Legal
Privacy Policy
Last updated: July 2026
This English version is a courtesy translation. The legally binding version of this document is the German original at skipperconnect.com/legal/datenschutz.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Ruben Schmidt c/o flexdienst – #21586 Kurt-Schumacher-Straße 76 67663 Kaiserslautern Germany
Email: info@skipperconnect.com Phone: +49 156 79816962
A data protection officer has not been appointed; there is no legal obligation to do so.
2. Overview
Skipper Connect consists of two parts: the website at skipperconnect.com, which provides information about the service, and the web app at app.skipperconnect.com for planning and organising sailing trips. This privacy policy applies to both. Personal data is processed only for the purposes described below. Where processing differs between the website and the web app, this is expressly indicated.
- No advertising cookies are set, no user profiles are created, and no data is transmitted to advertising networks. To measure reach and loading speed, anonymous usage statistics are collected; this takes place without cookies and without recognising individual persons (Section 7).
- Fonts and images are delivered from our own servers. When the website at skipperconnect.com and the web app at app.skipperconnect.com are accessed, no third-party domains are called.
- Queries for weather, place names, and exchange rates are performed server-side. The user's IP address is not transmitted to the respective providers in the process.
- One exception is the map display in route planning and the logbook. It is loaded from Mapbox only after prior consent (Section 6).
- Account and trip data are stored within the European Union (Frankfurt am Main). The provider's email mailbox is likewise operated within the European Union (Section 7).
The following sections describe the processing in detail.
3. User account
Data processed: Email address, password (exclusively in encrypted form; not accessible in plain text to anyone – not even the provider), first name, and last name (voluntary).
Purpose: Creation and administration of the user account, authentication, password reset, and assignment of trips to the account. The name is visible to the other members of the same trip; this is the purpose of the crew list.
Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract).
Confirmation email: After registration, a confirmation link is sent. The account is created only once this link is confirmed. If no confirmation is made, no data remains with the provider.
Company accounts: Charter companies and tour operators register separately. The data collected are company name, address, country, where applicable a VAT identification number, and telephone number. A company account contains no personal name.
4. Processing in the individual app areas
The app is divided into several areas. Not all of them process personal data. The user determines what content is entered.
4.1 Trip and crew
Trip: boat name, trip name, period, marina, country. Crew list: membership of the trip and assigned roles (e.g. skipper, co-skipper, steward).
This data is visible exclusively to the members of the respective trip. Other users of the app have no access to another trip.
4.2 Cash Log
Expenses, amounts, currencies, and details of who paid and who is included in the split. On this basis, the app calculates the mutual claims. Visible to the crew of the trip.
4.3 Logbook
Time, position (geographic longitude and latitude), course, speed, nautical miles, weather, engine hours, fuel levels, and notes.
A logbook documents the movement of the vessel and thus the whereabouts of the persons on board at a given time. Entries are made exclusively by the skipper; the skipper alone decides on their content.
Location query: The location is queried only at the user's express request (the “Use current position” button). The user grants the permission required for this via their browser. This permission constitutes the consent. Legal basis: Art. 6(1)(a) GDPR. The consent may be withdrawn at any time with effect for the future via the browser settings; in that case, the position can be entered manually.
4.4 Sea miles confirmation
Name of the recipient, role on board, trip, sailing area, boat type, distance, and the handwritten signature drawn by the skipper in the browser.
A sea miles confirmation is an evidentiary document that crew members submit, among other things, in connection with applications for sailing licences. A confirmation once issued therefore remains valid even if the issuing skipper later deletes their account; the name and signature remain on the document.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in the continued existence of the evidence for its recipient; a record that could be revoked afterwards would be unsuitable for the intended purpose. Issuing a confirmation is a separate, deliberate act by the skipper.
4.5 Route planning
Routes and points drawn on the map, each with the name of the creator. Visible to the crew of the trip.
4.6 Shopping list, packing list, boat handover, safety briefing
Entries made, checked off, or recorded as a note. The packing list is visible exclusively to the respective user; the other three lists are visible to the crew of the trip.
4.7 Weather
The location selected or determined by GPS is stored to avoid re-entry. Section 4.3 applies accordingly to the GPS query.
4.8 Recipes and games
Recipes contain no personal data. The games use the names from the crew list; these are not stored.
The legal basis for the processing under this Section 4 is Art. 6(1)(b) GDPR, unless a different legal basis is expressly stated above.
5. Cookies and storage on the device
Three cookies are set. They are strictly necessary for the operation of the app; without them, logging in is not possible. Consent is not required for this (Section 25(2) No. 2 TDDDG, German Telecommunications Digital Services Data Protection Act).
The cookies listed below are set exclusively in the web app at app.skipperconnect.com. The website at skipperconnect.com sets no cookies and uses no comparable techniques for storing or reading information on your device. Consent under Section 25 TDDDG is therefore not required there.
| Cookie | Purpose | Storage period |
|---|---|---|
| Login session | keeps you logged in | until logout |
| Active trip | stores the currently opened trip | until logout |
| Language | stores the selected language (German or English) | 1 year |
No advertising, analytics, or third-party cookies are set. Any further storage on the device takes place exclusively after prior consent (Section 6).
