PRIVACY
Privacy Policy
Last updated: July 2026
This legal page is currently provided in English.
WorththeRide respects your privacy. This Privacy Policy explains what information we collect, how we use it, how it may be stored, who it may be shared with, and the choices you have when using the WorththeRide website and app.
WorththeRide is a surf decision-support service. It helps users compare surf conditions, rider context, travel effort and nearby alternatives. Some information is processed to provide those features. If you create an account, certain information you choose to save is stored with trusted service providers so it can be available when you sign in.
This policy is written for users in the United Kingdom and Europe, including users checking or planning surf sessions in Portugal.
1. Who we are
WorththeRide provides the website and app described in this policy.
In this policy, “WorththeRide”, “WtR”, “we”, “us” and “our” refer to the WorththeRide service.
For privacy questions, data requests, corrections or deletion requests, contact:
2. What this policy covers
This policy applies to:
- the WorththeRide website;
- the WorththeRide web app;
- Surf Now, Surf Later, Spot Explorer and related surf-decision features;
- guest preferences and browser-local information;
- account creation, login and account profile features;
- account-backed saved spots, rider setup, saved sessions and planned sessions;
- contact, feedback and community messages sent to us;
- lightweight website analytics, when enabled;
- payment, donation, subscription or support features, if introduced.
This policy does not apply to third-party websites or services that WtR links to, such as forecast providers, beach cameras, official beach information, map services, water-quality references, payment providers, social platforms or other external links. Those services have their own terms and privacy policies.
3. Information we may collect
The information we collect depends on how you use WtR and whether you use the service as a guest or with an account.
Information you provide directly
You may provide information such as:
- your email address, if you contact us or create an account;
- account login information needed to create and secure your account;
- optional display name;
- rider settings, such as skill level, preferred surf-quality or wave preferences, travel distance, distance unit, language preference or broad base-location label;
- manual location information, such as a town, area or starting point;
- saved spots;
- saved surf-session summaries;
- planned session summaries;
- session status or outcome information, such as whether you went to a session;
- messages sent through the Contact form or by email, including reports of mistakes, missing beaches, broken links, facility corrections or local surf knowledge;
- support, donation, subscription or payment-related information, if those features are introduced.
Please avoid putting sensitive personal information into Contact form submissions, emails, feedback messages or correction reports unless it is genuinely necessary.
Contact form information
When the Contact form is enabled, it collects your email address, selected reason, message, interface language and, where applicable, an Other topic or optional business or organisation and website or social-profile text. Website or social-profile text is not fetched or previewed by the app.
The form also uses technical anti-abuse information, including a form-timing value, an invisible honeypot field and a Cloudflare Turnstile token. Cloudflare may process browser, device, network, IP-address and security signals to provide Turnstile. The backend verifies the token and may include a trusted client IP when one is available through the protected Cloudflare route.
Short-lived, process-local abuse counters use a client-IP identity (a validated Cloudflare IP when available, otherwise the socket peer) and a keyed, non-reversible value derived from the normalised email address. The submitted address and derived limiter value are not written to Contact-specific logs.
Accepted submissions are delivered through the configured SMTP or email provider to a fixed WorththeRide support inbox. The submitted email address is used as the Reply-To address and is included in the delivered message so a human can respond. The application does not create a dedicated Contact-message database or store submissions in Supabase or browser storage. The form accepts no attachments and sends no automatic acknowledgement.
Contact-specific structured application logs exclude the submitted email address, message, optional Contact text and Turnstile token. Infrastructure access and security logs may still contain standard network and request metadata. The configured email provider and support inbox still process and may retain accepted messages for delivery, response, issue handling, abuse prevention and reasonable operational records.
Guest browser information
If you use WtR without an account, some information may be stored locally in your browser so the app can work and remember choices on that device.
This may include:
- selected language or units;
- temporary form state;
- local browser preferences;
- device-only profile or saved information created before account features were introduced;
- temporary app state needed for the service to work.
Guest browser information may not sync across devices. It may be lost if you clear your browser data, use a different browser, change device, use private browsing, or if local storage is otherwise removed. Device-only information is not automatically uploaded or synced to your account.
Location information
WtR may use location information when you provide it or allow it.
This may include:
- a manually entered location;
- a selected town, area or starting point;
- browser geolocation, if you give permission;
- approximate distance or travel context used to support surf decisions;
- a broad saved base-location label in your account rider setup.
WtR does not need background location tracking. Location is used to support the surf decision you request, such as estimating whether a trip to a surf spot is worth making.
