August 2026

This policy explains what personal data MyNextDive processes when you use the Service, why, and the rights you have. We aim to collect as little as possible.

1. Who is responsible

The data controller is [legal entity name & address — to confirm]. For any privacy question, contact us at hello@mynextdive.com.

2. What we collect

You can search and browse without creating an account. We process:

  • Search inputs — the place, date, certification level and number of logged dives you enter. These are not, by themselves, identifying.
  • Referral events — when you click through to a dive centre to book, we record which dive/centre, the time, and the search context, to measure interest.
  • Technical data — IP address, device and browser information, and request logs kept by our hosting and infrastructure providers for security and reliability.
  • Approximate location — only if you use the “around me” option and your browser asks for your consent. It is used to run that search and is not stored for profiling.
  • Contact content — if you email us, the message and your address.

4. Cookies & similar technologies

Essential cookies needed for sessions and security are always active. Analytics cookies are optional and load only if you accept them in our cookie banner — for example Google Analytics, which helps us understand how the site is used. If you decline, no analytics cookies are set. We do not use advertising or cross-site tracking cookies. You can change or withdraw your choice at any time via “Manage cookies” in the footer.

Interactive maps load tiles from OpenStreetMap’s servers, which receive your IP address to deliver the map imagery.

5. Who we share data with

We do not sell your data. We share it only with providers who help us run the Service, acting as processors under contract:

  • hosting and content delivery (Vercel Inc.);
  • database hosting (Neon);
  • OpenStreetMap, whose tile servers receive your IP when a map loads;
  • Google (Google Analytics) — only if you accept analytics cookies.

When you click to book, you leave the Service for the dive centre’s own website, which is governed by its own privacy policy.

6. International transfers

Some providers may process data outside your country, including in the United States. Where required, such transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses [confirm with providers].

7. How long we keep data

Past dive departures are pruned once they can no longer be booked. Aggregate referral records are retained as demand evidence. Technical logs are kept for a limited period by our providers. We keep personal data no longer than necessary for the purposes above.

8. Your rights

Subject to applicable law, you may request access to, correction or erasure of your data, restrict or object to processing, and ask for portability. You can withdraw consent at any time. To exercise these rights, email hello@mynextdive.com. If you are in the EU/EEA you may also lodge a complaint with your local supervisory authority [e.g. the CNIL in France].