UK & Ireland
Browse freely. Create an account only if you want saved beaches and preferences across devices.
Updated 6 October 2026. Controller: BestSwell. Contact: contact@bestswell.com.
Information we handle
For accounts we use your username, email, managed authentication identity, skill level, saved beach IDs, preferences, verification status, terms acceptance version/time and separate email-alert preference. Supabase Auth handles passwords, verification codes and Google/Apple sign-in. BestSwell does not store your password. Login credentials pass securely through our server to Supabase. Provider tokens stay server-side; your browser receives an essential secure session cookie.
Sign in with Google
Google sign-in is optional. We request basic identity, email and profile access to authenticate you and create or link your BestSwell account. Google provides an account identifier, your email address and its verification status, and basic profile information such as your name and profile picture. Our authentication provider, Supabase, can retain those details in your managed authentication record. BestSwell's local account records use your authentication identifier and email, together with your chosen BestSwell username, surf profile and preferences. We do not request access to Gmail, contacts, calendars or Google Drive, and Google does not give us your Google password.
We use this information to sign you in and provide the account features you choose, such as saved beaches and preferences, reports and optional alerts. Identity information is processed by Supabase for authentication and by our hosted account service; it is not published with beach reports, sold, sent to Google Analytics or used for advertising. Our providers, international processing and retention arrangements are described below. You can revoke BestSwell's Google connection through your Google Account connections. Revoking access does not itself delete your BestSwell account; contact us to request account deletion as explained below.
Why we use it
We process account and preference information to provide the account service you request (performance of our agreement). We use limited security records and rate limits to prevent abuse (legitimate interests). Optional surf-alert emails require a separate opt-in that can be withdrawn. Agreeing to Terms is not consent to marketing. Optional email alerts and moderated beach reports are now supported when their server configuration is enabled.
Beach reports and email alerts
Beach reports contain a beach ID, observation time, submission time, report category, optional estimated breaking-surf height and wave texture. Signed-in reports are linked privately to your account; guest reports use an HMAC identifier based on the connection address for duplicate and abuse checks. No plain address is stored in the report database. We use the same review policy for guests and accounts. Approved reports can be published with their timestamp without your name. We use retained pre-observation forecasts for accuracy research, with no automatic scoring influence. Pending and rejected reports expire after 90 days; approved reports expire after one year. Forecast comparison evidence expires after 30 days. Delivery records, email content and unsubscribe tokens expire after 30 days. Alert rules and consent remain until you delete them or request account deletion. Rate-limit records expire after their one-hour or one-day abuse window. The forecast includes a satellite coastline map. Imagery loads from Esri when the map approaches the visible area or you open the expanded map; Esri receives connection details and the viewed beach area. The map shows the forecast beach, not your personal location. Camera links open external provider sites under their own policies.
Contact enquiries
If you send our contact form, we use your name, email, optional phone number and message to respond to your enquiry. This is not a marketing sign-up. Please avoid sensitive information. Messages are emailed to our support inbox through Resend, with your email as the reply address. The website does not store message bodies in its database or send them to analytics. Correspondence is retained while handling your enquiry and as needed for follow-up or legal obligations; contact us to request deletion. Cloudflare Turnstile checks submissions for abuse. Limited HMAC identifiers, rate counters and delivery receipts expire within 24 hours and are removed when the form is next used. Backup copies follow the retention arrangements below.
Location and browser storage
Your location is requested only when you choose the location button. Coordinates remain in browser memory and are not uploaded or stored in your account. Device preferences are remembered after you save or dismiss the surf-profile setup, unless browser storage is unavailable or you turn remembering off in Settings. While signed in, saved beaches and preferences are also stored on our server. Clearing browser data does not delete your account data.
Providers and sharing
OVH hosts the website and account preference database in London, United Kingdom. Our Supabase authentication project is configured in Paris, France; a project region does not mean all provider support and subprocessor processing stays there. Resend sends verification and recovery emails from Ireland (eu-west-1), but stores customer email data, including message content and delivery logs, in the United States. Cloudflare Turnstile processes browser and connection signals to prevent abuse and may process data outside the UK and EEA. Google and Apple receive sign-in information only if their login options are enabled and you choose them. We do not sell account data.
International processing
Provider processing agreements describe their international-transfer safeguards, including Standard Contractual Clauses and the UK Addendum where applicable. See the Supabase agreement, Resend agreement and Cloudflare agreement. Resend also describes its participation in the Data Privacy Framework, including the UK Extension. These arrangements do not mean that all service data stays in the UK or Europe.
