Coralbound Privacy Policy
Date Published: August 13, 2025
Introduction
Language Precedence: These Terms of Use are originally written in English. While translations into other languages may be provided for convenience, the English version is the only legally binding version and shall prevail in the event of any conflict, discrepancy, or difference in interpretation between the English version and any translated version.
PT Tur Tak Terkalahkan ("Coralbound", "we", "us") domiciled at Jl. Sunset Road No 89, Pertokoan Sunset Indah II, Kav 3, No 3B, 80361 Kuta, Bali, Indonesia, operates a travel booking platform covering liveaboard diving, hotels, tours, and domestic flights through the website https://coralbound.com (the "Platform").
We are committed to respecting and protecting the privacy of our customers, including participants in diving liveaboard experiences, hotel and resort guests, tour participants, individuals making inquiries, and visitors to our website at coralbound.com.
This Privacy Policy describes how we handle and protect your personal data—any information capable of identifying you as an individual—in our role as data controller. It applies to personal data provided to or obtained by us during interactions such as bookings, inquiries, or website use.
Our diving operator partners, accommodation providers, and destination management company (DMC) partners may act as co-data controllers or processors on our behalf, particularly in booking and service delivery processes.
For additional details on our general terms, please refer to the for the Coralbound website and booking platform.
Service Availability: This Platform is available to international users only. Services are not available to Indonesian residents in accordance with company policy.
Summary Of Collection And Use of Information
We collect and use personal data for commercial, legal, and business purposes, subject to applicable laws. This may be based on your consent, our legitimate interests, or other legal grounds. In some cases, collection is required to operate the platform or provide services.
We use your personal data to: fulfill information requests; process bookings for liveaboard diving, hotel accommodations, tours, and activities; evaluate and improve our services; distribute safety alerts, newsletters, and diving-related materials; analyze platform performance; prevent fraud; enforce our terms of service and agreements; comply with laws and reporting obligations; and accomplish other purposes you initiate.
We may use first- and third-party cookies and other tracking technologies to manage our platform, deliver services, and collect analytics. See the Cookie section below for details.
Please note that data handling may vary by interaction, and the examples provided are not exhaustive.
1. About This Policy
1.1 Who We Are
Coralbound is operated by PT Tur Tak Terkalahkan, a company incorporated in Indonesia with Business Identification Number (NIB): 2806230016874. We are headquartered at Jl. Sunset Road No 89, Pertokoan Sunset Indah II, Kav 3, No 3B, 80361 Kuta, Bali, Indonesia.
Data Controller Information:
- Primary Data Controller: PT Tur Tak Terkalahkan
- Contact: legal@coralbound.com
1.2 Services Covered
This policy applies to all Coralbound services including:
- Liveaboard diving cruise bookings
- Hotel and resort accommodation reservations
- Flight bookings through DMC partners
- Tour packages and activities through local DMC partners
- Mobile applications and website interactions
- Customer service and support communications
1.3 Legal Framework
We comply with:
- European Union: General Data Protection Regulation (GDPR)
- United Kingdom: UK General Data Protection Regulation (UK GDPR)
- United States: California CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA
- International: Canada PIPEDA, Japan APPI, Singapore PDPA, Australia Privacy Act
2. Information We Collect
2.1 Personal Information You Provide
Booking and Account Information:
- Full name, email address, phone number
- Date of birth, nationality, passport information
- Emergency contact details
- Diving certification level and experience
- Medical fitness declarations (as required for diving activities)
- Dietary restrictions and accessibility needs
- Travel preferences and special requests
Payment Information:
- Billing address and payment method details
- Transaction history and booking records
- Note: Credit card details are processed directly by our PCI DSS compliant payment processors (Xendit, Stripe) and never stored on our servers
Communication Data:
- Customer service interactions and support tickets
- Review and feedback submissions
- Marketing communication preferences
- Social media interactions with our accounts
2.2 Information Collected Automatically
2.3 Site Analytics Tools
To enhance our website's performance and user experience, we utilize PostHog EU, a GDPR-compliant analytics tool hosted within the European Union, for site analytics purposes. PostHog collects and processes anonymous usage data, such as page views, session duration, user interactions (e.g., clicks and scrolls), device information, and general location derived from IP addresses, to help us understand how visitors navigate our platform, identify areas for improvement, and optimize features like booking flows and dive safari recommendations. We do not use PostHog to collect personally identifiable information without your consent, and all data is anonymized or pseudonymized where possible to minimize privacy risks. Processing is based on our legitimate interests under GDPR Article 6(1)(f) for service improvement, with safeguards including data retention limits (typically 12 months) and EU-based servers to ensure compliance with EU data protection standards. You can opt out of analytics tracking via your browser settings or by contacting us at legal@coralbound.com; for more details on your rights, including data access or deletion requests, refer to the relevant sections of this policy.
