Privacy policy

DeckVakt is built so that the passage, the crew list, the rota, the deck log and the rest-hours records live on the device that holds them. We do not operate a DeckVakt cloud account for that data, and we do not receive a server copy of it. This policy explains the few things that do leave a device, who is responsible for what, and how EU data protection law applies to us as an Estonian-operated service.

Last updated 21 September 2026 · Estonian-operated service under EU GDPR · Applies to deckvakt.com, the optional desk chart table at deckvakt.com/app, and the DeckVakt iPhone and Android apps when they ship.
In one line
No DeckVakt account for your boat. Passage and crew data stay on your devices. We only receive what you choose to send us (for example a waitlist email) or what is needed to run this website and fix faults.
On this page
Who we are What this policy covers Who is the controller What stays on your device What we process Lawful bases Sharing between devices Exports, backups and loss Device permissions and location Website analytics Error reports Payments and support Processors and transfers Retention Security Your rights Rest-hours and flag-state records Children Changes Contact and complaints

Who we are

DeckVakt is the trading name of the operator of the DeckVakt website and apps, established and operated from Estonia (European Union). Privacy requests and complaints: everything@deckvakt.com. A person reads that inbox. English is the language of this policy; Estonian may be used for official correspondence with Estonian authorities where required.

We process personal data under the EU General Data Protection Regulation (GDPR) and applicable Estonian law, including the Personal Data Protection Act. Our lead supervisory authority in Estonia is the Data Protection Inspectorate (Andmekaitse Inspektsioon).

What this policy covers

It covers:

It does not cover third-party sites you leave us for (for example the App Store, Google Play, Apple Maps geocoding, or your own cloud drive when you export a file). Those services have their own policies.

Features may change as DeckVakt develops. If we ever introduce DeckVakt-operated cloud storage of passage or crew data, we will say so clearly in this policy before that happens — not quietly.

Who is the controller

For data we receive — for example a waitlist email, website analytics, error reports from this site or the desk app, and the fact that an optional contribution completed — DeckVakt is the controller.

For the passage file on a device — including crew names, roles, experience, berth, lifejacket and tether notes, seasickness notes, sleep and rest patterns derived from the rota, the deck log, standing orders, positions and waypoints you enter — the skipper or organisation that creates and holds that passage is the controller. DeckVakt supplies software that stores that information on the device. We do not receive a copy of it in the ordinary running of the product, so we are not the controller of that on-device file.

If you put other people’s personal data into a passage, you are responsible for having a lawful basis to do so and for telling them what you record. A briefing card or standing orders sheet is a practical place to do that.

What stays on your device

There is no DeckVakt user account for passages. The following typically stays only on the phone, tablet or browser that holds it:

How it is stored:

Some of that information is personal data under the GDPR. Notes such as seasickness can be health-related special-category data in the hands of the skipper. Because it stays under the skipper’s control on-device, DeckVakt does not process that category of data on our servers.

What we process

Aside from on-device passage data (which we do not receive), we may process:

Lawful bases

Where the GDPR applies to processing we carry out as controller:

You may withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

Sharing between devices

DeckVakt is designed for handoff without uploading to us:

Crew who join do not need a DeckVakt account. They pick their name on their own device after receiving the passage.

Exports, backups and loss

Because we do not hold a server copy, we cannot restore a passage for you. Export after every trip. Save the file somewhere you control (cloud drive, computer, memory device). Deleting the app, clearing browser storage, losing a device, or overwriting a file without a backup can permanently destroy the only copy.

PDF exports (deck log, rest-hours record, briefing cards) and calendar exports are created on the device and shared only if you choose a share target. Once you send a file to email, AirDrop, a cloud provider or another app, that destination’s rules apply.

Device permissions and location

Depending on platform and feature, the apps may ask for:

You can refuse or later revoke permissions in the system settings. Features that need them will then be limited or unavailable.

Website analytics

The marketing and guide pages on this website use Umami Cloud to produce aggregate statistics: page views, referring sites, approximate country, browser and device type, and selected events such as waitlist joins and clicks toward product or store pages. Umami is configured not to set cookies for that purpose and not to build advertising profiles or track you across unrelated websites.

