Version: 1.1
Last updated: 1 August 2026
Effective date: 1 August 2026
This Privacy Policy explains how SHORELY LTD (brand Shorely™, trading as Shorely Ibiza) (“Shorely”, “we”, “us”, or “our”) collects, uses, stores, and shares personal data when you use the Shorely Ibiza mobile application (the “App”), our website at shorelyibiza.app, and related services (together, the “Services”). Bookings are made in the App only; the website is informational and does not process bookings.
SHORELY LTD is a private limited company registered in England and Wales (Company No. 15894717), with registered office at 128 City Road, London, United Kingdom, EC1V 2NX. We are the data controller for personal data processed through the Services, unless stated otherwise. Cookie consent on the website is governed by our Cookie Policy; it does not apply inside the App.
By using the Services, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Services.
1. Data we collect
Depending on how you use the Services, we may collect the following categories of personal data:
Account & profile information
- Name, email address, and password (stored securely via our authentication provider)
- Profile details you choose to provide (e.g. display name, profile photo, language preference)
- Account identifiers and authentication tokens
- Communication preferences and privacy settings
Booking & transaction information
- Booking details (venue, beach resource, ferry route, activity, dates, party size, special requests)
- Contact details needed to fulfil a booking (name, email, phone number where required)
- Booking status, confirmations, cancellations, and support correspondence
- Payment-related metadata (amount, currency, transaction reference, payment status). We do not store full payment card numbers. Card payments are handled by Stripe.
Location data
- Precise or approximate device location only if you grant permission in your device settings
- Location is used for features such as maps, nearby discovery, distance estimates, and transport suggestions
- You can use many parts of the App without enabling location; some features may be limited
Usage & device information
- App interactions (screens viewed, taps on key actions such as directions or booking buttons)
- Device type, operating system, app version, language, and general technical logs
- Crash reports and diagnostic data to help us fix errors
- Deep link / referral data when you arrive via a shared link
Favourites, saved content & preferences
- Beaches, venues, activities, and other items you save or favourite
- Search and browsing preferences where stored in your account
Communications
- Messages you send to our support team
- Transactional emails and messages (booking confirmations, account notices) sent via our email and messaging providers
- Push notification delivery tokens and engagement data (see Push notifications below)
2. How we use your data
We use personal data to:
- Provide, operate, and improve the Services
- Create and manage your account
- Process and administer bookings (ferries, activities, venue resources, and related services)
- Process payments and prevent fraud
- Send booking confirmations, service updates, and support responses
- Send push notifications you have agreed to receive
- Personalise content (e.g. nearby recommendations when location is enabled)
- Measure app performance and understand how features are used
- Maintain security, detect abuse, and comply with legal obligations
- Respond to enquiries and enforce our terms
We do not sell your personal data.
3. Legal bases (UK GDPR & EU GDPR)
Where UK or EU data protection law applies, we rely on the following legal bases:
- Contract — to provide the Services and fulfil bookings you request
- Legitimate interests — to improve the App, secure our systems, analyse usage, and communicate about your account or bookings (balanced against your rights)
- Consent — for optional location access, push notifications, and certain marketing where required
- Legal obligation — where we must retain or disclose data to comply with law
You may withdraw consent at any time where processing is based on consent (see Your rights).
4. Location data
The App may request access to your device location through iOS or Android permission prompts. Location is used to show your position on maps, calculate distances, suggest nearby beaches and venues, and improve transport-related features.
You can disable location access at any time in your device settings. We do not use location for advertising profiling. Map and geocoding services are provided by third-party providers (see Sharing & processors).
5. Bookings & payments
Bookings
When you make a booking, we collect the information needed to complete it and share relevant details with the applicable partner (e.g. ferry operator, activity supplier, venue, or booking platform) so your reservation can be honoured.
Ferry bookings may be fulfilled through third-party ferry platforms and carriers. Activity bookings may involve partners such as Viator or other experience providers. Venue and resource bookings may be processed through our booking infrastructure and partner systems.
Payments (Stripe)
Payments for supported bookings are processed by Stripe Payments Europe Ltd (or its affiliates), our payment processor. When you pay, Stripe collects payment card details and billing information directly. We receive limited payment metadata (such as payment status, amount, and a transaction identifier) to confirm your booking and provide support.
