Privacy Policy

Last updated July 22, 2026

The privacy of your data is a big deal to us. In this Policy, we explain: what data we collect and why; how your data is handled; and your rights with respect to your data. We will never sell your data — not to advertisers, not to data brokers, not to anyone.

Scope of this Policy: This Policy covers the OneDive B2B Platform at onediveb2b.com — our platform for dive shops, distributors, and manufacturers. OneDive also offers separate products for divers and consumers; those products are governed by their own privacy policies. If you are using a different OneDive product, please refer to the privacy policy for that product at onedive.ai/privacy.


1. Who We Are

ONE DIVE, INC. (“OneDive,” “we,” “us,” or “our”) is a Florida corporation providing the OneDive B2B Platform — a cloud-based SaaS application serving dive shops, distributors, and manufacturers. Our address is 12649 SW 93rd St, Dunnellon, Florida 34432.

For privacy matters, contact us at: privacy@onedive.ai

This Policy applies to:

  • Customers — dive shops, distributors, manufacturers, and other businesses that subscribe to the OneDive B2B Platform
  • Users — employees, owners, instructors, and other staff authorized by Customers to access the Platform
  • Visitors — anyone who visits onediveb2b.com

Controller vs. processor distinction: We act as a data controller for Customer account and billing data. We act as a data processor for Customer Content — the operational data Customers store in the Platform (such as diver records, reservations, and inventory). The Customer is the data controller for that Customer Content.


2. What We Collect and Why

We collect data only when we have a legitimate reason to do so.

2.1 Account and Identity Information

When you create an OneDive account, we collect:

  • Business name, address, and contact details
  • Names and email addresses of account owners and authorized Users
  • Username/email and hashed password for account access
  • Phone number (optional, for support purposes)

Why: To create and manage your account, authenticate Users, communicate with you about your subscription, and provide customer support.

2.2 Billing and Payment Information

We collect billing address and contact information. We do not store payment card numbers (PAN), CVV codes, or full bank account numbers on our systems. All payment processing is handled by Stripe, Inc. Stripe stores and processes your payment credentials under Stripe’s own privacy policy and PCI-DSS certification. We receive only a payment token and the last four digits of a card from Stripe, which we use to identify your payment method.

Why: To process subscription fees and comply with accounting and tax obligations.

2.3 Customer Content (Catalog, Pricing, and Inventory Data)

The primary data Customers store in the OneDive B2B Platform is commercial product and pricing data, not personal data. Depending on the Customer’s role in the platform:

  • Manufacturers upload and manage product catalogs: SKUs, descriptions, specifications, images, and pricing
  • Distributors host their own master catalog and maintain wholesale price lists for their dealer network; when a distributor updates a price, that change cascades automatically to linked dealer inventory records
  • Dealers (dive shops) import catalog items from their distributor, maintain their own inventory linked to distributor pricing, and export that inventory to their Shopify storefront or other sales channels

This data — product records, SKUs, prices, stock levels, catalog attributes — is commercial business data, not personal data. We store and process it only on behalf of and under the instructions of the Customer.

Some Customer Content may incidentally include business contact information (e.g., a sales rep’s name on an account, or a dealer contact on a distributor’s record). We treat any such information as Confidential Information and do not use it for any purpose other than operating the Platform.

Why: To provide the core functionality of the OneDive B2B Platform — catalog hosting, price list management, inventory sync, and storefront export — as contracted.

2.4 Usage and Technical Data

We automatically collect technical data when you use the Platform:

  • Log data: IP address, browser type, operating system, pages visited, timestamps, error logs
  • Device identifiers (for security and session management purposes)
  • Feature usage patterns (which features are used, how often) — in aggregate and/or associated with the Customer account

Why: To maintain and improve the Platform, diagnose technical problems, detect fraud and abuse, and understand feature adoption.

2.5 Communications

If you contact us by email, support ticket, or otherwise, we retain the content of your communications and our responses. If you subscribe to product updates or newsletters, we retain your email address and preferences.

Why: To respond to your inquiries, provide support, and send you relevant product information.

2.6 Website Visitor Data

Our platform websites (onediveb2b.com) may use cookies and similar technologies to understand traffic and improve the site. We use privacy-respecting analytics. We do not use advertising cookies or retargeting pixels.

Why: To understand how visitors find and use our site and to improve it.


3. How We Use Your Data

We use the data we collect for the following purposes:

  • To provide, maintain, and improve the OneDive B2B Platform
  • To process payments and manage subscriptions
  • To communicate with you about your account, including billing, product updates, and support
  • To detect, investigate, and prevent fraudulent transactions and other illegal activities
  • To comply with legal obligations
  • To analyze aggregate, de-identified usage patterns to improve the Platform

We do not use Customer Content for advertising, marketing, or training AI models without your explicit written consent. We do not sell personal data.


4. AI-Powered Features

The OneDive B2B Platform includes AI-powered features — such as catalog enrichment, data suggestions, and similar automation tools — powered by third-party AI providers, including Anthropic, Inc. When you use AI features:

  • We send the relevant context (e.g., product name, category, attributes you provide) to Anthropic’s API to generate suggestions
  • We do not send Customer Content to AI providers for training purposes
  • AI-generated outputs may contain errors, inaccuracies, or omissions — you are responsible for reviewing and validating them before use
  • Anthropic processes API requests under their own privacy policy (anthropic.com/privacy)

We will notify you before any material change to how AI features use your data.


