Privacy Policy

Your privacy matters to us. Learn how we collect, use, and protect your information.

Effective Date: November 8, 2025

Your Privacy is Important

This Privacy Policy explains how Aquavora LLC ("Aquavora," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our boat rental platform.

By using Aquavora, you consent to the data practices described in this policy. If you do not agree with this Privacy Policy, please do not use our platform.

1. Information We Collect

1.1 Information You Provide Directly

We collect information you provide when creating an account, listing a boat, making bookings, or communicating on our platform:

Account Information:

  • • Email address (required for account creation)
  • • Password (encrypted and never stored in plain text)
  • • Display name (chosen by you)
  • • Account creation date

Profile Information:

  • • Profile picture (optional, stored securely in Supabase Storage)
  • • Bio/description (optional)
  • • Location (city/state - optional, used for search and display)
  • • Join date (automatically recorded)

Boat Listing Information (For Owners):

  • • Boat specifications (name, type, capacity, features)
  • • Boat photos (stored in secure cloud storage)
  • • Location coordinates (latitude/longitude for map display)
  • • Pricing information (hourly rates, minimum/maximum hours)
  • • Availability schedule (operating hours, blocked dates)
  • • Cancellation policy preference
  • • Captain preferences and requirements

Booking & Transaction Information:

  • • Booking dates, times, and durations
  • • Booking type (instant or request-to-book)
  • • Payment information (processed by Stripe - see Third-Party Services)
  • • Transaction history and amounts
  • • Cancellation records and refund details
  • • Booking status updates and timestamps

Communications:

  • • Messages exchanged through our in-platform messaging system
  • • Message attachments (photos, documents - stored securely)
  • • Inquiry messages about boat availability
  • • Email communications and preferences
  • • Read receipts and message timestamps

Reviews & Ratings:

  • • Star ratings (overall and category-specific)
  • • Written review content
  • • Review responses
  • • Review timestamps
  • • Booking relationship (which rental the review is about)

Damage Protection & Disputes:

  • • Damage claim submissions and evidence photos
  • • Dispute evidence and documentation
  • • Claim amounts and resolution details
  • • Payment status for approved claims

1.2 Information Collected Automatically

When you use our platform, we automatically collect certain technical information:

  • Usage Data: Pages visited, features used, time spent on platform, search queries
  • Device Information: Browser type, operating system, device type, screen resolution
  • Log Data: IP address, access times, referring URLs, error logs
  • Location Data: Approximate geographic location (from IP address) for search results and local content

1.3 Information from Third Parties

We may receive information from third-party services when you use them in connection with Aquavora:

  • Payment Processors (Stripe): Payment verification, transaction success/failure, fraud detection signals
  • Authentication Services: If you sign in using third-party authentication (future feature)
  • Analytics Providers: Aggregated usage statistics and performance metrics (see Section 6)

2. How We Use Your Information

We Use Your Information To:

🚤 Provide Platform Services

  • • Create and manage your account
  • • Process bookings and payments
  • • Facilitate communication between boat owners and renters
  • • Display boat listings in search results
  • • Show your profile to other users
  • • Enable reviews and ratings
  • • Process damage claims and disputes

💰 Process Payments & Payouts

  • • Process secure payments through Stripe
  • • Calculate platform fees and owner earnings
  • • Manage automatic payouts to boat owners
  • • Handle refunds and cancellations
  • • Track damage claim payments
  • • Generate financial records for tax compliance

📧 Send Important Communications

  • • Booking confirmations and reminders
  • • Payment confirmations and receipts
  • • Booking request notifications for owners
  • • Cancellation notices and refund updates
  • • Damage claim notifications
  • • Review prompts and reminders
  • • Account security alerts
  • • Platform updates and policy changes

🛡️ Safety, Security & Trust

  • • Verify user identities and prevent fraud
  • • Detect and prevent prohibited conduct
  • • Enforce our Terms of Service
  • • Calculate completion rates and performance metrics
  • • Track cancellation patterns and penalties
  • • Monitor for platform abuse or circumvention
  • • Resolve disputes between users
  • • Investigate damage claims and evidence

📊 Improve Our Platform

  • • Analyze usage patterns and trends
  • • Develop new features and functionality
  • • Optimize search results and recommendations
  • • Improve platform performance and reliability
  • • Conduct research and testing
  • • Fix bugs and technical issues

