Coming soon - Mareel Earth is in private development. The API is live, but accounts are not open yet. Early access: [email protected]

Privacy Policy

This Privacy Policy explains how we collect, use, share and protect Personal Data when you use Mareel Waters, our global tides API and developer platform available at https://mareelearth.com and admin.mareelearth.com (the "Service"). It is provided to satisfy our transparency obligations under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and serves as the privacy policy referenced by the Apple App Store and Google Play for our planned mobile apps.

This document is general information and not legal advice. Defined terms used here (such as API, Endpoint, API Key, Account, Usage Event, Output, Controller, Processor, Subprocessor, Personal Data, Data Subject, Standard Contractual Clauses (SCCs) and Data Privacy Framework (DPF)) carry the meaning given in our Terms of Service and in the GDPR.

1. Who we are (Controller identity and contact)

The Controller of your Personal Data is:

  • [[LEGAL_ENTITY]]
  • Registered address: [[REGISTERED_ADDRESS]]
  • Organisation number: [[ORG_NUMBER]]
  • VAT number: [[VAT_NUMBER]]
  • Privacy contact: [email protected]

For general legal correspondence you may use [email protected], and for product support [email protected]. The Service is operated from Sweden.

2. Data-protection contact and DPO statement

We have assessed our processing and concluded that we are not required to appoint a statutory Data Protection Officer (DPO) under Article 37 GDPR, because our core activities do not consist of large-scale processing of special categories of data or large-scale, regular and systematic monitoring of Data Subjects. We have nonetheless designated a single contact point for all privacy matters: [[DPO_OR_CONTACT]]. You can also reach us at [email protected].

Because the Controller is established in Sweden (within the EU), we are not required to appoint an EU representative under Article 27 GDPR.

3. What Personal Data we process

We deliberately collect as little Personal Data as possible. The categories below describe everything we hold.

Account data

  • Your account email address.
  • A bcrypt hash of your password. We never store your password in plain text.

API credentials

  • API Keys, which are stored only as sha256 hashes. The full key is shown to you once at creation and cannot be retrieved by us afterwards.
  • Emailed verification and password-reset tokens, stored only as sha256 hashes and valid for a limited time.

API Usage Events

For each call to the API we record a Usage Event containing:

  • the Endpoint called,
  • the HTTP status returned,
  • a timestamp,
  • the latitude and longitude coordinates supplied in the request, and
  • the cost of the call (for quota and billing accounting).

Usage Events do not store your IP address and do not store your user-agent.

Cookieless web and marketing analytics

Our first-party web analytics is cookieless and privacy-preserving. For visits to our marketing and documentation pages we may record:

  • a visitor id held in sessionStorage (which clears when the browser tab closes),
  • a daily-salted sha256 hash of your IP address (the salt rotates daily, so the hash cannot be linked across days; we do not store the raw IP),
  • a derived browser, operating-system and device family (we do not store the raw user-agent string),
  • a sanitised referrer (origin and path) and referrer host,
  • your country (derived at the Edge), and
  • a bot flag.

We use no third-party tracker and no third-party analytics processor for this.

4. Query coordinates and Outputs

When you call the API you send coordinates (latitude and longitude) and times. These are generally not Personal Data, and the Outputs we return are modelled tide and (planned) forecast values, not information about you. For full transparency, note that the per-call query coordinates are logged in Usage Events as described above. If you embed personal context in those coordinates (for example a home address), treat them accordingly.

5. Purposes and lawful bases

We process Personal Data only where we have a lawful basis under Article 6 GDPR.

  • Account creation and authentication (email, password hash): performance of our contract with you, Art. 6(1)(b). Providing your email is necessary to create an Account and use the Service.
  • Provisioning and securing API Keys (hashed keys, hashed tokens): performance of the contract, Art. 6(1)(b).
  • API Usage Events for rate-limiting, quota enforcement, abuse prevention, security and capacity planning: our legitimate interests, Art. 6(1)(f).
  • Cookieless first-party web analytics: our legitimate interests in understanding aggregate traffic and improving the Service, Art. 6(1)(f).
  • Billing and subscriptions via Stripe: performance of the contract, Art. 6(1)(b), and compliance with our legal accounting-retention obligations, Art. 6(1)(c) (in particular the Swedish Bookkeeping Act, Bokföringslagen).
  • Transactional email via Resend (verification, password reset, service notices): performance of the contract, Art. 6(1)(b).
  • Optional product and marketing email: your consent, Art. 6(1)(a), which you can withdraw at any time.

6. Legitimate interests and balancing test

Where we rely on legitimate interests (Art. 6(1)(f)), we have carried out a balancing test weighing those interests against your rights and freedoms.

  • For security and abuse prevention, we concluded that processing Usage Events (without IP or user-agent) is necessary to protect the Service and other users, that the data is minimal, and that you would reasonably expect this when consuming an authenticated API.
  • For cookieless analytics, we concluded that the privacy-preserving design (no cookies, no raw IP, daily-rotating salt, no third-party trackers, no cross-day linkage) is minimally intrusive and proportionate to the interest pursued.

You have the right to object to legitimate-interest processing at any time (see Section 11).

7. Recipients and Subprocessors

We do not sell your Personal Data. We share it only with the Subprocessors we need to run the Service:

  • Stripe - payment processing and subscription billing.
  • Resend - transactional email delivery.
  • Cloudflare - CDN, Edge, WAF, bot-management and tunnel.

A current list is maintained on our Subprocessors page.

Importantly, hosting is self-hosted on the operator's own server. Cloudflare acts only as the public Edge; it does not host your account database. We do not use Google Analytics and do not use any third-party analytics processor. We consider this a meaningful privacy advantage: your analytics data is not shared with an advertising or tracking company.

