Privacy Policy
Effective Date: March 8, 2026 | Last Updated: March 8, 2026
1. Overview
HELM™ Sea Conditions ("HELM™", "we", "us", or "our") is a product of Vaughn Venture LLC, a limited liability company registered in the State of Alabama, United States. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our websites, progressive web applications, and related services (collectively, the "Service"), including:
- helmseaconditions.com — marketing website and HELM™ Intelligence
- app.helmseaconditions.com — HELM™ Sea Conditions weather application
- tournaments.helmseaconditions.com — HELM™ Tournaments
- app.helmcatch.com — HELM™ Catch
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
Information You Provide Directly
- Account Information: When you create an account, we collect your email address and password (encrypted). We use Supabase Authentication for secure account management.
- Profile Information: Name, display name, and optional profile details you choose to provide.
- Subscription & Payment Information: When you subscribe to a paid plan, payment is processed securely by Stripe, Inc. We do not store your full credit card number, CVV, or bank account details on our servers. Stripe handles all payment data in compliance with PCI-DSS standards.
- Captain's Log Data: GPS tracks, fishing stops, route waypoints, notes, photos, and trip data you record within the Captain's Log feature.
- Catch Data: Species, weight, location, photos, and details of catches you log in HELM™ Catch.
- Tournament Data: Registration details, catch submissions, and standings when you participate in tournaments via HELM™ Tournaments.
- User Submissions: Content you submit through the HELM™ Intelligence submission form, including tournament results, catch reports, and fishing news.
- Communications: Emails or messages you send to us for support or feedback.
Information Collected Automatically
- Device Information: Browser type, operating system, device type, screen resolution, and unique device identifiers.
- Usage Data: Pages visited, features used, time spent on pages, click patterns, and referral sources.
- Location Data: With your explicit consent, we collect GPS coordinates for the Captain's Log, fishing spot mapping, and weather data localization. See Section 6 for details.
- Log Data: IP address, access times, and server logs for security and performance monitoring.
Information from Third-Party Sources
- Weather Data: We aggregate data from NOAA, StormGlass, DWD/ICON, GFS, Open-Meteo, and WaveWatch III to provide sea condition forecasts. This data does not contain personal information.
- Public Fishing Data: The HELM™ Discovery Engine aggregates publicly available tournament results, catch records, and fishing news from public websites, RSS feeds, and social media. This data is publicly available and does not constitute private personal information.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process subscriptions and payments
- Deliver personalized weather forecasts and Go/No-Go assessments based on your location and fishing preferences
- Enable Captain's Log GPS tracking, route planning, and trip recording
- Operate HELM™ Tournaments and HELM™ Catch features
- Aggregate and display fishing intelligence through the Discovery Engine
- Post curated fishing content to HELM™ social media channels (Facebook, Instagram, Twitter/X) with proper source attribution
- Send you service-related notifications (account confirmation, subscription updates, feature announcements)
- Improve and optimize the Service based on usage patterns
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
6. Location Data
Location data is central to the HELM™ experience, and we treat it with the highest care:
- Consent: We only collect GPS location data when you explicitly grant permission through your browser or device. You can revoke this permission at any time through your device settings.
- Captain's Log: GPS tracks and fishing stop locations are stored in your private account. This data is never shared with other users or third parties.
- Weather Localization: Your general location is used to provide accurate weather forecasts for your fishing region. We do not store this data beyond the active session unless you save it to a profile.
- GPS Privacy Protection: Our public views and API endpoints use the
public_tournament_catchesview, which strips latitude and longitude coordinates before any data is returned publicly.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account Data: Retained until you delete your account.
- Captain's Log & Catch Data: Retained until you delete individual entries or your account.
- Payment Records: Retained as required by tax and financial regulations (typically 7 years).
- Discovery Engine Data: Publicly sourced content is retained indefinitely as it is derived from public sources.
- Server Logs: Retained for up to 90 days for security and debugging purposes.
You may request deletion of your account and personal data at any time by contacting us.
9. Data Security
We implement industry-standard security measures to protect your information:
- All data transmitted between your device and our servers is encrypted using TLS/SSL.
- Database access is protected by Row-Level Security (RLS) policies ensuring users can only access their own data.
- Passwords are hashed and salted — we never store plaintext passwords.
- Payment processing is handled entirely by Stripe, which maintains PCI-DSS Level 1 certification.
- We maintain database backups with Point-in-Time Recovery (PITR), nightly backups, and application-level caching.
- File uploads are restricted by type whitelisting, size limits, and malware scanning.
- Admin access is restricted by email whitelist.
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal information, subject to legal retention requirements.
- Portability: Request your data in a structured, commonly used, machine-readable format.
- Opt-Out: Opt out of marketing communications at any time by clicking "unsubscribe" in any email or contacting us directly.
- Location Permissions: Revoke GPS permission at any time through your browser or device settings.
To exercise any of these rights, contact us at [email protected].
California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of the sale of your personal information. We do not sell personal information.
European Residents (GDPR)
If you are located in the European Economic Area, you have additional rights under the GDPR, including the right to lodge a complaint with a supervisory authority. Our legal basis for processing personal data is your consent (for location data), contractual necessity (for providing the Service), and legitimate interests (for security and analytics).
11. Children's Privacy
The Service is not directed to individuals under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete it. If you believe a child has provided us with personal information, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last Updated" date. For significant changes, we may also notify you via email or through the Service. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
Vaughn Venture LLC
Gulf Shores, Alabama, United States
Email: [email protected]
5. Social Media Integration
HELM™ operates branded pages on Facebook, Instagram, and Twitter/X. Our social media integration works as follows:
pages_manage_postsandpages_read_engagementpermissions. We do not access, collect, or store any Facebook user data beyond what is necessary to publish posts and read engagement metrics on our own Page.Important: We never access your personal Facebook, Instagram, or Twitter account data. Our social media integration is limited to publishing content on HELM™-owned pages only.