SaltRiders privacy policy

Last updated: September 2026

The short version

SaltRiders is a safety-first surf-coordination app, not a social network. We collect the minimum needed to run your account and the features you use. No advertising, no data sale, no tracking across other apps or websites, no engagement analytics. Your safety signals are never used for marketing, or anything except safety.

What we collect

Account: your email address and password credentials (managed by Supabase Auth). Your date of birth, which you tell us once (when you join, or from Settings if you joined before we asked): SaltRiders is for surfers 18 and over, we keep what you declared as the record that we asked, and no other member can see it. Profile: the display name, handle, pronouns, stance, skill level, home region, and avatar you choose. Content you create: sessions, pulses, crew messages, session-log entries, marketplace listings and messages, messages about your lesson bookings, direct and group messages (and the names of groups you start or rename), reports, and photos you upload. Messages: who is in each of your conversations, where you have read up to, which conversations you mute or archive, and who may send you message requests (your setting), so the app can show you your messages; and a count of the conversations you start and the messages you send over the last day, used only to limit spam and the same for every member. Safety records: your safety-quiz result, Respect Code acceptance, blocks, and reports. Device: if you turn on notifications, a push token for that device, so we can deliver them, and the name of its time zone (for example “Australia/Sydney”), which we use for one thing: delivering overnight notifications silently in your local time. A time zone is not a location, and we never use it to work out or show where you are. Both are removed when you sign out on that device and deleted with your account. Notifications go straight to Apple or Google for delivery and to no one else, and their text is written by us; it never quotes another member’s message. If you coach: the credentials you send (their type, issuer, level, region, cover amount, issue and expiry dates, and the last four characters of their reference), the photos of them (deleted as “Coaching credentials” below says), and each decision with its reason. If you turn on women-only spaces: that you told us you are a woman, and when; if a person at SaltRiders grants them to you instead: the grant, its reason and when.

Location is region-level only

Places in SaltRiders are regions (for example “Perth Metro”), never spots, and we never collect or store a precise position. If you tap “Use my location” (when you join, on Discover, in the region picker or in Settings), your device asks your permission and gives the app your approximate location, which the app rounds to about a kilometre before anything uses it. It is used on your device only, to find your nearest coasts on the map and in the list, and once you have allowed it, Discover uses it again each time it opens. It is never sent to us and never stored; the only thing that persists is the region you choose. You can decline, or turn location off for SaltRiders at any time in your browser or device settings, and search for a region instead. Photos are stripped of embedded location metadata on our servers before they become visible. There are no crowd maps and no spot-level tracking, by design.

Map tiles

The Discover map is drawn from map tiles served by a third-party host (OpenFreeMap, built on OpenStreetMap data). Like any online map, that host receives the area of the map you are looking at (a region-sized cell, since the map never zooms closer than that) and your IP address, in order to serve the tiles. It never receives your device location, and we send it nothing about you.

How we use it

To run the app: showing your profile to other members per your settings, coordinating sessions and crews, delivering notifications you have enabled, and keeping the community safe (reports, blocks, restriction decisions; always with human review for consequential decisions). We do not build advertising or engagement profiles, and feeds are chronological.

Crash reports, not our analytics

We run no product-analytics or tracking SDK of our own, and there is no advertising identifier. The app sends anonymous crash reports (via Sentry) so we can fix defects; these are scrubbed of personal data, are not linked to your identity, and never include your safety signals. The third-party components we build on do report their own diagnostics: Stripe records product-interaction events for its own analytics, and Google's sign-in library reports a device identifier and a coarse, network-derived location. None of this is used for advertising.

Who processes your data

Supabase (authentication, database, and file storage), Stripe (card payments; if you sell gear or coach, the identity and bank details you provide directly to Stripe to be paid; and, if you choose to verify your identity, the document check described below; we never see your card number or your documents), Apple and Google (sign-in, and push-notification delivery via APNs and Firebase Cloud Messaging if you enable push), and Sentry (anonymous crash diagnostics). These providers process data only to run SaltRiders. We do not sell or share your data for advertising.

Buying, selling, and lessons

When you buy gear or book a lesson we store the order (what it was for, the amount, its status, and Stripe's reference for the payment) so both sides can see what was agreed. Card details go straight to Stripe and never touch our servers. Sellers and coaches complete Stripe's own onboarding, which asks Stripe (not us) for legal name, date of birth, address, government ID and bank details in order to pay them out.

