Legal
What we collect on our website, in your booking, in the guest portal, and in the SXT app, and what we do with it.
Effective September 9, 2026. Policy version 2026-09b.
Scuba X Travel, Inc. dba SXT Adventures is responsible for personal information under this policy across the website, bookings, the guest portal, and the SXT mobile app.
The SXT app is developed and published by Blargo LLC for SXT Adventures. Blargo processes app data only on SXT Adventures’ behalf.
Where this policy says “the app,” it means the SXT mobile app for iPhone and Android. Where it says “the site,” it means this website.
When you send us a message or ask about a trip, we collect the name, email address, phone number, and message you give us. The website also uses Google Analytics, which records standard visit information such as pages viewed and browser type. Google Analytics runs on the website only. It does not run in the app.
To plan and run a trip we collect booking and payment details, your address and phone number, emergency contact, dietary preferences, dive certification, insurance, gear sizing, and the travel documents and health information a trip requires, including passport details and medical information you give us for safety.
Passport details, the medical parts of your health information, and documents you upload are hidden from staff by default. A staff member needs a specific permission to see them, has to reveal them deliberately, and every view, edit, and download is written to an access log.
The guest portal signs you in with an emailed link rather than a password. When you ask for a new link, our server records your guest id and a shortened hash of your email address so we can see that the request happened.
The SXT app does not collect any of the following:
If we add product analytics or native crash reports to the app later, we will update this policy before that starts.
The app includes Sentry error diagnostics. They run only in release builds, and only when they are turned on by configuration. They capture unhandled JavaScript errors only. They do not capture native crashes. There is no product analytics, no screen-view tracking, no session replay, no breadcrumbs, and no network request logging.
An error report sends the app version and build, the platform, the operating system version, the device model, a fixed screen and error code, and sanitized stack frames. It does not send names, email addresses, user or trip identifiers, message, document, or photo content, request bodies, or tokens. Sentry (Functional Software, Inc.) sees the network address the report comes from while it is in transit.
Group messages, photos, and announcements are visible to everyone on that trip. Other travelers see your name on anything you post, and on the roster when a trip turns the roster on. They do not see your passport details, medical information, address, phone number, email address, or what you paid. None of that is published to the app.
Staff can see your booking, your traveler profile subject to the access gate described above, group content, and your private messages with the team.
We do not sell your personal information, and we do not hand it to advertising partners.
The app has no sign-up. You can sign in only if you are already a guest in our system and have a confirmed booking on a trip. Staff sign in with an admin account. If your booking is no longer confirmed, the app stops signing you in.
We email you a sign-in link. It lasts 15 minutes, works once, and you can request at most three links for the same address in 15 minutes. Signing in creates a session that stays valid for 30 days of continued use, up to 90 days in total, and that we can revoke.
Group chat, shared photos, and announcements go to everyone on the trip, and your name appears on what you post. Private threads are between you and SXT staff. Deleting a message blanks its text in place.
Photos are re-encoded on our server at up to 2048 pixels, which removes the location metadata your camera attached, so where you took a picture is not carried into the app. Photos sit in a private bucket and are shown through links that expire after 1 hour. Deleting a photo removes it from the app. The stored file itself is not removed today, so ask us if you want it gone.
You must have the right to share any photo you post, and by posting it you allow SXT to show it to your trip group and staff in the app. Photos and documents SXT provides are ours or used with permission.
Documents staff share with you sit in a private bucket and are streamed through our API. They are never exposed by link. If staff revoke a document, it disappears at your next sync and your device deletes its cached copy then.
You choose whether to allow notifications when the app asks. You can turn them off in your device settings at any time, and you can mute a trip or a group inside the app.
Trip snapshots, messages, and approved PDFs are cached on your device for each account you sign in with. Signing out deletes the app’s copies.
Staff can remove content from a trip. If your version of the app includes reporting and blocking, you can report a message or photo to staff and block another traveler from your view of a trip. You can always email us at hello@sxtadventures.com. What we expect of everyone on a trip is set out in our community guidelines, and app support covers day-to-day questions.
The app is for travelers who are 18 or over.
We do not have a published retention schedule yet. We are writing one, and we will update this policy when it is set. In the meantime, here is what actually happens.
Traffic to our website, guest portal, and app is encrypted in transit, and our providers encrypt stored data at rest. Photos live in a private storage bucket and are reached only through links that expire. Documents are streamed through our API and are never exposed by link.
Access to staff tools is based on role. Passport details, medical fields, and documents you upload are hidden by default, need a specific permission to reveal, and every view, edit, and download is logged.
Trip messages are not hidden from us. SXT staff can read messages in the app, including private threads with the team. No method of sending or storing data is perfectly secure, so we cannot promise absolute security.
You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it. Email hello@sxtadventures.com and we will handle the request.
To ask us to delete your data, use our data deletion page. It explains what a deletion request covers, what we have to keep, and how the request is verified and handled.
For notifications, turn push off in your device settings, or mute a trip or group in the app. Marketing email carries an unsubscribe link, and you can ask us to remove you at any time. Email about a trip you are booked on is part of the service.
The website uses cookies for basic functionality and for Google Analytics. You can adjust cookie settings in your browser. The app does not use advertising identifiers.
If you live in California, or anywhere else, you can make these requests. We honor access, correction, and deletion requests for everyone who asks.
The SXT app is for people 18 and over. Our website is not directed to children.
We update this policy when what we do changes, including before we would add product analytics or native crash reports to the app. The effective date at the top of this page tells you which version you are reading.
For privacy questions and anything about the SXT app, email hello@sxtadventures.com or call +1 (909) 772-1843.
Scuba X Travel, Inc. dba SXT Adventures
4420 Holt Blvd
Montclair, CA 91763