Technical Data:
- IP address, device identifiers, browser type and version
- Operating system, screen resolution, time zone settings
- Website navigation patterns and click-through data
- Cookie and tracking technology data (see Section 6)
Location Data:
- GPS coordinates (with your consent) for dive site recommendations
- General location derived from IP address for currency and language preferences
- Location-based service preferences
Usage Analytics:
- Pages visited, time spent on site, bounce rates
- Search queries and booking abandonment data
- Feature usage patterns and performance metrics
- Platform interaction data for service improvement
2.4 Authentication and Account Management
For secure user authentication and account management, we partner with Clerk, a third-party service that handles all aspects of user login, registration, and session management on our platform. When you create an account or log in (including via social media platforms), Clerk securely stores and processes your account data, such as email addresses, usernames, and authentication tokens, while we do not retain passwords, social media connection details, or any sensitive authentication credentials on our servers. This data minimization approach ensures that Coralbound only accesses the minimum information necessary for service delivery, such as confirming your identity for bookings or personalized recommendations. Clerk acts as a data processor on our behalf, complying with GDPR and other applicable laws through measures like encryption, secure data centers, and strict access controls. Processing is based on contract performance (GDPR Article 6(1)(b)) for enabling access to our services, with data retained only as long as your account is active or as required by law. If you delete your account or request data erasure, we will coordinate with Clerk to fulfill your request; you can manage your authentication preferences directly through Clerk's settings or contact us at legal@coralbound.com for assistance.
2.5 Error Monitoring Tools
To maintain the reliability and security of our platform, we use Sentry.io, a third-party error monitoring and performance management tool, which helps us detect, diagnose, and resolve technical issues in real-time. Sentry collects anonymized or pseudonymized data related to errors and crashes, such as stack traces, browser/console logs, device information, IP addresses (which may be masked for privacy), and contextual details about user sessions (e.g., actions leading to an error during booking or navigation). This processing does not involve collecting sensitive personal data unless it's inadvertently included in error logs, in which case we promptly anonymize or delete it. As our data processor, Sentry operates with GDPR-compliant practices, including EU data hosting options, encryption, and short retention periods (typically 90 days), with processing based on our legitimate interests under GDPR Article 6(1)(f) for platform improvement and fraud prevention. We do not use Sentry for marketing or profiling; users can limit data sharing by opting out of non-essential tracking via browser settings, though error monitoring is essential for service functionality. For questions or to exercise data rights (e.g., access to any captured data), contact us at legal@coralbound.com.
2.6 Third-Party Information
- Social media profile data (when you connect accounts)
- Partner-provided information (dive operators, hotels, DMCs)
- Public business directories and travel databases
- Identity verification services (where required by applicable law)
2.7 Special Considerations Regarding Children
Age Restrictions: You must be at least 13 years of age (16 years of age in the EU) to register for a Coralbound account. Children under 18 years of age require parental consent for certain diving activities and may need additional parental approval for booking services.
Parental Consent Requirements: In consideration for use of Coralbound's services, parents/guardians agree to provide true and accurate information in registration forms for their children and to update registration information as necessary to keep it accurate and current. If false, inaccurate, not current or incomplete information is provided, or if Coralbound, in its sole discretion, determines that such information may be false, inaccurate, not current or incomplete, Coralbound has the right to suspend or terminate the account and refuse present or future use of Coralbound's services.