8. International transfers

Some of our Subprocessors (Stripe, Resend and Cloudflare) may process Personal Data in the United States or other third countries. Where Personal Data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, namely the EU Standard Contractual Clauses (SCCs) and/or, where the recipient is certified, the EU-US Data Privacy Framework (DPF). A copy of the relevant safeguards is available on request from [email protected].

9. Cookies

We use a small set of strictly necessary authentication cookies (an encrypted session token plus standard CSRF and callback tokens set by our authentication library) that keep you securely logged in. This is strictly necessary to provide the Service and is not used for tracking. We set no tracking or non-essential cookies, and our analytics is cookieless. For details, see our Cookie Notice.

10. Retention

We keep Personal Data only as long as necessary:

  • Account data (email, password hash, hashed keys): for the life of your Account, then deleted or anonymised within [[ACCOUNT_DELETION_WINDOW]] of a verified deletion request.
  • API Usage Events: retained for the life of your Account (we do not currently run automatic expiry), and deleted or anonymised when your Account is deleted, except where a record must be retained under *Billing and invoice records* below or to establish, exercise or defend a legal claim.
  • Cookieless analytics data: retained for the life of the service. It is not linked to your Account; it contains no raw IP and no raw user-agent (only a daily-salted IP hash and a derived device family), so it does not identify you.
  • Billing and invoice records: retained for 7 years as required by the Swedish Bookkeeping Act (Bokföringslagen).
  • Marketing communications: we do not currently send product or marketing email; if we introduce it, it will be strictly opt-in and described here before any such email begins.

11. Your rights

Under the GDPR you have the right to:

  • access the Personal Data we hold about you,
  • rectify inaccurate or incomplete data,
  • erase your data ("right to be forgotten"),
  • restrict processing in certain circumstances,
  • data portability (receive your data in a structured, commonly used, machine-readable format),
  • object to processing based on legitimate interests, and to object to direct marketing at any time, and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

You can rotate or revoke your API Keys in the developer portal. To update your account email, delete your Account, or exercise any other right, contact [email protected]; see our Account & Data Deletion page for the deletion route. To close your Account and remove your data, see our Account & Data Deletion page. We will respond within the time limits set by the GDPR (generally within one month).

12. Withdrawing consent

Where we rely on your consent (optional product and marketing email), you may withdraw it at any time, for example via the unsubscribe link in any marketing email or by contacting [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

13. Complaints to a supervisory authority

If you believe we have not handled your Personal Data lawfully, please contact us first at [email protected] so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority. Our lead authority is:

  • Integritetsskyddsmyndigheten (IMY) - the Swedish Authority for Privacy Protection
  • Box 8114, 104 20 Stockholm, Sweden
  • https://www.imy.se

If you are in another EEA country, you may instead complain to your local data protection authority.

14. Is provision of data required?

Providing your email address is required to create an Account. Without it we cannot authenticate you, provision API Keys, or provide the Service. Providing optional marketing consent is entirely voluntary and has no effect on your access to the Service.

15. Automated decision-making and profiling

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. Automated controls such as rate-limiting and quota enforcement are operational measures and do not make decisions of that nature.

16. Children and age

The Service is not directed to children. It is a developer product intended for users aged 16 or older (and, where contracting is involved, adults with capacity to enter a contract). We do not knowingly collect Personal Data from minors. If we become aware that we have collected data from a child, we will delete it. If you believe a minor has provided us data, contact [email protected].

17. US state privacy rights (California / CCPA-CPRA and other states)

If you are a resident of California or another US state with a comprehensive privacy law, the following applies to the extent that law covers you.

We do not sell and do not share your personal information as those terms are defined under the California Consumer Privacy Act (CCPA), as amended by the CPRA, and we have not done so in the preceding 12 months. We do not use or disclose your information for cross-context behavioural advertising.

Subject to applicable law, you have the right to:

  • know and access the personal information we have collected,
  • delete your personal information,
  • correct inaccurate personal information, and
  • not be discriminated against for exercising your rights.

To exercise these rights, contact [email protected]. Residents of other US states with similar laws (such as Virginia, Colorado, Connecticut, Utah and Texas) may exercise the equivalent rights granted by their state law in the same way.

18. Security measures

We apply reasonable technical and organisational measures appropriate to the risk, including:

  • bcrypt hashing of passwords,
  • sha256 hashing of API Keys,
  • hashing of emailed verification and reset tokens,
  • TLS encryption in transit,
  • no card or PAN data stored by us (card details are handled by Stripe), and
  • IP hashing (daily-salted) for web analytics.

No method of transmission or storage is completely secure, and we do not claim any specific certification or guarantee. In particular, we make no SOC 2, ISO 27001 or PCI certification claim, no encryption-at-rest guarantee, and no uptime SLA in this Policy.

19. Data breaches

If a personal data breach occurs, we will assess and handle it in accordance with our obligations under Articles 33 and 34 GDPR, including notifying the competent supervisory authority where required (generally within 72 hours of becoming aware) and informing affected Data Subjects where the breach is likely to result in a high risk to their rights and freedoms.

20. Mobile apps

Our iOS and Android apps are planned and not yet released. When they ship, the same data inventory described in this Policy applies, and the apps will provide an in-app path to delete your Account that links to our Account & Data Deletion page. Platform stores (Apple App Store and Google Play) may also collect their own data governed by their respective privacy policies.

21. Changes to this Policy

We may update this Policy from time to time to reflect changes in the Service, our Subprocessors, or the law. We will update the "Last updated" date at the top and, where changes are material, post a notice in the developer portal (and, where we hold a current email address for you, we may also email you). Your continued use of the Service after an update constitutes acceptance of the revised Policy where permitted by law.

Related pages

This Privacy Policy is general information and not legal advice.

Last updated: EFFECTIVE_DATE