Privacy Policy
Your privacy matters to us. Learn how we collect, use, and protect your information.
Effective Date: November 8, 2025
Your Privacy is Important
This Privacy Policy explains how Aquavora LLC ("Aquavora," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our boat rental platform.
By using Aquavora, you consent to the data practices described in this policy. If you do not agree with this Privacy Policy, please do not use our platform.
Table of Contents
1. Information We Collect
1.1 Information You Provide Directly
We collect information you provide when creating an account, listing a boat, making bookings, or communicating on our platform:
Account Information:
- • Email address (required for account creation)
- • Password (encrypted and never stored in plain text)
- • Display name (chosen by you)
- • Account creation date
Profile Information:
- • Profile picture (optional, stored securely in Supabase Storage)
- • Bio/description (optional)
- • Location (city/state - optional, used for search and display)
- • Join date (automatically recorded)
Boat Listing Information (For Owners):
- • Boat specifications (name, type, capacity, features)
- • Boat photos (stored in secure cloud storage)
- • Location coordinates (latitude/longitude for map display)
- • Pricing information (hourly rates, minimum/maximum hours)
- • Availability schedule (operating hours, blocked dates)
- • Cancellation policy preference
- • Captain preferences and requirements
Booking & Transaction Information:
- • Booking dates, times, and durations
- • Booking type (instant or request-to-book)
- • Payment information (processed by Stripe - see Third-Party Services)
- • Transaction history and amounts
- • Cancellation records and refund details
- • Booking status updates and timestamps
Communications:
- • Messages exchanged through our in-platform messaging system
- • Message attachments (photos, documents - stored securely)
- • Inquiry messages about boat availability
- • Email communications and preferences
- • Read receipts and message timestamps
Reviews & Ratings:
- • Star ratings (overall and category-specific)
- • Written review content
- • Review responses
- • Review timestamps
- • Booking relationship (which rental the review is about)
Damage Protection & Disputes:
- • Damage claim submissions and evidence photos
- • Dispute evidence and documentation
- • Claim amounts and resolution details
- • Payment status for approved claims
1.2 Information Collected Automatically
When you use our platform, we automatically collect certain technical information:
- Usage Data: Pages visited, features used, time spent on platform, search queries
- Device Information: Browser type, operating system, device type, screen resolution
- Log Data: IP address, access times, referring URLs, error logs
- Location Data: Approximate geographic location (from IP address) for search results and local content
1.3 Information from Third Parties
We may receive information from third-party services when you use them in connection with Aquavora:
- Payment Processors (Stripe): Payment verification, transaction success/failure, fraud detection signals
- Authentication Services: If you sign in using third-party authentication (future feature)
- Analytics Providers: Aggregated usage statistics and performance metrics (see Section 6)
2. How We Use Your Information
We Use Your Information To:
🚤 Provide Platform Services
- • Create and manage your account
- • Process bookings and payments
- • Facilitate communication between boat owners and renters
- • Display boat listings in search results
- • Show your profile to other users
- • Enable reviews and ratings
- • Process damage claims and disputes
💰 Process Payments & Payouts
- • Process secure payments through Stripe
- • Calculate platform fees and owner earnings
- • Manage automatic payouts to boat owners
- • Handle refunds and cancellations
- • Track damage claim payments
- • Generate financial records for tax compliance
📧 Send Important Communications
- • Booking confirmations and reminders
- • Payment confirmations and receipts
- • Booking request notifications for owners
- • Cancellation notices and refund updates
- • Damage claim notifications
- • Review prompts and reminders
- • Account security alerts
- • Platform updates and policy changes
🛡️ Safety, Security & Trust
- • Verify user identities and prevent fraud
- • Detect and prevent prohibited conduct
- • Enforce our Terms of Service
- • Calculate completion rates and performance metrics
- • Track cancellation patterns and penalties
- • Monitor for platform abuse or circumvention
- • Resolve disputes between users
- • Investigate damage claims and evidence
📊 Improve Our Platform
- • Analyze usage patterns and trends
- • Develop new features and functionality
- • Optimize search results and recommendations
- • Improve platform performance and reliability
- • Conduct research and testing
- • Fix bugs and technical issues
⚖️ Legal Compliance
- • Comply with legal obligations and regulations
- • Respond to law enforcement requests
- • Enforce our legal rights and agreements
- • Prevent illegal activity
- • Generate tax documentation (1099 forms for owners)
Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), we process your personal data based on:
- Contract Performance: Processing necessary to provide our services and fulfill our contract with you
- Legitimate Interests: Improving our platform, preventing fraud, ensuring security
- Legal Obligations: Complying with applicable laws and regulations
- Consent: Where required by law, such as for marketing communications (you can withdraw consent anytime)
4. Data Retention
How Long We Keep Your Information
We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this Privacy Policy. Specific retention periods vary by data type:
Account Information:
Retained for the life of your account plus 7 years after account deletion (for legal compliance, tax records, and dispute resolution).
