Skip to main content

Legal

Privacy Policy for NORDR

Last updated: 20 August 2026 · Effective date: 19 August 2026

Also see our Terms of Use and the PelagicLabs website privacy policy.

NORDR is a native iOS surf app distributed through the Apple App Store. This notice applies to the NORDR app and the backend services used by the app. It explains what personal data is handled, where it comes from, why it is used, how long it is retained, who receives it, and the rights available to you under the GDPR and other applicable data-protection law.

NORDR is local-first. Saved spots, custom spots, surf sessions, Quiver data, alert rules, and preferences are normally stored on your device and are not currently synchronized as a complete profile across devices. Information leaves the device when an online feature needs it, when you create or use an account or subscription, or when you deliberately share or submit information.

This legally operative notice is currently provided in English. You may contact us to request an explanation in another European language.

1. Controller and Scope

The controller for personal data processed through NORDR and the NORDR backend is:

PelagicLabs has not appointed a data-protection officer because the present scale and nature of the processing do not require one. Privacy requests are handled through the contact above.

This notice does not govern ordinary visits to pelagiclabs.io, website forms, or website analytics. Those activities are covered by the PelagicLabs website privacy policy linked above.

2. Personal Data NORDR Handles

2.1 Accounts and authentication

NORDR uses Firebase Authentication and supports anonymous guest access, email and password, Sign in with Apple, and Google Sign-In. Depending on the method you use, the data can include:

  • Firebase user ID and authentication-provider identifiers
  • Email address and, where supplied, display name or profile image
  • Authentication tokens, session state, login timestamps, and security metadata
  • An Apple authorization code stored in secure device storage when needed for Apple-linked account management
  • An anonymous Firebase identifier when you continue as a guest

Firebase Authentication handles passwords and identity tokens. PelagicLabs does not store your password in plaintext in the NORDR backend.

2.2 Location, maps, and surf spots

With foreground-location permission, NORDR can use your current or last-known latitude and longitude to find nearby surf spots and local conditions. The current app does not request continuous or always-on background location. Location-related data can include:

  • Current or last-known latitude and longitude
  • Selected, home, favorite, recent, and custom spot coordinates
  • Spot name, country or region, break type, facing direction, and tide settings
  • Reverse-geocoded city, region, or country information
  • Timezone, station, map viewport, forecast horizon, and related request parameters

Coordinates used for forecasts, maps, reverse geocoding, tides, bathymetry, buoy observations, and nearby-spot features are transmitted to the NORDR backend or the relevant platform or data service. You can deny location permission and select a spot manually.

2.3 Data stored locally in the app

NORDR stores app data in operating-system application storage and, for selected secrets, secure storage. Depending on the features you use, local data can include:

  • Home, favorite, recent, and custom spots
  • Surf-session journal entries, check-in history, and streak data
  • Surfboard Quiver, board preferences, surf level, and gear settings
  • Custom spot tuning, directional sectors, calibration rules, and alert rules
  • Language, units, appearance, haptics, onboarding, and notification preferences
  • Forecast, buoy, tide, map-score, source, reliability, and evidence caches

This complete local profile is not currently uploaded to a NORDR cloud database. Limited elements are transmitted only where a feature described in this notice requires them.

2.4 Notifications and device identifiers

  • Notification permission and local scheduling state
  • Alert thresholds, schedules, quiet hours, and duplicate-suppression history
  • Device platform and a randomly generated Smart Alerts installation identifier
  • Expo push token, if server-delivered Smart Alerts are enabled
  • Evaluation, cooldown, synchronization, and delivery timestamps

2.5 Purchases and subscriptions

NORDR uses RevenueCat to display offerings, complete and restore purchases, and determine paid entitlement status. RevenueCat may receive a Firebase user ID or anonymous app-user ID, product and transaction identifiers, receipt and subscription status, renewal and entitlement information, and app, platform, device, or SDK metadata needed to operate purchases. Apple or Google processes the payment. PelagicLabs does not receive your full payment-card details.