⚖️ Legal Compliance

  • • Comply with legal obligations and regulations
  • • Respond to law enforcement requests
  • • Enforce our legal rights and agreements
  • • Prevent illegal activity
  • • Generate tax documentation (1099 forms for owners)

Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your personal data based on:

  • Contract Performance: Processing necessary to provide our services and fulfill our contract with you
  • Legitimate Interests: Improving our platform, preventing fraud, ensuring security
  • Legal Obligations: Complying with applicable laws and regulations
  • Consent: Where required by law, such as for marketing communications (you can withdraw consent anytime)

3. How We Share Your Information

Important: We do not sell your personal information to third parties. We share your information only as described below to provide and improve our services.

3.1 Information Shared with Other Users

When you use Aquavora to rent or list boats, certain information is shared with other users to facilitate transactions:

Public Profile Information (Visible to All Users):

  • • Display name
  • • Profile picture (if uploaded)
  • • Bio/description (if provided)
  • • Location (city/state level - if provided)
  • • Join date
  • • Average rating and review statistics
  • • Completion rate and performance badges (for owners)
  • • Total rentals completed (aggregate count)

Shared with Booking Participants Only:

  • After booking confirmed: Full names, contact information for coordination
  • Boat details: Exact location, pickup instructions (for renters)
  • Messages: In-platform communications and attachments
  • Booking details: Dates, times, pricing, payment status

Privacy Note: We never share your email address publicly or with other users unless you explicitly include it in messages. Payment information is never shared - all payments are processed securely through Stripe.

3.2 Service Providers & Business Partners

We share information with trusted third-party service providers who help us operate the platform:

Stripe (Payment Processing)

Processes all payments, payouts, and refunds. View their privacy policy.

Supabase (Database & Storage)

Securely stores all platform data, including profiles, bookings, messages, and files. View their privacy policy.

Vercel (Hosting & Infrastructure)

Hosts our platform and provides infrastructure. View their privacy policy.

Resend (Email Delivery)

Delivers transactional emails (booking confirmations, notifications). View their privacy policy.

Google Maps API (Location Services)

Provides map displays, geocoding, and location search. View their privacy policy.

Data Processing Agreements: All service providers are contractually required to protect your data and use it only for the purposes we specify.

3.3 Legal Requirements & Safety

We may disclose your information when required by law or to protect rights and safety:

  • To comply with legal obligations, court orders, or regulatory requests
  • To respond to law enforcement or government agency requests
  • To enforce our Terms of Service or other agreements
  • To investigate suspected fraud, abuse, or security issues
  • To protect the rights, property, or safety of Aquavora, our users, or the public
  • In connection with legal proceedings or investigations

3.4 Business Transfers

If Aquavora is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred to the new entity. We will notify you of any such change and your options regarding your information.

3.5 Aggregate & De-Identified Data

We may share aggregate, anonymized, or de-identified information that cannot reasonably be used to identify you. For example:

  • Platform usage statistics and trends
  • Aggregate booking patterns by region
  • General performance metrics

4. Data Retention

How Long We Keep Your Information

We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this Privacy Policy. Specific retention periods vary by data type:

Account Information:

Retained for the life of your account plus 7 years after account deletion (for legal compliance, tax records, and dispute resolution).

Booking & Transaction Data:

Retained for 7 years after transaction date for tax compliance (IRS requirements), financial reporting, and potential disputes.

Messages & Communications:

Retained for 2 years after booking completion for dispute resolution and quality assurance, then permanently deleted unless part of an active dispute.

Reviews & Ratings:

Retained indefinitely as they form part of users' public reputation on the platform. You may request removal in certain circumstances (see Your Rights section).

Damage Claims & Disputes:

Retained for 7 years after resolution for legal compliance and future reference.

Technical & Usage Data:

Log files and usage analytics are typically retained for 90 days for security monitoring and platform improvement, then aggregated or deleted.

After Retention Periods: When information is no longer needed, we securely delete or anonymize it. Some backup copies may persist in our systems for disaster recovery purposes but are not actively used.

Legal Holds: If information is subject to legal proceedings, investigations, or regulatory requirements, we may retain it longer than the standard retention period.

