Privacy Policy
Effective Date: March 25, 2026 · Last Updated: August 4, 2026
This Privacy Policy explains how FoilNexus LLC ("Company," "we," "us," or "our"), a Washington State limited liability company, collects, uses, shares, and protects your personal data when you use the eFoilCrew website, progressive web application, and related services (the "Service").
We are committed to protecting your privacy. This policy is designed to comply with the EU General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA/CPRA), Brazil's Lei Geral de Proteção de Dados (LGPD), and other applicable data protection laws.
1. Data Controller
FoilNexus LLC is the data controller responsible for your personal data. For questions or requests, contact us at privacy@efoilcrew.com.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address and password (stored as a secure hash — we never store plaintext passwords). We verify your email address via a confirmation link.
2.2 Profile Information
You may optionally provide: display name, bio, avatar photo, cover photo, experience level, the year you started riding, gear description, home location (coordinates and label), and whether to show your location on the community map.
2.3 Session & Activity Data
When you record a session with our eFoilCrew Garmin watch app or upload a riding session as a GPX/TCX/FIT file, we collect: GPS tracks (full and simplified route linestrings), session start location, duration, distance, speed metrics (maximum and average), elevation gain, foil percentage, run counts, weather conditions at the time of riding, session notes, titles, and photos you choose to attach.
2.4 User-Generated Content
Content you create on the platform, including posts, comments, forum posts and replies, direct messages, spot condition reports (water state, wind, notes), gear setup configurations, and product interactions.
2.5 Social & Community Data
Follow relationships, likes, badge and achievement history, leaderboard rankings, and points ledger entries.
2.6 Location Data
With your permission, we may collect your device's geolocation during onboarding (to suggest your home location) and through GPS tracks recorded by our Garmin watch app or contained in sessions you upload. You can decline location access and manually enter your location instead. Spot locations you create or visit are also recorded.
2.7 eFoilCrew Garmin Watch App
When you use our eFoilCrew watch app on a compatible Garmin device, it records your GPS location, route, speed, and foil-session metrics on the watch during a session. When your watch reaches connectivity, the session is uploaded directly to your eFoilCrew account over an encrypted HTTPS connection, authenticated with a revocable device token created when you pair the watch. We do not receive any Garmin account password or credentials. You can revoke a paired watch at any time in your settings, which stops further uploads from that device.
2.8 Usage & Analytics Data
Read-only demo sessions
If you are viewing eFoilCrew through a shared demo link, analytics and session recording start when the demo opens. You are told rather than asked: the demo banner says that demo sessions are recorded, and it stays on screen for the whole visit. Your answer to the consent banner does not control any of this. The banner is suppressed once the demo chrome loads, and if it appears before that, declining it does not stop the recording. PostHog writes a cookie and a browser-storage entry for the visit, and identifies it by a random identifier minted when the link is opened. Where that identifier is not available, the visit is attached to the shared demonstration account instead, and that account's own name and email address go to PostHog with it.
A demo link is sent to a named business contact who holds no account with us, and a demo session shows a prepared demonstration account rather than your own data, so there is no account of yours for a consent answer to govern. We use these recordings to see how the demonstration is received and to improve the product. Form inputs are masked in these recordings exactly as they are in any other, we keep them for 30 days, and you can ask us to delete one. Where the rest of this policy says what your answer to the consent banner controls, it is describing a visit that is not a demo session.
Browser analytics on this website are opt-in. On our main pages and inside the app the analytics library is not loaded until you accept, so we collect no behavioural analytics from you there and PostHog writes no cookie and no identifier to your device. That holds whether you decline the banner or simply never answer it, and if you decline we store flags recording that choice. The banner appears the first time you open the app rather than on a public page. Our Cookie Policy describes by name what this site puts on your device, including the entries that are written whatever you answer. Error reporting is a separate matter and is covered in section 2.9.
Our standalone press pages are instrumented separately. They count page views and link clicks without waiting for an answer, because a press mention is a thing we need to be able to measure, but they keep it in memory: no analytics cookie, no analytics identifier, and no profile that follows you from one page to the next. If you have already accepted analytics, they behave like the rest of the site. If you have declined, they collect nothing beyond storing the flag that records your refusal.
When you accept, we collect behavioural analytics through PostHog, linked to your account: page views, feature usage events, and session recordings. Ride metrics are kept out of the analytics events themselves. Our event definitions carry no field for a top speed, a ride distance, a heart rate or a foiling percentage; an automated check rejects any event property whose name spells one of those, and the capture path that assembles properties while the app is running strips them before the event is sent. Those numbers live in our database, where they power your own insights, records and badges.
