Privacy Policy

Your Data is Safe with Us — We need your info for the Port Police, not for spies.

Last updated: December 2024

Sailing Virgins (“we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, book a course, or participate in our sailing programs.

We operate internationally, including in the European Union (Croatia, Greece) and other jurisdictions with strict data protection laws. This policy complies with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

1. Information We Collect

1.1 Information You Provide

Account & Booking Information

Name, email address, phone number, mailing address, date of birth, nationality, and payment information when you create an account or book a course.

Passport & Travel Documents (Required by Maritime Law)

Passport number, issue/expiry dates, and country of issue. This is required by international maritime law for crew manifests and port authority clearance. We cannot allow you to sail without this information.

Health & Dietary Information (Special Category Data)

Medical conditions, allergies, dietary restrictions, and medications. Under GDPR, this is “Special Category Data” requiring explicit consent. We collect this solely to ensure your safety at sea and to provision appropriate food.

Emergency Contact Information

Name, relationship, and contact details of your emergency contact person, used only in case of emergency at sea.

1.2 Information Collected Automatically

When you visit our website, we automatically collect certain information including:

  • Device information (browser type, operating system)
  • IP address and approximate location
  • Pages visited and time spent on site
  • Referring website
  • Cookies and similar tracking technologies (see Section 6)

2. How We Use Your Information

We use your personal data for the following purposes:

Course Delivery

Processing bookings, managing your course participation, and communicating course-related information.

Legal Compliance

Submitting crew manifests to port authorities, complying with maritime regulations, and maintaining required records.

Safety Management

Ensuring your safety at sea, responding to emergencies, and accommodating medical/dietary needs.

Payment Processing

Processing payments via Stripe, managing refunds, and maintaining financial records.

Marketing (With Consent)

Sending newsletters, course updates, and promotional materials. You can opt out at any time.

Service Improvement

Analyzing how you use our services to improve our courses, website, and user experience.

3. Who We Share Your Data With

We share your personal data only when necessary and with appropriate safeguards:

Charter Fleet Operators

Your passport and emergency contact details are shared with the charter company providing the vessel, as required for their insurance and legal obligations.

Government & Port Authorities

Crew manifest information (name, nationality, passport details) is submitted to port authorities as required by maritime law in all jurisdictions where we operate.

Payment Processors

Payment information is processed by Stripe. We do not store full credit card numbers on our servers. See Stripe's Privacy Policy.

Instructors

Your name, health information, and dietary requirements are shared with your assigned instructor to ensure your safety and comfort.

ASA/RYA Certification Bodies

Your name and course results are shared with the American Sailing Association or Royal Yachting Association to issue your certifications.

We do NOT sell your personal data to third parties for marketing purposes. We do not share your data with advertisers or data brokers.

4. Your Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights under GDPR:

Right to Access

Request a copy of all personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your data (subject to legal retention requirements).

Right to Restrict Processing

Request limitation of how we use your data.

Right to Data Portability

Receive your data in a machine-readable format.

Right to Object

Object to processing for marketing or other purposes.

To exercise any of these rights, please email us at privacy@sailingvirgins.com. We will respond within 30 days.

5. Data Retention

We retain your personal data for different periods depending on the type:

Data TypeRetention Period
Booking & financial records7 years (tax/legal requirements)
Certification recordsIndefinitely (required by ASA/RYA)
Health & medical informationDeleted 90 days after course completion
Marketing preferencesUntil you unsubscribe
Website analytics26 months

6. Cookies & Tracking

We use cookies and similar technologies for:

Essential Cookies: Required for the website to function (login, booking process).
Analytics Cookies: Google Analytics to understand how visitors use our site.
Marketing Cookies: Meta (Facebook) Pixel and Google Ads for retargeting (only with consent).

You can manage cookie preferences through your browser settings or our cookie consent banner. Note that disabling essential cookies may affect website functionality.

7. Photography & Media Rights

We love sharing the adventure! By participating in a Sailing Virgins course, you grant us the right to use photographs and video footage taken during the trip for marketing and promotional purposes, including:

  • Our website and social media channels
  • Marketing emails and brochures
  • Advertising campaigns
  • Press and media coverage

Opt-Out Available

If you prefer not to appear in marketing materials (for professional or personal reasons), please notify us in writing at privacy@sailingvirgins.com before your course begins. We will make reasonable efforts to exclude you from photos and videos.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit (SSL/TLS) and at rest
  • Secure cloud infrastructure (Supabase, Vercel)
  • Limited access to personal data on a need-to-know basis
  • Regular security assessments and updates
  • Employee training on data protection

While we take security seriously, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.

Contact Us About Privacy

For any questions, concerns, or requests regarding this Privacy Policy or your personal data:

Email: privacy@sailingvirgins.com

Data Protection Officer: James Kell

Mailing Address: Sailing Virgins LLC, 8 The Green, Dover, Delaware 19901, USA

For EU residents: You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.