Dive for everyone!
Last updated: May 19, 2026
Privacy Policy
This policy explains what data we collect, how we use and share it, and your rights, in line with applicable privacy laws (including Brazil’s LGPD where relevant) and information security best practices.
Personal data protection
We process personal data for specific purposes, with transparency, security, harm prevention, and accountability. We collect only what is needed to run divefy, bookings, communications, and service improvements.
Legal bases may include contract performance, legitimate interests (with balancing of rights), legal obligations, and consent where required.
You can exercise data-subject rights through the channels in this page and the Account & data area in the account app.
Privacy contact: use the support channels listed at the end of this document.
Data we collect
Account and profile: name, email, phone, ID when requested, photo, certifications, and preferences you provide.
Authentication: identifiers and metadata from your login provider (e.g. Google via Firebase Authentication).
Bookings and interactions: events, operators, participant names you enter, booking history, and terms acceptance.
Technical data: IP address, browser type, device, language, and similar identifiers (see our Cookie Policy for cookies and local storage).
Location: when you allow it, to show nearby events or maps.
Communications: push notifications, transactional email, and support records.
Sensitive data protection
We avoid collecting special categories of personal data (such as health or biometric data) unless strictly necessary and properly justified. When sensitive information is voluntarily provided (e.g. booking notes or dive certifications), we apply restricted access controls, encryption in transit (HTTPS/TLS), and limited retention.
Internal access only for roles that need to operate the service or meet legal duties.
We do not sell sensitive data or use it for behavioral advertising.
If an incident poses risk to individuals, we take containment and notification measures as required by law.
How we use data
Provide and improve the service (authentication, bookings, maps, notifications, operator tools).
Maintain security, prevent fraud and abuse, and resolve incidents.
Measure aggregated usage, performance, and reliability.
Communicate important updates about your account, bookings, and privacy.
Comply with legal, regulatory, and lawful authority requirements.
Application monitoring and infrastructure
To keep the platform stable and secure, we use observability and protection tools that may process IP addresses, requested URLs, error identifiers, and technical metadata:
Sentry (or equivalent): application errors and performance, with minimized data and no intent to capture unnecessary form content.
Cloudflare (or similar CDN/WAF): attack protection, caching, and edge delivery.
Server and database logs: limited retention for security audit and troubleshooting.
These activities rely on legitimate interest in operating and securing the service.
Sharing
We may share data with event operators to fulfill bookings and with vendors that help us run the platform (hosting, email, authentication, analytics, monitoring), under appropriate contracts or safeguards. We do not sell your personal data.
User action auditing
We log relevant security and operational events—such as sign-in, profile changes, bookings, terms acceptance, invites, data export, or account deletion—with timestamp, user identifier, and action type. These records support fraud prevention, support, legal compliance, and dispute resolution. Internal access is restricted and retention follows our retention policy.
Retention
We keep data as long as needed for the purposes described, rights defense, and legal obligations (e.g. booking or tax records). After account deletion, identifiable data is removed or anonymized as described in the deletion section; backups may persist for a limited period before routine purge.
Data export
In the Account & data section of the account app, you can request an export of your personal data in a structured format (e.g. JSON). The request is processed asynchronously; you will be notified when a secure, time-limited download link is available. The file may include profile, preferences, certifications, follow relationships, and activity metadata stored on the platform.
Account deletion and anonymization
You can request permanent account deletion in the same Account & data area. After you confirm:
We end your session and start deletion in our systems; the authentication account (Firebase) is removed and you cannot sign in again with the same credentials.
Identifiable personal data in your profile is deleted or replaced with irreversibly anonymized values.
Booking and sales records may be kept in anonymized form (no direct link to you) for legal duties, audit, and operator operational history.
We send email confirmation when the process completes, when applicable.
Deletion is irreversible; create a new account if you wish to use the service again.
Your rights
Confirm whether we process your data and access your personal data.
Correct incomplete, inaccurate, or outdated data.
Request anonymization, blocking, or deletion of unnecessary or unlawfully processed data.
Request portability to another provider where applicable.
Withdraw consent and obtain information on sharing and consequences of refusal.
Export or delete your account via the self-service tools above or privacy contact.
Contact
For questions about privacy, contact us through the support channels listed in the app.