3. Emergency Data Sharing
3.1 Medical Emergencies
Immediate Medical Response: When you experience a medical emergency during a Coralbound-booked service, we may need to share your personal information immediately to protect your vital interests:
- Emergency Contact Notification: Immediate contact of your designated emergency contacts using information provided during booking
- Medical Information Sharing: Sharing relevant medical fitness declarations and health information with local medical facilities, dive emergency services (such as DAN - Divers Alert Network), and emergency responders
- Hospital Coordination: Providing identification, insurance information, and medical history to receiving medical facilities
- Evacuation Services: Coordinating with medical evacuation services and sharing necessary personal and medical information
Medical Information Shared:
- Full name, nationality, and identification information
- Emergency contact details and relationships
- Medical fitness declarations and known health conditions
- Diving certification level and experience (relevant for diving-related medical emergencies)
- Insurance information and policy details
- Medication allergies and current medications (if provided)
- Blood type and other critical medical information (if provided)
Legal Basis: Vital interests protection under GDPR Article 6(1)(d) and legitimate interests for emergency response
3.2 Safety and Security Incidents
Maritime and Diving Emergencies:
- Coast Guard and Maritime Authorities: Sharing passenger manifests, diving experience levels, and emergency contact information with Indonesian Coast Guard, harbor authorities, and international maritime rescue coordination centers
- Dive Emergency Services: Immediate sharing with DAN (Divers Alert Network), local dive emergency response teams, and hyperbaric chamber facilities
- Search and Rescue Operations: Providing location data, personal identification, and emergency contacts to search and rescue authorities
- Vessel Emergency Response: Coordinating with vessel operators and emergency services for evacuation or rescue operations
Natural Disasters and Crisis Situations:
- Government Authorities: Sharing guest information with local emergency management authorities during natural disasters (earthquakes, tsunamis, volcanic eruptions)
- Embassy and Consular Services: Providing citizen information to relevant embassies and consulates for citizen welfare and evacuation assistance
- Family Notification: Immediate notification of emergency contacts and family members about safety status and location
- Evacuation Coordination: Sharing travel documents and identification information with evacuation services and transportation authorities
3.3 Law Enforcement and Security
Legal Requirements:
- Criminal Investigations: Cooperation with law enforcement agencies when required by valid legal process or court orders
- Immigration and Border Control: Sharing passenger information with immigration authorities as required by law
- Anti-Terrorism and National Security: Compliance with security screening requirements and watch list checking
- Customs and Border Protection: Providing travel information to customs authorities when legally required
Fraud and Safety Protection:
- Financial Crime Prevention: Sharing transaction information with financial crime prevention agencies and payment processors
- Safety Threat Response: Immediate sharing with authorities when credible safety threats are identified
- Missing Persons: Cooperation with law enforcement in missing person investigations
- Child Protection: Mandatory reporting to appropriate authorities when child safety concerns are identified
4. How We Use Your Information
4.1 Primary Processing Purposes
Service Delivery (Legal Basis: Contract Performance):
- Processing and confirming your liveaboard, hotel, and tour bookings
- Coordinating with dive operators, hotels, and local DMC partners
- Facilitating payment transactions through Xendit, Stripe and other processors
- Providing customer support and trip assistance
- Sending booking confirmations, vouchers, and travel documentation
Legal Compliance (Legal Basis: Legal Obligation):
- Safety and emergency response coordination with relevant authorities
- Compliance with travel and tourism regulations in service destinations
Legitimate Business Interests (Legal Basis: Article 6(1)(f) GDPR):
- Website functionality and security improvements
- Fraud detection and prevention systems
- Business analytics and performance optimization for service delivery
- Basic service personalization and safety-based recommendations
- Platform development and feature enhancement for user experience
- Customer service quality improvement and training
- Safety monitoring and emergency response capability
- Payment processing and transaction security
4.2 Automated Decision-Making and Artificial Intelligence
We use automated systems and artificial intelligence for various aspects of our platform to enhance your experience and ensure safety:
Dynamic Pricing and Availability:
- Commission-based pricing for liveaboard experiences using operator published rates
- Net pricing with markup for hotels, tours, and flights bookings
