Notice to mariners
Privacy Policy
Last updated 17 September 2026 · [email protected]
This policy explains how MarineGrib (“we”, “us”), operating marinegrib.com, handles personal data when you use the MarineGrib console, join an account, or pay for Pro, Annual, or Crew. English is the controlling language. Last updated 17 September 2026.
1. Who is responsible
MarineGrib is the controller of personal data processed through marinegrib.com. Write to [email protected] for access, correction, deletion, or a copy of your data.
Payments are taken by Square (Block, Inc. and Squareup International Ltd). Square is an independent controller of the card and billing data you enter on their checkout pages. We never see your full card number.
2. What we collect
We only keep what we need to run the watch:
- Account: skipper name, email, hashed password, and a session token.
- Membership: plan (free, Pro, Annual, Crew), status, and renewal date.
- Console use: region, model, satellite mode, and GRIB bounding boxes you request, so we can pack the right slice.
- Approximate location, only if you tap Use GPS or if your browser locale/IP is used once to set the first chart. We do not track the boat underway.
- Device storage: GRIB packs in IndexedDB, and locale, currency, and theme in local storage — these stay on the device.
3. What we do not collect
We do not sell personal data. We do not run advertising networks. We do not record AIS, AIS-derived tracks, or a live position history. The traffic overlay is a lane-based model for lookout context, not a SOLAS AIS receiver. Weather fields themselves (wind, swell, pressure, SST) are public forecast model output, not personal data.
4. Why we process it
We process data to:
- Create and keep your account, and attach Pro to the skipper, not the browser.
- Pack and cache GRIB for the box you asked for, including satellite-sized payloads.
- Take and confirm Square subscriptions and show the right paywall.
- Send service mail (password, billing return, material changes to these pages).
- Keep the service secure, rate-limit abuse, and debug failed downloads.
5. Legal bases (UK GDPR / GDPR)
Contract: running the account, packing GRIB, and delivering a paid plan. Legitimate interests: securing the service, preventing fraud, and remembering locale and chart settings on the device. Consent: optional GPS, and any non-essential cookie we may add later (none today). Legal obligation: tax and accounting records for Square payouts.
6. Who we share with
Square for checkout and recurring billing. Open-Meteo (and through them NOAA GFS and, on Pro, ECMWF IFS) for forecast fields — requests carry a bounding box, not your name. Google or X only if you choose to join with those providers. Hosting and edge cache (including Cloudflare Pages) process requests as processors. We do not share data with brokers.
7. Retention
Account and membership stay while the account is open, then up to 24 months for billing disputes. Session cookies expire with the login. IndexedDB GRIB packs can be cleared in the browser at any time. Server logs are rotated on a short cycle. You can ask us to delete the account at [email protected].
8. International transfers
Forecast and checkout vendors may process data outside the UK/EEA. Where they do, they rely on an adequacy decision or standard contractual clauses. Satellite-mode packs are generated so the skipper can work offline; that cache lives on the device you control.
9. Your rights
You may access, correct, delete, restrict, or port your data, and object to processing based on legitimate interests. You may complain to the UK Information Commissioner’s Office (ico.org.uk) or your local EU authority. These rights do not let us rewrite a forecast model.
10. Children
MarineGrib is for skippers aged 18 or over. We do not knowingly collect data from children.
11. Changes
We will post updates on this page with a new date. Material changes that affect a paid account will be flagged in the console. The Cookies Policy and Terms should be read with this notice.