Privacy Policy
Last updated: 11 September 2026 · Applies to meteoscience.com and its products: the Grid Dashboard, the S2S Energy Weather Widget, the Climate Risk Report Portal, and our mobile apps (including LightningSentry, SlopeSentry, WindSentry, VeloShield, MeteoGolf, MarineSentry, HeatSentry, and SkiShield).
1. Who we are
Meteoscience OÜ ("Meteoscience," "we," "us") is the data controller for the personal data described in this policy. We are registered in Estonia, Registry Code 17543147, legal domicile Pudisoo küla, Kuusalu vald, Harju maakond, 74626, Estonia. You can reach us at info@meteoscience.com for any privacy question or request.
2. What data we collect, and why
We collect meaningfully less personal data than most SaaS products, because most of what our products do runs on public weather data, not personal data. Specifically:
- Climate Risk Report Portal. When you submit an address or place name to generate a report, that text is sent to Open-Meteo's Geocoding API and, as a fallback, OpenStreetMap's Nominatim service, to resolve it into coordinates. We do not store submitted addresses in a database — but if report generation fails, the address may appear temporarily in our hosting provider's server error logs for debugging, and is not otherwise analyzed, sold, or retained beyond ordinary log rotation.
- S2S Energy Weather Widget — subscriptions. If you subscribe to the licensed tier, our payment processor, Stripe, collects your name, email address, billing address, and payment details directly — we never see or store your full card number. Stripe shares with us your name, email, and a Stripe customer identifier, which we use to recognize your account, keep your subscription active, and let you manage billing.
- Authentication. We use two first-party session cookies to keep you logged in — see our Cookie Policy for details. No personal data beyond a signed session token is stored in either.
- Server logs. Like virtually all websites, our hosting provider (Vercel) logs standard web request metadata (IP address, timestamp, requested URL) for security, abuse prevention, and operating the service.
- LightningSentry — location. With your permission, the app uses your device's GPS location (including, if you separately grant it, background location while an outdoor session is active) to calculate your distance from publicly reported lightning strikes and to trigger local proximity alerts. This calculation happens entirely on your device — your location is never transmitted to Meteoscience or any third party. The app's only network request is an anonymous, unauthenticated read of a public strike-data file; no location, device identifier, or other personal data is sent as part of it.
- LightningSentry — notifications. Sound and push-style alerts are generated locally on your device (via the operating system's local notification APIs) based on the on-device distance calculation above. We do not operate a remote push-notification server and do not receive a device token or any data when an alert fires.
- LightningSentry — subscriptions. If you subscribe to Pro features, purchases are processed by Apple App Store or Google Play and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- LightningSentry — local preferences. Settings like distance units, alert radius, and theme are stored only in local on-device storage and are not transmitted to us.
- SlopeSentry — location. This app does not access your device's GPS location at all. Resort weather is looked up using fixed coordinates for a small set of preset ski resorts, or coordinates you manually type in yourself under "Custom Feed Override" — neither involves reading your device's actual location.
- SlopeSentry — notifications. Powder alerts are generated locally on your device based on weather data already fetched for your selected resort. We do not operate a remote push-notification server and do not receive a device token or any data when an alert fires.
- SlopeSentry — subscriptions. If you subscribe to Pro features, purchases are processed by Google Play (and Apple App Store, once available) and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- SlopeSentry — trail reports and resort suggestions. If you submit a trail condition report or suggest a resort to add, we store the text you enter (resort, trail name, condition, and any optional note) so other users can see it. These submissions are anonymous — we do not attach your name, account, device identifier, or location to them, and there is currently no way to edit or delete a submission after posting other than contacting us directly.
- SlopeSentry — local preferences. Settings like your selected resort, alert threshold, and theme are stored only in local on-device storage and are not transmitted to us.
