GetSurfCoach

Privacy Policy

Effective 27 May 2026

Who we are

GetSurfCoach (“we”, “us”) runs a directory and video-review platform that helps surfers find coaches and lets coaches give feedback on surf footage. Contact: hello@getsurfcoach.com.

What we collect

  • Account info — email address and display name (from your sign-in provider).
  • Coach profile (coaches only) — bio, location, languages, price band, public contact handles you choose to display, and photos you upload.
  • Lesson content — video clips, screenshots, drawings, voice notes, and text comments created during a coaching session.
  • Messages — text exchanged between coaches and students inside the app.
  • Technical data — IP address and basic request metadata from your browser, used only for security and rate-limiting. We do not run third-party analytics or advertising trackers.

Google Drive integration

If you choose to connect a Google account, we request the drive.file scope only. This is a non-sensitive, per-file scope. It lets us write video copies and folders we create on your behalf inside your Drive, and read those same files back. We cannot see anything else in your Drive — no other files, no shared documents, no metadata about files we did not create.

We store an encrypted OAuth refresh token so we can keep uploading new clips after you've closed your browser. The token is encrypted at rest with AES-GCM using a key that never leaves our server. You can disconnect at any time from your profile page, or fully revoke access at myaccount.google.com/permissions.

We do not use Google user data for advertising, do not sell it, and do not share it with third parties. The data is used solely to provide the backup feature you opted into.

How we use your data

  • Operate the coach directory and student dashboard.
  • Deliver video clips and feedback to the people you've authorised — coaches see their students' clips, students see what their coach uploads about them.
  • Send transactional emails (lesson published, clip expiring, account events). We do not send marketing email.
  • Mirror videos into your Google Drive if you connected one.
  • Detect abuse, prevent spam, and enforce platform safety.

Who sees what

  • Public coach profiles — name, bio, location, languages, photos, tagline, and any contact handles the coach chose to display publicly. Visible to anyone on the open web.
  • Lesson content (videos, comments, drawings) — visible only to the owning coach and the specific student the clip is about. In a shared multi-student session, all participants and the coach can see clips in that session.
  • Messages — visible only to the two people in the conversation.
  • Drive copies — visible inside the personal Google Drive of whoever owns the mirror (coach mirrors land in the coach's Drive; student mirrors land in the student's Drive). We don't share them between users.

How long we keep it

  • Video clips are removed from our hot storage 20 days after upload. If you've connected Google Drive, the Drive copy stays so the clip is still playable when you scroll back into older sessions.
  • If you delete a clip in GetSurfCoach, we also remove the matching copy from any connected Drive — the two stay in sync.
  • If you disconnect Google Drive, new clips stop syncing, but Drive copies we already created stay in your Drive. They're yours from that point on, and you can delete them in Drive whenever you want.
  • Account data is kept while your account is active. Email us to delete it.
  • Messages are kept while the conversation is active.
  • Server logs are kept up to 30 days for security and debugging.

Your rights

You can request access to, correction of, or deletion of your personal data at any time. Email hello@getsurfcoach.com and we'll respond within 30 days. EU/UK users: this includes the GDPR rights to object, restrict, and port your data. California users: this covers your CCPA rights.

You can disconnect Google Drive from your profile page at any time. New clips stop syncing, and the Drive copies we already created stay in your Drive — manage them there if you want to remove them. To delete a specific clip from both GetSurfCoach AND your Drive in one step, delete it from GetSurfCoach: the two stay in sync.

Security

Data is stored on Cloudflare's infrastructure (D1, R2). Connections to and from our server use TLS. OAuth tokens are encrypted at rest. Passwords (when used) are hashed via the Better Auth library, never stored in plain text. No system is perfectly secure, but we follow industry-standard practice.

Children

The service is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we'll delete it.

Changes

We may update this policy. Material changes will be noted at the top of this page and, for registered users, via email. The current version always lives at this URL.

Contact

Questions, complaints, or data requests: hello@getsurfcoach.com.