Legal
Privacy Policy
How How's the Spot collects, uses, and safeguards your personal information — and the rights you have over it.
Effective date: June 2026 · Last updated:
This Privacy Policy is provided for transparency. Nothing on this site constitutes legal advice, and this policy should be reviewed by a qualified legal professional for your jurisdiction.
1. Introduction
How's the Spot (“we”, “us”, “our”) is an Australian-based organisation that operates a free online platform providing snorkeling condition forecasts, community features, and marine wildlife information for coastal locations. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit or use our website at https://howsthespot.com (the “Service”). We are the data controller responsible for your personal information.
We are a private organisation and do not currently publish an Australian Business Number (ABN) or company number on this Service. This Privacy Policy applies to all visitors and registered users of the Service, regardless of how you sign in.
This policy is designed to satisfy our obligations under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), which are overseen by the Office of the Australian Information Commissioner (OAIC). Because people around the world use the Service, we also describe how we apply equivalent rights under the European Union and United Kingdom General Data Protection Regulation (GDPR) to our international users.
Please read this policy carefully. If you do not agree with it, please do not access or use the Service. By using the Service, you consent to the collection and use of your information in accordance with this policy.
2. Information We Collect
We only collect the information we need to provide, protect, and improve the Service. The categories of information we collect are described below.
2.1 Account information
When you create an account using an email address and password, we store your email address, the display name you choose, and a bcrypt-hashed copy of your password. Passwords are never stored in plain text and cannot be read by anyone, including our staff. We also record your last login time, your community reputation or account access level, and the timestamps used to track any account-deletion requests.
2.2 Google sign-in information
You may also sign in with Google using OpenID Connect. When you do, we receive and store the information allowed by the OpenID, email, and profile scopes — your Google subject ID, email address, display name, and profile photo URL — solely for the purpose of creating or linking your account and logging you in. We confirm that your email address has been verified by Google. We do not store your Google access or refresh tokens: Google sign-in is used for login only, and your use of it is also subject to Google’s own terms and privacy policies.
2.3 User-generated content
When you contribute to the Service, we store the information you provide. This includes:
- Community condition reports — the report title, freeform text, condition ratings, observed-conditions text, and the visit date;
- Images you upload with a report, which are stored in S3-compatible object storage (limited to approximately 5 MB and image file types only);
- Proposed edits to spot content, together with an append-only audit trail that records who proposed and who reviewed each change, and the old and new content.
2.4 Waitlist entries (future feature)
We may offer a waitlist for new spot or feature notifications in the future. If you join such a waitlist, we would collect your email address, the spot you are interested in, and the source from which you signed up. At the time of writing, no waitlist is active on the Service and no waitlist data is being collected.
2.5 Usage analytics (privacy by design)
We operate our own first-party, server-side analytics to understand how the Service is used. We do not use third-party analytics or advertising SDKs. For each visit we record the page path, the page section, the referrer, the time spent on the page, and a flag indicating whether the request appears to be from a bot. Identifiers are not stored in clear text: both the user-agent string and the session identifier are hashed using SHA-256 before storage, so they cannot be used to identify you.
2.6 Spam prevention and verification
To protect the Service from automated abuse, we use a privacy-friendly proof-of-work verification (Altcha — not Google reCAPTCHA) and automated spam detection. In connection with verification we may temporarily record your IP address, but IP addresses are automatically purged after 24 hours. After repeated failed login attempts we may also apply an account lockout for security purposes.
2.7 Location information
To show nearby spots, we may use an approximate location derived from your browser or device. This is used only to deliver the nearby-spots feature and is not used to track you. The coordinates of the snorkeling spots themselves are public map data and are not treated as personal information.
3. How We Use Your Information
We use the information we collect to:
- Provide and operate the Service — delivering forecasts, wildlife data, accounts, and the features you request;
- Display community content — showing your reports, edits, and profile information within the Service;
- Improve the Service — using effectively anonymised analytics to understand and enhance how it works;
- Moderate and keep the community safe — reviewing safety-relevant content and enforcing our guidelines;
- Prevent abuse and spam — using verification, rate limiting, and security monitoring;
- Communicate with you — sending transactional emails such as password resets and notifications you have requested.
We do not sell your personal information to anyone, and we do not share it with third parties for their own marketing purposes or for cross-context behavioural advertising.
4. Legal Basis for Processing
Under the Australian Privacy Principles, we collect and use your personal information for the purposes described in this policy (for example, the collection of information necessary for our functions under APP 3, and use or disclosure for those purposes under APP 6). For users in the EU and UK, we rely on the following GDPR lawful bases:
- Performance of a contract or steps at your request — creating your account, storing your user content, and providing the features you ask for;
- Legitimate interests — keeping the Service secure, preventing fraud and spam, and running first-party analytics that are effectively anonymised, in each case where your rights and freedoms are not overridden;
- Consent — where we rely on your consent, such as for optional analytics or functional cookies, which you can withdraw at any time; and
- Legal obligation — where processing is required to comply with applicable law.