Session recordings are a second channel, and the rule above does not reach them. A recording replays a page the way it looked on your screen, so a ride metric that was on screen is part of the recording: the speeds and distances on your stats, records and progress screens, your heart rate where we display it, the figures on a session card. What we mask is narrower than the page. Form fields are masked, and so are the email address on your account settings screen, the body of a chat message and the message preview in your chat list. The rest of a page is recorded as the text it displays.
Recording runs when you have accepted analytics, and during the read-only demo sessions described above. If you declined the banner, or have not answered it, the recorder is not started for your visit. We keep recordings for 30 days, and you can ask us to delete one sooner. Analytics events are kept for much longer than a recording is; section 7 gives both periods.
Separately from the banner, our servers keep operational records of things that happen to your account: an account being created, an email address being confirmed, an invite being sent or accepted, a watch being paired, a ride being added. Each carries your account identifier and context about the event itself. That context can include where a sign-up came from (the site that referred you, and any campaign parameters on the link you followed), which device was paired, or your trust level at the time. They contain no ride metrics and no health data, we keep them whatever your analytics choice is, and they are what tell us the product is working.
Separately, the eFoilCrew Garmin watch app reports small anonymous diagnostic events so we can confirm the app installs, connects, and works correctly: when it is first opened, when pairing succeeds or fails, and when your first and tenth rides are recorded. These events contain only a randomly generated identifier, the app version, the watch software version, the watch model, and — where pairing failed — the error code involved. They contain no location data, no ride content, no health data, and no account or contact information, and they are not linked to your identity. The random identifier is reset if you unpair the watch. These diagnostics are sent by the watch app itself and are not controlled by the website cookie banner.
The watch app also keeps a running count of how many times each of its data screens has been displayed, and reports those totals with your usual sync so we can see which screens are worth improving. These are counts only: they record how often a screen was shown, never when, in what order, or for how long, and they cannot be used to reconstruct what you did during a ride. Your app settings are reported the same way, so we can tell which options people actually use.
2.9 Device, Technical & Error Data
Browser type, operating system, device type, screen resolution, IP address (for security and approximate geolocation), and referral source. This data is collected automatically when you access the Service.
Error reporting runs whether or not you accept analytics, because a site that breaks silently cannot be fixed. When something goes wrong we send the error to Sentry along with technical context about the visit, such as the page it happened on, the page that referred you there, and your browser, operating system and device type, and we record a short replay of the moments before the failure with all text masked and all images blocked. Your IP address is not attached to the report. We do not attach your name or email.
If you have accepted analytics, an error report also carries your account identifier, so we can tell whether a bug hit one rider or fifty. If you declined, or have not answered, it does not, and the report is not linked to your account. A read-only demo session can instead attach the identifier of the shared demonstration account, which belongs to no individual and holds none of your data.
Enabling error reporting also means an entry called sentryReplaySession is written to your browser's session storage when a page loads, whatever your analytics choice is. It holds a random identifier for the current tab so a replay of a crash is not cut in half, it is erased when you close the tab, and it is described in our Cookie Policy. Sentry is listed as a subprocessor in section 4.
3. How We Use Your Information
We use your personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Account creation and authentication | Contract performance |
| Session tracking, analysis, and display | Contract performance |
| Community features (posts, follows, messaging) | Contract performance |
| Spot discovery and conditions reporting | Contract performance |
| Gear catalog and setup management | Contract performance |
| Leaderboards, badges, and achievements | Contract performance |
| Behavioural analytics and session replay | Consent (opt-in) |
| Analytics and session replay during a read-only demo session | Legitimate interest (notice given in-product, no account or personal data of the viewer involved) |
| Service improvement and bug detection | Legitimate interest |
| Security, fraud prevention, and abuse detection | Legitimate interest |
| Responding to support requests | Contract performance |
| Compliance with legal obligations | Legal obligation |
| Sponsored content and advertising | Legitimate interest / Consent |
4. Data Sharing & Third-Party Processors
We do not sell your personal data. We share data with the following categories of third-party service providers who process data on our behalf:
| Provider | Purpose | Data Region |
|---|---|---|
| Supabase | Database, authentication, file storage | US (Oregon) |
| Vercel | Website hosting and CDN | US (San Francisco) |
| PostHog | Analytics and session replay (opt-in, apart from read-only demo sessions) | US |
| Sentry | Error monitoring and crash reports | US |
| Mapbox | Static map images and place-name lookup | US |
| MapTiler | Interactive map tiles (outdoor and satellite views) | EU (Switzerland) |
| OpenFreeMap | Interactive map tiles (dark view) | EU |
| OpenStreetMap (Nominatim) | Place-name lookup for spot locations | EU |
| OpenWeatherMap | Weather data for riding conditions | EU/US |
| Open-Meteo | Historical and forecast weather by coordinates | EU |
| Linear | Bug report processing | US |
How map and weather providers are contacted. Some of these requests are made by our servers, which send only a coordinate and no information about you. Others are made directly by your browser — map tiles, static map images, and some place-name and forecast lookups. When your browser contacts a provider directly, that provider necessarily receives your IP address along with the coordinates being displayed, in the same way it would if you visited their own website. We do not send them your name, email, or account identifier in either case.
