DiveVerse
Features Gallery Mission For clubs Download Join a club Create a club

Privacy Policy

Effective 2026-09-08

DiveVerse is an app and web service for dive clubs and their members, provided by Bainbridge Services (registration number I25008115), 30 Calodyne Bungalows, St Francois, Mauritius 31726. This policy explains what personal data we handle, why, who else sees it, how long we keep it, and what you can ask us to do with it.

Who is responsible for your data

Two different organisations have responsibilities for the data in DiveVerse, and which one applies depends on the data:

  • Your dive club is the controller of the data you give it in order to be a member: your medical declaration, your medical certificate, your emergency contact, your qualifications, your insurance documents, your signed acceptance of the club's terms, and your participation in its events, courses and equipment hire. The club decides what to ask for and who in the club may see it. DiveVerse acts as its processor, under a written data processing agreement each club accepts before it can operate here.
  • DiveVerse is the controller of your account itself (your sign-in credentials, your name and email, your device push tokens), of the records we need to run and bill the platform, and of anything you choose to publish across clubs, such as a dive site you add to the shared map or a species sighting you publish.

For questions about how your club uses your data, contact the club. For anything about the platform, contact us at app@diveverse.org.

Bainbridge Services is established in Mauritius, outside the UK and the European Union. Our UK Article 27 representative is Christopher Bainbridge, reachable at app@diveverse.org. We have not yet appointed an EU representative; until then, write to the same address for anything you would otherwise raise with one, including a request relating to an EU data protection authority, and we will treat it accordingly.

What we collect, and why

DataWhyLawful basis
Name, email address, phone number, date of birth, profile photo To create and run your account, to identify you to your club, and to apply the age rules below Contract
Password (stored only as a hash by Firebase Authentication, never in readable form) To sign you in Contract
Health data: your medical declaration answers, declared conditions, and any medical certificate you upload So your club's Diving Officer can confirm you are fit to dive before you go in the water Explicit consent (Art. 9(2)(a)), which you give when you sign the declaration and can withdraw at any time
Your emergency contact's name and phone number So the club can reach someone if you are hurt on a dive Vital interests, and our legitimate interest in dive safety. See the note below
Diving and instructor qualifications, and photos of the cards To check you meet the prerequisites for a dive, a course or a piece of equipment Contract
Insurance policy details and uploaded documents Because many clubs require cover before you can dive with them Contract
Your electronic signature, drawn or typed, on the club's terms and on your medical declaration To evidence that you accepted them, and which version Legal obligation (Art. 7(1)) and legitimate interests
Precise location: your device's GPS position when you ask the app to find nearby clubs, events or dive sites, or when you place a dive site, meeting point or sighting on the map To show you what is near you and to record where a site or sighting actually is Consent, given through your device's location permission, which you can revoke in your device settings
Dive and event history, course enrolments, lesson sign-offs, equipment hires, incident reports To run the club's activities and keep its safety record Contract, and legal obligation for incident records
Messages, photos, posts and comments you write in club chats and the community feed To deliver them to the people you sent them to Contract
Payment records: what you paid, when, and the reference the payment provider gave it To take membership, course and event payments, and to keep the accounts Contract, and legal obligation to retain accounting records
Push notification tokens and device identifiers To send you the notifications you have turned on Contract
Access logs recording who viewed a member's medical data, and when So you can find out who has looked at your health information Legal obligation (Art. 32) and legitimate interests
Server logs, including IP address and request times To keep the service running and to investigate abuse Legitimate interests

A note about emergency contacts

Your emergency contact is a real person who has not signed up to anything here. Before you enter their details, please tell them that you have given their name and phone number to your dive club through DiveVerse, that it will be used only to contact them in an emergency, and that they can ask us to remove it at app@diveverse.org. You can clear it yourself at any time in the app.

What we do not do

DiveVerse has no analytics or advertising SDK. We do not track you across other apps or websites, we do not build advertising profiles, we do not sell personal data, and we do not use your data to train machine learning models.

Who else sees your data

Inside your club

Other members see your name, profile photo, qualifications and the events you have joined. Your health data is different: your medical declaration, conditions and certificate are visible only to you, to your club's administrators and Diving Officers, and to us where we have to for support. That restriction is enforced by the server, not just hidden in the app, and every such view is logged and shown to you on request.

Sub-processors

We use the following services to run DiveVerse. Each receives only what that job needs.

