ScubaDR

Privacy Policy

Last updated: May 31, 2026
This Privacy Policy explains how Dren Group LLC ("ScubaDR") handles information. It is a general template and not legal advice; consult your own attorney for your jurisdiction (including GDPR/CCPA obligations that may apply to you as the data controller of your customers' data).

1. Roles

For the data your shop and its customers enter ("Customer Data"), your shop is the data controller and ScubaDR is a data processor acting on your instructions. For your own account and billing data, ScubaDR is the controller.

2. Information we collect

3. How we use it

To provide, secure, support and improve the service, process billing, and communicate with you. We do not sell your data, and we do not use Customer Data for advertising.

4. Sharing & subprocessors

We share data only with service providers needed to run ScubaDR: Stripe (payments), Supabase (database & storage), Netlify/Cloudflare (hosting & delivery), and email delivery providers. These act under contract and only as needed.

5. Data isolation & security

Each shop's data is logically isolated with row-level security so that one shop cannot access another's records. Uploaded documents are stored in a private bucket accessible only to your shop. We use encryption in transit and reasonable safeguards, but no system is perfectly secure.

6. Retention

We retain Customer Data while your account is active. After cancellation you have 30 days to export it, after which routine operational data may be deleted.

Records that evidence what happened — signed liability releases, medical questionnaires, and the bookings and audit entries attached to them — are kept for seven (7) years from the date of the dive. We keep these because a claim can be brought long after a dive, and the signed release is what answers it. You may request earlier deletion of anything outside that set, and we will honour it unless we are required to keep the record.

ScubaDR is operated from the United States by Dren Group LLC, a Wyoming limited liability company, and data is processed in the United States.

7. Your choices & rights

You may access, correct, export or delete your account data by contacting us. Your customers' rights requests should be directed to your shop as the controller; we will assist you as processor.

8. Sensitive data

If you upload identity documents, medical information, or waivers, you are responsible for having a lawful basis and any required consents. Only upload what you need.

9. Children

The service is for businesses, not for use by children. Where your customers are minors, you are responsible for obtaining guardian consent as required.

10. International transfers

Data may be processed in jurisdictions where our providers operate. By using the service you acknowledge this transfer.

11. Cookies & consent

ScubaDR uses only strictly necessary cookies and local storage — the secure token that keeps you signed in, plus your interface and language preferences. Under the EU ePrivacy Directive and equivalent guidance, strictly necessary cookies are exempt from prior consent, and US law imposes no cookie-banner requirement, so we do not display a cookie consent banner. We set no advertising, social, or third-party tracking cookies; any analytics run in a cookieless mode. Payment pages may set cookies controlled by Stripe under its own policy. You can view or clear cookies at any time in your browser settings.

12. Changes & contact

We may update this policy; changes are posted here with a new date. Contact: support@scubadr.com.