Privacy and Data Protection Notice
Last updated: 25 August 2026
This Notice explains how Yachtara handles personal data through the Yachtara marketing website, web and mobile applications, support channels and community features.
1. Controller and contact
The controller is:
AD Internet Consulting BV, offering Yachtara under the commercial name Yachtara
Registered office: Ringlaan 11, 3560 Lummen, Belgium
Enterprise number: 0470.419.019
VAT number: BE 0470.419.019
Privacy contact: privacy@yachtara.com
Support: support@yachtara.com
Yachtara has not appointed a data protection officer because its current activities do not require one. Privacy requests should be sent to the privacy address above.
2. Key points
- Yachtara does not sell personal data.
- Yachtara does not use personal data for third-party behavioural advertising.
- The current Yachtara code contains no advertising, third-party analytics, crash-reporting or external AI SDK.
- Core account and user-content processing is hosted by AWS in Frankfurt, Germany (
eu-central-1). - Stripe handles card and payment credentials on Stripe-hosted pages; Yachtara does not receive full card details.
- Anchor-watch GPS processing is local to the user's device and is not transmitted to the Yachtara backend.
- Community location posts are user-initiated public posts and are stored at reduced precision of about three decimal places.
- Map requests made directly from a device disclose network information such as the IP address and requested map area to the relevant map provider.
- Telemetry, NMEA ingestion and AI boat intelligence are not live production features at the date of this Notice.
3. Personal data we process
3.1 Account and identity data
We process the email address used to register and authenticate, an internal account identifier, email-verification state, authentication and security records, subscription status and account settings. A password is handled through AWS Cognito authentication systems and is not available to Yachtara staff in readable form.
If profile settings allow additional information, we may process the name, profile image, preferred units, country, language or other information the user chooses to provide.
3.2 Vessel and ownership data
We process information entered about a vessel, which may include vessel name, type, dimensions, displacement, draft, equipment, systems, owner details, maintenance history, incidents and other operational records.
Vessel information can become personal data where it identifies or can be linked to an owner, operator, crew member or location.
3.3 Crew, invitations and schedules
We process crew profiles, roles, access permissions, invitations and watch or work schedules. A vessel owner or administrator may provide an invitee's email address before the invitee creates an account. We use it to deliver and manage the requested invitation.
The invite email links to this Notice. Pending invitations should expire and be deleted after 30 days unless they are reissued, accepted, required to prevent abuse or subject to a legal dispute.
Members of a vessel workspace can see shared vessel and crew information according to their assigned permissions. Users should not place information in a shared workspace unless it is appropriate for the authorised members who can access it.
3.4 Maintenance, documents and manuals
We process maintenance tasks, work logs, service history, equipment records, incidents, uploaded manuals, photographs and vessel documents. Files are stored in the user's account or shared vessel workspace and are made available to authorised members.
Storage limits depend on the plan. Current technical allowances are 100 MB for Free, 5 GB for Essential, 50 GB for Premium and 200 GB for the future AI tier. Display of a future tier does not mean its AI functions are available.
Do not upload passports, national identity documents, full payment-card information, medical files or other highly sensitive information unless Yachtara expressly provides a feature designed for that purpose.
3.5 Weather, routes and logbook information
Weather and marine-data sources are primarily retrieved server-side without sending those providers an identifiable Yachtara user record.
Route calculations currently run in the client environment. When a user chooses to save, synchronise or include route or logbook information in an account or offline package, Yachtara processes that information as user content. Route and logbook data can reveal vessel movements and should be treated as potentially sensitive location information.
3.6 Anchor-watch location
The anchor-watch feature reads precise device location continuously while operating. Its anchor position, swing circle and alarm state are stored locally on the device. The anchor feature does not send this GPS stream or anchor position to the Yachtara backend and does not make it visible to other users.
Device operating systems control location permissions. Background location access should be requested only when needed for the user-requested anchor-watch function. Yachtara does not use anchor-watch location for advertising, profiling or unrelated analytics.
3.7 Community data
We process public profile information, boards, topics, posts, reports and moderation records. The current service has no private direct-message function.
Location-board posts may include coordinates deliberately submitted by the user. The backend rounds latitude and longitude to three decimal places before storage, approximately 111 metres at the equator. This reduces precision but does not make the location anonymous.
Community content is manually reviewed by authorised administrators when reported or otherwise necessary. Yachtara currently uses no automated content classifier or third-party moderation service.
3.8 Payment and subscription data
Stripe handles checkout, recurring billing and the customer portal. Stripe receives payment credentials and may act as an independent controller for information it collects directly to provide regulated payment services, prevent fraud and meet legal obligations.