- Real-time availability checking and booking confirmation systems
- Future implementation of dynamic pricing algorithms based on demand, seasonality, and market conditions (not currently active)
Personalization and Recommendations:
- Customized diving experience recommendations based on certification level, experience history, and preferences
- Personalized accommodation suggestions using booking history and stated preferences
- Targeted content delivery based on browsing behavior and engagement patterns
- Smart search results ranking based on relevance algorithms
Customer Service Automation:
- AI-powered chatbots for initial customer inquiries and basic booking questions
- Automated email responses for common support requests
- Intelligent routing of support tickets to appropriate human agents
- Predictive support - identifying potential issues before they occur
Operational Efficiency:
- Automated booking confirmations and travel document generation
- Smart matching between divers and appropriate operators based on experience levels
- Predictive maintenance alerts for partner vessels and equipment
- Resource allocation optimization for customer service staffing
5. Cookies and Tracking Technologies
5.1 Consent Management Tool
We employ Cookiebot, a fully GDPR-compliant Consent Management Platform (CMP), to manage cookie consents and ensure transparent handling of tracking technologies on our website. Cookiebot enables you to view, customize, and withdraw your cookie preferences at any time through our consent banner and settings panel (accessible via the website footer), categorizing cookies into essential, preferences, statistics, and marketing types as detailed in Section 5.1. As our data processor, Cookiebot stores consent logs, including timestamps, user choices, and device information, to demonstrate compliance with laws like GDPR, ePrivacy Directive, CCPA, and other international frameworks, with data processed in secure, EU-based environments and retained for up to 12 months for audit purposes. This tool does not collect additional personal data beyond what's necessary for consent management, and processing is based on legal obligations (GDPR Article 6(1)(c)) and our legitimate interests in providing a compliant user experience. If you encounter issues with consent management or wish to exercise rights like revoking consent, you can do so directly via Cookiebot's interface or by contacting us at legal@coralbound.com; note that revoking consent may limit certain non-essential features.
5.1 Cookie Categories
Strictly Necessary Cookies:
- Session management and user authentication
- Security and fraud prevention
- Basic website functionality and navigation
- Booking process management
Preference Cookies:
- Language and currency preferences
- Personalized content delivery
- Location-based service enhancements
- Social media integration features
Statistics Cookies:
- Error tracking and performance monitoring
- A/B testing for feature improvements
- User experience research and heat mapping
Marketing Cookies:
- Retargeting and remarketing campaigns through various third-party advertising platforms
- Conversion tracking and attribution across advertising networks
- Interest-based advertising and audience segmentation
- Cross-platform marketing coordination and customer journey tracking
- Custom audience creation and lookalike audience development
5.2 Cookie Management
- Granular Controls: Manage cookie preferences in our Cookie Consent Settings (Avaiable in the Footer of the Website)
- Browser Settings: Configure cookie acceptance in your browser settings
- Regular Review: Update your preferences anytime through Cookie Consent Settings
5.3 Third-Party Cookies and Remarketing
We work with various third-party advertising partners for remarketing and personalized advertising campaigns. These may include but are not limited to Google, Meta, X, and other advertising networks and platforms.
Types of Remarketing Activities:
- Website visitor remarketing and conversion tracking
- Custom audience creation based on customer data
- Lookalike audience development for similar customer targeting
- Cross-platform advertising coordination and optimization
- Interest-based advertising based on user behavior and preferences
6. Service-Specific Data Collection and Use
6.1 Liveaboard Diving Experience Participants
What information does Coralbound obtain? For participants in liveaboard diving experiences, Coralbound may obtain participant name, email address, phone number, postal address, nationality, date of birth, passport information, diving certification level and number, dive experience history, medical fitness declarations, dietary restrictions, emergency contact information, and associated dive operator/liveaboard vessel information.
How is the information used? Coralbound uses participant information to coordinate with dive operators and liveaboard vessels for booking fulfillment, send booking confirmations and travel documentation, provide customer support throughout the diving experience, distribute diving safety alerts and important operational updates, and for quality management processes including post-trip evaluation forms and related correspondence.
