Privacy Policy
Last updated: 24 July 2026
1. Who we are
Ocean Fever Surf Travel ("Ocean Fever", "we", "us", "our") is a trading name of PURE ONE Group Ltd, a company registered in England & Wales. We are the data controller responsible for personal data collected via https://oceanfever.com.
Website: https://oceanfever.com
Questions or data-protection requests: hello@oceanfever.com.
2. Legal framework
This policy explains how we comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and — for visitors in the EU/EEA — the EU GDPR and the ePrivacy Directive.
3. Personal data we collect
- Contact details you provide (name, email, phone) when you enquire, book or subscribe.
- Booking & trip details (dates, room preferences, dietary needs, ability level).
- Payment data — handled directly by our booking partner WeTravel; we do not store card numbers.
- Correspondence you send us by email or contact form.
- Technical data (IP address, device, browser) and usage data via cookies (see our Cookie Policy).
4. How we use your data & legal bases
- Contract — to arrange, deliver and administer your surf trip.
- Legitimate interests — to reply to enquiries, improve our site, and prevent fraud.
- Consent — to send our newsletter and to set non-essential (analytics/marketing) cookies. You can withdraw consent at any time.
- Legal obligation — accounting, tax and consumer-protection records.
5. Sharing your data
We share personal data only with parties that help us deliver our service:
- Accommodation, transfer and surf-guide suppliers for your specific trip.
- WeTravel (booking & payments).
- Google (Analytics) — only if you consent to analytics cookies.
- Email & hosting providers acting on our instructions.
- Authorities where legally required.
We never sell your personal data.
6. International transfers
Some of our providers are based outside the UK/EEA. Where that happens, transfers are protected by adequacy decisions or Standard Contractual Clauses with appropriate safeguards.
7. How long we keep data
Booking and financial records: 7 years (tax law). Enquiries: up to 2 years. Newsletter data: until you unsubscribe. Cookie preferences: 12 months.
8. Your rights
Under UK & EU GDPR you have the right to:
- Access, rectify or erase your data.
- Restrict or object to processing.
- Data portability.
- Withdraw consent at any time.
- Lodge a complaint with the UK ICO (ico.org.uk) or your local EU supervisory authority.
To exercise any right, email hello@oceanfever.com.
9. Security
We use TLS encryption, access controls and vetted processors. No system is 100% secure, but we take appropriate technical and organisational measures.
10. Children
Our services are not directed to children under 16. We do not knowingly collect their data.
11. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top shows the latest revision.
