Privacy & Data Protection

Privacy Policy

Last updated: September 2026 • Compliant with EU General Data Protection Regulation (GDPR)

Zero Third-Party Ad Trackers

We do not sell personal data, run programmatic tracking pixels, or share subscriber lists with third-party data brokers.

Explicit Double Opt-In

Email capture requires an unticked consent checkbox and human confirmation. We never add addresses without verified permission.

Instant Permanent Erasure

Every email contains a direct unsubscribe link that permanently purges your record and saved beach data from our database.

1. Who We Are

Shores (shores.cc) is an independent European coastal intelligence directory documenting 737 beaches across 31 countries. We are committed to processing all user information transparently and in strict accordance with Regulation (EU) 2016/679 (GDPR).

2. What Personal Data We Collect

We practice strict data minimization (GDPR Article 5). We only collect information you voluntarily provide:

  • Email Address: When you request sea condition alerts or an email backup of your saved beach shortlist.
  • Saved Beach Identifiers: The slug IDs of beaches you favorited at the moment of subscription (e.g. praia-da-marinha-pt), used solely to personalize your sea temperature alerts.
  • Consent Metadata: Exact timestamp and text of the consent granted, maintained as proof of compliance under GDPR Article 7(1).
  • Cryptographic Tokens: Ephemeral tokens for double opt-in verification and direct unsubscription.

We do not collect names, physical addresses, phone numbers, payment details, or IP tracking profiles.

3. Legal Basis for Processing

The legal basis for processing your email and saved shortlist is Consent (GDPR Article 6(1)(a)). You grant this consent explicitly by checking an unticked confirmation box prior to submission. You may withdraw this consent at any time.

4. How We Use Your Information

Your data is used exclusively for:

  • Sending a one-time verification link and permanent restoration URL for your saved beach shortlist.
  • Delivering monthly seasonal sea temperature curves and swimming window updates for your saved coastal regions.

5. Data Storage & Security

Subscriber records are encrypted in transit via TLS 1.3 and stored in Cloudflare's secure distributed Key-Value infrastructure. Access is restricted strictly to automated verification and dispatch functions.

6. Your GDPR Rights (Right to Erasure)

Under the GDPR, you retain the following rights regarding your personal data:

  • Right to be Forgotten (Erasure): Every email sent by Shores contains an instant unsubscribe link. Clicking it immediately executes a complete deletion of your email and saved records from our storage.
  • Right of Access: You may request confirmation of what data we hold on you.
  • Right to Data Portability: You can export your saved beach list anytime via your permanent shortlist URL.

To exercise your rights manually or ask questions regarding privacy, contact us directly at [email protected].

7. Cookies & Local Storage

Shores operates on a cookieless model for first-party browsing:

  • Essential Local Storage: We use browser localStorage purely to remember your chosen theme (dark/light), temperature units (°C/°F), and saved beach IDs on this device.
  • Privacy-First Analytics: We use Cloudflare Web Analytics, a cookieless, non-invasive metrics system that measures overall site traffic without tracking individual users or building cross-site behavioral profiles.
  • Commercial Partner Links: Outbound links to verified travel partners (e.g. Booking.com, Localrent, Welcome Pickups) only activate referral tracking when you click out to visit the partner site.