5. Third-Party Services
We rely on the following third-party services to operate the Service. We only share the minimum information each service needs to function, and we do not knowingly share your personal information for cross-context behavioural advertising:
Open-Meteo
Weather and marine forecasts. We send location coordinates only — no personal information is transmitted.
OpenStreetMap (Overpass API)
Coastline and geospatial data. We send bounding-box coordinates only — no personal information is transmitted.
iNaturalist API
Wildlife species data and images. We send location coordinates and a search radius only — no personal information is transmitted. Cached wildlife images carry their own attribution and licence.
OpenID Connect sign-in. When you choose to sign in with Google, Google receives and processes your OpenID, email, and profile scope data so we can log you in. We do not store your Google access tokens.
Resend
Transactional email delivery. We share the recipient email address and email content necessary to deliver messages you have requested.
Altcha
Proof-of-work verification (CAPTCHA). Used to prevent automated abuse. Receives challenge and verification data only.
S3-compatible object storage
Stores user-uploaded images (for example, community report photos). This may be a provider such as DigitalOcean Spaces, MinIO or AWS S3, or local storage.
Redis
Caching and rate limiting. Stores cached API responses and rate-limit data — no personal information is persisted long-term.
Prometheus, Grafana and Alertmanager
Internal infrastructure monitoring. These tools operate within our infrastructure and do not process personal information.
We may also use hosting and infrastructure providers to run the Service, with servers located in Australia. We do not sell, trade, or rent your personal information, and we do not share it for cross-context behavioural advertising.
6. Data Retention
We keep your personal information only for as long as we need it for the purposes described in this policy, and then delete or anonymise it. Our retention periods include:
- CAPTCHA IP addresses — automatically purged after 24 hours;
- Usage analytics events — retained for 90 days, then deleted;
- Spam flags — deleted after 90 days;
- Account and user content — kept while your account is active. After account deletion, your published community reports may be retained and anonymised, as described in Section 10.
Where we are required to keep limited information to comply with a legal obligation, protect security, or resolve disputes, we will retain only what is necessary for that purpose.
7. Your Rights
Depending on where you live, you may have the following rights over your personal information:
- Access — request a copy of the personal information we hold about you;
- Correction or rectification — ask us to fix inaccurate or incomplete information;
- Erasure or deletion — request deletion of your personal information, subject to our retention obligations;
- Restriction — ask us to limit our processing in certain circumstances;
- Objection — object to processing based on our legitimate interests;
- Data portability — receive your information in a structured, machine-readable format;
- Withdrawal of consent — withdraw consent at any time where processing relies on it, without affecting processing that already occurred.
Australian users: You have rights under the Privacy Act 1988 and the APPs, including access and correction rights, and the right to complain to the OAIC if you believe your privacy has been breached.
International users: We offer equivalent rights to those available under the EU/UK GDPR, and you may also lodge a complaint with your local data-protection authority.
To exercise any of these rights, email [email protected]. We will respond within 30 days, and may need to verify your identity before proceeding.
8. Cookies
We use cookies and similar technologies to operate and improve the Service. When you first visit, a consent banner lets you choose Accept All, Reject All, or Customise your preferences. Essential cookies are always on because they are required for the Service to function; analytics and functional cookies are optional and only set if you consent.
This is only a summary. For full details, including which cookies we use and how long they last, please see our Cookie Policy . You can update your choices at any time on our Privacy Preferences page.
9. Data Security
We use appropriate technical and organisational measures to protect your personal information, including:
- Encryption in transit — all traffic is encrypted using HTTPS/TLS (provided by DigitalOcean App Platform ingress);
- Secure cookies and authentication — secure, HttpOnly,
__Host--prefixed cookies and JSON Web Token (JWT) authentication; - Password protection — passwords are stored as bcrypt hashes and never in plain text;
- Application protections — CSRF protection, content sanitisation, rate limiting, and security headers;
- Access controls and monitoring — restricted internal access and ongoing security monitoring.
While we follow industry practice, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
10. Account Deletion
You can request deletion of your account at any time through your account settings or by emailing [email protected]. When you do:
- your account is deactivated and enters a 30-day grace period, during which you can cancel the request and restore your account;
- after the grace period, we anonymise your account record — for example, by redacting your email and display name and invalidating your credentials;
- we delete your pending proposed edits and any waitlist entries; and
- we anonymise your published community reports, which remain visible but are disassociated from your identity.
This approach balances your right to erasure with preserving the value of community content that others rely on.
11. Children's Privacy
The Service is not directed to children under 13, and the minimum age to create an account is 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will take steps to delete it.
12. International Users
How's the Spot is operated from Australia. If you access the Service from outside Australia, your information may be transferred to, stored in, and processed in Australia. For international users we apply the rights described in Section 7, and data-protection laws in Australia may differ from those in your country of residence.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, where practicable, notify users of material changes. Your continued use of the Service after any changes takes effect constitutes your acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data-protection rights, please contact us at:
How's the Spot
Website: https://howsthespot.com
Privacy: [email protected]
Terms & legal: [email protected]
We will endeavour to respond to your request within 30 days. In some cases, we may need to verify your identity before processing your request.