Privacy Policy
Last updated: June 12, 2026
This Privacy Policy describes how Secure Cyber USA LLC, a Florida limited liability company ("we," "us," "our") collects, uses, and shares information when you use where-to-dive.com (the "Site").
The short version: we run a dive charter directory. We don't process bookings or payments, we don't sell your personal information, and we collect a modest amount of usage data to operate the Site and understand which listings people click.
1. Information We Collect
Information collected automatically:
- Server and usage logs. Like most websites, our hosting infrastructure logs requests, including IP address, browser type, device information, pages visited, and timestamps.
- Referral click data. When you click a link to an operator or booking platform, we record the click — including which charter was clicked, the destination platform, the time, your IP address, and your browser user-agent string. This helps us understand which listings are useful and supports our referral relationships.
- Cookies and similar technologies. We use cookies or local storage only for basic site functionality, such as remembering your theme preference. We do not use advertising cookies or trackers.
Information you provide:
- Contact and operator inquiries. If you email us or submit a form (e.g. to list or correct a charter), we receive what you send, including your name and email address.
- Account information. If you create an account, we collect your email address and authentication credentials.
We do not collect payment information. Bookings and payments happen entirely on operators' or booking platforms' sites under their own privacy policies.
2. How We Use Information
We use the information we collect to:
- Operate, maintain, and improve the Site
- Understand which listings and destinations are most useful
- Track referrals to operators and booking platforms, including for commission purposes
- Respond to inquiries and listing requests
- Protect the Site against abuse, fraud, and security threats
- Comply with legal obligations
We do not use your information for targeted advertising, and we do not sell or share personal information for cross-context behavioral advertising as defined by California law.
3. How Information Is Shared
We share information only with:
- Service providers that host and operate the Site on our behalf: Vercel (hosting and edge network), Supabase (database), and MapTiler (map tiles — when the map loads, your browser requests tiles directly from MapTiler, which receives your IP address as part of that request). These providers process data under their own terms as our processors.
- Referral and booking platforms. When you click through to an operator or platform (e.g. FareHarbor, PADI Travel, Rezdy), you leave our Site, and that destination collects data under its own privacy policy. Referral links may include an identifier indicating the visit came from us; they do not transmit your personal information from us.
- Legal and safety. We may disclose information if required by law, or to protect the rights, safety, or property of users, the public, or ourselves.
- Business transfers. If we are acquired or our assets are transferred, information may transfer as part of that transaction, subject to this policy.
We do not sell personal information.
4. Data Retention
We retain raw server logs and referral click records (including IP address and user agent) for up to 90 days, after which they are deleted or de-identified. Aggregated, de-identified click statistics may be retained indefinitely.
5. Your Rights
California residents (CCPA/CPRA): You have the right to know what personal information we collect and how it's used, to request deletion, to request correction, and to not be discriminated against for exercising these rights. Because we do not sell or share personal information for behavioral advertising, no opt-out is required, but you may still submit requests at rameenhash@gmail.com. We will verify and respond to requests within the time required by law.
Visitors from the EEA/UK (GDPR): Our legal bases for processing are legitimate interests (operating and securing the Site, measuring listing usefulness) and consent where required. You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. To exercise these rights, contact rameenhash@gmail.com.
Other jurisdictions: We honor applicable privacy rights under the law of your residence; contact us at rameenhash@gmail.com.
6. Children's Privacy
The Site is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us at rameenhash@gmail.com and we will delete it.
7. Security
We use reasonable technical and organizational measures to protect information, including access controls and encrypted connections (HTTPS). No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International Transfers
We are based in the United States and process information there. If you access the Site from outside the U.S., you understand your information will be transferred to and processed in the U.S.
9. Changes to This Policy
We may update this policy from time to time. The "Last updated" date reflects the current version, and material changes will be posted on the Site.
10. Contact
Privacy questions or requests: rameenhash@gmail.com Secure Cyber USA LLC, 222 W Yamato Rd, Ste 106-379, Boca Raton, FL 33431