Privacy Policy

Last updated: June 29, 2025

1. Introduction

Thalassa LLC ("Thalassa," "we," "us," or "our") is a Delaware limited liability company operating the Thalassa platform for dive center management. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Service. By using the Service, you agree to the practices described in this Policy.

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, please note that we comply with applicable data-protection laws including the General Data Protection Regulation (GDPR) where relevant.

2. Information We Collect

Account & Contact Information

Name, email address, business name, and password when you register or apply for a Founding Member spot.

Dive Center & Business Data

Information you enter about your dive center, locations, pricing packages, and team members as part of normal platform use.

Customer & Booking Data

Data about your customers, bookings, and sessions that you create or import into the platform. You are the data controller for this information; we process it on your behalf.

Payment Information

Subscription payments are processed by Stripe. We do not store your full card number. We receive and retain limited billing details (last 4 digits, card type, billing address) as provided by Stripe for record-keeping.

Usage & Technical Data

IP address, browser type, device information, pages visited, and feature interactions. We use this data to maintain and improve the Service.

Cookies & Similar Technologies

We use strictly necessary session cookies to authenticate users. We may use analytics cookies to understand aggregate usage patterns. You can control cookie preferences through your browser settings.

3. How We Use Information

  • To provide, operate, and maintain the Service.
  • To process payments and manage your subscription.
  • To send transactional communications (receipts, account alerts, security notices).
  • To send product updates and announcements related to the Service (you may opt out at any time).
  • To diagnose technical issues and improve platform reliability.
  • To comply with legal obligations.

We do not sell your personal information or use it for third-party advertising.

4. Data Sharing & Disclosure

We share data only as described below:

  • Stripe — payment processing. Stripe's privacy policy governs its handling of your payment data.
  • Infrastructure & hosting providers — cloud services used to operate and store the platform (e.g., database, object storage). These providers act as processors under data-processing agreements.
  • Legal requirements — if required by law, court order, or governmental authority.
  • Business transfers — in the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction with appropriate notice.

We do not sell, rent, or share your personal data with any third party for their own marketing purposes.

5. Data Retention

We retain your account and associated data for as long as your subscription is active. Following account cancellation or termination, we retain data for up to 30 days to allow for export, after which it is deleted from production systems. Anonymized or aggregated data may be retained indefinitely for analytical purposes. We retain billing records as required by applicable tax and accounting laws (typically 7 years).

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate or incomplete data.
  • Deletion — request deletion of your personal data, subject to retention obligations.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection / Restriction — object to or restrict certain processing activities.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us at hello@thalassa.app. We will respond within 30 days. If you are in the EEA, you also have the right to lodge a complaint with your local data-protection authority.

7. International Data Transfers

Thalassa LLC is based in the United States. If you are located outside the US, your data will be transferred to and processed in the US. For transfers from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms as required by applicable law. By using the Service, you acknowledge and consent to this transfer.

8. Security

We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but are committed to addressing breaches promptly and in compliance with applicable law.

9. Children's Privacy

The Service is intended for business use by individuals 18 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal data, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will notify you by email or through a prominent notice in the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

11. Contact

For privacy-related inquiries or to exercise your rights, contact:

Thalassa LLC
hello@thalassa.app