Verifying your identity

Members aged 18 and over can choose to verify their identity. Coaches must verify before they can take bookings. The check is run by Stripe, in a Stripe screen inside the app: you photograph a government-issued document and take a selfie, and Stripe checks that the two match. Matching a selfie to a photo is biometric processing, and it happens only because you chose to start the check. Stripe holds that document, the selfie and what it reads from them; they never reach SaltRiders’ servers, and we never ask Stripe for what your document says. What we keep is the outcome (verified, in review, not passed (with a general reason, such as “document expired”), or withdrawn by our trust & safety team) and Stripe’s reference for the check, which you cannot see and which exists so we can resume the check and ask Stripe to delete its copy. A small number of authorised SaltRiders staff can open a check in Stripe’s dashboard, and do so only to handle a report about it, to finish a deletion, or, if you apply to coach, to check that the name on your credentials matches the name you verified. Other members see only whether you are verified, as a ring on your profile. It does not change your declared date of birth. When women-only spaces open, it will be one of two requirements for them (the other is your own declaration), and nothing on your document will be read for it. When you delete your account we ask Stripe to redact every check it holds for you, and we record whether it accepted that request (Stripe completes a redaction within a few days). You can also ask us at any time (privacy@saltriders.com) to have Stripe delete its copy without deleting your account; your verified status stays. Where the check is offered for a fee, you buy a check pass as an in-app purchase through the App Store or Google Play, at the price the store shows you: the store takes your payment, so we never see your card or your store account. We keep a record of the purchase (the store’s reference for it, what was bought, the price and currency the store reported, and how many checks it has been used for) so that we can honour it and act on a refund the store makes. The store is given a random reference for the purchase, never your SaltRiders account id.

Coaching credentials

If you apply to coach, only the SaltRiders staff who review credentials can open your documents. They sign in with two-factor authentication, never review their own application, and open a document through a link that expires within two minutes; each opening is recorded before the link is made. Learners see each checked credential’s type, its issuer, the month it was checked, the month it expires and the date SaltRiders last checked them all, never the document or its reference. A document is deleted 30 days after a person decides on it (or, if you ask for another review, 30 days after that review is decided), and at once if you withdraw the credential. When you delete your account, your credentials and their documents are deleted; the record of each decision is kept, with its link to you removed.

Who can see what

Access is enforced row-by-row in the database. Other members see only what the app's rules allow: region-level activity, profiles per your visibility, and opt-in spaces (like women-only sessions) restricted to eligible members. Blocking someone hides you from each other everywhere. A direct or group message can be read only by the people in that conversation. If anyone in it reports a message, a copy of that message and of up to 20 messages before it, whoever sent them, is shared with our safety team. Precise meetup details are revealed only to approved participants.

Your rights: export and deletion

From Settings you can export your data (GDPR Art. 20) and permanently delete your account and personal data (GDPR Art. 17), immediately, from within the app, no support ticket required. Deletion removes your account and personal records; an erasure record is retained as a legal audit trail: the deleted account’s internal id, the date, and whether Apple and Stripe accepted our requests to remove what they held. If Stripe’s removal still has to be finished by hand, the record also keeps Stripe’s reference for your check so that a person can finish it. A record of any identity-check pass you bought is kept as a financial record, and the record of each coaching-credential decision is kept, both with their link to your account removed. Messages you sent about a lesson booking stay with the other person on that booking, and direct and group messages you sent stay with the people you sent them to, in each case with your name removed (see Retention). Your export includes the direct and group messages you sent, the conversations you are in and your message settings, but not other people's messages.

Retention

We keep your data while your account exists. When you delete your account, personal data is erased or de-identified. Safety records that must survive for legal or community-protection reasons (for example reports about conduct) are retained in de-identified form. When a message is reported, we save a copy of it, and of up to 20 messages before it, whoever sent them, with the report for a person on our team to review. Messages attached to a report are kept for 180 days after our decision. Messages you sent about a lesson booking stay readable by the other person on that booking, with your name removed, because they are that person's record of the lesson. Direct and group messages are kept until everyone who was ever part of the conversation, or asked to join it, has deleted their account; leaving a conversation, or declining it, does not delete it. When you delete your account, the messages you sent stay readable by the people you sent them to, shown as from “A former member”, because they are those people's record of the conversation. If you had blocked someone who later deletes their account, their messages stay hidden from you.

Children

SaltRiders is not directed at children. You must be at least 18 to create an account.

Changes and contact

We will update this policy as the product evolves and note the date above. Questions or requests: privacy@saltriders.com.