Oceans

Privacy, Data and Cookies Policy

Effective date: 21 August 2026 · Version 1.0

Applies to the Oceans website, the Oceans mobile applications for Android and iOS, and all related services.

Oceans operates its servers and networks so as to protect your personal data and the information associated with it — both the data you give us and the data we obtain automatically when you use the Website and its services. We value your trust and we work to deserve it: alongside our legal obligations we hold ourselves to the ethical principles we consider the foundation of our relationship with every user.

This Policy explains what data we collect, how we collect it, why we collect it, who we share it with, how long we keep it, and how you can access, correct or delete it.

Who is responsible for your data. The data controller is Martians Tech (“Oceans”, “we”, “us”), Kingdom of Saudi Arabia.
Privacy contact: privacy@oceans.app
Data protection officer: dpo@oceans.app

Contents

  1. Scope and definitions
  2. Data we collect
  3. Why we use your data and on what legal basis
  4. Cookies and similar technologies
  5. Data that identifies you personally
  6. Who we share data with
  7. Transfers outside Saudi Arabia
  8. Security
  9. How long we keep data
  10. Deleting your account and your data
  11. Your rights under the Saudi PDPL
  12. Children
  13. Disclosure required by law
  14. Change of ownership
  15. Data breaches
  16. Changes to this Policy
  17. How to contact us and how to complain

1. Scope and definitions

Where this Policy refers to the Website, that term covers the Oceans website, platform and applications, and all software, applications and sites owned by Oceans that run on smartphones, tablets, other electronic devices and computers, on any operating system and in any browser.

This Policy is governed by the Personal Data Protection Law of the Kingdom of Saudi Arabia (Royal Decree M/19 of 1443H, as amended) and its Implementing Regulations (“PDPL”), supervised by the Saudi Data & AI Authority (SDAIA).

The definitions in our Terms and Conditions apply to this Policy. The Terms and Conditions and this Policy together form one indivisible agreement between Oceans and its users.

Third party means the merchants and operators who offer their services through Oceans — owners of vessels, boats and yachts, and stores selling marine food, goods, products, clothing, fashion and equipment — to whom we connect you as an intermediary.

2. Data we collect

2.1 Data you give us

2.2 Data we collect automatically

2.3 Data we collect only with your permission

2.4 Data we do not collect

We do not knowingly collect health data, biometric data, genetic data, religious or political affiliation, or any other category of sensitive data, and we do not ask you for it. Please do not include such data in reviews, chat messages or support requests.

3. Why we use your data and on what legal basis

Under the PDPL we must have a lawful basis for every use of your personal data. Ours are set out below.

PurposeData usedLegal basis
Creating and managing your account; authenticating you Identity, contact, account data Performance of a contract with you
Processing bookings and purchases and passing them to the third-party provider Identity, contact, booking, payment, verification data Performance of a contract with you
Customer support and dispute handling Account, booking, support and device data Performance of a contract; our legitimate interests
Security, fraud prevention, abuse detection, service protection Device, connection, usage, account data Legitimate interests; legal obligation
Fixing defects, diagnosing errors, improving and developing the service Usage, device, crash data Legitimate interests
Showing nearby boats and offers Precise location Your consent
Marketing messages, personalised offers, advertising Contact data, usage data, advertising identifier Your consent, which you may withdraw at any time
Analytics and market analysis Aggregated or pseudonymised usage data Your consent (non-essential cookies); legitimate interests for aggregate statistics
Meeting accounting, tax and regulatory obligations Transaction and invoice data Legal obligation

We do not use your personal data for any purpose that is materially different from those listed here without first telling you and, where the law requires it, obtaining your consent.

We do not sell your personal data.

4. Cookies and similar technologies

Cookies are small text and software files placed on your device when you use the Website. In our apps, equivalent technologies (local storage, SDK identifiers) serve the same purposes and this section applies to them too.

4.1 Strictly necessary cookies (browsing and session)

Required for the Website to work at all: they keep you signed in, keep your session consistent, balance load and enable security protections. They are deleted automatically when you leave and close the Website. These cannot be switched off without breaking the service.

4.2 Functional and performance cookies

Remember your settings and preferences — language, page layout, the date of your visit, the content you viewed, your region as derived from your IP address, the device and browser you used. They let you find the trips and products you chose without searching again if your connection drops.

4.3 Analytics cookies

Tell us which pages and features are used, and where the service fails, so we can improve it. Used in aggregated or pseudonymised form.

4.4 Advertising and tracking cookies

Recognise the offers and advertisements likely to interest you, and let our advertising partners show you relevant promotions on this and other websites. Some of these are set by third parties and are governed by their own privacy policies.

4.5 Social media cookies

Added so you can share content and offers with your friends and followers on social platforms, and so shared content displays correctly.

4.6 Your choices

We place non-essential cookies (functional, analytics, advertising, social) only after you give consent through our cookie banner. Continuing to browse is not consent. You can change or withdraw your choices at any time through the cookie settings link on the Website, and you can block or delete cookies through your browser settings. If you block non-essential cookies, the Website still works; if you block strictly necessary cookies, it will not.

Session cookies are stored temporarily and deleted when you leave. Other cookies remain on your device for the period stated in our cookie settings, and no longer than 13 months for advertising and analytics cookies.

5. Data that identifies you personally

We do not try to establish your personal identity from data collected automatically or through cookies. Your identity becomes known to us through the data you provide voluntarily — your name, phone number, address, social media accounts — or where an identifier such as an IP address or username is linked to your account.