Marketing and Promotional Use (Requires Explicit Consent): With your separate, explicit consent, participant information may be used by Coralbound to:
- Promote additional diving experiences and travel opportunities
- Send newsletters and diving industry updates
- Provide personalized recommendations based on your diving experience
- Share information with our trusted dive operator partners for marketing purposes (separate consent required)
- Include you in partner promotions for diving, training and dive-related products and services
Service Delivery (Legitimate Interests - No Consent Required):
- Booking coordination and confirmation
- Safety communications and emergency alerts
- Customer service and support
- Quality assurance and feedback collection
- Fraud prevention and payment security
6.2 Hotel and Resort Booking Participants
What information does Coralbound obtain? For hotel and resort bookings, Coralbound obtains guest name, contact information, booking preferences, special requests, payment information (processed securely through third-party processors), and accommodation history.
How is the information used? This information is used to coordinate reservations with accommodation providers, provide personalized service recommendations, send booking confirmations and check-in instructions, facilitate customer support, and enhance future booking experiences through personalized recommendations.
6.3 DMC Tour and Activity Participants
What information does Coralbound obtain? For tours and activities booked through our destination management company (DMC) partners, Coralbound obtains participant details, activity preferences, physical fitness requirements, dietary restrictions, and emergency contact information.
How is the information used? Information is shared with our trusted DMC partners to ensure proper tour coordination, safety compliance, and personalized experiences. We use this data to match participants with appropriate activities based on skill level and interests, provide safety briefings and equipment, and maintain quality standards across all tour offerings.
6.4 Website Visitors and Mobile App Users
What information does Coralbound obtain? When someone visits coralbound.com or uses Coralbound mobile applications, the following information may be obtained: email address, name, contact information, personal demographic information, browsing behavior, search preferences, device information, and location data.
Service Delivery and Functionality:
- Website performance optimization and technical functionality
- Basic personalization for user experience (language, currency preferences)
- Security monitoring and fraud prevention
- Analytics for service improvement and platform development
- Error tracking and technical support
Marketing and Enhanced Personalization (Requires Explicit Consent): With your separate, explicit consent, visitor information may be used for:
- Personalized marketing recommendations and promotions
- Enhanced content personalization beyond basic service delivery
- Marketing analytics and audience development
- Targeted advertising and remarketing campaigns
- Newsletter subscriptions and promotional communications
Data Sharing Policy: Coralbound will not provide, market, trade or sell visitor information to third parties for marketing purposes without explicit consent. We may share aggregate, non-personally identifiable information as part of statistical reports that do not include personally identifying information.
Email addresses collected from website/app communications are used for customer service responses and, with your consent, marketing communications. Coralbound will not share any information with third parties unless they have agreed to maintain confidentiality, security and integrity of the personal information they obtain from Coralbound.
What does Coralbound use to track information from users? Coralbound uses various standard web-measuring tools to trace website visitor movements, such as Google Analytics, Facebook Analytics, and other performance monitoring tools. Google Analytics uses Cookies to collect and record information about visitor behavior on coralbound.com. This data is not tied to personally identifiable information. Coralbound has enabled demographic and interest reporting to understand user preferences better. You can use the Google Analytics Opt-Out Browser Add-on to disable tracking by Google Analytics.
6.5 Customer Service and Support Interactions
What information does Coralbound obtain? Through customer service interactions, Coralbound obtains contact information, booking details, service inquiries, feedback, complaint details, and resolution preferences.
How is the information used? This information is used to provide timely and effective customer support, resolve booking issues, improve service quality, train customer service staff, and maintain records for quality assurance and dispute resolution purposes.
7. Limits on Coralbound's Abilities to Protect Personal Information
Your privacy is very important to Coralbound. However, due to the existing legal and technical environment, Coralbound cannot ensure that your personally identifiable information will not be disclosed to third parties in ways not described in this Privacy Policy. For example, Coralbound may be forced to disclose information to the government or third parties under certain circumstances, or third parties may unlawfully intercept or access transmissions or private communications.
Additionally, Coralbound can (and you authorize Coralbound to) disclose any information about you to private entities, law enforcement or other government officials as Coralbound, in its sole discretion, believes necessary or appropriate to address or resolve inquiries or problems, prevent fraud, or protect the safety of our customers and partners.
8. Links to Third-Party Sites
Coralbound's website may provide links to third-party websites or information as a service to users. If you use these links, you will leave the Coralbound website. Such links do not constitute or imply an endorsement, sponsorship or recommendation by Coralbound of the third party, the third-party website or the information contained therein, and Coralbound shall not be responsible or liable for your use thereof. Such use shall be subject to the terms of use and privacy policies applicable to those sites.
