Riverways Privacy Policy
Last Updated: 15th July 2026
This Privacy Policy describes how Riverways (“Riverways”, “we”, “us”, “our”) collects, uses, discloses, and protects information in connection with the Riverways application, website, APIs, and related services (collectively, the “Service”).
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Scope
This Privacy Policy applies to all users of the Service, including mobile applications, web applications, APIs, and any associated software, features, or content.
This Policy does not apply to third-party services that may be accessed through the Service. Those services are governed by their own privacy policies.
2. Information We Collect
We design Riverways to minimise the collection of personally identifiable information. However, in order to operate, maintain, secure, and improve the Service, we may process the following categories of data.
2.1 Device and Technical Information
We may collect technical and device-related information, including:
- Device model and hardware identifiers (non-personalised where possible)
- Operating system version
- Application version
- Language settings
- Browser type (web use)
- Network information (including IP address)
- Approximate geographic location derived from IP address or from your device’s GPS if consent is granted
- System configuration and performance metrics
2.2 Usage and Interaction Data
We collect information about how users interact with the Service, including:
- Feature usage and navigation patterns
- Route searches and interactions with mapping and routing functionality
- View and engagement events (e.g. map interactions, POI selection)
- Error logs, diagnostic data, and crash reports
- Performance telemetry (latency, load times, service responsiveness)
2.3 Location Data
We may infer approximate location from IP address for purposes such as:
- Service optimisation
- Regional content delivery
- Fraud prevention and security monitoring
We do not rely on continuous background GPS tracking unless explicitly enabled and disclosed within the application.
We do use your precise location when enabled within the application for the following purposes:
- Recommending locations and businesses to visit through paid advertising or organic means
- Advising on safe navigation
- Giving you directions
- Displaying your location on a map
3. Analytics and Diagnostics
We use third-party analytics and crash reporting providers, including:
- PostHog
These services assist in:
- Understanding usage trends
- Diagnosing application errors and crashes
- Improving performance, stability, and reliability
Data processed by these providers may include device identifiers, IP address, usage events, and diagnostic information. This data is not used by Riverways to directly identify individual users.
4. Business and Aggregated Insights
The Service may process interaction data relating to businesses, points of interest, and mapped entities within Riverways.
We may generate aggregated and anonymised insights such as:
- Footfall or interaction trends
- Feature engagement metrics
- General usage statistics for mapped locations or listings
Where such insights are shared with business owners or partners:
- Data is aggregated and does not identify individuals
- No personally identifiable information is disclosed
- Users cannot be individually identified from shared outputs
5. Payments
Payments are processed via third-party payment processors, including Stripe.
Riverways does not store full payment card details.
All payment transactions are subject to the privacy policies and terms of the relevant payment provider. We encourage users to review those policies independently.
6. Legal Basis for Processing (UK GDPR / EU GDPR)
Where applicable, we process personal data under one or more of the following legal bases:
- Legitimate Interests – including service improvement, security, fraud prevention, and analytics
- Contractual Necessity – to provide access to the Service and fulfil user requests
- Legal Obligation – where required to comply with applicable law or regulatory requirements
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- Provision of the Service
- Security and fraud prevention
- Compliance with legal obligations
- Resolution of disputes and enforcement of agreements
Aggregated, anonymised, or de-identified data may be retained for longer periods.
8. Data Security
We implement appropriate technical and organisational security measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures include, where appropriate:
- Encryption of data in transit and at rest
- Access controls and authentication mechanisms
- Network security monitoring
- Logging and audit systems
- Segregation of production systems and data environments
No system can be guaranteed to be completely secure, and we cannot guarantee absolute security of information transmitted to or from the Service.
9. International Data Transfers
Personal data may be processed and stored in the United Kingdom and the European Union.
Where data is transferred outside the UK or EU, we implement appropriate safeguards in accordance with applicable data protection laws, including standard contractual clauses or equivalent mechanisms where required.
10. Children’s Privacy
The Service is not directed to individuals under the age of 13, and we do not knowingly collect personal data from children under 13.
If we become aware that such data has been collected inadvertently, we will take reasonable steps to delete it promptly.