Site-usage analytics and your choice
BestSwell uses Google Analytics 4 (G-0RTJ79P6FC) by default to understand aggregate visits and use of public pages and improve the website. It is not used by BestSwell for personalised advertising, remarketing, behavioural advertising, decisions about individual visitors or personal profiles. Advertising storage and advertising-data/personalisation states are denied, and our integration disables Google Signals and personalised advertising signals. We do not send account identifiers, usernames, email addresses, passwords, verification codes, personal coordinates or form contents. Page-view URLs are limited to recognised public pages and beach IDs; other query parameters and fragments are stripped.
Google processes public-page events, browser/device information and network information. Google states that GA4 does not log or store IP addresses, although the address is involved in transmitting the request. We have not configured a User-ID or a cross-device account identifier. Session-only analytics cookies still distinguish activity within a browser session; Google-held event data is not made anonymous merely by shortening a cookie lifetime. Google Analytics property settings separately control event retention, sharing and automatic measurement. Aggregated reporting may be retained separately.
You can turn analytics off at any time, free of charge, in . Turning it off stops further measurement on this browser and removes accessible Google Analytics cookies. Previously collected information is not automatically deleted. We honour previous saved rejections. The choice is stored separately from your account and preferences, without a local-storage expiry and with a first-party fallback preference cookie renewed during visits. It applies to this browser; clearing site data removes it. No analytics choice dialog interrupts normal use.
We assess statistical measurement to improve the service on the basis of legitimate interests under UK data-protection law, with a right to object. A storage/access exception applies only when its conditions are met; there is no blanket exemption for every Google Analytics configuration. Google may process information outside the UK and EEA. See our Cookie policy, Google’s privacy policy and Google’s processing terms.
Cookies and security
Essential HttpOnly, Secure, SameSite cookies maintain a login session and an OAuth verification flow. Session cookies and corresponding records expire within one hour; OAuth flows within ten minutes. Rate-limit records use an HMAC identifier rather than a plain IP address and expire after fifteen minutes. Expired records are removed by daily cleanup and during account requests. The application does not log passwords, verification codes, session tokens or normal browsing histories. Nginx access logging is disabled for account API routes, and their Nginx error logging is restricted to critical errors. Other Nginx logs rotate daily when non-empty, retaining 14 rotated files; this is not a guaranteed 14-day expiry because empty logs do not rotate. Host diagnostic journals have separate settings.
Retention and control
Your account identity, saved preferences and terms acceptance remain while you use the account. You can change saved beaches and preferences. You can request an export, correction or account deletion through the contact above. We verify ownership before acting. Deletion includes the managed authentication record and local account records; a minimal record may be retained where required for a legal obligation or an active dispute. The current local server backup script removes daily archives using an age threshold of -mtime +2 and weekly archives using -mtime +14, subject to its safeguards. Daily archives are also uploaded to an operator-controlled Windows backup destination. That uploader has no automatic remote expiry rule; copies can remain until removed separately. We have not yet verified that the new local account database is included in those server archives. Backups are not used for routine account access. Resend states that email and log data are retained for 30 days on its Free, Pro and Scale plans, with backups persisting for 7 days; see Resend retention details. Other provider-held records follow their respective published retention arrangements.
Your rights
Depending on the circumstances, you can request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. You can withdraw optional email-alert consent without affecting earlier lawful processing. Contact us with a request; you may also complain to the UK Information Commissioner’s Office.
Age and changes
Account registration is for people aged 16 or over. This notice will be updated before adding SMS, app notifications or advertising.
Day cards show remaining daylight surf ranges and early / midday / late wind samples. Colours show surf quality. Arrows show travel; compass labels show where wind and waves come from.
—
YOUR DAYLIGHT WINDOW
—
—
Find your moment
OFFSHORE WAVES
——WIND
——SEA LEVEL
—Relative to mean sea levelPRIMARY SWELL
——WATER
—Modelled temperatureDAYLIGHT
—Local UK / Ireland timeAIR
—Modelled temperaturePRECIPITATION
—Amount in the preceding hourOCEAN CURRENT
—Coarse model · not beach ripsWind & swell at the coast
Arrows show travel towards; compass labels show where it comes from. Satellite imagery is a coastline reference, not live surf.
THE SHAPE OF YOUR DAY
Plan your session
Hourly surf quality from our forecasting engine, out of 100.
LOOK BEYOND THE AVERAGE
Compare the models
+
Individual offshore model values; distinct from estimated breaking surf.