Last updated: 21 July 2026
This policy should be read alongside the Terms of Use.
In short (the plain-language version — the full policy below is what binds us): we collect very little. If you make an account we hold your email and name; we keep the searches you run and the areas you ask us to forecast; we count visits to our own pages anonymously (no cookies), we don’t track you around the web, we show no ads, and we never sell your data. If you use the locate button, your position stays in your browser — we don’t store it. You can ask us for a copy of your data, ask us to delete it, or complain — to us first at privacy@tidebutbetter.com, and to the ICO at any time.
1.1 This policy explains how Obtanium Software Limited (“we”, “us”, “our”), a company registered in England and Wales (company number 17327621), of 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, collects and uses personal data when you use TideButBetter (the “Service”), and the rights you have. For the purposes of the UK GDPR, we are the data controller.
1.2 For any privacy question or to exercise your rights, contact us at privacy@tidebutbetter.com.
1.3 Where we operate and who this policy covers. We operate the Service from the United Kingdom and are established in the UK, so the UK GDPR governs our processing. The Service is available to, and can be purchased from, users worldwide. Because we offer the Service to individuals in the European Union, the EU GDPR also applies to that processing under its Article 3(2). We have not appointed a representative in the EU under Article 27 of the EU GDPR: we rely on the exemption in Article 27(2)(a) for processing that is occasional, does not involve large-scale processing of special categories of data, and is unlikely to result in a risk to individuals’ rights and freedoms — which reflects this Service (a small user base, no special-category data, and low-risk account and usage data). We keep this position under review as our EU user numbers grow, and have recorded the assessment internally in our data protection impact assessment. Wherever you are, you have the rights set out in §12, and the international-transfer safeguards in §7 are designed to satisfy both the UK GDPR and the EU GDPR.
To be clear up front: we do not sell your personal data, we do not use it for third-party advertising, and the Service does not run advertising or behavioural-tracking technology. The only usage measurement we do is the cookieless, aggregate page-view analytics described in §10 — it does not follow you across other sites and stores nothing on your device. If this ever changes, we will update this policy and obtain consent where the law requires it.
We collect only what we need to run the Service.
The Service centres the map on a default location and on places you search for. It also offers an optional locate button: if you choose to use it (and grant your browser’s permission prompt), your device’s precise location is used, and tracked while the feature is active, to centre the map and the tide graph on your position. Your precise position is processed in your browser and is not stored by us or sent to our servers. Note that as the map follows your position, your browser’s map-tile requests necessarily reveal the map area you are viewing (together with your IP address) to our map provider, Stadia Maps, like any other panning or zooming (§3.2). You can stop location use at any time via the button or your browser settings. We do not otherwise request or track your device’s location. This section concerns your device’s live position only: places you deliberately choose — a saved home club or venue preference, and the geographic areas of simulations you request — are stored with your account as described in §3.1.
Under the UK/EU GDPR we rely on the following legal bases:
We use personal data to:
We do not currently send marketing emails. If we introduce them, we will only do so on a lawful basis and you will be able to opt out at any time.
We do not sell your data. We share it only with service providers who process it on our behalf, or (in Stripe’s case) as the merchant of record that takes payment for your purchase as our agent. Our current providers are:
| Provider | Role | Typical data involved | Location |
|---|---|---|---|
| Clerk | Authentication / account management (only if accounts are enabled) | Email, name, social-login profile, role/credits, home club preference | USA |
| Vercel | Application hosting, serverless compute, file (Blob) storage, logs, and cookieless web analytics (aggregate usage statistics, §10) | Technical/log data, stored results, aggregate page-view analytics (§3.2) | USA |
| Neon | Database (system of record for simulation requests) | Simulation request records and the account id that owns them | USA |
| Modal | On-demand simulation compute | The geographic area and dates of a requested simulation (no account profile data) | USA |
| Stadia Maps | Basemap / vector map tiles and place-search geocoding | Your search text, IP address and map area requested | USA / EU |
| Stripe (shown to buyers as Onelink) | Merchant of record for purchases (subscriptions and commissioned
simulations), acting on our behalf: takes payment, collects and remits taxes,
issues receipts, invoices and credit notes in its own name, and handles refunds
and disputes. Stripe is an independent controller of the
transaction data it processes as merchant of record, under its own privacy
policy; you may create an Onelink account at onelink.com |
Your name and billing/payment details (held by Stripe as merchant of record, not us); we receive subscription status, a customer reference and billing email | USA |
6.1 Other disclosures. We may also disclose personal data: (a) to comply with the law or a valid legal request, or to protect our rights, users or the public; and (b) in connection with a reorganisation, merger or sale of the business, in which case any recipient will remain bound by this policy or an equivalent one.
6.2 Each provider acts under our instructions and/or its own published privacy terms, and may not use your data for its own unrelated purposes beyond what is necessary to provide its service.