Booking & Transaction Data:
Retained for 7 years after transaction date for tax compliance (IRS requirements), financial reporting, and potential disputes.
Messages & Communications:
Retained for 2 years after booking completion for dispute resolution and quality assurance, then permanently deleted unless part of an active dispute.
Reviews & Ratings:
Retained indefinitely as they form part of users' public reputation on the platform. You may request removal in certain circumstances (see Your Rights section).
Damage Claims & Disputes:
Retained for 7 years after resolution for legal compliance and future reference.
Technical & Usage Data:
Log files and usage analytics are typically retained for 90 days for security monitoring and platform improvement, then aggregated or deleted.
After Retention Periods: When information is no longer needed, we securely delete or anonymize it. Some backup copies may persist in our systems for disaster recovery purposes but are not actively used.
Legal Holds: If information is subject to legal proceedings, investigations, or regulatory requirements, we may retain it longer than the standard retention period.
5. Your Privacy Rights
You Have Rights Over Your Personal Data
Depending on your location, you have certain rights regarding your personal information:
5.1 Rights for All Users
✅ Access Your Information
Request a copy of the personal information we hold about you. Most information is accessible directly through your account dashboard.
✏️ Update Your Information
Update your profile, contact information, and preferences directly in your account settings at any time.
🗑️ Delete Your Account
Request account deletion at any time. Note: Some information may be retained for legal compliance (see Data Retention).
📧 Opt Out of Marketing
Unsubscribe from promotional emails using the unsubscribe link in any marketing email. Note: You'll still receive transactional emails (booking confirmations, etc.).
📩 Data Portability
Request a copy of your data in a portable format (e.g., JSON or CSV) that you can transfer to another service.
5.2 Additional Rights (GDPR - European Users)
If you are located in the European Economic Area (EEA), UK, or Switzerland, you have additional rights under GDPR:
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data in certain circumstances
- Right to Restriction of Processing: Limit how we use your data in certain situations
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent for processing based on consent (doesn't affect prior lawful processing)
- Right to Lodge a Complaint: File a complaint with your local data protection authority
5.3 Additional Rights (CCPA - California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request details about the categories and specific pieces of personal information we collect
- Right to Delete: Request deletion of your personal information (subject to legal exceptions)
- Right to Opt Out of Sale: We do not sell personal information, but you have the right to opt out if practices change
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
📧 How to Exercise Your Rights
To exercise any of these rights, contact us at:
Subject line: "Privacy Request - [Your Request Type]" (e.g., "Privacy Request - Data Access")
We will respond to your request within 30 days. For security purposes, we may need to verify your identity before processing your request.
5.4 Limitations on Rights
Note: These rights are not absolute. We may deny requests that are manifestly unfounded, excessive, or where we have compelling legal grounds to continue processing. For example, we may retain financial records for tax compliance even after account deletion.
7. Third-Party Services
External Services We Use
Aquavora integrates with several trusted third-party services to provide core functionality. These services have their own privacy policies that govern how they handle your data:
Stripe (Payment Processing)
What they do: Process all payments, payouts, refunds, and Connect account management for boat owners.
