Privacy Policy
Effective 29 September 2026
This policy explains what information Setform collects, why, with whom it is shared, and the rights you have over it.
1. Who runs Setform
Setform is an independent surf-forecasting project operated by Brian Wilson, an individual based in Switzerland. Setform is not a registered company. You can reach the operator at setform@proton.me.
For data-protection purposes, the operator acts as the data controller for any personal data described below.
2. What we collect
2.1 Anonymous visitors
If you visit Setform without creating an account, and without submitting one of our optional forms (see 2.4), Setform does not ask for or store personal data about you. Our service providers process some technical data, such as your IP address, to deliver and protect the site (see sections 2.5 and 4). We use cookieless aggregate analytics (Cloudflare Web Analytics and PostHog Cloud EU) to understand which spots are viewed and which features are used. We have configured both services not to set cookies or localStorage entries, not to record sessions, and not to create cross-site identifiers on your device. According to these providers, your IP address is used, if at all, only briefly to estimate an approximate location and is not stored by them for analytics. Setform does not store your IP address in its analytics.
2.2 Account holders
If you create a free account we collect:
- Email address: required, used to sign you in and to send account-related messages (verification, password reset, important service notices).
- Password: stored as a salted hash by our authentication provider (Supabase). The operator cannot see your password.
- First name: optional, used to address you in emails and to show your initial on your account button. You may leave it blank.
- Default surf spot: an optional preference you may set in your account page. Used to tailor what you see in the app.
- Display preferences: your measurement units (feet or metres) and whether the map opens on your default surf spot or on the region around it. Set in your account page.
- Marketing-email preference: a single yes/no flag captured during signup and editable from your account page. Off by default.
From the moment you create an account, and whenever you are signed in, our analytics provider (PostHog) associates your usage with an opaque internal identifier so we can understand retention and feature use at the account level. Setform does not send your email address, name or other account details to PostHog, only the opaque identifier.
2.3 Forecast lookups
When you view a spot, Setform's server requests the forecast from the Open-Meteo APIs on your behalf. The request contains the coordinates of the spot. Setform does not add your account identifier or other details about you to these requests.
2.4 Information you submit voluntarily
Setform has optional forms, for example "Request this spot" when a search finds no match. If you choose to submit one, we collect:
- Email address: required for a spot request or a suggestion, so we can follow up with you about it.
- Your message: the spot you requested or the feedback you wrote, plus, for a spot request, the search term that returned no result.
- Basic technical metadata: your browser's user-agent string, stored with the submission to help us reproduce issues. We do not store your IP address with these submissions, although Cloudflare Turnstile checks it when you submit (see 2.5).
We use this only to respond to you and to decide which spots to add and how to improve the service. Submissions are stored by Supabase (see section 4), and a copy of a new submission is emailed to the operator via Resend so it can be actioned. We do not use the email address you provide here for marketing.
2.5 Bot protection on forms
The sign-up, sign-in, password reset, spot request and feedback forms use Cloudflare Turnstile to tell people apart from automated bots. When you open one of these forms, Turnstile processes your IP address, basic details about your browser and connection, and the address of the page. Cloudflare uses this to detect and block bots and to improve its bot detection, and states that it does not use it to identify, profile or target individuals. See Cloudflare's Turnstile privacy terms. Setform does not receive or store these details.
3. Why we collect it
- To provide the service: deliver forecasts, sign you in, save your preferences across devices.
- To keep the service working: aggregate analytics tell us which features are used and which are not, so we can improve them.
- To communicate with you: account-related messages (always), and marketing emails (only if you opted in).
The legal bases for this processing under the GDPR / Swiss FADP are: performance of the agreement with you (the account and the service), the operator's legitimate interest in running a functional, secure, improvable site (aggregate analytics, protecting forms against automated abuse, and responding to feedback you choose to send us), and your explicit consent for marketing emails.
4. Who else processes your data
Setform uses a small set of third-party service providers ("sub-processors") to run. Each is named below with what it handles and, where known, where it stores the data.
- Cloudflare: site hosting (Cloudflare Pages) and edge security. Operates globally; serves you from the nearest edge. Like any web host, it processes your IP address to deliver and protect the site.
- Cloudflare Web Analytics: cookieless aggregate analytics. According to Cloudflare, IP addresses are not stored for analytics.
- Cloudflare Turnstile: bot protection on the forms listed in section 2.5. Processes your IP address and basic browser details to detect automated traffic.
- PostHog Cloud EU (Frankfurt, Germany): cookieless product analytics. For account holders, your events are tagged with an opaque internal identifier; no email or name is shared.