8. User Forums and Public Disclosure
You should be aware that whenever you publicly disclose information online through reviews, forums, or social media interactions with Coralbound, that information could be collected and used by others. Coralbound is not responsible for any action or policies of any third parties who collect information that users publicly disclose in any such forums or platforms.
9. Business Transfers and Corporate Changes
9.1 Merger, Acquisition, or Asset Sale
Data Transfer in Business Transactions: In the event that PT Tur Tak Terkalahkan undergoes a business transition such as a merger, acquisition by another company, or sale of all or a portion of its assets, your personal data may be transferred to the successor entity as part of the transaction.
Your Rights and Protections:
- Advance notification: Minimum 30 days' notice via email and prominent website notice
- Privacy policy continuity: The acquiring entity must honor this Privacy Policy for a minimum transition period of 90 days
- Enhanced protections: If the new entity's privacy practices are materially less protective, you will have the right to request deletion of your personal data before the transfer, opt-out of the data transfer (where legally permissible), and receive detailed information about the new entity's privacy practices
Due Diligence Requirements: We commit to conducting appropriate due diligence to ensure the acquiring entity maintains adequate data protection standards comparable to ours, has proper legal basis for the data transfer under applicable privacy laws, implements appropriate technical and organizational security measures, and respects all existing user consent preferences and opt-out choices.
10. Contact Information and Complaints
10.1 Privacy Contact Details
Primary Contact:
- Email: legal@coralbound.com
- Address: PT Tur Tak Terkalahkan, Jl. Sunset Road No 89, Pertokoan Sunset Indah II, Kav 3, No 3B, 80361 Kuta, Bali, Indonesia
- Business Hours: Monday-Friday, 9:00 AM - 6:00 PM WITA
10.2 Complaint Procedures
- Submit complaint through any contact method above
- Acknowledgment within 72 hours
- Investigation and response within 30 days
- Appeal process for unsatisfactory resolutions
10.3 Language Support and Translation Disclaimer
- Official Language: English is the official language of this Privacy Policy
- AI Translations: This policy may be translated into other languages using artificial intelligence or automated translation services for user convenience
- Translation Accuracy: While we strive for accuracy, automated translations may contain errors or inaccuracies
- Legal Precedence: In the event of any conflict, discrepancy, or difference in interpretation between the English version and any translated version of this Privacy Policy, the English version shall prevail and be considered the authoritative and legally binding document
- Human Translation: For critical legal matters, we recommend consulting the English version or seeking professional human translation services
- Translation Updates: Translated versions may not be immediately updated when the English version is revised. Always refer to the English version for the most current and accurate information
11. Policy Updates and Changes
11.1 Change Notification and Consent
By using Coralbound's services and website, you consent to the collection, use, and storage of your personal data by Coralbound in the manner described in this Privacy Policy. Coralbound reserves the right to make changes to this Privacy Policy from time to time.
11.2 Version Control and Historical Access
- Previous versions of this Privacy Policy archived and available upon request
- Effective date tracking for all modifications
- Users may request historical versions for their records
12. Non-Agency Disclosure and Acknowledgment
As a user of Coralbound's platform and services, you are informed, understand and agree that diving operators, liveaboard vessels, hotels, resorts, and DMC partners are independent businesses that are licensed to provide services booked through Coralbound, but are not agents, employees or franchisees of Coralbound.
You are further informed, understand and agree that the business activities of these service providers are independent, and are neither owned nor operated by Coralbound. While Coralbound establishes standards for service providers on our platform and facilitates bookings, we are not responsible for, nor do we have the right to control, the day-to-day operations of these independent businesses or their staff's conduct during service delivery.
Coralbound acts as a booking platform and facilitator, connecting travelers with qualified service providers, but the actual diving, accommodation, and tour services are provided by independent third parties who maintain their own insurance, certifications, and operational standards.
This privacy policy describes Coralbound's data processing practices and your privacy rights. We process personal data in accordance with applicable privacy laws and provide transparency about our data handling practices.
Policy Owner: PT Tur Tak Terkalahkan