- WindSentry — location. With your permission, the app can use your device's GPS location to look up wind, wave, and tide conditions near you. Unlike LightningSentry, your coordinates are transmitted off-device as part of this lookup — to Open-Meteo, our third-party weather data provider — so it can return a forecast for that location. This is the only use of your location: we don't receive it ourselves, store it, or use it for anything else. You can also use the app entirely without granting location access, by selecting one of the preset sailing/kitesurfing spots or entering coordinates manually instead.
- WindSentry — wind alerts and notifications. Saved alert configurations (spot, minimum wind speed, direction preference, daylight-only setting) are stored only in local on-device storage. Checking whether a saved alert's conditions are met, and any resulting notification, happens entirely on your device when you open or refresh the app — we do not operate a remote push-notification server and do not receive a device token or any data when an alert fires.
- WindSentry — subscriptions. If you subscribe to Pro features, purchases are processed by Google Play (and Apple App Store, once available) and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- WindSentry — Strava Sync. This screen is currently a "Coming Soon" placeholder. No Strava account connection exists yet and no Strava data is collected, read, or stored — this will be updated if and when the integration is actually built.
- VeloShield — location. The app requests location permission but does not currently use your device's GPS anywhere — route weather is calculated for the coordinates of a small set of preset cycling routes, not your actual location. We plan to either wire this permission to a real "use my location" feature or remove the request; until then, no location data is read, transmitted, or stored.
- VeloShield — route weather. When you select a route, its preset coordinates (not your device location) are sent to Open-Meteo, our third-party weather data provider, to fetch real wind, temperature, and rain forecasts for each point along that route.
- VeloShield — subscriptions. If you subscribe to Pro features, purchases are processed by Google Play (and Apple App Store, once available) and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- VeloShield — Strava Sync. This screen is currently a "Coming Soon" placeholder. No Strava account connection exists yet and no Strava data is collected, read, or stored — this will be updated if and when the integration is actually built.
- VeloShield — local preferences. Settings like measurement units and theme are stored only in local on-device storage and are not transmitted to us.
- MeteoGolf — location. With your permission, the app uses your device's GPS location to fetch weather for where you actually are, sent to Open-Meteo (directly, or via our own backend) to return a forecast. The course/hole selector doesn't yet match your resolved coordinates to a specific course automatically — you may need to pick your actual course manually — but your real location is used for the weather itself once resolved. You can also use the app entirely without granting location access, by selecting one of the preset courses instead.
- MeteoGolf — lightning alerts. To check for nearby lightning strikes, your selected or resolved coordinates and search radius are sent to our own backend, which compares them against a public real-time strike-detection feed and returns whether any strikes are within range. We do not store these coordinates ourselves beyond what's needed to return that check. A separate "Simulate Lightning Strike Alarm" toggle in Settings only triggers a local test of the alert banner and involves no location data or network request.
- MeteoGolf — subscriptions. If you subscribe to Pro features, purchases are processed by Google Play (and Apple App Store, once available) and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- MeteoGolf — local preferences. Settings like distance/wind units, grass type, and theme are stored only in local on-device storage and are not transmitted to us.
- MarineSentry — search coordinates. The app does not access your device's GPS location. Coordinates you search or select from a preset port are sent to our backend, and to NOAA/Open-Meteo as part of fetching real sea-surface-temperature, buoy, and bar-crossing-safety data for that location. We do not store your search history.
- MarineSentry — subscriptions. If you subscribe to Pro features, purchases are processed by Google Play (and Apple App Store, once available) and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- HeatSentry — location. With your permission, the app uses your device's GPS location (attempted automatically on first launch, and via an explicit "use my location" button) to compute current heat-safety (WBGT) conditions near you. Unlike WindSentry, your coordinates are sent to our own backend rather than directly to a third party — our backend then fetches the underlying weather data from Open-Meteo on your behalf. You can also use the app entirely without granting location access, by searching for a location or selecting a saved job site instead.
- HeatSentry — job sites (Pro feature). Locations you save under "Job Sites" (a name and coordinates) are stored only in local on-device storage and are not transmitted to us, unless you also create a heat alert for that location (see below).