- Supabase (Frankfurt, Germany): authentication and account-data storage. Holds your email, password hash, first name, and preferences, and may record technical details such as IP addresses in its security logs. When you confirm your current password, to change it or to delete your account, the time of each attempt is recorded against your account for a short time, to limit repeated guessing.
- Open-Meteo (Germany): forecast data provider. Receives the coordinates of the spot, with no account identifier.
- Resend (United States): transactional and marketing email delivery. Receives the email address it is sending to and the message content.
Each of these providers has its own privacy policy. Where data is transferred outside the EU/EEA/Switzerland (for example to Cloudflare and Resend), these providers state in their data processing terms that such transfers rely on the European Commission's Standard Contractual Clauses or equivalent safeguards recognised in Switzerland.
5. Cookies and tracking
Setform does not use any cookies for analytics, advertising, or cross-site tracking. For signed-in users, our authentication provider (Supabase) stores a session token in your browser's local storage. This is what keeps you signed in across reloads, and clearing your browser data signs you out.
Setform also keeps a few settings in your browser so the site opens the way you left it: your measurement units, the surf spots you viewed recently, a copy of your account preferences so your page loads faster, a count of forecast requests made from this browser, and, on a business display, its access code. For the current visit only, it also keeps recent forecasts and the surf spot you opened first. None of this is sent to Setform or to anyone else, and clearing your browser data removes it.
We do not run advertising, do not embed third-party social-media widgets, and do not load any pixels or trackers from external networks. Your browser loads scripts from an external network in two cases: the Cloudflare Web Analytics beacon described in section 4, which is cookieless and, according to Cloudflare, does not store IP addresses for analytics, and Cloudflare Turnstile, which loads only when you open one of the forms listed in section 2.5. Our product analytics (PostHog) are served through this site's own domain, and the sign-in library is served from this site directly.
6. Your rights
If you are based in the EU/EEA, the UK, or Switzerland (and in many other jurisdictions), you have the following rights over your personal data:
- Access: see what we hold about you.
- Rectification: correct anything that is wrong.
- Deletion: have us erase your account and associated data.
- Portability: receive a copy in a portable format.
- Restriction: ask us to stop certain processing.
- Objection: object to processing based on legitimate interest.
- Withdraw consent: for marketing emails or any other consent-based processing, at any time.
- Complain: lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your local data-protection authority).
Most of these rights can be exercised directly from your account page. You can edit your first name, change your password, change your default surf spot and display preferences, toggle marketing emails, and delete your account, which deletes your account and the data stored with it, as described in section 7. To exercise any other data-protection right (for example, requesting a copy of your data), email setform@proton.me; under the GDPR and Swiss FADP we will respond within one month, and will let you know if a complex request needs longer, as those laws permit. For general questions or feedback you can use the same address. Replies to messages that are not rights requests can take longer.
7. How long we keep your data
- Analytics: kept in aggregate for as long as they are useful, within the retention periods set by each analytics provider. Anonymous analytics are not designed to identify individuals.
- Account data: retained while your account exists. When you delete your account, your account and the data stored with it are deleted from Setform's database straight away. Backup copies held by our provider are removed as part of its normal backup cycle. Analytics events already recorded under your internal identifier (section 2.2) are not deleted, but after deletion they are not linked to any account, and form submissions (section 2.4) are handled separately.
- Form submissions: feedback and spot requests (section 2.4) are kept while they are needed to reply to you or to decide which spots to add and what to improve, then deleted. You can ask us to delete yours sooner by emailing the address below.
- Email logs: transactional and marketing email-delivery logs are retained by Resend for a limited period under its own policy.
8. Security
Passwords are stored as salted hashes by Supabase and the operator cannot see them. Account data is protected by row-level security, which is designed to stop one account from reading another account's data. The site uses HTTPS throughout and applies a Content Security Policy. These measures reduce risk but cannot remove it, and no online service can guarantee complete security.
9. Children
Setform is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has created an account, email setform@proton.me and we will delete it.
10. Changes to this policy
The "Effective" date at the top of this page always reflects the current version.
If a change would meaningfully alter what we collect, why we collect it, or who receives it, in a way that is adverse to you, account holders will be notified by email at least 14 days before it takes effect. Other changes take effect when published, shown by an updated "Effective" date. These include corrections, clarifications, renumbering, changes that reduce what we collect or who receives it, and changes required by law.
If you do not accept a change, you may delete your account at any time from your account page.
Questions about this policy or your data? Email setform@proton.me.