5. Your Privacy Rights

You Have Rights Over Your Personal Data

Depending on your location, you have certain rights regarding your personal information:

5.1 Rights for All Users

✅ Access Your Information

Request a copy of the personal information we hold about you. Most information is accessible directly through your account dashboard.

✏️ Update Your Information

Update your profile, contact information, and preferences directly in your account settings at any time.

🗑️ Delete Your Account

Request account deletion at any time. Note: Some information may be retained for legal compliance (see Data Retention).

📧 Opt Out of Marketing

Unsubscribe from promotional emails using the unsubscribe link in any marketing email. Note: You'll still receive transactional emails (booking confirmations, etc.).

📩 Data Portability

Request a copy of your data in a portable format (e.g., JSON or CSV) that you can transfer to another service.

5.2 Additional Rights (GDPR - European Users)

If you are located in the European Economic Area (EEA), UK, or Switzerland, you have additional rights under GDPR:

  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data in certain circumstances
  • Right to Restriction of Processing: Limit how we use your data in certain situations
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Withdraw Consent: Withdraw consent for processing based on consent (doesn't affect prior lawful processing)
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

5.3 Additional Rights (CCPA - California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request details about the categories and specific pieces of personal information we collect
  • Right to Delete: Request deletion of your personal information (subject to legal exceptions)
  • Right to Opt Out of Sale: We do not sell personal information, but you have the right to opt out if practices change
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

📧 How to Exercise Your Rights

To exercise any of these rights, contact us at:

info@aquavora.com

Subject line: "Privacy Request - [Your Request Type]" (e.g., "Privacy Request - Data Access")

We will respond to your request within 30 days. For security purposes, we may need to verify your identity before processing your request.

5.4 Limitations on Rights

Note: These rights are not absolute. We may deny requests that are manifestly unfounded, excessive, or where we have compelling legal grounds to continue processing. For example, we may retain financial records for tax compliance even after account deletion.

6. Cookies & Analytics

Privacy-First Approach

We respect your privacy and use minimal cookies. We've chosen privacy-focused analytics that don't require cookie consent banners.

6.1 Essential Cookies Only

Aquavora uses only essential cookies required for platform functionality. We do not use tracking cookies, advertising cookies, or other non-essential cookies.

Essential Cookies We Use:

  • Authentication: Keeps you logged in to your account
  • Security: Protects against unauthorized access and CSRF attacks
  • Session Management: Remembers your preferences during your visit

These cookies are necessary for the platform to function and cannot be disabled.

6.2 Privacy-Focused Analytics

To understand how users interact with our platform and improve the experience, we use Plausible Analytics - a privacy-focused analytics service that:

  • Does not use cookies - No tracking cookies stored on your device
  • Does not collect personal data - No IP addresses, unique identifiers, or cross-site tracking
  • Fully GDPR & CCPA compliant - No consent banners required
  • Aggregated statistics only - We see page views and traffic trends, not individual user behavior
  • Open source and transparent - View their code at github.com/plausible/analytics

What Plausible Collects (Without Cookies):

  • • Page views and unique visitors (anonymized)
  • • Referrer sources (where visitors come from)
  • • Browser and device type (for compatibility)
  • • Country-level location (from IP, not stored)

Plausible does not identify you as an individual. All data is aggregated and anonymous.

6.3 Your Control Over Analytics

Because Plausible doesn't use cookies or collect personal data, you don't need to opt in or accept anything. However, you can still opt out if you prefer:

  • Browser Extensions: Use privacy-focused browsers or extensions like uBlock Origin
  • Do Not Track: Enable "Do Not Track" in your browser settings (we honor this signal)
  • Ad Blockers: Most ad blockers automatically block analytics scripts

6.4 No Third-Party Advertising

We do not use advertising cookies, tracking pixels, or any third-party advertising networks. You will never see targeted ads based on your Aquavora activity.

6.5 Managing Cookies

You can control cookies through your browser settings:

  • Most browsers allow you to view, manage, and delete cookies
  • You can block all cookies, but this may prevent you from logging in
  • We recommend allowing essential cookies for proper platform functionality

Note: If you disable essential cookies, you will not be able to use key features like authentication and booking management.