If browser geolocation is used, it is used for the feature you request. WtR does not store precise GPS coordinates in your account profile and does not use precise GPS location for website analytics.
You can deny or revoke browser location permission in your browser or device settings.
Account information
If you create an account, WtR may store information needed to create, secure and operate your account.
This may include:
- email address;
- authentication identifiers;
- optional display name;
- rider setup and preferences;
- saved spots;
- saved sessions;
- planned sessions;
- account settings, such as language or distance unit;
- account deletion request marker, if you request account deletion.
WtR does not currently offer social login in the public product. If social or third-party login options are introduced later, this policy should be updated to explain what information may be shared by that login provider.
Technical information
When you use WtR, we or our service providers may process technical information needed to operate, secure and improve the service.
This may include:
- IP address;
- browser and device type;
- operating system;
- pages or features requested;
- timestamps;
- server logs;
- error reports;
- security and abuse-prevention signals.
Website analytics information, when enabled
When analytics are enabled, we aim to collect limited website traffic information to understand how the site is used and how it performs.
This may include:
- pages visited;
- referrers;
- broad location, such as country or region;
- broad device or browser information;
- basic performance information.
At the time of this update, WtR does not use product or funnel event tracking, session replay, autocapture, form capture or advertising cookies in the public product.
We do not intend to send precise GPS location, raw typed location or search text, raw session notes, full rider profile data, full session payloads, display names, email addresses or unnecessary personal information to website analytics tools.
Payment and support information, if introduced
If payment, donation, subscription or support features are introduced, payments will be handled by third-party payment providers.
WtR does not store full payment card details directly. Payment providers may process payment information under their own terms and privacy policies. WtR may receive limited information such as payment status, transaction reference, support status, subscription status or billing-related records needed to provide the feature and keep appropriate records.
Forecast and surf-condition information
WtR uses forecast and marine-condition information from third-party data providers.
Forecast providers may process request information needed to return forecast data, such as coordinates, date, time or forecast parameters. WtR does not intend to send account information, saved session details, display names or rider notes to forecast providers unless required for a feature and clearly explained.
4. How we use information
We use information to provide, maintain, secure and improve WtR.
This includes using information to:
- provide Surf Now, Surf Later and Spot Explorer features;
- calculate surf decisions based on conditions, rider context, travel effort and alternatives;
- remember your settings and preferences;
- create, secure and operate accounts;
- save and retrieve account-backed spots, rider setup, saved sessions and planned sessions;
- provide account controls, such as display name, sign out and account deletion request;
- respond to emails, feedback and correction requests;
- investigate mistakes, broken links or missing beaches;
- improve reliability, performance and usability;
- monitor errors and fix bugs;
- secure the service and prevent abuse;
- understand broad website traffic and performance when analytics are enabled;
- process payment, donation, subscription or support features, when introduced;
- comply with legal, accounting or regulatory obligations where required.
WtR may generate automated surf-decision recommendations, such as “Worth it”, “Borderline” or “Not worth it”. These outputs are decision-support information only. They do not make legal, financial or similarly significant decisions about you.
5. Legal bases for using personal information
Where UK or EU data protection law applies, we rely on different legal bases depending on the type of information and how it is used.
| Purpose | Type of information | Legal basis |
|---|---|---|
| Providing surf-decision features | Rider settings, selected location, surf search inputs, travel context and feature inputs | Contract or steps requested by you; legitimate interests in operating the service |
| Remembering guest choices in your browser | Local browser storage, language/unit preferences, temporary app state and device-only preferences | Legitimate interests; consent where required for non-essential storage |
| Account creation and login | Email address, authentication identifiers and account session information | Contract or steps requested by you |
| Saving account data across devices | Display name, rider setup, saved spots, saved sessions, planned sessions and account settings | Contract; legitimate interests in providing a useful account service |
| Browser geolocation | Location permission and location data used for the requested feature | Consent |
| Responding to contact, feedback or correction messages | Email address, selected reason, message, language and applicable optional topic or business details | Legitimate interests; contract or steps requested by you where relevant |
| Website analytics, when enabled | Page visits, referrers, broad location, device/browser information and basic performance information | Consent where required; legitimate interests where lawful and privacy-safe |
| Security, abuse prevention and debugging | IP address, logs, error reports and security signals | Legitimate interests in protecting and maintaining the service |
| Payments, donations, subscriptions or support features, if introduced | Payment status, transaction reference, billing/support status | Contract; legal obligation where accounting rules apply |
| Legal compliance | Records required by law | Legal obligation |
Where we rely on consent, you may withdraw consent where technically available or by contacting us. Withdrawing consent does not affect processing that happened before consent was withdrawn.