- HeatSentry — heat alerts and notifications. This is the one place in HeatSentry where we differ from most of our other apps' "checked only on refresh" model. If you create a saved alert, its location (coordinates and the name you gave it), workload category, and acclimatization setting are sent to and stored on our backend, so we can check real heat-safety conditions on your behalf on a recurring schedule and deliver a push notification via Firebase Cloud Messaging when your saved threshold is crossed — including while the app is closed. Deleting an alert in the app removes the corresponding record from our servers; if you uninstall the app without first deleting a saved alert, contact us to have it removed. As of this writing, background notification delivery is not yet fully active (our Firebase project setup is still in progress) — alert data is already stored and evaluated on the schedule described above, but a push notification may not yet reach your device while the app is closed.
- HeatSentry — subscriptions. If you subscribe to Pro features, purchases are processed by Google Play (and Apple App Store, once available) and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- HeatSentry — local preferences. Your workload category, acclimatization setting, NIOSH/ISO 7243 framework choice, and theme are stored only in local on-device storage and are not transmitted to us, except as part of an alert you explicitly save (see above).
- SkiShield — location. With your permission, the app uses your device's GPS location (attempted automatically on first launch, and via an explicit "use my location" button) to compute current snowmaking wet-bulb conditions near you. As with HeatSentry, your coordinates are sent to our own backend rather than directly to a third party. You can also use the app entirely without granting location access, by searching for a location or selecting a saved zone instead.
- SkiShield — zones (Pro feature). Zones you save (a name, coordinates, and your configured snow-gun count) are stored only in local on-device storage and are not transmitted to us, unless you also create a status alert for that zone (see below).
- SkiShield — status alerts and notifications. If you create a saved alert, its zone location, name, and snow-gun count are sent to and stored on our backend, so we can check real snowmaking status on your behalf on a recurring schedule and deliver a push notification via Firebase Cloud Messaging whenever that zone's status changes — including while the app is closed. Deleting an alert in the app removes the corresponding record from our servers; if you uninstall the app without first deleting a saved alert, contact us to have it removed. As of this writing, background notification delivery is not yet fully active (our Firebase project setup is still in progress) — alert data is already stored and evaluated on the schedule described above, but a push notification may not yet reach your device while the app is closed.
- SkiShield — subscriptions. If you subscribe to Pro features, purchases are processed by Google Play (and Apple App Store, once available) and managed on our behalf by RevenueCat, which receives a device/purchase identifier and your entitlement status to keep your subscription active across sessions. We do not receive or store your payment details.
- SkiShield — local preferences. Theme is stored only in local on-device storage and is not transmitted to us, except as part of an alert you explicitly save (see above).
We do not run advertising or analytics trackers of any kind on these products — there is nothing else collecting data about you as you browse or use our apps.
3. Legal basis for processing
Under the GDPR, we rely on:
- Performance of a contract (Art. 6(1)(b)) — to generate the report you requested, or to provide and bill your Widget subscription.
- Legitimate interests (Art. 6(1)(f)) — to keep our services secure, prevent abuse, and maintain server logs necessary to operate the product.
- Consent (Art. 6(1)(a)) — for LightningSentry's, WindSentry's, MeteoGolf's, HeatSentry's, and SkiShield's location access, which is only requested and used after you grant the relevant OS-level permission, and which you can withdraw at any time in your device settings.
Outside of mobile location permissions, we do not currently rely on consent as a legal basis, because we do not use any cookies or tools that would require it (see our Cookie Policy).
4. Who we share data with
We use the following processors and third-party services, each acting under its own privacy terms:
- Stripe — payment processing and subscription billing.
- Open-Meteo — weather, climate, and geocoding data (receives coordinates, and address text for geocoding).
- OpenStreetMap / Nominatim — fallback geocoding service.
- Vercel — website and application hosting.
- RevenueCat — subscription and entitlement management for our mobile apps, on top of Apple App Store / Google Play billing.
