Introduction
Welcome to MyBoatOS (“we,” “our,” or “us”). We provide a software platform (the “Platform”) to help professional boat operators — including vessel owners (“Owners”), captains (“Captains”), and crew — manage their operations, including bookings, guest communications, crew management, compliance, maintenance, and payments with their customers (“Guests”).
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform, whether as an Owner, Captain, crew member, Guest, or other user. Please read this policy carefully. By using the Platform, you consent to the practices described herein.
Information We Collect
Information You Provide Directly
- Account Information: Name, email address, phone number, and password when you create an account
- Organization Information: Business name, address, contact details, and billing information for operator accounts
- Vessel Data: Vessel specifications, registration details, hull identification numbers, systems inventory, and maintenance records
- Trip and Booking Data: Departure/arrival information, engine hours, fuel usage, crew and guest counts, charter details, and scheduling information
- Financial Records: Revenue, expenses, invoices, payment amounts, and financial transaction details for operations management
- Voice Memos: Audio recordings you create within the Platform for transcription and note-taking purposes
- Photos and Documents: Images you upload including helm displays, receipts, damage documentation, insurance certificates, and other operational documents
- Crew Information: Credentials, certifications (USCG licenses, medical certificates, drug test records), compensation details, availability, and professional profiles for crew members
Guest Information (Collected on Behalf of Operators)
When Guests interact with the Platform through booking portals, we collect information on behalf of the vessel operator, including:
- Guest name, email address, and phone number
- Party size and composition (adults, children)
- Dietary preferences, allergies, and special requests
- Special occasion details (birthdays, celebrations)
- Digital waiver signatures and charter agreement acceptance
- Payment information (processed by Stripe — see Payment Data section below)
Operators are the data controllers for Guest information collected through their booking portals. MyBoatOS processes this information on behalf of the operator.
Information Collected Automatically
- Device information (browser type, operating system)
- Usage data (pages visited, features used, timestamps)
- IP address and approximate location
- Session and authentication data
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our fleet management and operations services
- Process bookings, payments, and related transactions
- Facilitate communication between operators, crew, and guests
- Send operational notifications, including booking confirmations, pre-charter information, and post-charter follow-ups
- Send technical notices, updates, security alerts, and support messages
- Generate analytics, reports, and business intelligence for operator accounts
- Transcribe voice memos and extract data from documents and images using AI services
- Track crew credentials and send renewal reminders for compliance purposes
- Provide weather, tide, and marine condition information from public data sources (NOAA)
- Monitor and analyze usage trends to improve the Platform
- Enforce our Terms of Service and protect against fraud
Third-Party Services
We use the following third-party services to operate MyBoatOS. Each service processes your data in accordance with their own privacy policies:
- Supabase: Database hosting, authentication, file storage, and row-level security
- Vercel: Application hosting, deployment, and serverless functions
- Stripe: Payment processing, deposit collection, and operator payouts (see Payment Data section)
- Twilio: SMS and MMS notifications and messaging (see SMS Communications section)
- Microsoft Azure: Email notifications via Azure Communication Services; calendar synchronization via Microsoft Graph API
- Google: Calendar synchronization via Google Calendar API
- OpenAI: Voice transcription via Whisper API
- Anthropic: Document analysis, data extraction, and AI-powered features via Claude API
- NOAA: Weather, tide, and marine condition data from public National Oceanic and Atmospheric Administration APIs
We do not sell your personal information to any third party. We share information with the services listed above only as necessary to provide and improve the Platform.
Payment Data
We use Stripe, Inc. to process payments. When you make a payment through MyBoatOS, your payment information (credit card number, billing address) is collected and processed directly by Stripe. We do not store, access, or transmit full credit card numbers — Stripe handles all PCI-DSS compliance. We receive only transaction confirmations, amounts, and a truncated card identifier from Stripe.
For vessel operators using Stripe Connect, your business information, banking details, and identity verification documents are shared directly with Stripe for Know Your Business (KYB) verification as required by financial regulations. Stripe's privacy policy is available at stripe.com/privacy.
MyBoatOS charges a platform fee on charter bookings processed through the Platform. This fee structure is disclosed to operators before they connect their Stripe account and is detailed in our Terms of Service.
SMS and MMS Communications
MyBoatOS sends SMS and MMS messages for operational updates related to your account, bookings, crew assignments, and charter operations. If you opt in to SMS notifications, you may receive text messages about:
- Booking confirmations and updates
- Pre-charter information and reminders
- Captain and crew assignment notifications
- Maintenance reminders and alerts
- Critical operational and safety notifications
- Account and security alerts
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Message frequency varies based on your notification preferences and account activity.
To opt out: Reply STOP to any SMS message to unsubscribe from all text notifications. Reply START to re-enable SMS notifications. Standard message and data rates may apply.
Reply HELP for help or contact us at support@myboatos.com. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
You can also manage your SMS preferences in your account settings at any time.
Calendar and Email Integration
If you connect your Microsoft 365 or Google Calendar account, we access calendar events and, where authorized, email messages to automatically create booking drafts and synchronize your charter schedule. We access only the data necessary for this purpose and do not store the full content of unrelated emails. Calendar and email access can be revoked at any time from the Integrations settings page.
Data Retention
We retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:
- Account data: Retained until account deletion is requested
- Trip logs and booking records: Retained for tax and regulatory compliance (minimum 7 years)
- Financial records: Retained as required by applicable tax law
- Waiver signatures and charter agreements: Retained for the statute of limitations period applicable to maritime claims
- Voice memos and photos: Retained until deleted by the user or account closure
- Crew credentials: Retained for the duration of the crew member's association with the organization
Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Secure authentication with session management
- Row-level security (RLS) ensuring users can only access data within their organization
- Role-based access controls (Owner, Manager, Captain, Crew) limiting data visibility by function
- Token-gated portal access for guests, brokers, and contractors (no account creation required)
- Regular security reviews and dependency updates
However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete personal data
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Export: Request your data in a portable, machine-readable format
- Opt-out: Unsubscribe from marketing communications and SMS notifications at any time
- Restriction: Request that we limit how we process your data under certain circumstances
To exercise any of these rights, contact us at privacy@myboatos.com. We will respond to verified requests within 30 days.
Children's Privacy
Our Platform is not directed to children under 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@myboatos.com and we will take steps to delete such information.
International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you are located, including the United States. These countries may have different data protection laws. By using the Platform, you consent to the transfer of your information to the United States and other jurisdictions where our service providers operate.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page, updating the “Effective Date” at the top, and, where appropriate, notifying you via email or in-app notification. Your continued use of the Platform after such changes constitutes acceptance of the updated Privacy Policy.
Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your data rights, please contact us at:
Email: privacy@myboatos.com
Website: www.myboatos.com