5. When We Share Your Data

We share data only in these limited circumstances.

5.1 Service Providers (Subprocessors)

We use third-party service providers to operate the Platform. We have executed appropriate data processing agreements with each subprocessor where required. Our current subprocessors include:

ProviderPurposeLocation
Supabase, Inc.Database hosting, authentication, row-level securityUnited States
Vercel, Inc.Application hosting, edge infrastructureUnited States / global CDN
Stripe, Inc.Payment processingUnited States
Anthropic, Inc.AI inference API for AI-powered featuresUnited States
Resend, Inc.Transactional email deliveryUnited States

We will notify Customers of any material changes to our subprocessor list with reasonable advance notice.

5.2 Legal Requirements

We may disclose data if required to do so by law, regulation, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to: (a) comply with a legal obligation; (b) protect and defend our rights or property; (c) prevent or investigate possible wrongdoing; or (d) protect the safety of Users or the public. We will attempt to notify affected Customers before complying with any such request unless prohibited by law or a court order.

5.3 Business Transfers

If ONE DIVE, INC. is involved in a merger, acquisition, reorganization, or sale of substantially all of its assets, Customer data may be transferred as part of that transaction. We will notify Customers via email and/or a prominent notice on our website in advance of any such transfer and before Customer data becomes subject to a different privacy policy.

5.4 With Your Consent

We may share data in other cases with your explicit written consent.


6. Data Retention

We retain data for as long as necessary to provide the Platform:

  • Account data: Retained while the subscription is active and for 60 days after termination, then deleted upon written request.
  • Customer Content: Retained while the subscription is active. Customers may export their data at any time. Following termination, Customer Content is available for export for 30 days; after that period, we delete it within 60 days.
  • Billing records: Retained for 7 years to comply with accounting and tax obligations, even after account deletion.
  • Usage and log data: Retained for up to 12 months for security monitoring and troubleshooting, then deleted or anonymized.
  • Communications: Retained for up to 2 years after the last interaction, or as long as required by law.

If you request deletion of your account, we will delete or anonymize all personal data within 30 days, except where retention is required by law.


7. Security

We implement commercially reasonable technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Row-level security (RLS) in our database — each Customer’s data is isolated from other Customers’
  • Multi-tenant authentication with short-lived JWTs and secure session management
  • Role-based access controls limiting data access to authorized Users only
  • Regular security reviews and vulnerability monitoring

No system is completely secure. In the event of a data breach that materially affects your account, we will notify you without undue delay and within 72 hours of becoming aware, where feasible.


8. Your Rights

Depending on your location, you may have the following rights with respect to your personal data. To exercise any of these rights, contact us at privacy@onedive.ai.

8.1 For All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Portability: Request your data in a machine-readable format. Customer Content can be exported through the Platform at any time.

8.2 California Residents (CCPA/CPRA)

Under the CCPA and CPRA, ONE DIVE, INC. operates as a “service provider” to its B2B Customers with respect to Customer Content. This means:

  • We process Customer Content only for the purposes specified in our Terms of Service
  • We do not sell or share personal information as defined under the CCPA/CPRA
  • We do not use personal information we receive for any commercial purpose outside of providing the Platform

If you are a California resident who interacts with us directly (as a job applicant, website visitor, or direct contact), you have the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of any sale or sharing (we do neither). Submit requests to privacy@onedive.ai or via onediveb2b.com/privacy.

8.3 Florida Residents

Florida residents may have additional rights under the Florida Digital Bill of Rights (FDBR) if applicable. Contact us at privacy@onedive.ai to exercise any applicable rights.

8.4 EU/UK Residents

The OneDive B2B Platform is currently marketed primarily to U.S.-based dive businesses. If you are an EU or UK resident, please contact us before using the Platform. For EU/UK enterprise Customers, we will execute a GDPR-compliant Data Processing Addendum (DPA) upon request at privacy@onedive.ai.


9. Cookies and Tracking

Strictly necessary cookies: Required for authentication, session management, and security. These cannot be disabled and are required for the Platform to function.

Analytics cookies: Used on our marketing and platform websites to understand traffic. We use privacy-respecting analytics that do not identify individual users and do not share data with advertisers.

We do not use advertising, retargeting, or behavioral tracking cookies.


10. Children’s Privacy

The OneDive B2B Platform is intended for use by businesses and their authorized adult staff. If you believe that a minor’s personal data has been submitted to our Platform without appropriate authorization from the Customer, contact us at privacy@onedive.ai and we will promptly investigate and delete the data.


11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify Customers via email to the account’s primary contact address and by posting a notice in the Platform at least 30 days before changes take effect. Your continued use of the Platform after the effective date of the updated Policy constitutes acceptance of the changes.

Minor changes such as clarifications or corrections may be made without prior notice. We will always update the “Last Updated” date at the top of this Policy.


12. Contact Us

For privacy-related questions, requests, or complaints:

Email: privacy@onedive.ai
Mail: ONE DIVE, INC., 12649 SW 93rd St, Dunnellon, FL 34432
Web: onediveb2b.com/privacy

We will respond to verifiable privacy requests within 30 days.