11. Data Subject Rights
Subject to applicable law, individuals may have the following rights:
- Right of access to personal data
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to object to processing
- Right to data portability (where applicable)
Requests may be submitted to us using our
We may require verification of identity before processing requests.
12. Data Deletion Requests
Users may request deletion of their personal data by submitting a request using our
support form.
Upon verification, we will delete or anonymise personal data unless retention is required for legal, regulatory, security, or legitimate business purposes.
13. Third-Party Services
We integrate third-party services to support operation and functionality of the Service, including:
- PostHog (usage analytics, error monitoring and diagnostics)
- Stripe (payment processing)
These providers process data under their own privacy policies and terms. Riverways does not control third-party processing activities.
14. Data Sharing and Disclosure
We do not sell personal data.
We may disclose information in the following limited circumstances:
- To service providers acting on our behalf
- To analytics providers in aggregated or pseudonymised form
- To comply with legal obligations or lawful requests
- To protect the rights, safety, and security of Riverways, users, or the public
We do not disclose personally identifiable information to third-party businesses for commercial profiling or advertising purposes.
15. No Sale of Personal Data
Riverways does not sell personal data.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in technology, legal requirements, or our services.
Where required by law, we will provide notice of material changes. Continued use of the Service constitutes acceptance of the updated Privacy Policy.
17. Partner Data and Integrated Services
Riverways may integrate with third-party partners, including but not limited to boatyards, marinas, charter providers, booking platforms, and other travel or marine service providers (“Partners”), in order to enable enhanced functionality within the Service.
17.1 Partner-Provided Information
Where you interact with a Partner through or in connection with the Service (for example, making a booking with a partnered boatyard or marina), we may receive limited information from that Partner relating to your interaction.
This may include, where applicable:
- Booking confirmation status
- Reservation details (e.g. dates, location, vessel or service type)
- Itinerary or service fulfilment information necessary to support your experience within the Service
- Basic reference identifiers associated with your booking
17.2 Purpose of Processing Partner Data
Any Partner-provided information is used solely for the purpose of:
- Displaying and managing your bookings or reservations within the Riverways application
- Providing a personalised and context-aware user experience (for example, showing relevant moorings, routes, or services during your trip)
- Supporting customer service and trip-related functionality
- Enabling seamless integration between the Service and Partner systems
This processing is intended to enhance your travel or boating experience by providing relevant, contextual information within the Service.
17.3 Storage and Transmission of Partner Data
Riverways does not operate as the primary repository for Partner booking systems.
Where Partner data is received:
- It is used transiently to support in-app functionality and user experience
- It is not used to create independent commercial datasets
- It is not combined with advertising profiles
- It is not used for profiling beyond what is necessary to provide the Service
In certain integrations, Partner data may be processed in real time and may not be persistently stored by Riverways systems, depending on the nature of the integration and technical implementation.
17.4 Data Responsibility and Third-Party Terms
Each Partner acts as an independent data controller for their own booking systems and services unless otherwise stated.
Your interactions with Partners, including bookings and contractual arrangements, are governed by the Partner’s own terms and privacy policies. Riverways is not responsible for the privacy practices, policies, or content of Partners.
We encourage users to review the relevant Partner terms before completing any booking or transaction.
17.5 No Sale or Commercial Use of Partner Booking Data
Riverways does not sell, rent, or commercially exploit Partner booking data or reservation information.
Partner data is not used for targeted advertising, behavioural profiling outside the Service, or third-party commercial analytics.
17.6 Security and Minimisation
We apply data minimisation principles to Partner data and implement appropriate technical and organisational measures to protect such information, including encryption in transit and access controls where applicable.
We only process Partner data to the extent necessary to deliver the integrated functionality requested by the user.
17.7 Service Personalisation
Where Partner data is available, it may be used to provide a tailored in-app experience, such as:
- Showing relevant waterways, routes, or facilities near your booked location
- Displaying contextual trip information during active reservations
- Enhancing navigation and planning around booked services
This personalisation is strictly limited to the functionality of the Riverways Service and is not used to build external user profiles.
18. Contact Information
If you have questions about this Privacy Policy or our data practices, you may contact us at:
Riverways Support
Submit a support request