6.3 Payment data and deletion through Onelink. Because Stripe (Onelink) is the merchant of record and an independent controller for your purchase transaction data, requests about that data — including deletion of your payment information — are handled by Stripe under its own privacy policy, through your Onelink account or Onelink support. When payment data is deleted at Stripe, Stripe may cancel any active subscription and delete the related billing objects on its side and notify us at our business email; we then update your account and entitlements accordingly. You can still exercise all of your rights against us for the data we hold (§12).
Some of our providers are located outside the UK and European Economic Area, including in the United States. Where personal data is transferred outside the UK/EEA, we rely on an appropriate safeguard — such as the UK International Data Transfer Addendum together with the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the recipient is certified — to ensure your data receives an equivalent level of protection. Of our current providers, Clerk, Vercel, Neon (a Databricks company) and Stripe are certified under the EU–US Data Privacy Framework, including its UK Extension, with Standard Contractual Clauses as a contractual fallback in their data-processing agreements; for Modal and Stadia Maps we rely on data-processing agreements incorporating the Standard Contractual Clauses and, for UK transfers, the UK Addendum. You can ask us for more detail using the contact above.
We keep personal data only for as long as we need it for the purposes set out above, and then delete or anonymise it. In particular:
We may keep certain data longer where necessary to comply with legal, accounting or tax obligations, or to establish, exercise or defend legal claims.
9.1 Our authentication provider (Clerk) sets strictly necessary cookies so you can sign in and stay signed in. The Service also stores a small number of preferences in your browser’s local storage, on your own device only:
theme — your light/dark display preference;tbb-help-seen — that you have seen the first-visit help;tbb-safety-ack — that you have acknowledged the safety
notice;tbb:recent — your recent place searches (kept on your device;
your searches are separately sent to the geocoding provider to get results,
§3.2).You can clear all of these at any time with the “Reset saved settings” button in the Help panel, or via your browser settings.
9.2 We do not use analytics, advertising or cross-site tracking cookies. The aggregate usage analytics described in §10 operates without cookies and without storing or reading anything on your device. If we ever introduce any non-essential cookies or similar technologies, we will first provide the required information and obtain your consent where the law (including UK PECR / EU ePrivacy rules) requires it.
The Service uses one privacy-preserving analytics tool: Vercel Web Analytics, provided by our hosting platform. It gives us aggregate statistics — page views, referrers, countries, browser and device types — so we can understand how the Service is used and improve it. It is cookieless: it sets no cookies, stores nothing on and reads nothing from your device, and does not track you across other websites. Visitors are counted using a short-lived anonymised identifier derived from the IP address and browser information sent with every web request; it is rotated and discarded daily and is never exposed to us. Because nothing is stored on or accessed from your device, this does not require consent under UK PECR; our lawful basis for the underlying processing is our legitimate interest in understanding and improving the Service in aggregate (§4).
Beyond this, the Service contains no other analytics, tag managers, session-recording, advertising pixels or similar tracking. If any such technology is added in future, this policy will be updated and cookie-consent obligations re-assessed.
The Service is not directed at children. You must be at least 16 to use it, matching our Terms of Use. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it. (The plain-language summary at the top of this policy is there so that younger readers who encounter the Service can understand it too.)
Subject to the conditions and exceptions in applicable law, you have the right to:
To exercise any of these rights, contact us at privacy@tidebutbetter.com. We will respond within the statutory time limit (one month under the UK/EU GDPR, which may be extended for complex requests), carrying out the reasonable and proportionate searches the law requires. We may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Complaints. If you are unhappy with how we have handled your personal data, you can complain to us directly by emailing privacy@tidebutbetter.com with the subject line “Data protection complaint” (or by post to the address in §15). We will acknowledge your complaint within 30 days and respond substantively without undue delay, telling you what we have done or why we disagree. Complaining to us first often resolves things fastest, but it is not a precondition — you can also complain to the ICO at any time. (For complaints about the Service itself, rather than personal data, see §1.3 of the Terms of Use, which also states our position on alternative dispute resolution.)
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, disclosure, alteration or destruction, and we work with reputable infrastructure providers. Simulation outputs are stored at unguessable randomised URLs, protected stream data is encrypted and its keys are issued only to signed-in, authorised users, and key requests are logged for audit (see §3). However, no method of transmission over the internet or electronic storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping any account credentials confidential; please notify us promptly of any suspected unauthorised use.
We may update this policy from time to time. We will post the updated version with a new “last updated” date and, where changes are material, take reasonable steps to bring them to your attention. Your continued use of the Service after an update takes effect indicates your awareness of the revised policy.
For any question about this policy or our handling of your personal data, or to exercise your rights, contact Obtanium Software Limited at privacy@tidebutbetter.com, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.