We do not process automatically collected data in order to identify you, and we do not disclose or use it except for the purposes described in section 3 or where the law requires it.

6. Who we share data with

RecipientWhat we shareWhy
Third-party providers you book with (boat and yacht owners, stores) Name, phone number, email, booking details, invoice, and where legally required an ID document To fulfil the booking or purchase you requested
Payment service providers Transaction amount, order reference, and the data you enter directly with them To take payment and handle refunds and chargebacks
Cloud hosting and infrastructure providers All data stored in the service, encrypted in transit and at rest To host and operate the service
Communications providers (email, SMS, push) Email address, phone number, device token, message content To send confirmations, one-time passwords and notifications
Analytics and crash-reporting providers Pseudonymised usage, device and crash data To measure and fix the service
Advertising networks Advertising identifier and aggregated or pseudonymised interest data Marketing — only where you have consented
Our own staff, and professional advisers Only what the specific task requires Operating the service, resolving disputes, legal and accounting advice
Competent authorities What is legally required See section 13

Every processor acting on our behalf is bound by a written agreement that limits them to our instructions, requires appropriate security measures, and forbids them from using your data for their own purposes.

Data we share for analytics, statistics and advertising is aggregated or pseudonymised: it tells the recipient about patterns, not about you by name.

7. Transfers outside Saudi Arabia

Our infrastructure is hosted on Amazon Web Services (AWS). Some processing therefore takes place outside the Kingdom of Saudi Arabia, in the AWS regions listed in our transfer register, available on request.

Where we transfer personal data outside the Kingdom we do so only on a basis permitted by Article 29 of the PDPL and the Regulation on Personal Data Transfer outside the Kingdom: to a country recognised by SDAIA as providing an adequate level of protection, or under appropriate safeguards including standard contractual clauses and a documented transfer risk assessment, and only to the extent necessary for the purposes in section 3.

Note. The specific AWS regions used, and the transfer mechanism relied on for each, are recorded in our internal Record of Processing Activities and are provided on request to any user or to SDAIA.

8. Security

We apply organisational, technical and administrative measures appropriate to the risk, including:

No system is perfectly secure. If you believe your account has been compromised, contact security@oceans.app immediately.

9. How long we keep data

DataRetention period
Account and profile dataWhile your account is active, then deleted or anonymised within 30 days of account deletion
Booking, invoice and transaction recordsRetained for the period required by Saudi commercial, tax and anti-money-laundering law, currently 10 years from the transaction
Identity verification documentsDeleted as soon as the verification purpose ends, unless a legal retention duty applies
Support correspondence3 years from closure of the request
Security, access and audit logs12 months
Analytics and advertising identifiersMaximum 13 months
Marketing consent recordsFor as long as the consent is relied on, plus 3 years as proof that it was given

When a retention period ends we delete the data or irreversibly anonymise it so that it can no longer be linked to you.

10. Deleting your account and your data

You can ask us to delete your Oceans account and the personal data associated with it, at any time and free of charge, by either route:

We verify that the request comes from the account holder, then delete your account and its personal data within 30 days. We keep only what the law obliges us to keep — principally transaction and invoice records for the statutory period in section 9 — and those records are put beyond routine use.

You may also ask us to delete specific data (for example a review or a profile photo) without deleting the account.

11. Your rights under the Saudi PDPL

Subject to the conditions and exceptions in the PDPL, you have the right to:

To exercise any of these rights, write to privacy@oceans.app from your registered email address. We respond within 30 days. We may ask you to verify your identity before we act, and we may extend the period once, by a further 30 days, where the request is complex — we will tell you if that happens and why. Exercising your rights is free of charge.

You can also change most of your data yourself, at any time, in your account profile, and manage marketing and notification preferences in your account settings or by using the unsubscribe link in any marketing message.

12. Children

Oceans is not directed at children. You must be at least 18 years old to create an account and to make a booking. We do not knowingly collect personal data from anyone under 18. A minor may be named as a passenger on a booking made by a responsible adult; in that case we collect only the minimum data the operator requires and we keep it only for the duration of the booking and the statutory record-keeping period.

If you believe a child has provided us with personal data, contact privacy@oceans.app and we will delete it.

Laws or administrative decisions in the Kingdom of Saudi Arabia may oblige us to provide the competent authorities with data relating to users; a judicial ruling may require it; or we may need to provide it to a competent administrative or judicial authority in order to deal with a dispute involving a user. We disclose only what is legally required, and we notify affected users where we are permitted to do so.

14. Change of ownership

If Oceans, or the Website, is merged, acquired or otherwise transferred to a new owner, personal data may be transferred as part of that transaction. We will notify you in advance where the law requires it, the new owner remains bound by this Policy until it is lawfully replaced, and you may exercise your deletion right (section 10) before or after the transfer.

15. Data breaches

If a personal data breach occurs that may cause you harm, we notify SDAIA within the period prescribed by the PDPL Implementing Regulations (currently 72 hours of becoming aware of it) and we notify affected users without undue delay, telling you what happened, what data was involved and what you should do.

16. Changes to this Policy

We may update this Policy. The effective date and version at the top of this page always show the current version. For material changes we notify you in advance by email or in the app, and where the change requires your consent we ask for it before it takes effect.

17. How to contact us and how to complain

Privacy and data protection: privacy@oceans.app
Data protection officer: dpo@oceans.app
Security issues: security@oceans.app

If you are not satisfied with our response, you may lodge a complaint with the Saudi Data & AI Authority (SDAIA), the supervisory authority for personal data protection in the Kingdom of Saudi Arabia, at sdaia.gov.sa.