Skip to content
CruiseOfLife

Privacy Policy

What personal data we process, why, for how long and what your rights are (art. 13 and 14 GDPR).

Effective from 2026-10-10. The Polish version is binding; this is a translation.

1. Data controller

The controller of your personal data is Dawid Ziniewicz, a private individual not running a registered business, email: dawidziniewicz@gmail.com. For anything related to personal data, write to dawidziniewicz@gmail.com or use the contact form (topic “Data protection”). No data protection officer has been appointed.

2. What data we process

  1. Account data: full name, username, email address, password (stored only as a cryptographic hash), role, date of accepting the Terms.
  2. Sailing data: whether you hold a licence and which, licence number, SRC certificate status and number, STCW training, experience at sea, other qualifications and, for Skippers, whether they act as a business (trader).
  3. Listings: type, name, dates, place, yacht, travel, price, description, photos, proposed route and the Skipper's contact details given in the Listing.
  4. Crew lists: first and last name, status (invited, confirmed, not coming), yacht assignment and, optionally, phone, email, date of birth, nationality, ID card or passport number, emergency contact and notes for the Skipper.
  5. Messages: data given in the contact form, an illegal content notice or a complaint (name, email, message, URL).
  6. Technical data: IP address, browser information, session identifier, log of failed login attempts.

3. Purposes and legal bases

  1. Concluding and performing the Account agreement and providing the Service, including trip sign-ups and crew lists (art. 6(1)(b) GDPR).
  2. Showing Skippers' qualifications and checking them for the safety of trips (art. 6(1)(b) and (f) GDPR).
  3. Replying to messages and handling complaints (art. 6(1)(b), (c) and (f) GDPR).
  4. Handling illegal content notices and moderation decisions under the Digital Services Act (art. 6(1)(c) GDPR).
  5. Keeping the Service secure and preventing abuse, including limiting login attempts (art. 6(1)(f) GDPR).
  6. Establishing, exercising or defending legal claims (art. 6(1)(f) GDPR).

Our legitimate interest is running the Service securely and reliably, communicating with Users and protecting ourselves against claims.

4. Is providing data mandatory

Providing data is voluntary but necessary to create an Account. A Skipper must give a licence number and SRC status to create a Skipper Account. Data in the contact form is necessary for us to reply.

5. Recipients

  1. Cloudflare, Inc. (hosting, database, content delivery network) as a processor acting on our behalf.
  2. Unsplash: photos in the Service are loaded from images.unsplash.com, so your browser sends that server your IP address and basic technical information.
  3. Other Users, for data published in a profile or Listing.
  4. The trip's Skipper: crew list data for that trip. The Skipper is a separate controller of this data to the extent they use it to organise the trip (for example to prepare a crew list for the harbour master). Names are also visible to the other people on the trip and to people who know the trip code.
  5. Route maps come from OpenStreetMap and OpenSeaMap. Our server fetches the map tiles, so your IP address is not sent to these services.
  6. Public authorities, where the law requires us to disclose data.

6. Transfers outside the EEA

Cloudflare, Inc. may process data in the United States. Transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework, in which Cloudflare participates, and additionally on standard contractual clauses. You can obtain a copy of the safeguards by contacting us.

7. How long we keep data

  1. Account data: until the Account is deleted. Database backups are overwritten within 30 days.
  2. Login sessions: up to 30 days or until you log out.
  3. Listings and photos: until the Skipper deletes them or their Account; access gained with a code expires after 12 hours. Photos uploaded but never saved in a Listing are deleted after 24 hours.
  4. Crew lists: names until the trip is deleted; additional details (phone, email, date of birth, nationality, document number, emergency contact, notes) are deleted 30 days after the trip ends.
  5. Log of login and sign-up attempts (IP address): up to 24 hours.
  6. Messages, notices and complaints: up to 12 months after the matter is closed and, where necessary, until claims become time-barred.

8. Your rights

  1. Right of access and to a copy of your data (you can download your data under “My account”).
  2. Right to rectification.
  3. Right to erasure (you can delete your Account yourself under “My account”).
  4. Right to restriction of processing.
  5. Right to data portability.
  6. Right to object to processing based on legitimate interest.
  7. Right to lodge a complaint with the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl) or the supervisory authority in your country.

Your data is not used for automated decision-making or profiling.

9. Cookies and similar technologies

The Service uses only what is strictly necessary for it to work. We do not use analytics, advertising or tracking cookies, so we do not ask for cookie consent.

  1. col_session: login session cookie (HttpOnly, Secure), valid for up to 30 days or until you log out. Logging in is not possible without it.
  2. col_t_…: cookie that lets you view a private trip after entering the correct code (HttpOnly, Secure), valid for 12 hours.
  3. col_c_…: cookie that remembers that a place on a crew list was confirmed in this browser without logging in, so the answer can be changed later (HttpOnly, Secure), valid for 180 days.
  4. col-intro (browser sessionStorage): remembers that the welcome animation has already been shown. Deleted when you close the tab.

You can delete or block cookies in your browser settings; blocking the session cookie prevents logging in.

10. Security

Connections to the Service are encrypted (HTTPS). Passwords are stored as PBKDF2 hashes with a random salt and session identifiers as SHA-256 hashes. Only the Service's administrators can access User data.

11. Changes

This policy may be updated. The current version is always available at https://cruiseoflife.com/. We will inform Users with an Account about significant changes.