Privacy Policy

Last updated: February 19, 2026

1. Who We Are

Avant Surf School ("we", "us", "our") operates the website at avantsurfschool.com. We are committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable privacy laws.

2. What Data We Collect

We collect the following personal data:

Data you provide directly

  • Account information: email address, name, password (encrypted), avatar image
  • Profile data: gender, surf level preferences

Data collected automatically

  • IP address: recorded at sign-up and login for security and fraud prevention
  • Page views: pages visited, timestamps, and associated IP addresses for analytics
  • Device information: browser type, operating system (via standard HTTP headers)

Cookies

  • Session cookie (_lms_surf_school_session): Essential for site functionality. Expires when you close your browser.
  • Remember me cookie (remember_user_token): Keeps you logged in. Expires after 2 weeks. Essential for authentication.
  • Cookie consent cookie (cookie_consent): Stores your cookie preference. Expires after 1 year. Essential.
  • Referral cookie (ref_code): Tracks referral attribution. Expires after 30 days. Non-essential — only set with your consent.

3. Why We Collect Your Data

Purpose Data Used Legal Basis
Provide your account and courses Email, password, profile Contract performance
Prevent fraud and referral abuse IP address at sign-up Legitimate interest
Login security IP address at sign-in Legitimate interest
Site analytics Page views, IP address Legitimate interest
Referral tracking Referral cookie Consent
Gamification (XP, levels, badges) Course progress, quiz scores Contract performance

4. How Long We Keep Your Data

  • Account data: retained while your account is active. Deleted upon account deletion request.
  • IP addresses (sign-up/login): retained for 90 days, then anonymized.
  • Activity logs: retained for 90 days, then anonymized (IP removed).
  • Cookie consent records: retained for 3 years (legal requirement to prove consent).

5. Who We Share Your Data With

We do not sell your personal data. We share data only with:

  • Polar.sh: payment processing (email, subscription ID). See Polar's Privacy Policy.
  • Hosting provider: our servers process your data to deliver the service.

6. Your Rights (GDPR)

You have the right to:

  • Access your personal data (request a copy)
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability (receive your data in a structured format)
  • Object to processing based on legitimate interest
  • Withdraw consent at any time (for cookie consent and referral tracking)

To exercise any of these rights, contact us at privacy@avantsurfschool.com.

7. Cookies & Consent

We use a cookie consent banner that appears on your first visit. Non-essential cookies (referral tracking) are not set until you consent. You can change your cookie preferences at any time by clearing your browser cookies, which will trigger the consent banner again.

Essential cookies (session, authentication, consent preference) do not require consent and are necessary for the site to function.

8. Data Security

We protect your data with:

  • Encrypted passwords (bcrypt)
  • HTTPS/TLS encryption in transit
  • CSRF protection on all forms
  • Rate limiting on authentication endpoints

9. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent revision. Continued use of the site after changes constitutes acceptance.

10. Contact

For privacy inquiries or data requests:
Email: privacy@avantsurfschool.com

Privacy Policy Terms of Service © 2026 Avant Surf School
We use essential cookies to make the site work. With your consent, we also use a referral tracking cookie. Read our Privacy Policy for details.