Surf Track Pro legal
Surf Track Pro Privacy Policy
What information Surf Track Pro currently handles, why it is needed and the controls available to you.
Pre-launch legal review required. This tailored draft is operational guidance, not legal advice or a claim of solicitor approval.
Scope and status
This policy reflects an initial audit of the current Surf Track Pro code and configured services. It does not claim completed legal compliance. The operating entity, verified privacy contact, provider regions, retention schedule and Privacy Act coverage must be confirmed before public launch.
Information we collect
- Early-access requests: the email address you submit, the testing notice and contact-consent version, request dates and the campaign link that brought you to the form. A request does not create an account.
- Account identity: email, provider identity, verification status, nickname and roles.
- Surf preferences: units, ability, board, home break, favourites and alert settings.
- Community material: posts, comments, reports, reviews, observations, photos, competition activity and moderation history.
- Location-related information you choose to submit, such as home break, check-ins, route origin and spot updates.
- Security and technical records: sessions, IP-derived rate-limit identifiers, browser/device details, audit events, upload signatures and provider request identifiers.
- Privacy-limited usage records: provider user ID, normalized route class, device class, named product control, outcome and timing. Query strings, form contents, private conversations, photos, credentials, raw IP addresses and precise locations are excluded from product-usage records.
- Support, complaint, appeal and policy-acceptance records.
Why we use it
- Manage interest in controlled testing, contact suitable early-access applicants and measure which approved campaign link produced a request.
- Authenticate accounts and prevent fraud or disposable-email abuse.
- Personalise forecasts, units, saved spots, trips and daylight surf alerts.
- Operate Community, competitions, moderation, appeals and user administration.
- Secure uploads, investigate abuse, maintain audit history and diagnose service failures.
- Understand feature adoption, usability problems and performance across the service and for an affected account without collecting the content of the user’s activity. Individual usage summaries are restricted to the protected owner and authorised administrators.
- Improve forecast calibration using clearly separated, reputation-weighted observations.
- Send service messages and, only where permitted, optional marketing.
Service providers and overseas processing
The current architecture uses Supabase for authentication and account records and Cloudflare-hosted Sites, D1 and R2 for application hosting, structured data and private files. It may send routing inputs to Geoapify, forecast coordinates to marine or weather providers, and sanitised image derivatives to OpenAI when external image safety and surf-relevance screening is enabled. Social sign-in sends the minimum required authentication information to Google, Apple or Microsoft when selected.
These providers may process information outside Australia. Exact recipient countries, contractual safeguards, retention and production-region settings must be verified and recorded before public launch. We do not sell personal information.
Photos and AI screening
Unapproved images are stored privately. File metadata is stripped where appropriate and a sanitised derivative is preferred for external screening. Supported safety scores and provider request identifiers may be retained with moderation evidence; raw provider responses are not intended to be stored. High-risk material has restricted review access. See the Content Rules and Moderation Policy.
Marketing choices
Requesting early access gives permission only for emails about early access and product testing; it does not subscribe you to unrelated marketing. Marketing consent is separate, optional and off by default. Service and safety messages may still be sent where needed to operate your account. Commercial electronic messages must identify the sender and provide a working, no-cost unsubscribe process.
Security and retention
Surf Track Pro uses private storage, server-side permissions, expiring review links, audit logs and session controls. No online service is risk-free. Product-usage event records are automatically deleted after 90 days. Account data lasts while the account is active; rejected image assets are intended to be deleted after the decision; moderation, consent, security and transaction evidence may be kept longer where reasonably required. Retention outside product analytics still requires final pre-launch review.
Access, correction, deletion and complaints
Use account settings to update supported profile information. Requests for access, correction, deletion, privacy complaints or withdrawal of marketing consent must use the contact procedure in the Legal Centre. Identity verification may be required. We aim to acknowledge privacy complaints promptly, investigate fairly and explain the outcome.
Children
Surf Track Pro is not designed for unsupervised child accounts. The minimum age, parental-consent flow and handling of child-focused images require legal and safety review before public registration opens.
Changes
Material changes receive a new version, change summary and notice. A material change may require renewed acceptance before continued use. Previous versions are preserved for audit.