2.6 Network, security, and operational data

Internet requests expose an IP address and standard request metadata to the NORDR backend, hosting infrastructure, and relevant providers. Operational records can include authenticated user ID where required, request path and method, timestamp, status code, latency, response size, rate-limit state, and bounded error context. These records are used for service delivery, security, abuse prevention, debugging, and reliability, not to create an advertising profile or movement history.

3. Where Personal Data Comes From

  • From you: account details, selected spots, custom spots, Quiver, sessions, alert rules, settings, shared payloads, and messages you send to support
  • From your device and operating system: location when permitted, platform information, notification permission, push token, app version, language, and network metadata
  • From Apple, Google, and Firebase: identity and authentication data associated with the sign-in method you select
  • From RevenueCat and app stores: purchase, subscription, restoration, and entitlement status
  • From marine, weather, tide, buoy, map, and bathymetry providers:environmental and geospatial data returned for the location or station requested

PelagicLabs does not buy NORDR user profiles from data brokers or enrich NORDR accounts with public social-media profiles.

4. Purposes and Legal Bases

Where the GDPR applies, the table below explains the principal purpose and legal basis for each processing activity. A feature can involve more than one basis when the purposes differ.

Processing purposeGDPR legal basis
Create, authenticate, secure, recover, and delete an optional accountArticle 6(1)(b), performance of the service contract; Article 6(1)(f) for authentication security and fraud prevention
Deliver forecasts, maps, nearby spots, tides, buoy data, personalization, local storage, and other features you requestArticle 6(1)(b), performance of the service contract; Article 6(1)(a) where consent is legally required for access to device location or another optional permission
Schedule local notifications and, when available, deliver server Smart AlertsArticle 6(1)(b), providing the alert service you enabled; Article 6(1)(a) where consent is required. Operating-system notification permission is also required
Create and restore purchases and determine NORDR Pro entitlementArticle 6(1)(b), performance of the purchase or subscription contract; Article 6(1)(c) for applicable tax, accounting, and consumer-law duties
Create a custom-spot share link or process a support request you initiateArticle 6(1)(b), taking the action you requested; Article 6(1)(f) for support history, troubleshooting, and legal claims where needed
Protect NORDR, enforce rate limits, prevent abuse, diagnose faults, and maintain service availabilityArticle 6(1)(f), PelagicLabs' legitimate interests in secure, reliable, and fraud-resistant services
Respond to legal requests, exercise or defend legal claims, and comply with data-protection obligationsArticle 6(1)(c), legal obligation; Article 6(1)(f), establishment, exercise, or defence of legal claims

The legitimate interests relied on are service security, abuse and fraud prevention, technical reliability, support continuity, and protection of legal rights. You can object to processing based on legitimate interests as described in Section 12.

5. What Is Required and What Is Optional

  • Account: optional for guest-accessible features. Features that require an authenticated backend request or account management cannot work without a Firebase identity. You can use an anonymous account without supplying an email.
  • Location: optional. Without foreground-location permission, NORDR cannot automatically find nearby spots or use your current position, but you can select a spot manually.
  • Network request data: coordinates, spot or station identifiers, IP address, and request parameters are technically necessary for fresh online forecasts and other location-based network features. Cached or local features may remain available without a connection.
  • Notifications: optional. Without operating-system permission, NORDR cannot display local or server-delivered alerts.
  • Purchase data: required only to buy, restore, or verify paid access. Free features remain available without a purchase.
  • Sharing and support: optional and initiated by you. A share link cannot be created without sending the selected custom-spot payload to the backend.

You can withdraw consent or revoke an operating-system permission at any time. This does not affect processing that was lawful before withdrawal. Where processing is necessary to provide a feature, withdrawing the relevant permission means that the feature may stop working.

6. Notifications and Smart Alerts

Notifications are optional. Standard surf alerts are evaluated and scheduled on your device. Background re-evaluation may refresh forecasts and check alert rules when iOS permits NORDR to run; the operating system controls whether and when this happens.

