Privacy Policy

Last updated: April 2026

1. Who we are

SailHub is operated by SailHub. If you have questions about how we handle your data, contact us at [email protected].

2. What data we collect and why

We collect the following personal data to allow you to participate in sailing events and manage crew manifests:

  • Name and email address — to identify your account and communicate with you
  • Date of birth and nationality — required for official crew manifests submitted to maritime authorities
  • Passport or ID number — required for official crew manifests; stored encrypted
  • Skipper licence number — to verify your qualification to command a vessel; stored encrypted

3. Legal basis for processing

We process your personal data on the basis of contract performance (Article 6(1)(b) GDPR) — processing is necessary to provide you with the SailHub service and to meet legal requirements for crew documentation.

4. How long we keep your data

We retain your personal data for as long as you hold an active account. When you delete your account, all personal data is permanently and immediately erased. We do not apply any automated retention period — your data is kept until you ask us to delete it.

5. Who we share your data with

We do not sell or share your personal data with third parties for marketing purposes. Your data is shared only with:

  • AWS (Amazon Web Services) — our cloud infrastructure provider, operating in the EU (eu-west-1 region), under a Data Processing Agreement
  • Event organisers — your name, nationality, date of birth, and passport number may appear in crew manifests downloaded by the organiser of events you join

6. Your rights

Under GDPR you have the following rights:

  • Access — you can view all your personal data in your profile
  • Rectification — you can update your data at any time in your profile settings
  • Erasure — you can permanently delete your account and all associated data from Account Settings → Delete Account
  • Portability — contact us at [email protected] to request a copy of your data
  • Complaint — you have the right to lodge a complaint with your national data protection authority

7. Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

8. Cookies

We use only essential cookies required for login sessions and form security (Django session and CSRF cookies). No analytics or tracking cookies are used.