Effective 8 October 2026

Privacy policy

Catch Signal is a free fishing-forecast website for Scarborough and the Redcliffe Peninsula. This policy explains what personal information we collect, why, who else handles it, and how you can see, change or delete it.

The short version

  • You can read every forecast without an account. We only hold personal information about you if you sign in with Google or Facebook.
  • Your display name, picture, bio, comments and catch reports are public. Your email address, trips and fishing history are private.
  • If you turn on your location on the Conditions now page, your position stays on your device. It is never sent to or stored on our server.
  • We never sell your information, show ads or send marketing email.
  • You can delete your account and everything in it at any time, straight from your profile.

1. Who we are

Catch Signal (catchsignal.com.au) is a free, non-commercial community website run from Queensland, Australia. In this policy, "we", "us" and "our" mean the person who runs Catch Signal.

For anything about privacy, email privacy@catchsignal.com.au.

As a small, non-commercial site we may not be covered by the Privacy Act 1988 (Cth). We choose to handle personal information in line with the Australian Privacy Principles anyway, and this policy is written to meet them.

2. What we collect

When you sign in with Google

We ask Google only for basic sign-in details (the openid, email and profile permissions). Google gives us:

  • a unique ID for your Google account;
  • your name and a link to your profile picture;
  • your email address, and whether Google has verified it.

When you sign in with Facebook

We ask Facebook only for your public profile and, if you allow it, your email address. Facebook gives us:

  • an ID that identifies you to Catch Signal only (an "app-scoped" ID);
  • your name and a link to your profile picture;
  • your email address, if you choose to share it.

We never see your Google or Facebook password. Google and Facebook send us a temporary access token at sign-in; we use it once to read the details above and then throw it away. We don't post anything to your accounts.

What you give us

  • Profile: your display name (it starts as your Google or Facebook name and you can change it), a short bio, your default location (the spot the site opens on for you, also called your home spot) and whether you usually fish from the shore, a boat or a kayak.
  • Comments you post on forecast days, spots and catch reports.
  • Catch reports: when and where (from our list of spots) you fished, the species, how many you caught and kept, size, bait, method and notes.
  • Trips and trip logs: the spot, times, mode, target species and notes for trips you plan, the forecast at the time you booked, and what you record afterwards (fish caught and kept, species, hours fished, a rating and notes).
  • Emails you send us.

What is collected automatically

  • A sign-in cookie while you are signed in (see section 8).
  • Technical information. Every request to the site passes through our host, Cloudflare, which processes your IP address, browser type, the address requested and the time. This is needed to deliver pages, keep the site secure and fix faults.
  • Preferences on your device. Some choices, such as shore, boat or kayak and the spot you picked, may be saved in your browser's local storage so the site remembers them. They stay on your device. If you're signed in and save a spot as your default location, it is kept with your profile (see above), so it follows you to the other devices you sign in on.
  • Your location, only if you turn it on. The Conditions now page uses your location only after you tap "Use my location". Your browser asks your permission first, then gives your position to the page so it can find the nearest spot, the distance to sheltered spots and whether you're in a marine park green zone. This is worked out entirely on your device: your position is never sent to or stored on our server, or sent to anyone else. So that the page can pick up where it left off, we remember on this device that you turned your location on (not where you were). Next time you open Conditions now it resumes on its own, as long as your browser still allows location for this site, until you tap "Stop using my location". If the browser no longer allows it, or can't tell us, the note is cleared and you tap again. You can say no and pick a spot instead, and you can take the permission back in your browser's settings at any time.
  • Spam protection. If it is switched on, Cloudflare Turnstile runs a check in your browser when you start writing a comment, to tell people from bots.

We don't use advertising or tracking cookies, analytics services or social media "pixels".

What we don't collect

Passwords, payment details or government identifiers. We never receive your device's location: catch reports use our fixed list of spots, and the location feature described above runs only on your device.

3. How we use it

We use personal information only to:

  • create your account and keep you signed in;
  • show your display name and picture next to the comments and catch reports you post, and on your public profile;
  • store your trips and fishing history so you can look back at them;
  • moderate the site, prevent spam and abuse (for example, limits on how often you can post) and keep it secure;
  • recognise the site administrator when they sign in;
  • reply when you contact us.

We do not sell or rent personal information, show ads, build advertising profiles or send marketing email. Information we receive from Google and Facebook is used only as this policy describes.

Fishing ratings are calculated the same way for everyone from weather and tide data. We don't use automated processing to make decisions about you that significantly affect your rights or interests.

4. What is public and what is private

Who can see each kind of information
Public: anyone can see it, even without signing inPrivate: only you (and the site administrator)
Display name, profile picture, bio and the date you joinedYour email address
How many comments and catch reports you've postedYour trips, trip logs and fishing history
Your commentsYour default location and preferred mode
Your catch reports, including the spot, species, numbers, size, bait, method and notesWhich sign-in providers you use

Anyone can read, copy or share public content, and search engines may index it. If you'd rather keep a catch to yourself, record it in a trip log instead of posting a catch report.

The site administrator can see stored information when needed to run and moderate the site.

