An emergency app has to hold a few sensitive things: where you are, who is aboard, who to call. This page says exactly which ones, why, how long, and who else ever sees them. No legalese where plain words work.
Every item below exists because the app cannot do its job without it. The legal basis under the GDPR is named for each one.
Email address, and a name if you enter one. Used to give you an account, restore your data on a new phone and send service messages.
Craft name and type, MMSI or registration number, length, colour, number of people aboard. These are the details a rescue centre asks for first — the app has them ready so you do not have to remember them.
Read from the phone’s GPS and shown on screen. It is transmitted only when you send an SMS alert, place a call from the app, or turn Tracking on for a trip. We do not build a movement history from it, and there is no silent background collection.
The name and phone number of anyone you add so the app can alert them. Because these are someone else’s details, please tell them you have added them — you are the one they will hear from.
When an alert is sent we keep what was sent, to whom and at what time. This is the record that shows what happened if an incident is later reviewed.
Device model, OS version and error traces when something breaks. In a safety app a silent crash is a real risk, so we need to see them.
Subscriptions are sold through the Apple App Store and Google Play. They handle the payment and we never see your card number. We receive only the fact that a subscription is active and when it renews. Their own privacy terms apply to the transaction.
Invoices and accounting records are kept for 7 years, as Estonian law requires.
Two groups, and no others: the rescue services you choose to alert, and the service providers that run our infrastructure under a data processing agreement.
Where a provider processes data outside the European Economic Area, the transfer runs on the European Commission’s Standard Contractual Clauses. The named, current list of providers is available from privacy@vesselsos.com on request.
Write to privacy@vesselsos.com and we answer within one month. Account deletion is also available inside the app, under Account.
If you think we have handled your data badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority in your own country.
We do not sell or share personal information as those terms are used in California law, and we do not use it for cross-context behavioural advertising. Residents of California and other US states with privacy laws have the right to know, delete, correct and opt out; the same address, privacy@vesselsos.com, handles those requests, and we will not treat you differently for making one.
The app is for people aged 16 and over in the European Union and 13 and over elsewhere, and we do not knowingly create accounts below that. A younger person can of course be aboard and be counted among the people on the vessel — that is a number, not a profile. If you believe a child has an account, write to us and we will remove it.
This site sets no advertising or tracking cookies, which is why you were not asked to click a consent banner. Visit counts come from aggregated, cookie-free statistics that cannot identify you. If that ever changes, a consent banner appears before anything is set, and this section is rewritten first.
Data travels encrypted in transit and is stored encrypted at rest. Access inside the company is limited to the people who need it. If a breach ever affects your data, we notify the authority within 72 hours and tell you directly when the law requires it.
When this notice changes in a way that matters, we email account holders before the change takes effect. The date at the top always shows the current version.