Privacy Policy
Last updated: May 2026
1. Who We Are
Coastal Hub is an independent marine monitoring platform. This privacy policy explains how we collect, use, and protect your personal data.
2. Data We Collect
| Category | Purpose | Retention |
|---|---|---|
| Account details (name, email) | User authentication and communication | While account is active |
| Password hash | Authentication | While account is active |
| Alert preferences | Delivering pager and DSC alerts | While account is active |
| Radio access code | Authentication with radio platform | While account is active |
| Session data | Maintaining login state | 7 days maximum |
| Audit logs | Security and troubleshooting | 1000 most recent entries |
| Pushover user key | Sending Pushover notifications | While account is active |
| Pager station selections | Filtering alert delivery | While account is active |
| DSC alert areas | Filtering DSC alert delivery | While account is active |
3. Data We Do NOT Collect
- We do not track your browsing behaviour or use analytics cookies
- We do not sell or share your data with third parties
- We do not collect payment information
4. How We Use Your Data
Your data is used solely for:
- Authenticating your account
- Delivering pager and DSC alerts based on your preferences
- Providing access to radio audio
- Managing your hosted stations (if applicable)
- Sending account-related emails (verification, password reset, approval notifications)
5. Data Sharing
We do not share your personal data with third parties except:
- Pushover — Your Pushover user key is used to send notifications via the Pushover API. Pushover processes messages on our behalf.
- Legal requirements — We may disclose data if required by law.
6. Data Retention
- Audio recordings: Maximum 30 days, then automatically deleted
- DSC upload files: Maximum 7 days, then automatically deleted
- Account data: Retained while your account is active. Deleted upon account removal.
- Sessions: Expired after 7 days and automatically cleaned up
- Audit logs: Capped at 1000 most recent entries
- MMSI cache: Retained indefinitely for vessel identification purposes
7. Your Rights (GDPR)
Under the UK General Data Protection Regulation, you have the right to:
- Access — Request a copy of your personal data
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your account and data
- Restriction — Request restriction of processing
- Portability — Request your data in a portable format
- Objection — Object to processing of your data
To exercise any of these rights, contact us at [email protected].
8. Account Deletion
You can delete your own account from the Account page. This archives your account data and signs you out. Hosted stations are retained for admin review. For complete data removal, contact the administrator.
9. Security
We use HTTPS for all connections, hash passwords using PBKDF2, and store data on a secured server. Access to the server is restricted and monitored.
10. Cookies
We use a single session cookie (coastalhub_session) to maintain your login state. This cookie is HTTP-only and expires when your session ends.
11. Changes to This Policy
We may update this privacy policy at any time. Changes will be posted on this page with an updated date.
12. Contact
For privacy-related enquiries, contact us at [email protected].