- Apple App Store / Google Play — process mobile subscription payments directly; we never see your card details.
- Firebase Cloud Messaging (Google) — delivers push notifications to devices that have registered for background alerts (currently HeatSentry's heat alerts and SkiShield's status alerts; see Section 2). Google receives a device push token, not your underlying location or alert content.
Our typefaces (Inter, Space Grotesk, and JetBrains Mono) are self-hosted on our own servers rather than loaded from Google Fonts, so no font-related request is made to Google or any other third party.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
5. International data transfers
Some of the providers above (including Stripe and Vercel) may process data on servers located outside the European Economic Area, including in the United States. Where this occurs, it is carried out under those providers' own data transfer safeguards (such as Standard Contractual Clauses). We recommend confirming the current status of each provider's transfer mechanism as part of a full legal review of this policy.
6. How long we keep data
- Session cookies expire automatically — 12 hours for the shared demo login, 30 days for a subscriber's login.
- Subscription and billing records are retained by Stripe under its own policy, and by us for as long as your subscription is active plus any period required by Estonian accounting and tax law.
- We do not retain report-generation addresses beyond the request itself, other than the limited, incidental appearance in error logs described in Section 2.
- LightningSentry's location data is never transmitted off your device, so we do not store it at all. Local app preferences and premium/entitlement status are retained on your device until you uninstall the app or clear its data; RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
- SlopeSentry's trail reports and resort suggestions are retained indefinitely on our servers so they remain useful to other users, unless you contact us to have a specific submission removed. Local app preferences and premium/entitlement status are retained on your device until you uninstall the app or clear its data; RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
- WindSentry's location is transmitted to Open-Meteo only to fetch a forecast and is not stored by us at all. Saved wind alerts and local preferences are retained on your device until you delete them, uninstall the app, or clear its data; RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
- VeloShield does not read your location at all currently, and preset route coordinates sent to Open-Meteo are not stored by us. Local app preferences are retained on your device until you uninstall the app or clear its data; RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
- MeteoGolf's location, once resolved, is used to fetch weather and check for nearby lightning strikes, but is not stored by us afterward. Local app preferences are retained on your device until you uninstall the app or clear its data; RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
- MarineSentry does not read your device's location at all -- search coordinates are used to fetch data and are not stored by us afterward. RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
- HeatSentry's GPS location, when used, is sent to our own backend to compute a heat-safety reading and is not stored by us afterward beyond ordinary request logs. Job Sites you save are retained on your device until you delete them or uninstall the app. If you create a heat alert, its location, workload, and acclimatization setting are retained on our servers until you delete the alert in the app or contact us to remove it after an uninstall. Local app preferences and premium/entitlement status are retained on your device until you uninstall the app or clear its data; RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
- SkiShield's GPS location, when used, is sent to our own backend to compute a wet-bulb reading and is not stored by us afterward beyond ordinary request logs. Zones you save are retained on your device until you delete them or uninstall the app. If you create a status alert, its zone location, name, and snow-gun count are retained on our servers until you delete the alert in the app or contact us to remove it after an uninstall. Local app preferences and premium/entitlement status are retained on your device until you uninstall the app or clear its data; RevenueCat retains subscription/entitlement records under its own policy for as long as needed to keep your subscription functioning.
7. Your rights
Under the GDPR, you have the right to request access to, correction of, or erasure of your personal data, to restrict or object to our processing, to receive your data in a portable format, and to withdraw consent where consent is the basis for processing. To exercise any of these, contact info@meteoscience.com. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), or with the supervisory authority in your own EU member state.
8. Children's privacy
Our products are intended for business and professional use and are not directed at children under 16. We do not knowingly collect personal data from children.
9. Changes to this policy
We may update this policy as our products or legal obligations change. We will update the "Last updated" date above when we do; material changes will be noted here.
10. Contact
Meteoscience OÜ, Pudisoo küla, Kuusalu vald, Harju maakond, 74626, Estonia. info@meteoscience.com.