Yachtara receives and stores limited billing information such as the Stripe customer or subscription identifier, selected plan, subscription status, billing period, renewal date, grace period and transaction or invoice references. Yachtara does not receive or store the full card number, CVV or card expiry date.
3.9 Support and communications
We process support tickets, messages, contact details, correspondence and attachments to answer requests, diagnose problems, manage complaints and keep a record of the resolution.
Transactional emails include account verification, password recovery, crew invitations, service notices, receipts and subscription messages. Marketing messages, if introduced, will use a separate lawful basis and provide an unsubscribe facility.
3.10 Technical, security and diagnostic data
When the website, app or API is used, infrastructure may process IP addresses, timestamps, requested resources, request and response identifiers, account or authentication identifiers, browser or application type, operating-system information, error information, security events and diagnostic details.
Production application logs are currently configured for retention of up to 365 days. Yachtara must minimise personal data in logs and restrict access. Technical logs are not used for advertising or cross-service profiling.
The current app does not collect an advertising identifier, device fingerprint or push-notification token. Local notifications are scheduled on the device.
3.11 Website storage and cookies
The current marketing website does not use advertising or optional analytics cookies. Strictly necessary cookies, local storage, authentication state, service-worker caches and similar technologies may be used to provide the website and application. Details are in the Cookie and Similar Technologies Notice.
4. Where data comes from
We obtain data:
- directly from the user;
- from a vessel owner or administrator who invites a crew member or creates authorised vessel records;
- from the user's device when the user activates a function or makes a request;
- from Stripe in relation to subscription status and payment events;
- from security and technical infrastructure; and
- from public authorities or other parties where necessary to comply with law or resolve abuse, ownership or legal disputes.
5. Why we process data and our legal bases
Providing the contract
We process account, vessel, crew, documents, maintenance, route, community, support and subscription information where necessary to create the account, provide requested features, manage the subscription, deliver support and perform the contract.
Legitimate interests
We rely on legitimate interests where proportionate for:
- securing the Service and preventing fraud, abuse and unauthorised access;
- maintaining technical logs and diagnosing faults;
- sending and managing a crew invitation requested by a vessel owner or administrator;
- administering community reports and enforcing rules;
- establishing, exercising or defending legal claims; and
- understanding service reliability through first-party operational information that does not involve optional behavioural tracking.
Users may object to processing based on legitimate interests. We will consider the request and stop unless compelling legitimate grounds or legal claims justify continuation.
Consent
We rely on consent where the law requires it, including for optional cookies, non-essential tracking, direct electronic marketing and certain device permissions. Consent can be withdrawn at any time without affecting processing that occurred before withdrawal.
A device's operating-system permission is not used as a blanket consent for unrelated processing. Location permission is requested for the user-selected feature that needs it.
Legal obligations
We process and retain information where required by tax, accounting, consumer-protection, sanctions, law-enforcement, court-order or other legal obligations.
Protecting people and rights
In an emergency or serious safety incident, we may process limited data where necessary to protect vital interests or comply with a lawful request. Yachtara is not an emergency monitoring service and does not continuously monitor users or vessels.
6. Recipients and service providers
Personal data may be disclosed to the following categories where necessary:
- Amazon Web Services (AWS): authentication, API, compute, database, file storage, email delivery, logs and content delivery;
- Stripe: checkout, subscription billing, fraud prevention and customer portal;
- Microsoft 365: Yachtara business email and correspondence;
- Esri / ArcGIS Online: map tiles requested directly by the user's device, which disclose the IP address and requested map area;
- OpenStreetMap Foundation tile infrastructure: map tiles requested directly by the user's device where that endpoint is used, which disclose the IP address and requested tile;
- Apple and Google: app distribution and store services under their own privacy terms;
- professional advisers, insurers, auditors and potential transaction counterparties subject to confidentiality; and
- courts, regulators, law-enforcement bodies or other recipients where disclosure is legally required or necessary to protect rights.
Marine weather and forecast providers used through server-side ingestion generally receive requests from Yachtara infrastructure rather than identifiable end-user accounts.
We do not disclose personal data to third parties for their own behavioural advertising and we do not sell personal data.
7. Hosting and international transfers
Core Yachtara backend storage and processing is configured in AWS eu-central-1 in Frankfurt, Germany. AWS accounts are restricted to that region, with us-east-1 permitted for CloudFront certificate management. Certificates do not contain Yachtara user content.
CloudFront is a global content-delivery network and may process IP addresses, request data and cached delivered content at edge locations outside the EEA. Map providers, Stripe, Microsoft, Apple and Google may also process data internationally under their respective services.