6. Guest use, browser storage and accounts
You can use Surf Now, Surf Later and Spot Explorer without creating an account.
Guest use
When you use WtR without an account, the app may store limited information in your browser so it can work on that device.
This means:
- the information may only be available on that browser and device;
- it may not be recoverable if deleted;
- it may not sync to another device;
- clearing browser storage may remove it.
Some device-only information created before account features were introduced may still exist in your browser. It is not automatically uploaded, synced or migrated to your account.
Account use
If you create an account, you can save certain information so it is available when you sign in.
This may include:
- optional display name;
- rider setup and preferences;
- saved spots;
- saved sessions;
- planned sessions;
- app preferences such as language or distance unit;
- account deletion request marker, if you request account deletion.
Account data may be stored by trusted account, authentication, database, hosting or infrastructure providers used to operate WtR.
7. Location data
Location is used to help WtR answer practical surf questions, such as whether a trip to a spot is worth making.
You may provide location by:
- entering it manually;
- selecting a location;
- allowing browser geolocation.
Browser geolocation only works if you allow it. You can turn it off or revoke permission through your browser or device settings.
WtR does not need background location tracking. We do not intend to use precise GPS location for website analytics.
Location data may be processed by WtR and its service providers to calculate travel context, distance, nearby spots or surf-decision outputs.
8. Cookies, local storage and similar technologies
WtR may use cookies, local storage, session storage or similar technologies.
These technologies may be used to:
- keep the app working;
- remember preferences;
- store guest settings or temporary app state;
- maintain login sessions;
- protect the service from abuse;
- understand broad website traffic and performance when analytics are enabled.
Essential storage
Some storage is necessary for the app to work properly, remember user choices, secure the service or maintain account sessions.
Non-essential analytics
When analytics are enabled, they may use cookies or similar technologies to understand how people use WtR. Where consent is required, analytics should only be enabled in line with applicable consent requirements.
At the time of this update, WtR does not use session replay, autocapture, form capture or advertising cookies in the public product.
Browser controls
Most browsers let you delete or block cookies, local storage and similar technologies. If you block or clear them, some WtR features may not work properly, and guest-only saved information may be lost.
Advertising cookies
WtR does not currently use advertising cookies.
9. What we do not do
WtR is designed to avoid unnecessary data collection.
We do not intend to:
- sell your personal information;
- use precise GPS location for website analytics;
- track your location in the background;
- use session replay;
- use autocapture or form capture in the public product;
- use product or funnel event tracking in the public product at this stage;
- collect full payment card details directly;
- store precise GPS coordinates in account profiles;
- store raw provider payloads in account profiles;
- store raw typed location or search text for analytics;
- store raw session notes or free-text notes in account-backed V2.1 profile features;
- send display names, email addresses, full rider profiles or full session payloads to analytics tools;
- build advertising profiles from your surf decisions;
- let raw user feedback automatically change surf scoring or spot data without review.
10. Third-party service providers
WtR uses third-party service providers to operate the service.
These may include providers for:
- website and app hosting;
- backend hosting and infrastructure;
- domain, security and performance services;
- forecast and marine-condition data;
- account, authentication and database features;
- lightweight website analytics, when enabled;
- anti-abuse and security verification, including Turnstile;
- contact email delivery and inbox handling;
- payment, donation, subscription or support features, when introduced.
Service providers should only receive the information needed to provide their service.
For example, a forecast or marine-condition provider may need coordinates, date, time or forecast parameters to return forecast information. An account or database provider may process login and saved account information so your account works. A payment provider may need payment and transaction information if payment features are introduced.
For Contact, the anti-abuse provider may process a verification token and technical security signals, while the configured email provider and fixed support inbox process the accepted email address, message and applicable optional details needed to deliver and answer the enquiry.
Third-party providers process information under their own terms and privacy policies where applicable.
11. External links and third-party websites
WtR may include links to external websites and services, such as forecast sources, beach cameras, official beach information, water-quality references, useful surf links, payment providers, support pages or social platforms.
External links are provided for convenience and context. They do not mean that WtR controls, endorses or is responsible for those third-party websites, services, content, privacy practices or security.
If you use an external link, the information you provide to that service is handled under that service’s own terms and privacy policy.
12. When we may share information
We may share information:
- with service providers needed to operate WtR;
- with anti-abuse and email providers needed to verify and deliver a Contact submission to the fixed support inbox;
- when you ask us to provide a feature that requires sharing information;
- to process payments, donations, subscriptions or support features, if introduced;
- to respond to legal requests or comply with law;
- to protect WtR, users or the public from fraud, abuse, security threats or harm;
- in connection with a reorganisation, transfer or sale of the service, if applicable;
- with your consent.