7. Third-Party Services

External Services We Use

Aquavora integrates with several trusted third-party services to provide core functionality. These services have their own privacy policies that govern how they handle your data:

💳

Stripe (Payment Processing)

What they do: Process all payments, payouts, refunds, and Connect account management for boat owners.

Data shared: Payment information, transaction details, bank account info (for owners), identity verification data

Security: PCI DSS Level 1 certified (highest security standard). We never store your credit card details - Stripe handles all payment data.

View Stripe Privacy Policy →
🗄️

Supabase (Database & Storage)

What they do: Secure cloud database storage for all platform data, file storage for photos and attachments, real-time data synchronization

Data shared: All platform data (profiles, bookings, messages, photos, etc.)

Security: Enterprise-grade PostgreSQL with encryption at rest and in transit. Row-level security policies protect your data.

View Supabase Privacy Policy →
☁️

Vercel (Hosting & Infrastructure)

What they do: Host our platform, provide CDN for fast global access, infrastructure monitoring

Data shared: Technical data (IP addresses, access logs, performance metrics)

Security: Automatic HTTPS encryption, DDoS protection, SOC 2 Type II certified

View Vercel Privacy Policy →
📧

Resend (Email Delivery)

What they do: Deliver transactional emails (booking confirmations, notifications, etc.)

Data shared: Email addresses, names, email content (booking details, notifications)

Security: Encrypted email transmission, delivery tracking, bounce handling

View Resend Privacy Policy →
🗺️

Google Maps API (Location Services)

What they do: Provide map displays, geocoding (converting addresses to coordinates), location search and autocomplete

Data shared: Location coordinates, search queries, IP address (for geolocation)

Privacy: Google Maps API usage is subject to Google's privacy policy and terms of service

View Google Privacy Policy →
📊

Plausible Analytics (Privacy-Focused Analytics)

What they do: Provide privacy-focused website analytics without cookies or personal data collection

Data shared: Aggregated, anonymized page views and traffic statistics only (no personal data, no IP addresses stored)

Privacy: GDPR & CCPA compliant by default. No cookies, no cross-site tracking, no personal data collection. Open source and transparent.

View Plausible Privacy Policy →

Important: Our Privacy Responsibilities

While we carefully select and vet third-party services, we are not responsible for their privacy practices. We encourage you to review their privacy policies directly. We contractually require service providers to protect your data and use it only for the purposes we specify.

8. Data Security

How We Protect Your Information

We take data security seriously and implement industry-standard technical and organizational measures to protect your personal information:

🔒 Encryption

  • • HTTPS/TLS encryption for all data in transit
  • • Database encryption at rest
  • • Encrypted password storage (hashed with bcrypt)
  • • Secure file storage with access controls

🔐 Access Controls

  • • Row-level security policies in database
  • • Role-based access control (RBAC)
  • • Multi-factor authentication for admin access
  • • Principle of least privilege

🛡️ Infrastructure Security

  • • Enterprise-grade cloud infrastructure
  • • Regular security updates and patches
  • • DDoS protection and rate limiting
  • • Automated backups and disaster recovery

👁️ Monitoring & Response

  • • 24/7 security monitoring
  • • Automated threat detection
  • • Incident response procedures
  • • Regular security audits

Payment Security

PCI DSS Compliance Through Stripe

All payment processing is handled by Stripe, which is PCI DSS Level 1 certified (the highest level of payment security). We never store your credit card numbers, CVV codes, or sensitive payment information on our servers. Stripe handles all payment data securely on their PCI-compliant infrastructure.

Your Security Responsibilities

While we implement robust security measures, your cooperation is essential:

  • Strong Passwords: Use unique, complex passwords (8+ characters with uppercase, numbers, and symbols)
  • Keep Credentials Private: Never share your password or account access with others
  • Logout on Shared Devices: Always log out when using public or shared computers
  • Report Suspicious Activity: Contact us immediately if you suspect unauthorized access
  • Update Contact Info: Keep your email address current for security notifications

⚠️ No System is 100% Secure

Despite our best efforts, no security measures are perfect or impenetrable. We cannot guarantee the absolute security of your information. If we become aware of a data breach affecting your personal information, we will notify you in accordance with applicable laws.