Your browser loads the analytics script from cloud.umami.is. We do not send crew names, passage contents, log entries or waitlist email addresses into Umami. Form contents are not attached to analytics events.

The desk chart table and the mobile apps do not use Umami.

If your browser sends a Global Privacy Control or Do Not Track signal, this website does not load Umami or error reporting.

Error reports

When something breaks on this website or in the desk chart table, a technical report may be sent to Sentry, which processes it for us on servers in the European Union. A report may include the fault, stack location, release version, and browser or environment details needed to fix it.

We configure Sentry with personally identifying defaults off. Before send, reports are filtered: user objects and free-form extras are stripped; URLs are cut at the query string so share codes cannot travel; and, in the desk app, values the app knows are yours (crew names, boat, ports, codes) are redacted if they appear. Click, typing and console breadcrumbs are not kept for that purpose.

Desk opt-out. In the chart table, Settings → Error reports. Turning reports off takes effect immediately for that browser.

Marketing site. There is no separate Settings toggle yet; Global Privacy Control and Do Not Track stop collection, as does our internal “do not collect” flag for our own testing.

Mobile apps do not currently send Sentry (or equivalent) crash reports to us. If that changes, this policy will be updated first.

Payments and support

DeckVakt’s core features are free. Optional one-time contributions may be offered:

A contribution unlocks no feature, entitlement or content. It is not a subscription. Apple, Google or the card processor is the merchant of record for the payment and holds card details. We may learn that a contribution completed so the product can stop prompts; we do not store full payment card data.

Refunds follow the rules of the store or processor that took the payment.

Processors and international transfers

We use service providers who process data on our instructions or as independent controllers for their payment products:

Where personal data is transferred outside the European Economic Area, we rely on an appropriate GDPR safeguard (for example an adequacy decision, the European Commission’s Standard Contractual Clauses, or the provider’s certified transfer tools). Sentry error processing for DeckVakt is configured to the EU. Ask us if you need a current list of sub-processors for a formal request.

If you are in the United Kingdom, the UK GDPR may also apply to our offering of the service to you. In that case you may complain to the UK Information Commissioner’s Office as well as to the Estonian Data Protection Inspectorate; we still treat Estonia as our establishment and lead authority for EU GDPR.

Retention

Security

We design so that the most sensitive operational data never reaches us. On-device storage uses each platform’s private app storage or browser storage. Exports and local sharing are under your control — protect them as you would paper crew lists and logs.

No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach affecting data we control, we will assess it and notify the Estonian Data Protection Inspectorate and affected individuals where the GDPR requires.

Your rights

Under the GDPR, you may have the right to access, rectify, erase, restrict or object to processing, and to data portability, and not to be subject to certain automated decisions. Those rights apply to personal data we hold.

For data only on your device, you can access, correct or delete it yourself in the app or by clearing storage — you do not need to ask us. For a waitlist email or other correspondence we hold, email everything@deckvakt.com. We may need to verify the request. We aim to respond within one month, as the GDPR requires.

You also have the right to lodge a complaint with a supervisory authority. For us that is primarily the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). If you live elsewhere in the EEA you may also contact your local authority; if you are in the UK you may contact the ICO.

Rest-hours and flag-state records

DeckVakt can generate MLC-style hours-of-rest summaries and exports from the rota you run. If you keep such records for compliance, you (or your company) are the keeper of those records. Retention and form are set by your flag state and employment arrangements, not by this policy. We do not file them with any authority on your behalf.

Children

DeckVakt is aimed at skippers and adults standing watches. It is not directed at children. We do not knowingly collect personal data from children via our website forms. If a child is listed as crew in a passage file, that is information the skipper holds on their device; the same controller responsibilities apply as for any other crew member. If you believe a child has sent us personal data directly, contact us and we will delete what we hold.

Changes

We will update this page when our practices change. The “Last updated” date at the top will change. Material changes — especially any move to DeckVakt-operated storage of passage or crew data — will be described prominently here.

Contact and complaints

Privacy questions, data-subject requests and complaints: everything@deckvakt.com.

Related: Terms of use.

This is the official privacy policy of DeckVakt. If anything here conflicts with mandatory consumer or data-protection law that applies to you, that law prevails.