6. Map display (Mapbox)
The maps in route planning and the logbook are provided by:
Mapbox Inc., 1133 15th St NW, Suite 825, Washington, DC 20005, USA
When the map is loaded, the map tiles are obtained directly from Mapbox. In doing so, Mapbox receives the user's IP address and the map section requested. Mapbox also stores an anonymous identifier in the browser's local storage (mapbox.eventData) and reports the map access to one of its own servers (events.mapbox.com); this serves Mapbox's usage counting. Trip data, routes, and positions are not transmitted to Mapbox.
After examination, this counting cannot be disabled without impairing the map function. The map is therefore loaded only after consent. Until consent is given, no data is transmitted to Mapbox and no data is stored on the device.
Legal basis: Section 25(1) TDDDG and Art. 6(1)(a) GDPR (consent).
Withdrawal: at any time in the account settings with effect for the future. Data already transmitted is not subject to withdrawal.
Without consent, route planning and the logbook remain usable; only no map is displayed.
Transfer to the USA: Mapbox is certified under the EU-US Data Privacy Framework. By adequacy decision of 10 July 2023, the European Commission determined that certified US companies ensure an adequate level of data protection. In addition, the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR apply. Notwithstanding these bases, the United States does not provide a level of data protection equivalent to that of the European Union; under certain conditions, US authorities may access data without the data subject becoming aware of it or being able to obtain effective legal remedy. For this reason, the integration takes place only after consent.
Mapbox privacy policy: https://www.mapbox.com/legal/privacy
7. Recipients and processors
7.1 Processors
A data processing agreement pursuant to Art. 28 GDPR exists with each of the following service providers.
Supabase (database and authentication) Storage of the data referred to in Sections 3 and 4. Server location: Frankfurt am Main, Germany.
Vercel (hosting) Vercel delivers the app. In doing so, the server logs record the IP address, time, page requested, and browser type; this information is technically unavoidable and is not evaluated. Processing region: Frankfurt am Main. Vercel Inc. is based in the USA and is certified under the EU-US Data Privacy Framework; the Standard Contractual Clauses apply in addition. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation).
Vercel Web Analytics and Speed Insights (reach and performance measurement) Vercel Web Analytics and Vercel Speed Insights are used to measure reach and loading speed. The data recorded are the page requested, the referring page, the approximate location at country level, information on device type, operating system, and browser, and technical metrics on loading speed. No cookies are set and no identifiers are stored on the device. The analysis is carried out without a persistent identifier; recognition of individual persons or tracking across multiple websites does not take place. The measurement scripts are delivered from the respective domain accessed, not from a third-party domain. Vercel Inc. is based in the USA and is certified under the EU-US Data Privacy Framework; the Standard Contractual Clauses apply in addition. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in shaping the service around how it is actually used, and in delivering it quickly).
Resend (email delivery) Delivery of confirmation and password emails; receives the email address for this purpose. Processing region: Ireland. Resend is based in the USA and is certified under the EU-US Data Privacy Framework; the Standard Contractual Clauses apply in addition.
Google Workspace (email mailbox) Email traffic via the address info@skipperconnect.com is handled through Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The content and header data of incoming and outgoing messages are processed. Google Ireland Limited is a processor on the basis of the Google Cloud Data Processing Addendum. In the course of operation and support, access by Google LLC (USA) may occur. The Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR apply to this; in addition, Google LLC is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable email operation), and for contract-related enquiries Art. 6(1)(b) GDPR.
Mapbox – see Section 6; integration exclusively after consent.
7.2 Payment processing (Stripe)
When paid features are purchased, payment is processed via Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). The payment-method and transaction data required for payment are entered directly with Stripe and collected by Stripe; card and account details do not reach the provider. The provider receives from Stripe the information required for contract and accounting purposes (in particular name, invoice data, and payment status).
Insofar as Stripe processes payment data for its own purposes – in particular for fraud prevention and to fulfil its own regulatory, anti-money-laundering, and tax obligations – Stripe is an independent controller in that respect. Stripe may transfer data to its parent company Stripe, Inc. (USA); the latter is certified under the EU-US Data Privacy Framework, and the Standard Contractual Clauses apply in addition.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (compliance with legal obligations, in particular commercial and tax retention obligations).
Stripe privacy information: https://stripe.com/privacy
7.3 Services queried server-side
For weather, place names, and exchange rates, the query is made by the provider's server, not by the user's browser. The following providers receive the server's IP address, not that of the user.
- Open-Meteo – weather data. Receives coordinates; no identifier and no IP address of the user.
- Nominatim / OpenStreetMap Foundation – conversion of coordinates into place names. Receives coordinates only.
- frankfurter.app – exchange rates of the European Central Bank. Receives currency codes only (e.g. “USD”, “EUR”). No personal data.
7.4 Transfer to a charter company
If a trip was created by a charter company, the company receives access to a limited section of that trip's data.
Visible to the company: the trip data (boat, period, sailing area), the crew list with names and roles, and boat handover and safety briefing.
Not visible to the company: Cash Log, logbook, route planning, sea miles confirmations, and shopping list.
This is a technical barrier: if a company account accesses one of the aforementioned non-visible areas, the data concerned is not loaded from the database. Furthermore, a company account cannot become a member of a crew and cannot enter content in any trip.
Legal basis: Art. 6(1)(b) and (f) GDPR; the company organises the trip and has a legitimate interest in knowing the persons on board.
The charter company is independently responsible for processing this data outside the app.
7.5 No further recipients
Data is not passed on for advertising purposes and is not sold. Data is transmitted to authorities only where there is a legal obligation to do so.
8. Newsletter
If the user ticks the corresponding box during registration, they are added to the newsletter.
Procedure (double opt-in): The tick constitutes the declaration. It becomes effective only when the confirmation link in the email sent is clicked. Only with this confirmation is an entry created with the provider.
Data stored: Email address, time of confirmation, and the exact wording of the consent. The wording serves as proof of consent (Art. 7(1) GDPR).
Legal basis: Art. 6(1)(a) GDPR.
Withdrawal: at any time without giving reasons, via the unsubscribe link in every newsletter email or informally to info@skipperconnect.com. The withdrawal does not affect the lawfulness of the processing carried out up to that point.
When the account is deleted, the newsletter entry is deleted as well.
On registration pages reached via the invitation link of a charter company, no newsletter tick box is displayed.
9. Contact by email
You can contact the provider by email at any time. The contact address is given in the imprint.
When you send an email, the provider processes the information you transmit: your sender address, your name where applicable, the content of your message, and the technical header data of the email, in particular the time of receipt. No further information is required. You decide for yourself which personal data you include in the text of your message.
Purpose: Handling and answering your enquiry and processing any subsequent correspondence.
Legal basis: Art. 6(1)(b) GDPR insofar as the enquiry serves the initiation or performance of a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries). If it is a commercial or business letter, Art. 6(1)(c) GDPR applies in addition.
Storage period: Enquiries are deleted as soon as they have been conclusively dealt with and no statutory retention obligations conflict with this. For emails that qualify as commercial or business letters, the commercial and tax retention periods of six years pursuant to Section 257 HGB (German Commercial Code) and Section 147 AO (German Fiscal Code) apply.
Recipient: The provider's email mailbox is operated via Google Workspace. Details on this under Section 7.
A contact form is deliberately not offered. Contact is made via your own email program; the message reaches the provider's mailbox directly. During the act of making contact itself, no data is collected either on the website at skipperconnect.com or in the web app at app.skipperconnect.com.
10. Storage period and deletion
Personal data is stored for the duration of the existence of the user account. There is no automatic deletion after a trip has ended; the data remains available to the user for further use.
When the account is deleted (Account → “Delete account”), the following applies:
Irreversibly deleted:
- the user's packing list,
- the stored weather locations,
- the sea miles confirmations received by the user,
- the crew memberships,
- the newsletter entry,
- access (email address and password are rendered unusable, and the account is permanently blocked).
Anonymised, not deleted: The user's name is replaced by “Former crew member”. Contributions on which the use by other persons is based are retained without any personal reference.
Background: In the Cash Log, a user's expenses are linked to those of the other crew members. Complete deletion would render the crew's settlement incorrect. Anonymised data is not personal data within the meaning of the GDPR.
The following remain unaffected:
- Trips that the user has created; they remain usable for the crew. The user appears in them as “Former crew member”.
- Sea miles confirmations that the user has issued as skipper; they remain valid with name and signature (Section 4.4).
To leave an individual trip, the “Leave trip” function is available in the crew list; deleting the account is not required for this.
Statutory retention obligations (in particular the retention of invoices under tax and commercial law for a period of eight or ten years) remain unaffected and take precedence over deletion.
11. Rights of the data subject
Data subjects have the right to:
- access to the personal data processed (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR); for the procedure, see Section 10,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on legitimate interest (Art. 21 GDPR),
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR); this concerns the newsletter, location, and map display.
An informal message to info@skipperconnect.com is sufficient to exercise these rights.
Right to lodge a complaint: Data subjects may lodge a complaint with a data protection supervisory authority at any time. The competent supervisory authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany https://www.lda.bayern.de
12. No profiling, no personal tracking, no advertising
- Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.
- No personal tracking takes place: no advertising pixels are used, no user profiles are created, and no data is combined across multiple websites. The reach and performance measurement under Section 7 operates without cookies and without recognising individual persons.
- Data is not passed on to advertisers and is not sold.
13. Data security
The connection to the app is encrypted throughout (HTTPS/TLS). Passwords are stored exclusively as a cryptographic hash and are readable by no one – not even the provider. Access to the database takes place exclusively server-side; the database is not reachable from the browser.
14. Minors
The app is aimed at users of legal age. Persons under the age of 16 may create an account only with the consent of their legal guardians.
15. Changes to this privacy policy
This privacy policy will be adjusted if changes to the service or the legal situation make this necessary. The current version is available at this location. Users will be informed of material changes in the web app.
