Privacy
Privacy Policy
How Experience Scuba collects, uses, and protects your personal information.
01.Information We Collect
- Personal information: Name, email address, phone number, nationality, date of birth when you make a booking or create an account.
- Medical information: Health declarations and medical conditions relevant to scuba diving activities, provided voluntarily for your safety.
- Payment information: Payment details are processed securely through CCAvenue. We do not store your full card details on our servers.
- Usage data: Browser type, IP address, pages visited, and interaction data to improve our website experience.
- Booking data: Dates, preferences, special requests, and activity history associated with your bookings.
02.How We Use Your Information
- To process and manage your dive bookings, courses, and experiences.
- To communicate with you regarding booking confirmations, reminders, and updates via email and WhatsApp.
- To ensure your safety by screening for medical conditions relevant to diving activities.
- To process payments securely through our payment gateway partner (CCAvenue).
- To send you promotional offers and updates about our services (only if you opt in).
- To improve our website, services, and customer experience based on aggregated usage data.
03.Data Sharing & Third Parties
- CCAvenue: Payment processing. Subject to CCAvenue's privacy policy.
- Amazon Web Services (AWS SES): Email delivery for booking confirmations and notifications.
- Meta (WhatsApp Business API): Sending booking confirmations and reminders via WhatsApp.
- We do NOT sell, trade, or rent your personal information to third parties for marketing purposes.
- We may share data when required by law, legal proceedings, or to protect the safety of our customers and staff.
04.Data Security
- All data transmitted between your browser and our servers is encrypted using SSL/TLS encryption.
- Passwords are hashed using industry-standard bcrypt encryption and are never stored in plain text.
- Payment information is handled entirely by CCAvenue's PCI-DSS compliant infrastructure.
- Access to customer data is restricted to authorized staff members only, with role-based permissions.
- We conduct regular security reviews and follow industry best practices to protect your data.
05.Your Rights
- Access: You can request a copy of the personal data we hold about you.
- Correction: You can update or correct your personal information through your account or by contacting us.
- Deletion: You can request deletion of your account and personal data. Some data may be retained for legal or business requirements.
- Opt-out: You can unsubscribe from promotional communications at any time.
- Data Portability: You can request your data in a machine-readable format.
06.Cookies & Tracking
- We use essential cookies for website functionality, authentication, and session management.
- We use analytics to understand how visitors use our website and improve user experience.
- No third-party advertising cookies or trackers are used on our website.
- You can control cookie preferences through your browser settings.
07.Data Retention
- Booking records are retained for a minimum of 5 years for legal and business purposes.
- Account data is retained as long as your account is active. Upon deletion request, data is removed within 30 days.
- Medical declarations are retained for the duration required by diving safety regulations.
- Payment records are retained as required by applicable tax and financial regulations.
08.Children's Privacy
- Our kids diving programs (Bubble Maker, Seal Team) require parental or guardian consent for children under 18.
- We collect minimal information for children and only with verified parental consent.
- Parents or guardians can request access to, correction of, or deletion of their child's information at any time.
09.Changes to This Policy
- We may update this privacy policy from time to time to reflect changes in our practices or legal requirements.
- Significant changes will be communicated via email to registered users.
- The 'Last Updated' date at the top of this page indicates when the policy was last revised.
- Continued use of our services after changes constitutes acceptance of the updated policy.