Data shared: Payment information, transaction details, bank account info (for owners), identity verification data
Security: PCI DSS Level 1 certified (highest security standard). We never store your credit card details - Stripe handles all payment data.
View Stripe Privacy Policy →Supabase (Database & Storage)
What they do: Secure cloud database storage for all platform data, file storage for photos and attachments, real-time data synchronization
Data shared: All platform data (profiles, bookings, messages, photos, etc.)
Security: Enterprise-grade PostgreSQL with encryption at rest and in transit. Row-level security policies protect your data.
View Supabase Privacy Policy →Vercel (Hosting & Infrastructure)
What they do: Host our platform, provide CDN for fast global access, infrastructure monitoring
Data shared: Technical data (IP addresses, access logs, performance metrics)
Security: Automatic HTTPS encryption, DDoS protection, SOC 2 Type II certified
View Vercel Privacy Policy →Resend (Email Delivery)
What they do: Deliver transactional emails (booking confirmations, notifications, etc.)
Data shared: Email addresses, names, email content (booking details, notifications)
Security: Encrypted email transmission, delivery tracking, bounce handling
View Resend Privacy Policy →Google Maps API (Location Services)
What they do: Provide map displays, geocoding (converting addresses to coordinates), location search and autocomplete
Data shared: Location coordinates, search queries, IP address (for geolocation)
Privacy: Google Maps API usage is subject to Google's privacy policy and terms of service
View Google Privacy Policy →Plausible Analytics (Privacy-Focused Analytics)
What they do: Provide privacy-focused website analytics without cookies or personal data collection
Data shared: Aggregated, anonymized page views and traffic statistics only (no personal data, no IP addresses stored)
Privacy: GDPR & CCPA compliant by default. No cookies, no cross-site tracking, no personal data collection. Open source and transparent.
View Plausible Privacy Policy →Important: Our Privacy Responsibilities
While we carefully select and vet third-party services, we are not responsible for their privacy practices. We encourage you to review their privacy policies directly. We contractually require service providers to protect your data and use it only for the purposes we specify.
8. Data Security
How We Protect Your Information
We take data security seriously and implement industry-standard technical and organizational measures to protect your personal information:
🔒 Encryption
- • HTTPS/TLS encryption for all data in transit
- • Database encryption at rest
- • Encrypted password storage (hashed with bcrypt)
- • Secure file storage with access controls
🔐 Access Controls
- • Row-level security policies in database
- • Role-based access control (RBAC)
- • Multi-factor authentication for admin access
- • Principle of least privilege
🛡️ Infrastructure Security
- • Enterprise-grade cloud infrastructure
- • Regular security updates and patches
- • DDoS protection and rate limiting
- • Automated backups and disaster recovery
👁️ Monitoring & Response
- • 24/7 security monitoring
- • Automated threat detection
- • Incident response procedures
- • Regular security audits
Payment Security
PCI DSS Compliance Through Stripe
All payment processing is handled by Stripe, which is PCI DSS Level 1 certified (the highest level of payment security). We never store your credit card numbers, CVV codes, or sensitive payment information on our servers. Stripe handles all payment data securely on their PCI-compliant infrastructure.
Your Security Responsibilities
While we implement robust security measures, your cooperation is essential:
- Strong Passwords: Use unique, complex passwords (8+ characters with uppercase, numbers, and symbols)
- Keep Credentials Private: Never share your password or account access with others
- Logout on Shared Devices: Always log out when using public or shared computers
- Report Suspicious Activity: Contact us immediately if you suspect unauthorized access
- Update Contact Info: Keep your email address current for security notifications
⚠️ No System is 100% Secure
Despite our best efforts, no security measures are perfect or impenetrable. We cannot guarantee the absolute security of your information. If we become aware of a data breach affecting your personal information, we will notify you in accordance with applicable laws.
Security Incident Response
If we discover a security incident that affects your personal information, we will:
- Notify affected users within 72 hours (or as required by law)
- Provide details about the nature of the breach
- Explain steps we're taking to mitigate harm
- Offer guidance on protective measures you can take
- Cooperate with regulatory authorities as required
9. Children's Privacy
Aquavora is Not for Children
Aquavora is intended for users who are 18 years of age or older. We do not knowingly collect personal information from children under 18.