Where GDPR-restricted data is transferred outside the EEA, Yachtara uses an applicable adequacy decision, the European Commission's Standard Contractual Clauses, binding corporate rules or another lawful transfer mechanism, together with supplementary safeguards where required. Processor agreements and transfer safeguards must be maintained with relevant suppliers.
8. Retention
We retain personal data only for as long as necessary for the relevant purpose, including the following operational periods:
- Account, vessel, crew, maintenance and active documents: for the life of the account or vessel workspace, followed by the deletion process, except where a legal hold applies.
- Pending crew invitations: 30 days after issue unless accepted, reissued, needed to prevent abuse or involved in a dispute.
- Unverified registrations: no longer than 30 days unless verification is completed or security requires limited retention.
- Abandoned pending uploads: normally reclaimed after 24 hours.
- Support tickets and messages: up to 24 months after closure, or longer where necessary for an unresolved dispute or legal claim.
- Production application and security logs: up to 365 days, with access restricted and log content minimised.
- Community posts: until deleted by the user or removed by Yachtara. On account erasure, posts are deleted or author information is anonymised where lawful and appropriate. Reports and moderation evidence may be retained for up to two years after closure or longer for legal claims.
- Subscription, transaction and accounting records: for the statutory accounting and tax period, which may be up to 10 years.
- Erasure completion record: a minimal tombstone may be retained for up to five years to demonstrate completion, prevent re-association and defend legal claims. It must not preserve erased profile content.
- Backups and non-current file versions: removed or overwritten according to the backup cycle and no later than 90 days after deletion from active systems, unless a legal hold applies. Backup data is not restored to ordinary production use after an erasure request.
- Consent records and suppression lists: for as long as necessary to demonstrate the user's choice and ensure that an opt-out is respected.
Where the same record is needed for several purposes, the longest applicable lawful period applies. Data may be anonymised so that it can no longer be linked to an individual; genuinely anonymised information is not personal data.
9. Account and data deletion
Users can request deletion through the account function when available or by emailing privacy@yachtara.com. We may verify identity before acting.
Deletion removes the account and associated personal data from active systems unless retention is required by law, security, fraud prevention, unresolved transactions, community integrity or legal claims. Public contributions may be deleted or anonymised. Data in backups ages out under the backup cycle.
Account deletion and subscription cancellation are separate actions. A user should cancel an active paid subscription before deleting the account or ask support to perform both.
10. Security
Yachtara uses measures appropriate to the risk, including authenticated access, role-based permissions, encryption in transit, cloud access controls, separation of environments, logging, document-security scanning and administrative allowlists.
No online service can guarantee absolute security. Users should use a unique password, protect their device and report suspected compromise promptly.
11. Rights
Subject to applicable conditions, individuals may request:
- access to their personal data and information about its processing;
- correction of inaccurate or incomplete data;
- deletion;
- restriction of processing;
- portability of data supplied under contract or consent;
- objection to processing based on legitimate interests;
- withdrawal of consent; and
- review of any automated decision covered by applicable law.
Send a request to privacy@yachtara.com. We normally respond within one month under GDPR, subject to permitted extensions. We may ask for proportionate identity verification.
EEA individuals may complain to the Belgian Data Protection Authority:
Data Protection Authority / Gegevensbeschermingsautoriteit
Rue de la Presse 35 / Drukpersstraat 35
1000 Brussels, Belgium
https://www.dataprotectionauthority.be
Individuals elsewhere may also contact the authority in their jurisdiction. These rights are not waived by agreeing to the Terms.
12. Automated decision-making and AI
Yachtara does not currently make decisions producing legal or similarly significant effects through AI or profiling.
Weather routing is rule-based planning support and does not take action for the user. Subscription access is determined by plan status and a fixed grace-period rule. Community moderation is currently performed by authorised people, not an automated classifier.
No production path currently sends user content to an external AI provider. Before an AI feature is released, Yachtara will assess the data protection impact, identify the provider and purposes, update this Notice and obtain consent where required.
13. Children
The Service is intended for adults aged 18 and over. Yachtara does not knowingly offer accounts to children. If we learn that a child created an account, we may suspend it and delete the associated data after appropriate verification.
14. Third-party sites and stores
Links, app stores, Stripe checkout and external map services have their own privacy notices. Yachtara is responsible for its own processing and for processors acting on its instructions, but not for independent processing performed by a third party under that party's own purposes and legal obligations.
15. Changes
We update this Notice before materially changing how personal data is used. Material changes will be communicated through the Service or by email where appropriate. A new purpose incompatible with the original purpose will not be introduced without a valid legal basis and any required notice or consent.
16. Contact
Privacy questions and rights requests: privacy@yachtara.com
Service support: support@yachtara.com