Server-delivered Smart Alerts are rollout-controlled and may be unavailable in the current production build. When enabled for an eligible account, the NORDR backend can evaluate custom alerts while the app is closed. The backend record can contain:

  • Firebase user ID and per-device Smart Alerts installation ID
  • Expo push token and device platform
  • Enabled custom-alert names, conditions, schedules, and cooldown settings
  • Target spot IDs, names, coordinates, country, timezone, facing direction, and forecast-profile information
  • Synchronization, evaluation, cooldown, and notification timestamps

Smart Alerts records use a rolling 90-day expiry that is refreshed when the record is updated. Disabling server Smart Alerts requests deletion of the relevant device record. If a record remains because teardown did not complete before sign-out or account deletion, it expires no later than 90 days after its last refresh. You may contact PelagicLabs to request earlier deletion of data still under our control.

7. Custom-Spot Sharing and Support

7.1 Custom-spot share links

When you choose to create a short link for a custom spot, NORDR sends the selected share payload to the backend. It can include the spot name, precise coordinates, break type, optimal tide, directional tuning, calibration rules, and an optional gear override. The backend stores the payload for 90 days.

Anyone with the link can retrieve the payload during that period. Do not create or distribute a link for a location you want to keep private. Share links are not tied to your Firebase account and are not automatically removed by account deletion; they expire automatically after 90 days. If the short-link service is unavailable, NORDR can create a deep link that contains the payload directly.

7.2 Support and privacy requests

If you email PelagicLabs or use another external support channel, we process the contact details, message, attachments, and technical context you choose to provide so we can respond, investigate faults, maintain support history where necessary, and protect legal rights. The current in-app feedback text field does not transmit the entered text to PelagicLabs.

8. Automated Scoring and Personalization

NORDR automatically calculates surf scores, forecast calls, board suggestions, spot similarity, and alert matches. The logic combines environmental data such as wave height, period, direction, wind, tide, and reliability with spot geometry and, where you provide them, your surf level, Quiver, custom tuning, selected spots, and alert thresholds.

These outputs are advisory surf-planning information. They do not produce a decision that has legal or similarly significant effects on you, and NORDR does not use solely automated decision-making of the kind described in GDPR Article 22. Purchase entitlement is automatically displayed from the transaction status supplied by the app store and RevenueCat.

9. Recipients and Service Providers

PelagicLabs discloses only the information needed to operate the relevant feature. Provider roles can vary: some act for PelagicLabs, while others, such as app stores or identity providers, may act as independent controllers for their own services.

Recipient categoryPurpose and relevant data
Firebase AuthenticationGuest identity, email/password or provider sign-in, sessions, password reset, and account deletion; user ID, account data, tokens, and security metadata
Apple and Google identity servicesOptional Apple or Google sign-in; provider account and authentication data
RevenueCat and the Apple App StoreOfferings, purchases, restores, billing, and entitlement status; app-user ID, transaction, receipt, subscription, device, and platform data
Expo, Apple Push Notification service, and Firebase Cloud MessagingServer-delivered alerts when enabled; push token, platform, and notification payload and delivery metadata
Apple or Google platform map and location servicesDevice location, map display, and geocoding depending on platform and feature; coordinates, map requests, and platform metadata
NORDR backend, hosting, and Redis infrastructureForecast aggregation, caching, Smart Alerts, share links, security, and reliability; coordinates, spot and station IDs, authenticated alert records, shared payloads, IP address, and request metadata
Marine, weather, tide, buoy, map, and bathymetry providersConditions and geospatial data. Depending on location and feature, sources can include Open-Meteo, Rijkswaterstaat, MDK, CEFAS, SMHI, MET Norway, BSH, DMI, EMODnet, and OpenStreetMap. Requests can include coordinates, station IDs, parameters, and network metadata where a request reaches the provider
Professional advisers and public authoritiesLegal, accounting, security, or regulatory matters where disclosure is necessary and lawful

10. International Transfers

Some providers operate or use infrastructure outside Belgium, the EEA, or the United Kingdom. Where PelagicLabs is responsible for a restricted transfer, we use an applicable European Commission adequacy decision where available or safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required. Providers acting as independent controllers are responsible for their own transfer arrangements.