ServiceWhat it doesWhat it receives
Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging), United States Hosts the entire service Everything in the table above
Zoho Books Bookkeeping for clubs that connect it Member name and email, and the amounts and dates of their payments
PayPal Takes club and member payments Name, email and the payment amount. Card details go to PayPal directly and never reach us
Paddle Bills clubs for their DiveVerse subscription The club's billing contact name and email, and the subscription amount
Our email provider (SMTP) Sends verification, password reset, guardian permission and notification emails Your email address and the contents of that email
Cloudflare Turnstile Blocks bots on the public signup and contact forms Your IP address and a browser challenge token. No account data
OpenStreetMap and Nominatim Map tiles and place search The map area you are looking at, and what you typed into place search. Not your identity
OpenSeaMap and Esri (ArcGIS) Nautical and satellite map layers The map area you are looking at
iNaturalist Species lookup, and publishing a sighting there if your club chooses to Species search terms. For a published sighting: the species, date and location, under a platform account, not your name
Open-Meteo, OpenTopoData, Overpass and TideCheck Weather, tide, depth and map data for dive sites Coordinates of a dive site. No personal data
Your club's own WordPress site, if it connects one Publishes the club's dive reports Only what the report itself contains, which the club controls
Google Fonts Serves the typefaces on this website Your IP address when you load a page here

We will also disclose data where we are legally required to, or where it is necessary to protect someone's safety or to investigate fraud or abuse of the service.

Where your data is held

Bainbridge Services, the controller for the data described above, is established in Mauritius. The platform itself runs on Google Cloud infrastructure in the United States, so your data is transferred outside the UK and the European Economic Area regardless of where you are. That transfer relies on Google LLC's certification under the EU-US Data Privacy Framework and its UK extension, and on the Standard Contractual Clauses incorporated into the Google Cloud data processing terms we are party to. Our other sub-processors are covered by their own equivalent safeguards. You can ask us for details of any of these at app@diveverse.org.

How long we keep it

DataKept for
Your account and profile Until you delete it, or you ask us to
Medical declarations, declared conditions and medical certificates 12 months from the last time you reviewed them. Your club asks you to review them once a year; if a year passes without a review, they are deleted automatically
Medical access logs, recording who viewed the above 24 months. Long enough to investigate a complaint, and bounded
Notifications 12 months
Payment and membership records Up to 7 years after the payment, to meet tax and accounting requirements. Your identity is replaced with a pseudonym when you delete your account, leaving the amounts and dates without your name attached
Dive, event, course and equipment records, and incident reports Kept as the club's safety record. When you delete your account your name and identifier are replaced with a placeholder, so the dive still happened but is no longer attributed to you
Uploaded files you have not touched in 3 years Moved to cold archive storage, still recoverable on request. Profile photos, equipment photos and dive site photos are excluded and stay live
Server logs As retained by Google Cloud Logging under its default policy

Your rights

Wherever DiveVerse is the controller, and through your club where it is, you can:

  • Get a copy of your data. Settings, then My Data, then Download my data produces a machine readable export of everything we hold about you, including the log of who has viewed your medical information.
  • Correct anything wrong. Most of it you can edit directly in the app; for the rest, ask your club or us.
  • Delete your account. Settings, then My Data, then Delete my data. See the account deletion page for exactly what this removes, what is anonymised, and what has to be kept.
  • Withdraw consent to the processing of your health data, by clearing your medical declaration. Your club may not be able to let you dive with it withdrawn, but withdrawing it is always your choice.
  • Object to, or ask us to restrict, processing we do on the basis of legitimate interests.
  • Take your data elsewhere. The export above is in a structured, commonly used, machine readable format.
  • Complain. If we have not put something right, you can complain to your national data protection authority. In the UK that is the Information Commissioner's Office at ico.org.uk; in the EU, your own national supervisory authority (listed at edpb.europa.eu).

Write to app@diveverse.org to exercise any of these. We will respond within one month.

Children and young people

Diving is something a lot of people start young, so DiveVerse is open to under 18s. Anyone under 16 needs a parent or guardian's permission before their account can be used: we ask for the guardian's name and email at registration, email them a link, and the account stays locked until they follow it. We record who gave permission, when, and to which version of the wording. A parent or guardian can withdraw that permission, or ask us to delete the account, at app@diveverse.org.

How we protect it

All traffic is encrypted in transit. Data at rest is encrypted by Google Cloud. Medical certificates, electronic signatures, insurance documents and qualification cards are stored privately and served only through an authenticated endpoint that checks who is asking, rather than by a public link. Access to health data is restricted server-side to you, your club's administrators and its Diving Officers, and every such access is logged. Passwords are never stored in readable form.

If a breach happens that is likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell you directly where the risk to you is high.

Changes to this policy

We will update this page when the service changes, and change the effective date at the top. Where a change materially affects how we use your data, we will tell you in the app or by email rather than relying on you to check.

Contact

Questions, requests, or anything that looks wrong: app@diveverse.org.

DiveVerse

Explore. Dive. Share. Connect.

Product

Features Gallery Download the app Join a club Create a club

Company

Our mission Terms & conditions Privacy policy Data processing agreement Delete my account Contact us

Already run a club?

Admin console →
© 2026 DiveVerse.