We may also use AI services (Anthropic, OpenAI, Google) for administrative functions such as content synthesis and session analysis. These services process aggregated or anonymised data and are not used to make automated decisions about individual users.
5. International Data Transfers
Your data is primarily stored in the United States (Oregon and San Francisco). If you are located outside the US, your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and UK Information Commissioner's Office, and other appropriate safeguards, to ensure your data is protected during international transfers.
6. Cookies & Local Storage
We use cookies and browser local storage for essential functions and optional analytics. For full details, see our Cookie Policy.
Essential storage (no consent required): authentication session tokens, theme/palette preferences, UI state preferences. Optional storage (consent required): PostHog analytics cookies and identifiers. Until you accept, PostHog writes no cookie and no identifier to your device, apart from the read-only demo sessions described in section 2.8. If you decline, we store flags recording that refusal, and no analytics identifier of any kind. Separately from your analytics choice, some session-storage entries are written and then erased when you close the tab. The Cookie Policy describes these by name.
7. Data Retention
- Account data: Retained for as long as your account is active. Deleted upon account deletion request.
- Session & activity data: Retained for as long as your account is active. You can hide or delete individual sessions at any time.
- User-generated content: Retained until you delete it or your account. Content shared in community contexts (posts, forum replies) may persist in other users' feeds.
- Analytics data: Session recordings in PostHog are kept for 30 days. Analytics events are kept longer: our PostHog retention period for them is set to 84 months.
- Paired-watch device tokens: Retained while a watch is paired to your account. Revoked and deleted immediately when you unpair the watch.
- Server logs: Access and error logs are retained for up to 30 days for security and debugging purposes.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
8.1 All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your personal data and account.
- Withdraw consent: Withdraw your consent for optional data processing (e.g., analytics) at any time.
8.2 EU/UK Residents (GDPR)
- Data portability: Receive your data in a structured, machine-readable format.
- Restriction: Request restriction of processing in certain circumstances.
- Object: Object to processing based on legitimate interests.
- Lodge a complaint: File a complaint with your local Data Protection Authority.
8.3 California Residents (CCPA/CPRA)
- Right to know: Request disclosure of the categories and specific pieces of personal information we collect.
- Right to delete: Request deletion of personal information.
- Right to opt-out: We do not sell or share your personal information for cross-context behavioural advertising.
- Non-discrimination: We will not discriminate against you for exercising your CCPA rights.
8.4 Brazil Residents (LGPD)
- Confirmation & access: Confirm whether we process your data and access it.
- Correction & deletion: Correct inaccurate data or request deletion of unnecessary data.
- Portability: Transfer your data to another service provider.
- Revocation of consent: Revoke consent at any time.
To exercise any of these rights, email us at privacy@efoilcrew.com. We will respond within 30 days (or the applicable statutory period).
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including: HTTPS/TLS encryption in transit, secure password hashing via Supabase, encrypted storage of authentication and paired-device tokens, row-level security (RLS) policies in our database to restrict data access, and regular security reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authorities within 72 hours of becoming aware of the breach (as required by GDPR) and will notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
11. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from someone under 18, we will take steps to delete that information promptly and close the account. If you believe someone under 18 has provided us with personal data, please contact us at privacy@efoilcrew.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and updating the "Last Updated" date. For significant changes, we may also notify you by email. Your continued use of the Service after such changes constitutes acceptance of the revised policy.
13. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
FoilNexus LLCData Protection Contact
Email: privacy@efoilcrew.com
If you are in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.