Security Incident Response

If we discover a security incident that affects your personal information, we will:

  • Notify affected users within 72 hours (or as required by law)
  • Provide details about the nature of the breach
  • Explain steps we're taking to mitigate harm
  • Offer guidance on protective measures you can take
  • Cooperate with regulatory authorities as required

9. Children's Privacy

Aquavora is Not for Children

Aquavora is intended for users who are 18 years of age or older. We do not knowingly collect personal information from children under 18.

COPPA & Age Restrictions

Our platform complies with the Children's Online Privacy Protection Act (COPPA) and international regulations regarding children's data:

  • Age Requirement: You must be at least 18 years old to create an Aquavora account or use our services
  • Age Verification: By creating an account, you represent and warrant that you are 18 or older
  • Parental Consent Not Offered: We do not offer mechanisms for parental consent because our services are not designed for users under 18

If We Learn of Underage Users

If we become aware that we have collected personal information from anyone under 18 years of age, we will:

  • • Immediately delete the account and associated data
  • • Not use the information for any purpose
  • • Not disclose the information to third parties (except as required by law)
  • • Take reasonable measures to prevent future underage access

Reporting Underage Users

If you believe someone under 18 has created an account on Aquavora, please contact us immediately at:

info@aquavora.com

Subject: "Underage User Report"

10. International Data Transfers

Cross-Border Data Processing

Primary Location: United States

Aquavora is based in Minnesota, United States. Our servers and infrastructure are primarily located in the United States. By using our platform, you acknowledge and agree that your personal information may be transferred to, stored, and processed in the United States.

For European Users (GDPR)

If you are located in the European Economic Area (EEA), UK, or Switzerland:

  • Legal Basis: Data transfers to the US are based on your consent and our legitimate interests in operating a global platform
  • Safeguards: We implement appropriate safeguards, including:
    • Standard Contractual Clauses (SCCs) with service providers
    • Technical security measures (encryption, access controls)
    • Regular data protection assessments
  • Data Protection Rights: You maintain all rights under GDPR regardless of where data is processed
  • Supervisory Authority: You can file complaints with your local data protection authority

International Service Providers

Some of our service providers operate globally and may process data in multiple countries:

  • Stripe: Processes data globally with servers in US, EU, and other regions
  • Supabase: Data stored in US data centers with global CDN delivery
  • Vercel: Edge network with global points of presence

Note: The United States may not provide the same level of data protection as your home country. However, we ensure appropriate safeguards are in place to protect your information regardless of where it is processed.

Your Consent to Transfer

By creating an account and using Aquavora, you:

  • Consent to the transfer of your personal information to the United States and other countries
  • Acknowledge that US and other countries' laws may differ from your home country
  • Agree that disputes will be governed by Minnesota law (see Terms of Service)

11. Changes to This Privacy Policy

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You of Changes:

  • Material Changes: We will notify you by email and/or prominent notice on the platform at least 30 days before changes take effect
  • Minor Changes: Posted to this page with updated "Effective Date" at the top
  • Acceptance: Continued use of the platform after changes constitute acceptance of the updated policy

Review Regularly

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. You can always find the current version at:

Your Options After Changes

If you don't agree with changes to this Privacy Policy:

  • You may stop using the platform
  • You may request deletion of your account (see Section 5 - Your Privacy Rights)
  • You may exercise any applicable data protection rights

Important: If you continue to use Aquavora after we post changes, you accept the updated Privacy Policy and any information practices it describes.

Previous Versions

If you would like to review a previous version of this Privacy Policy, please contact us at info@aquavora.com.

12. Contact Us

Questions About This Privacy Policy?

For all privacy inquiries, data requests, security reports, and general support:

info@aquavora.com

📋 Privacy Requests

Subject: "Privacy Request - [Access/Delete/Modify]"
Data access requests, deletion requests, GDPR/CCPA inquiries

🔒 Security Issues

Subject: "Security Report - [Brief Description]"
Report security vulnerabilities or suspected breaches

👤 Underage Users

Subject: "Underage User Report"
Report accounts of users under 18 years old

💬 General Support

Subject: [Your topic]
Platform questions, technical support, account issues

Aquavora LLC
Plymouth, Minnesota, United States
© 2025 Aquavora. All rights reserved.

Response Time: We typically respond to privacy inquiries within 30 days as required by applicable law. Urgent security matters are prioritized.

By using Aquavora, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Last updated: November 8, 2025