We do not sell personal information.
13. International processing
Some service providers may process information outside your country, including outside the United Kingdom or European Economic Area.
Where required, we aim to rely on appropriate safeguards, such as adequacy decisions, standard contractual clauses or equivalent protections used by the relevant service provider.
14. How long we keep information
We keep information only for as long as needed for the purposes described in this policy, unless a longer period is required by law.
Retention may depend on the type of information:
- guest browser data remains in your browser until you remove it, the app removes it, or the browser clears it;
- account data is generally kept while your account remains active;
- saved spots, saved sessions, planned sessions, rider setup and account settings may be kept until you delete the relevant item, update it, request account deletion, or close your account;
- account deletion request markers may be kept while we process, verify or record the request;
- Contact submissions are not kept in a dedicated application message database, but copies in the configured email provider and support inbox may be kept for as long as needed to respond, manage the issue and keep reasonable operational records;
- technical logs may be kept for a limited operational period for security, debugging and reliability;
- payment, donation, subscription or accounting records, when those features are introduced, may be kept for as long as required by law;
- analytics data, when enabled, may be kept according to the settings and retention period of the analytics provider.
If exact retention periods are not set, we use criteria such as the age of the data, the reason it was collected, whether it is still needed, legal requirements, security needs and whether deletion is technically possible.
Some information may remain in backups or archived records for a limited period after deletion from active systems. Where this happens, it will not be used for normal service purposes and will be removed or overwritten according to the relevant backup or retention process.
After an account deletion request, we may retain limited information where needed for security, fraud prevention, troubleshooting, legal compliance, accounting, dispute resolution or enforcement of our terms.
15. Your rights and choices
Depending on where you live and how your information is used, you may have rights over your personal information.
These may include the right to:
- access personal information we hold about you;
- correct inaccurate information;
- request deletion;
- restrict certain processing;
- object to certain processing;
- request portability of certain information;
- withdraw consent where processing is based on consent;
- complain to a data protection authority.
To make a request, contact:
We may need to verify your identity before responding to some requests.
If you are in the UK, you may also have the right to complain to the Information Commissioner’s Office. If you are in the EU or EEA, you may have the right to complain to your local data protection authority.
16. How to clear or delete your data
Guest browser data
If you use WtR without an account, you can remove local browser information by:
- clearing site data, cookies or local storage in your browser;
- using a different browser profile or private browsing mode;
- using any in-app remove controls that remain available for device-only data.
Clearing local browser data may permanently remove guest-only information. WtR may not be able to recover local-only data.
Account data
If you have an account, you can delete some saved account information from within the app, such as saved spots, saved sessions or planned sessions where controls are available.
You can request account deletion from the Account area or by contacting:
Account deletion is currently handled as a request. Requesting deletion does not instantly delete your login account or all associated records. We may need to verify the request and process it manually.
Some information may be retained where required for legal, security, accounting, troubleshooting or dispute-resolution reasons.
17. Security
We use reasonable technical and organisational measures to protect information handled by WtR.
These may include:
- HTTPS;
- access controls;
- secure hosting providers;
- limited access to account or operational systems;
- monitoring for errors, abuse or security issues;
- avoiding unnecessary personal data collection.
No online service is completely secure. We cannot guarantee that unauthorised access, loss, misuse or alteration will never occur.
You are responsible for keeping your account login details safe when you have an account.
18. Children and younger surfers
WtR is not designed for children under 13.
If you are under 18, you should use WtR with guidance from a parent, guardian, coach or responsible adult, especially when making decisions about entering the water.
Surfing involves real-world risks. WtR provides decision-support information, but it does not replace adult supervision, local safety advice, lifeguards, flags, signs or personal judgement.
If you believe a child has provided personal information to WtR without appropriate permission, contact:
19. Marketing communications
Sending a Contact form submission does not subscribe you to marketing. It is used to respond to the enquiry, and the form sends no automatic reply. Marketing email would require a separate, explicit request or another lawful basis.
If marketing emails are introduced, we will provide a way to opt out where required.
Service-related emails, such as account, security, welcome, onboarding or support messages, may still be sent when necessary.
20. Changes to this policy
We may update this Privacy Policy from time to time.
When we make changes, we will update the “Last updated” date. If changes are significant, we may provide additional notice where appropriate.
21. Contact
For privacy questions, data requests, corrections or deletion requests, contact:
