Privacy policy
What data yachtcockpit.app processes on the website and in the app, why, and what rights you have.
1. Controller
The controller responsible for processing personal data on the website yachtcockpit.app and in the application app.yachtcockpit.app is:
Dipl.-Ing. (FH) Michael JirgalGunthergasse 61
3430 Tulln
Austria
Email: michael@jirgal.at
Legal notice
You can contact this address with any questions about data protection and to exercise your rights. We are not required to appoint a data protection officer.
2. Overview
This privacy policy applies to the website yachtcockpit.app and the application app.yachtcockpit.app (the “app”). The website is purely informational. After signing up, you manage your boat’s data in the app.
A closed beta test is currently running: only people who have been invited can sign up, and nothing is paid. Sections that only apply once regular operation starts are marked as such.
We only process personal data to the extent necessary to run the website and the app, to perform our contract with you or because of legal obligations. We do not sell data and do not pass it on for advertising purposes.
3. Visiting the website
When you visit the website, our hosting provider Cloudflare (section 12) processes technically necessary data: IP address, date and time, page visited, browser and operating system. This serves the secure and stable delivery of the pages and the defence against attacks.
- Legal basis: legitimate interest in secure operation (Art. 6(1)(f) GDPR).
- Retention: we do not keep access logs for the website ourselves and do not analyse visits. Cloudflare processes the data only briefly for delivery and security.
The website sets no cookies, uses no tracking and no analytics tools, and does not load fonts, scripts or content from third parties.
4. Sign-up and user account
To use the app you create a user account. During the beta test this is only possible with a personal invitation; for this we store the invitation with email address, deadline and an encrypted check value of the invitation link. For the account we process:
- name and email address,
- your customer number, which we assign when you sign up,
- your country,
- your password exclusively in encrypted (hashed) form and, if you sign in with a second factor, its secret and backup codes,
- the time of sign-up, email confirmation and sign-ins,
- the time and version of the terms of use you accepted and of the privacy policy you acknowledged,
- voluntary profile details such as address, telephone number and emergency contact.
For each session we store the IP address and browser identifier to secure the session and detect misuse. We delete these details as soon as the session expires. We log sign-in events (email address, IP address, country, browser, type of event) for 7 days to detect attacks.
The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR); for securing the session and logging sign-ins, our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
5. Cookies in the app
The app only uses strictly necessary cookies. They contain no advertising or analytics data and can only be read by the app itself (HttpOnly, Secure, SameSite=Lax). No consent is required for them (§ 165(3) Austrian Telecommunications Act 2021).
| Cookie | Purpose | Duration |
|---|---|---|
__Secure-better-auth.session_token | Sign-in session | 7 days |
__Secure-better-auth.two_factor | Intermediate step of sign-in with a second factor | 10 minutes |
__Secure-better-auth.trust_device | Trusted device, only if you choose it | 30 days |
yc_tenant | Selected customer account, if you have access to several accounts | 1 year |
In addition, the app only remembers in your browser’s storage (localStorage) which boat you last selected when recording expenses.
6. Content in your account
In the app you store data about your boat, for example boat data and documents (CE documents, registration, insurance, radio data with call sign and MMSI, bill of sale), photos and documents, maintenance and service entries, expenses and receipts, berths, items, checklists, guides and contacts.
We process this content to provide the app’s features, i.e. to store, display, search, back up and export it. The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR).
Each account is technically separated from all other accounts. Other customers have no access to your data. Uploaded files are kept in private storage and only delivered after sign-in.
If your boat has a survey report from yachtgutachten.at, we can prepare your boat for you with data and files from the report. Until you take it over, this data is kept separate from all accounts; if you do not accept the invitation, we delete it 90 days after the invitation expires.
In “My contacts” we show accessory suppliers marked as advertising partners. We do not pass any of your data on to these advertising partners.
7. Connection to Victron VRM (on-board status)
On the Premium plan you can voluntarily connect the app to your account on Victron Remote Management (VRM). This is Victron Energy’s online portal to which a Victron device on board (e.g. Cerbo GX) sends readings. The app then shows these readings as the “on-board status” of your boat.
- What you give us: an access token that you create yourself in your VRM account, and the assignment of your VRM installation to a boat. We do not receive your VRM login details (email address and password).
- What we retrieve: roughly every 30 minutes, read-only, the readings of your assigned installation: name of the installation, battery (state of charge, voltage, current, charge cycles), solar and charging power, tank levels, temperature, humidity and air pressure, alarms and, if a GPS is connected on board, the position of the boat. We do not switch or change anything in your system or in your VRM account.
- What we store: the latest state and one daily value for the history. If limits that you set are exceeded, the app creates a to-do.
- Protection of the token: the token is stored encrypted, never displayed (only its last four characters), not logged and not included in the backup. Only you as the owner can enter, replace or remove it. The operator only sees whether a connection exists, not the readings.
- Withdrawal: you can disconnect at any time under Settings → Connections. The token is then deleted immediately. You can also revoke the token in your VRM account at any time.
For the retrieval we only transmit the token and the installation ID to Victron. Victron Energy B.V. (De Paal 35, 1351 JG Almere, Netherlands) is itself responsible for your VRM account and the data in it. Victron’s privacy information: Privacy Policy VRM.
The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR), as you only use the connection if you set it up yourself.
8. Data about other people (crew, contacts, co-users)
In “My crews”, “My contacts” and in service entries you can record data about other people, such as names, contact details, emergency contacts, roles, qualifications and SRC. You are responsible for these details yourself: only record them if you are entitled to do so, and inform the people concerned. We only process this data to store and display it for you and do not use it for any purposes of our own. The legal basis for this is our legitimate interest in providing the app to you (Art. 6(1)(f) GDPR).
ID details (number, issuing country, validity, without a scan) can only be stored on the Premium plan. If your account switches to the Basic plan, this data is deleted immediately and permanently.
If you invite co-users, we use their email address to send the invitation and to match it when they sign in. Invitations that are not accepted are deleted 7 days after they expire.
9. Access by the operator
How far the operator of yachtcockpit.app can view the content of an account depends on the plan:
- Beta test, trial and Basic: all content of the account, read-only, including documents and photos. People in “My crews” are not shown, only their number.
- Premium (paid, from regular operation): only the basic data of the boats, i.e. boat name, make, length, beam and year built.
The purpose of this access is to help you with questions and problems, to find and fix errors and to improve the app. The legal basis is our legitimate interest in a working and evolving service (Art. 6(1)(f) GDPR). You can object to this access (section 15).
Every access is logged with time and area; the log is kept for as long as your account exists. The operator sees contract data (name, email address, customer number, country, plan, invoices) on every plan, as it is needed for the contract and billing. We do not pass content on to third parties.
10. Trial, plans and payment
During the beta test nothing is paid. We do not ask for payment details, and no subscription is created. Premium is unlocked until the date stated in your invitation; for this we store the end date and reason of the unlock.
Every new account receives 7 days of Premium once. To prevent the same email address from receiving several trials, we store an encrypted check value (hash) of the address.
From the start of regular operation, the Premium subscription (annual or monthly) is handled by the payment provider Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). You enter your payment details (e.g. card details) directly with Stripe; we do not receive them.
- We transmit to Stripe: name, email address, country, customer number and an internal account identifier. You enter your billing address with Stripe yourself. Stripe does not receive boat, crew or other content from the app.
- We store from Stripe: identifiers of customer and subscription, status, term, interval and the key data of the invoices.
- Stripe is partly responsible itself for payment processing, for example for fraud prevention and for legal obligations. Stripe’s privacy information: stripe.com/privacy.
When you book, we store that you requested Premium to start immediately, with the time and wording. If you declare a withdrawal or a cancellation, we process the details from the form (name, email address, customer number, type and time of the declaration) to carry it out and confirm receipt to you. For a cancellation without signing in, we check from the country in your account whether this route is open to you; it applies to customers with Germany as their country.
- Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and statutory retention obligations (Art. 6(1)(c) GDPR); for the check value of the trial, our legitimate interest in preventing misuse (Art. 6(1)(f) GDPR).
11. Emails
We send you emails that are necessary for use: confirmation of your email address, password reset, invitations, notices about the end of the trial and of an unlock, new terms of use, account deletion and, later, payments and renewals. For sending we use Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany). Brevo processes your email address, your name and the content of the email on our behalf for this purpose. We do not send newsletters or advertising.
For each email we log the recipient, delivery status and message ID for 7 days to detect delivery problems.
The legal basis is the performance of the contract of use (Art. 6(1)(b) GDPR) and, for the delivery log, our legitimate interest in reliable delivery (Art. 6(1)(f) GDPR).
12. Hosting and other service providers
The website and app are run on Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). The app’s database and uploaded files are stored in the European Union.
As Cloudflare is a company based in the USA, data may be transferred to the USA, for example for technical logs or support. Cloudflare is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR); in addition, the data processing agreement contains the EU standard contractual clauses (Art. 46 GDPR).
Data processing agreements (Art. 28 GDPR) are in place with all service providers who process data on our behalf: with Cloudflare, with Brevo and, from the start of regular operation, with Stripe. Stripe is also partly responsible itself for some payment data (section 10).
13. Retention and deletion
- Account and content: for as long as your account exists. If you delete your account, all content and files are deleted immediately and permanently. Technical backup copies of our hosting provider are overwritten after 30 days at the latest.
- Record of the trial: after an account is deleted, we only keep the encrypted check value of your email address so that the same address does not receive a second trial. The address cannot be recovered from the check value.
- ID details: immediately when switching to the Basic plan.
- Unconfirmed sign-ups without content: after 7 days.
- Session data (IP address, browser identifier): when the session expires; expired confirmation and reset links after 7 days.
- Sign-in log, email delivery log, request limiting: after 7 days.
- Backups you create or upload: temporary storage after 24 hours.
- Victron access token: immediately when you disconnect or delete your account. On-board status history: daily values for 400 days, older ones are deleted automatically; after disconnecting, the history remains until you delete it under Settings → Connections or delete your account. If your account switches to the Basic plan, retrieval stops; token, assignment and history are kept but locked.
- Billing and subscription data (from regular operation): 7 years in accordance with statutory retention obligations, also after an account is deleted; then without any link to your account.
- Declarations of withdrawal and cancellation (from regular operation): 3 years as evidence.
- Logs of operator access: for as long as your account exists.
You can delete your account yourself at any time in the app under User management, or request deletion by email to the address above. Beforehand, with Premium you can download all data as a ZIP using the backup or, on any plan, request a copy of your data by email free of charge.
14. Data security
- Encrypted transmission (HTTPS) for website and app.
- Technical separation of all customer accounts.
- Passwords only in hashed form, protection against repeated sign-in attempts, sign-in with a second factor available.
- Operator access only with a second factor and with logging.
- Uploaded files are checked for their actual file type, stored privately and only delivered after sign-in.
- Access tokens for the Victron connection are stored encrypted; the key for this is kept separately from the database.
15. Your rights
You have the right of access, rectification, erasure and restriction of processing, the right to data portability and the right to object to processing based on legitimate interest (Art. 15 to 21 GDPR). Simply write to michael@jirgal.at.
For data portability, the backup as a ZIP is available to you on the Premium plan; on any plan we will send you a copy of your data by email free of charge on request, in a common, machine-readable format.
If you believe that the processing of your data infringes data protection law, you can lodge a complaint with the supervisory authority. In Austria this is the Data Protection Authority:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)Barichgasse 40–42, 1030 Vienna, Austria
Email: dsb@dsb.gv.at · www.dsb.gv.at
16. Changes
We adapt this privacy policy when the app or the legal situation changes, at the latest when regular operation starts. In the event of significant changes, we inform registered users by email and in the app.