COPPA & Age Restrictions
Our platform complies with the Children's Online Privacy Protection Act (COPPA) and international regulations regarding children's data:
- Age Requirement: You must be at least 18 years old to create an Aquavora account or use our services
- Age Verification: By creating an account, you represent and warrant that you are 18 or older
- Parental Consent Not Offered: We do not offer mechanisms for parental consent because our services are not designed for users under 18
If We Learn of Underage Users
If we become aware that we have collected personal information from anyone under 18 years of age, we will:
- • Immediately delete the account and associated data
- • Not use the information for any purpose
- • Not disclose the information to third parties (except as required by law)
- • Take reasonable measures to prevent future underage access
Reporting Underage Users
If you believe someone under 18 has created an account on Aquavora, please contact us immediately at:
Subject: "Underage User Report"
10. International Data Transfers
Cross-Border Data Processing
Primary Location: United States
Aquavora is based in Minnesota, United States. Our servers and infrastructure are primarily located in the United States. By using our platform, you acknowledge and agree that your personal information may be transferred to, stored, and processed in the United States.
For European Users (GDPR)
If you are located in the European Economic Area (EEA), UK, or Switzerland:
- Legal Basis: Data transfers to the US are based on your consent and our legitimate interests in operating a global platform
- Safeguards: We implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) with service providers
- Technical security measures (encryption, access controls)
- Regular data protection assessments
- Data Protection Rights: You maintain all rights under GDPR regardless of where data is processed
- Supervisory Authority: You can file complaints with your local data protection authority
International Service Providers
Some of our service providers operate globally and may process data in multiple countries:
- Stripe: Processes data globally with servers in US, EU, and other regions
- Supabase: Data stored in US data centers with global CDN delivery
- Vercel: Edge network with global points of presence
Note: The United States may not provide the same level of data protection as your home country. However, we ensure appropriate safeguards are in place to protect your information regardless of where it is processed.
Your Consent to Transfer
By creating an account and using Aquavora, you:
- Consent to the transfer of your personal information to the United States and other countries
- Acknowledge that US and other countries' laws may differ from your home country
- Agree that disputes will be governed by Minnesota law (see Terms of Service)
11. Changes to This Privacy Policy
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
How We Notify You of Changes:
- • Material Changes: We will notify you by email and/or prominent notice on the platform at least 30 days before changes take effect
- • Minor Changes: Posted to this page with updated "Effective Date" at the top
- • Acceptance: Continued use of the platform after changes constitute acceptance of the updated policy
Review Regularly
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. You can always find the current version at:
Your Options After Changes
If you don't agree with changes to this Privacy Policy:
- You may stop using the platform
- You may request deletion of your account (see Section 5 - Your Privacy Rights)
- You may exercise any applicable data protection rights
Important: If you continue to use Aquavora after we post changes, you accept the updated Privacy Policy and any information practices it describes.
Previous Versions
If you would like to review a previous version of this Privacy Policy, please contact us at info@aquavora.com.
12. Contact Us
Questions About This Privacy Policy?
For all privacy inquiries, data requests, security reports, and general support:
📋 Privacy Requests
Subject: "Privacy Request - [Access/Delete/Modify]"
Data access requests, deletion requests, GDPR/CCPA inquiries
🔒 Security Issues
Subject: "Security Report - [Brief Description]"
Report security vulnerabilities or suspected breaches
👤 Underage Users
Subject: "Underage User Report"
Report accounts of users under 18 years old
💬 General Support
Subject: [Your topic]
Platform questions, technical support, account issues
Aquavora LLC
Plymouth, Minnesota, United States
© 2025 Aquavora. All rights reserved.
Response Time: We typically respond to privacy inquiries within 30 days as required by applicable law. Urgent security matters are prioritized.
Related Information
By using Aquavora, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Last updated: November 8, 2025