Privacy & accounts
Browse freely. Create an account only if you want saved beaches and preferences across devices.
Updated 5 October 2026. Controller: BestSwell operator — account setup pending. Contact: Published when account registration is enabled.
Information we handle
For accounts we use your username, email, managed authentication identity, skill level, saved beach IDs, preferences, verification status, terms acceptance version/time and separate email-alert preference. Supabase Auth handles passwords, verification codes and Google/Apple sign-in. BestSwell does not store your password. Login credentials pass securely through our server to Supabase. Provider tokens stay server-side; your browser receives an essential secure session cookie.
Why we use it
We process account and preference information to provide the account service you request (performance of our agreement). We use limited security records and rate limits to prevent abuse (legitimate interests). Optional surf-alert emails require a separate opt-in that can be withdrawn. Agreeing to Terms is not consent to marketing. Alerts and surf-report submissions are not active in this release.
Location and browser storage
Your location is requested only when you choose the location button. Coordinates remain in browser memory and are not uploaded or stored in your account. Optional browser storage remembers device preferences when enabled. While signed in, saved beaches and preferences are also stored on our server. Clearing browser data does not delete your account data.
Providers and sharing
OVH hosts the website and account preference database in London, United Kingdom. Our Supabase authentication project is configured in Paris, France; a project region does not mean all provider support and subprocessor processing stays there. Resend sends verification and recovery emails from Ireland (eu-west-1), but stores customer email data, including message content and delivery logs, in the United States. Cloudflare Turnstile processes browser and connection signals to prevent abuse and may process data outside the UK and EEA. Google and Apple receive sign-in information only if their login options are enabled and you choose them. We do not sell account data.
International processing
Provider processing agreements describe their international-transfer safeguards, including Standard Contractual Clauses and the UK Addendum where applicable. See the Supabase agreement, Resend agreement and Cloudflare agreement. Resend also describes its participation in the Data Privacy Framework, including the UK Extension. These arrangements do not mean that all service data stays in the UK or Europe.
Cookies and security
Essential HttpOnly, Secure, SameSite cookies maintain a login session and an OAuth verification flow. Session cookies and corresponding records expire within one hour; OAuth flows within ten minutes. Rate-limit records use an HMAC identifier rather than a plain IP address and expire after fifteen minutes. Expired records are removed by daily cleanup and during account requests. The application does not log passwords, verification codes, session tokens or normal browsing histories. Nginx access logging is disabled for account API routes, and their Nginx error logging is restricted to critical errors. Other Nginx logs rotate daily when non-empty, retaining 14 rotated files; this is not a guaranteed 14-day expiry because empty logs do not rotate. Host diagnostic journals have separate settings.
Retention and control
Your account identity, saved preferences and terms acceptance remain while you use the account. You can change saved beaches and preferences. You can request an export, correction or account deletion through the contact above. We verify ownership before acting. Deletion includes the managed authentication record and local account records; a minimal record may be retained where required for a legal obligation or an active dispute. The current local server backup script removes daily archives using an age threshold of -mtime +2 and weekly archives using -mtime +14, subject to its safeguards. Daily archives are also uploaded to an operator-controlled Windows backup destination. That uploader has no automatic remote expiry rule; copies can remain until removed separately. We have not yet verified that the new local account database is included in those server archives. Backups are not used for routine account access. Resend states that email and log data are retained for 30 days on its Free, Pro and Scale plans, with backups persisting for 7 days; see Resend retention details. Other provider-held records follow their respective published retention arrangements.
Your rights
Depending on the circumstances, you can request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. You can withdraw optional email-alert consent without affecting earlier lawful processing. Contact us with a request; you may also complain to the UK Information Commissioner’s Office.
Age and changes
Account registration is for people aged 16 or over. This notice will be updated before adding SMS, app notifications, active reports, advertising or analytics.
Enable JavaScript to explore the cached hourly forecasts, charts and nearby surf windows. The spot directory and information links remain available below the forecast.