Privacy policy
Last updated 14 September 2026. Applies to Go Dive Trips (https://godivetrips.com). Operated by Simon Hansen, Thailand. Questions: hello@godivetrips.com.
In short: reading the site sends us nothing but the ordinary server log. We only receive personal data when you send it: a booking request, a contact message, a WhatsApp message or an email. We use it to answer you and to arrange the booking with the dive operator, we keep it as long as that takes plus what accounting law requires, and we do not sell it or use it for advertising.
1. Who is responsible
The controller is Simon Hansen, trading as Top Dive Shops / Go Dive Trips, [postal address — required for EU visitors], Thailand. Email hello@godivetrips.com. The same person operates both Go Dive Trips and Top Dive Shops; this policy covers both sites.
We are established outside the EU and UK and do not have a representative there yet. Our processing of EU and UK visitors' data is occasional and limited to what is described here; if that changes we will appoint a representative under Article 27 GDPR and name them on this page.
2. What we collect, why, and on what legal basis
| When | Data | Purpose | Legal basis (GDPR) | Kept |
|---|---|---|---|---|
| You visit any page | IP address, time, page requested, browser type and referrer, in the hosting provider's server log | Delivering the pages, security, abuse prevention | Legitimate interest (Art. 6(1)(f)) | Up to 30 days in the host's logs |
| You send a booking request | Name, email, phone or WhatsApp number, dates, group size, certification level, message | Checking availability with the operator, confirming your booking, sending the payment link, support | Contract (Art. 6(1)(b)) | Duration of the booking, then 7 years for accounting records |
| You use the contact form | Name, email, message | Answering you | Legitimate interest (Art. 6(1)(f)), or contract if you ask about a booking | Until answered, then up to 12 months |
| You write on WhatsApp or email | Your number or address, the conversation | Answering you, arranging a booking | Contract or legitimate interest | As above |
| You pay a deposit | Name, email, amount; card data goes to Stripe only | Taking the deposit, refunds, accounting | Contract; legal obligation for accounting (Art. 6(1)(c)) | 7 years |
| You allow third-party embeds | IP address and cookies sent to Google, Meta (Instagram) or TikTok by your browser | Showing an operator's Google Maps photos or social posts | Consent (Art. 6(1)(a)), given in the cookie banner; withdraw any time via "Cookie settings" | Your choice is stored in your own browser only |
| You pick a currency | The currency code, in your browser's local storage | Showing prices the way you chose | Strictly necessary for the function you requested | Until you clear your browser |
| You email us a correction or a review | Name, email, what you tell us | Improving the rankings and guides | Legitimate interest | As long as the content it concerns is published |
We do not run analytics, advertising pixels or A/B testing tools, and we do not build profiles. If we add a privacy-preserving, cookie-free analytics tool later, we will list it here first.
3. Who else sees your data (processors and recipients)
- Hostinger International Ltd. (Cyprus) hosts the sites and our mailboxes. Data may be stored in the EU or in other regions Hostinger operates in.
- Web3Forms relays contact and booking forms to our mailbox. It stores the submission only long enough to deliver it.
- Stripe Payments Europe Ltd. processes deposits. Stripe is an independent controller for the payment itself; see Stripe's privacy policy. We never see your full card number.
- The dive operator you book with receives your name, contact details, dates, group size and certification level, because they need them to run your dive. Operators are in Thailand, Indonesia, the Maldives and other destinations outside the EU. They are independent controllers for the data they hold.
- WhatsApp (Meta Platforms Ireland Ltd.) when you choose to message us there. Meta's terms and privacy policy apply to the transport.
- Google LLC, Meta Platforms Ireland Ltd., TikTok Technology Ltd. only if you allow embeds. They receive your IP address and set their own cookies when the embed loads.
- Google (Gmail): our mailboxes forward to a Google Workspace / Gmail account we control, so email to us is stored by Google.
We do not sell personal data, and we do not share it with data brokers or advertisers.
4. International transfers
We are based in Thailand. Data you send us therefore leaves the EU/UK. Thailand's Personal Data Protection Act (PDPA) applies to us domestically. For transfers to processors in the US (Web3Forms, Stripe, Google, Meta) we rely on their EU–US Data Privacy Framework certification or standard contractual clauses, as published by each provider. Transfers to dive operators are necessary to perform the contract you asked for (Art. 49(1)(b) GDPR).
5. Your rights
Wherever you are, you can ask us what we hold about you, ask us to correct or delete it, ask for a copy in a portable format, object to processing based on legitimate interest, and withdraw consent (for embeds: click "Cookie settings" at the bottom of any page). Email hello@godivetrips.com; we answer within 30 days. We may ask you to confirm the email address the request comes from.
- EU / EEA: you can also complain to your national data protection authority (list at edpb.europa.eu). Swedish visitors: Integritetsskyddsmyndigheten (IMY).
- UK: the Information Commissioner's Office, ico.org.uk.
- Thailand: the Personal Data Protection Committee (PDPC).
- California (CCPA/CPRA): we do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. You have the rights to know, delete, correct and not be discriminated against; use the email above.
- Other places (Australia, Canada, Brazil, Switzerland and so on): the same rights apply in practice; write to us.
6. Security
The sites are served over HTTPS only. Forms post over HTTPS. Mail is stored in password-protected mailboxes with two-factor authentication. Booking records are kept in our mailbox and a spreadsheet we control, not in a public tool. We cannot guarantee the security of email or WhatsApp in transit, so please do not send us passport numbers, card numbers or medical details; the operator will ask for what they need on the day.
7. Children
The sites are for adults. Dive operators set their own minimum ages (usually 10 for a junior certification). A booking for a minor must be made by a parent or guardian, who is our contact.
8. Changes
We update this page when what we do changes. The date at the top is the version that applies. Substantial changes to how we use booking data are announced on this page for at least 30 days.