Dive Shop Manager Back to the site

Privacy

Last updated 13.09.2026

Short version: we do not measure you. There is no analytics, no advertising, no third-party script and no social plug-in on this site. The three cookies we set are the ones the service cannot work without. Nothing you or your guests enter is ever sold, and nothing is used to train anything.

1. Who is responsible

Aquatics Global Holdings LLC
5830 E 2nd St, Ste 7000 #17826
Casper, Wyoming 82609
United States of America

Reach us at privacy@diveshopmanager.com. Our representative in the Union under Article 27 GDPR: Markus Th. Ruediger — the address is in the legal notice.

2. Two different roles

This matters, because it decides who answers your questions.

DataWho decidesOur role
Your account with us, your billing data, this website We doController
Everything a dive centre enters about its guests and staff The dive centreProcessor

If you are a guest of a dive centre and want to know what is stored about you, ask that dive centre. They decide; we only hold the data for them, under a data processing agreement.

3. Visiting this website

Our hosting provider records the usual server log entries — IP address, time, the page requested, the referring page and browser identification. These are needed to deliver the page and to defend against attacks (Art. 6(1)(f) GDPR). We do not build profiles from them and do not merge them with anything else.

Fonts and images are served from our own domain. No request leaves to a third party when you open this site — no Google Fonts, no CDN, no embedded video.

The one exception, and you decide it

Two places in the software can reach outside, and both are the same thing: the map. It appears on the dive sites page and in the setup step where you pin a site. It uses Google Maps.

It does not load until you click "Load the map". Until you do, no request goes to Google and nothing about you reaches them. The button says what will happen before it happens. If you click it, your IP address and the map's technical request reach Google LLC in the United States, under Art. 49(1)(a) GDPR — your explicit consent for that transfer. You can always type the coordinates by hand or paste a map link instead; the map is a convenience, not a requirement, and nothing in the software depends on it.

Your click is remembered for the browser session, and no longer. It is kept in your browser's session storage, not in a cookie: close the browser and it is gone, and the next time you open the page nothing loads again until you ask. We chose the session rather than the single page view because the dive sites page is a map — somebody dismissing the same question twenty times a day is not deciding anything any more, and a consent you click away is not a consent.

Cookies

Three, and the service does not work without them. No consent banner can make them optional, so we do not pretend otherwise.

NamePurposeLifetime
dsm_sessionKeeps you signed in. Signed, so it cannot be forged.Until you sign out
dsm_langThe language you chose1 year
dsm_themeLight or dark1 year
dsm_hinweisRemembers that you have seen the cookie notice1 year

4. Using the service

As a dive centre

We store what you give us when you open a centre: name, email address, a hash of your password (never the password), your business name, country, time zone and currency, plus the record of what you did in the system. Legal basis: the contract with you (Art. 6(1)(b)).

Data about your guests and staff

You decide what goes in. The system is built for: name, contact details, date of birth, certifications and dive history, equipment sizes, an emergency contact, and — separately — the dive medical statement.

The medical statement is treated as what it is: health data under Article 9. Three facts are stored, and no more:

Which question was answered yes is never asked for and never stored. Each statement carries its own deletion date and is removed when it expires, independently of the rest of the guest record.

5. Where the data is

On servers in the United States. That is a transfer out of the EU, and we say so plainly rather than burying it.

WhoWhat forWhere
Vercel Inc.Hosting and delivery of the applicationUSA
Neon Inc.The databaseUSA (us-east-1)
Resend, Inc.The three access emailsUSA

All three act only on our instructions, under written agreements. Transfers rest on the European Commission's Standard Contractual Clauses, which are part of our data processing agreement with you.

The service sends three emails, and all three are about getting in: a password reset link, a note that a password was changed, and an invitation to join a dive centre. No newsletter, no marketing, no reminders. For those three we use Resend (Resend, Inc., United States). What reaches them is the recipient address, the subject, the text of the message and whether it arrived.

We do not measure whether you opened it. Resend can report opens and clicks; we deliberately do not take those events. The question we need answered is „did it arrive", not „did he read it" — and what we do not collect, we need neither protect nor explain.

Registration links for guests and partner statements are still shown on screen and not mailed.

Every message that leaves is written down with recipient, subject, time and delivery status, so a dive centre can see what went out in its name. That log is deleted after one year.

A dive centre can set up its own sending domain and its own logo. Invitations then arrive from the centre rather than from us — the mail provider stays the same. The logo sits on our servers and is fetched by the mail program when the message is displayed. Its address carries nothing about the individual message, only about the centre: from such a request it cannot be told who opened which message. That is a deliberate design decision, and it is what keeps the sentence above true.

6. How long

7. Your rights

Under the GDPR you may ask for access, rectification, erasure, restriction, portability, and you may object. You may withdraw a consent at any time without it affecting what happened before.

Portability is not a promise here, it is a button. Every table belonging to your centre comes out in one file, on any day you ask — that has been in the product since the first week, not added because a law required it.

You can also complain to a supervisory authority in the EU member state where you live or work.

8. Security

Some of it, in plain words, because it is the part that actually protects the data:

9. Nothing is sold

We do not sell personal data and we do not share it for cross-context behavioural advertising, in the sense of the California Consumer Privacy Act or otherwise. We do not use your data, or your guests' data, to train machine learning models.

10. Changes

If this notice changes in a way that matters, we will say so in the product before the change takes effect.