5. Who else handles your information

We use a few outside services. Each one receives only what it needs:

  • Cloudflare, Inc. (United States) hosts the website and our database and carries all traffic to the site, including your IP address. Our database is set to be stored in the Oceania region, but Cloudflare may process, cache and back up data in other countries where it operates, including the United States. See Cloudflare's privacy policy.
  • Google LLC (United States), only if you sign in with Google. Google knows that you signed in to Catch Signal. See Google's privacy policy.
  • Meta Platforms (Facebook), only if you sign in with Facebook. Facebook knows that you signed in to Catch Signal. See Meta's privacy policy.
  • Google Fonts. Our pages load their typefaces from Google's font servers, so your browser connects to Google, which receives your IP address and browser details.
  • Profile pictures are loaded straight from Google's or Facebook's servers, so those companies can see the IP address of anyone who views a picture.
  • Open-Meteo supplies our weather and sea forecasts. Forecast requests go through our server, so Open-Meteo sees our server, not your IP address or anything about you.
  • Queensland Government open data (tide predictions, water levels and marine park zones) and the Coastwatch fishing report are fetched by our server or when we build the site. No personal information is sent to them.

We may also disclose information if the law requires it (for example, a court order), or where it's needed to protect someone's life, health or safety.

Overseas: because of the services above, your information is likely to be stored or processed outside Australia, mainly in the United States, and in other countries where Cloudflare, Google and Meta operate.

6. Security

  • All traffic to the site is encrypted (HTTPS).
  • Your sign-in session is a long random token in a secure cookie that page scripts can't read. We store only a one-way hash of it, so a copy of our database can't be used to sign in as you.
  • We don't keep Google or Facebook access tokens.
  • The keys that connect us to Google, Facebook and Cloudflare are kept as encrypted server secrets, never in the website's code.
  • We collect as little as we can and don't ask for anything we don't use.

No system is perfectly secure. If a data breach is likely to cause you serious harm, we'll tell you as soon as we can and explain what we're doing about it.

7. How long we keep it

  • Your account, profile, comments, catch reports and trips: until you delete them or delete your account.
  • Sign-in sessions: up to 30 days, renewed while you keep using the site. Expired sessions are deleted automatically every day, and signing out deletes yours straight away.
  • Backups: deleted data can stay in Cloudflare's database recovery backups for up to 30 days before it is overwritten. We don't restore deleted accounts from them.
  • Request logs: our own application logs are kept for about 3 days. Cloudflare may keep some network and security logs longer under its own policy.
  • Facebook deletion requests: when Facebook asks us to delete someone's data, we keep a confirmation code, the dates, the outcome and a one-way hash of the Facebook ID, so the status link Facebook gives you keeps working. It contains no name, email or picture.
  • Emails you send us: as long as we need them to deal with your request.

8. Cookies and local storage

Cookies used by Catch Signal
NamePurposeLasts
__Host-cs_sessionKeeps you signed in. Set only when you sign in.Up to 30 days
__Host-cs_oauthProtects the sign-in round trip to Google or Facebook against forgery.10 minutes

Both are strictly necessary, can't be read by page scripts and are never shared with anyone. Your browser's local storage may also hold your preferences (such as shore, boat or kayak and the spot you picked) and, if you turned your location on, a note that it is on (never your position). They never leave your device. If Cloudflare ever needs to check that a visitor isn't a bot (for example during an attack on the site), it may set its own short-lived security cookie, such as cf_clearance; see Cloudflare's cookie list. Because we use no advertising or analytics cookies, there's no cookie banner.

9. Seeing and correcting your information

  • Your profile page shows your details and lets you change your display name, bio, default location and mode.
  • You can edit a comment for 24 hours after posting it, and delete your comments, catch reports and trips at any time.
  • Your picture comes from your Google or Facebook account and is refreshed each time you sign in.
  • For a copy of everything we hold about you, or to correct something you can't change yourself, email privacy@catchsignal.com.au. We'll respond within 30 days, free of charge. We may need to confirm it's really you, for example by asking you to write from the email address on your account.

10. Deleting your information

  • In the app: Profile → Delete my account. This immediately deletes your profile, email address, sign-in links and sessions, all your comments (and the comments on your catch reports), your catch reports and your trips.
  • Through Facebook: remove Catch Signal from your Facebook apps and websites and send the deletion request. Facebook tells us automatically and we delete your data straight away. If you also sign in with Google, this removes only your Facebook link and the details that came from Facebook; use Delete my account to remove everything.
  • By email: write to privacy@catchsignal.com.au and we'll delete your account within 30 days, usually much sooner.

The data deletion page has step-by-step instructions, exactly what is deleted, and how to remove our access at Google and Facebook.

11. Questions and complaints

If you have a question or think we've mishandled your information, email privacy@catchsignal.com.au. We'll look into it and reply within 30 days.

If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC): oaic.gov.au/privacy/privacy-complaints.

12. Children

Catch Signal is not directed at children. You need to be at least 13 to sign in, which is also the minimum age for Google and Facebook accounts in Australia. If we learn that someone under 13 has an account, we'll delete it. Parents or guardians can contact us at privacy@catchsignal.com.au.

13. Changes to this policy

If we change this policy we'll update this page and the effective date at the top. For significant changes, such as a new kind of information or a new service that receives it, we'll also put a notice on the site before the change takes effect.