Stripe’s privacy policy is available at stripe.com/gb/privacy.
6. Analytics
We use analytics tools to understand how the App is used and to improve performance. This may include:
- PostHog — product analytics: screens viewed, feature usage events, and aggregated usage statistics
- Firebase Analytics (Google) — legacy usage analytics, being phased out
- Internal analytics tied to your account where you are signed in
Analytics data is generally collected in aggregated or pseudonymous form. Where required by your device settings or applicable law, we respect platform-level tracking preferences.
We rely on legitimate interests for product analytics. You can turn analytics off at any time in the App under Profile → Privacy → Analytics & Recording. We do not currently record or replay your screen; if we introduce session replay we will ask for your consent first.
PostHog’s privacy policy: posthog.com/privacy.
Google’s privacy information: policies.google.com/privacy.
7. Push notifications
With your permission, we send push notifications via OneSignal, Inc. for purposes such as booking updates, account notices, and relevant service announcements.
- We associate your account with a push subscription token on your device
- You can disable notifications in your device settings or within the App where available
- OneSignal’s privacy policy: onesignal.com/privacy
8. Sharing & processors
We share personal data only as needed to operate the Services, including with:
- Supabase — authentication, database, storage, and backend functions (hosted in the United Kingdom)
- Stripe — payment processing
- OneSignal — push notification delivery
- PostHog — product analytics
- Google (Firebase Analytics) — legacy usage analytics
- Mapbox — maps, geocoding, and location-based map features
- Zoho ZeptoMail — transactional emails
- Zoho Sign — Partnership Agreement execution with venues
- Twilio — booking-related WhatsApp or SMS where enabled
- Ferryhopper — ferry search, booking, and ticketing, together with the ferry operator carrying you
- Viator — activity and experience bookings
- Venues and reservation systems — the venue you have booked, so your reservation can be honoured
- ChottuLink — deep links and referral link attribution
- Bugsink — crash and error reporting to maintain reliability (self-hosted by Shorely)
- Professional advisers & authorities — where required by law or to protect rights and safety
These providers act as data processors on our instructions, or as independent controllers where they provide services directly to you (e.g. payment processing). We require appropriate safeguards under contract where applicable.
9. Retention
We keep personal data only for as long as necessary for the purposes described in this policy, including:
- Account data — while your account is active and for a reasonable period after deletion to handle disputes and legal obligations
- Booking records — for the period required to administer bookings, taxes, accounting, and legal claims
- Analytics & logs — typically in aggregated or shortened form according to provider retention settings
We may retain anonymised or aggregated data that cannot identify you.
10. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS), access controls, and secure authentication. No method of transmission or storage is completely secure; please use a strong, unique password and keep your device protected.
11. International transfers
Our primary database and account records are hosted in the United Kingdom. Transfers between the UK and the European Economic Area rely on the adequacy decisions in force between them.
Some of our service providers process data in the United States or other countries — including Stripe, OneSignal, Twilio, Google, and Mapbox. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable.
12. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (“right to be forgotten”) in certain circumstances
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority (in the UK: the ICO at ico.org.uk)
To exercise your rights, contact us at privacy@shorelyibiza.app. We may need to verify your identity before responding. We aim to respond within one month.
You can delete your account from within the App where that feature is available, or by emailing us. Some data may be retained where we have a legal obligation or legitimate need (e.g. completed booking records).
13. Children
You must be 18 or over to create a Shorely account or make a booking, as set out in our Terms of Service. The Services are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, please contact us and we will take steps to delete it.
Where an adult account holder provides passenger details for a child travelling with them (for example on a ferry booking), we process that data solely to fulfil the booking, on the account holder’s instruction.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be communicated through the App, by email, or on our website where appropriate. Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
15. Contact
SHORELY LTD (trading as Shorely Ibiza)
Company No. 15894717
128 City Road, London, United Kingdom, EC1V 2NX
Privacy & data requests:
privacy@shorelyibiza.app
General support:
support@shorelyibiza.app
Website:
shorelyibiza.app