You can contact PelagicLabs to request more information about the transfer mechanism used for your data and how to obtain a copy of relevant safeguards, subject to appropriate redactions for confidentiality and security.

11. Retention and Deletion

  • Local app data: remains until you delete an entry, use the in-app account-deletion flow, clear app data, or uninstall NORDR. Operating-system backups and secure-storage retention follow your Apple or Google settings and the platform's rules.
  • Firebase account data: remains while the account is active and is deleted through the in-app flow, subject to provider backup, security, fraud, and legally required retention.
  • Forecast caches: retained according to cache freshness and reliability needs and replaced or expired as conditions update. They are not used to build a user movement history.
  • Smart Alerts: when server delivery is enabled, the device record is deleted when teardown succeeds or expires automatically no later than 90 days after its last refresh.
  • Custom-spot share links: expire 90 days after creation. Because the short link is not tied to your account, account deletion does not automatically locate or delete it.
  • Purchase records: retained by RevenueCat and the app stores for subscription operation, fraud prevention, accounting, legal obligations, and dispute handling under their retention rules.
  • Support and privacy requests: retained for as long as needed to answer and document the request, maintain necessary support continuity, protect legal rights, and meet legal obligations.
  • Security and operational records: retained only for as long as reasonably necessary for security, abuse prevention, fault investigation, reliability, and applicable legal claims. The exact period depends on record type, severity, and infrastructure-provider retention.

Deleting a NORDR account does not cancel an Apple App Store subscription. Manage or cancel the subscription through the Apple account used for purchase.

12. Your GDPR Rights

Subject to the conditions and limits in applicable law, you can request:

  • Access to personal data and information about how it is processed
  • Correction of inaccurate or incomplete personal data
  • Erasure of personal data where the legal conditions are met
  • Restriction of processing in the circumstances provided by law
  • A portable copy of data you provided where processing is automated and based on consent or contract
  • Objection, on grounds relating to your situation, to processing based on legitimate interests; PelagicLabs will stop unless compelling legitimate grounds or legal claims justify continuation
  • Withdrawal of consent at any time where consent is the legal basis
  • Complaint to a competent data-protection supervisory authority

Send a request to lukasmeerschaut@pelagiclabs.io. State that the request concerns NORDR and provide enough information to locate the relevant account or record. PelagicLabs may request proportionate information to verify your identity and protect other users. We respond without undue delay and in principle within one month, subject to the extensions permitted by law.

You may complain to the supervisory authority where you live, work, or believe an infringement occurred. PelagicLabs' Belgian supervisory authority is the Belgian Data Protection Authority, Drukpersstraat / Rue de la Presse 35, 1000 Brussels, Belgium, contact@apd-gba.be, +32 (0)2 274 48 00.

13. Children

NORDR is a general surf and weather utility and is not specifically directed at children. Where a child cannot lawfully consent to optional processing under the rules of their country, valid authorization from a parent or guardian is required. A parent or guardian can contact PelagicLabs to request review or deletion of a child's personal data.

14. Security, Local Storage, Advertising, and Tracking

PelagicLabs uses reasonable technical and organizational measures appropriate to the processing, including HTTPS, Firebase ID-token verification for protected routes, operating-system app sandboxing, secure device storage for selected secrets, input validation, rate limiting, and restricted service access. No system can be guaranteed completely secure.

NORDR uses local device storage to provide requested functions, preserve settings, maintain caches, and support offline behavior. It does not use local storage for third-party behavioral advertising or cross-app tracking.

PelagicLabs does not sell or rent NORDR personal data. The current native app does not include a programmatic advertising SDK or a separately configured product- analytics or crash-reporting service. Operational records created by Firebase, RevenueCat, app stores, push infrastructure, the backend, and upstream providers may still be processed as necessary to operate, secure, and troubleshoot those services.

15. Changes and Contact

PelagicLabs may update this notice when NORDR's data practices, providers, or legal obligations change. The date at the top identifies the current version. Material changes may also be communicated in the app or through another appropriate channel before they take effect where required.

Privacy questions and requests: lukasmeerschaut@pelagiclabs.io