Skip to content
Sailcorner, home
Search yachts

Privacy policy

We collect as little as we can, and only to run the service you are using.

Last updated

What we collect

  • Booking request details: your name, email address, phone number if you give it, travel dates, number of guests and your message. We need these to pass your request to the operator.
  • Preferences: your chosen display currency and language, stored in small cookies so pages load in the right format.
  • Favourites: if you are not signed in, the yachts and stops you save stay in your browser's local storage on this device and are not sent to us. When you sign in, they are added to your account, stored on our server so they appear on every device where you sign in, and removed from this device's storage.
  • Account (optional): you can use Sailcorner without an account. If you create one, we store your email address, how you sign in (email code and, if you use Google, your Google account ID and the email address Google reports), a name only if you give one or Google provides it, and your signed-in sessions: a short device label such as "Chrome on Android" and when each was last active. We do not store your browser's full user-agent string.
    • Saved trips: which trips you saved to your account, when you saved them, when you last opened each one from the account, and which of the trip's devices saved it. When you open a trip from your account, we record which signed-in session opened it on which device, so signing out of the account can sign that device out of the trip too. Deleting your account removes these links; the trips themselves stay.
  • Sign-in codes: when you ask for an email code, we store only a hash of the code, never the code itself. Codes expire after 10 minutes and work once. The IP address the request came from is stored only as a hash, to investigate abuse.
  • Sign-in events: a security log of sign-ins, sign-outs and account changes (such as connecting Google or deleting the account). These records hold a random account identifier and the sign-in method, with no email address and no IP address.
  • Basic technical logs: IP address, browser type and pages requested, kept briefly to keep the site secure and working.

How we use it

We use booking request details to send your request to the operator of the yacht you chose and to follow up on it. Account data is used only to sign you in, keep your favourites, and list your booking requests, shared lists and saved trips in one place. We do not sell personal data, and we do not use it for third-party advertising.

Who we share it with

Only the charter operator you send a request to, and service providers who host the site or send email on our behalf under contract (sign-in codes are sent through our email provider, Resend). If you sign in with Google, Google confirms who you are; we keep only your Google account ID, its email address and your name from Google. Operators handle your data under their own privacy policy once they receive your request.

Chat support

When you use the chat, we store your messages, the page you started the chat on (without anything after the "?" in its address) and — only if you give them — your name and email address. Your email address is stored encrypted and is shown only to the Sailcorner support team when they need to reply. Messages are read and answered by people on the Sailcorner team: not by the charter operator, and not by an AI. When team alerts are switched on, the team is told about new messages by email (through our email provider, Resend) or Telegram, with a short excerpt of the message — never your email address.

A cookie named chat holds a random identifier that connects this browser to your conversation; it is not used for tracking. We delete a conversation 90 days after it ends, or after 90 days without any new message.

Handover photo records

On a trip you can photograph the yacht at check-in and check-out. Before a photo is stored we re-save it without hidden data such as location and camera details; the original file isn't kept, only its fingerprint (hash). We store the time our server received each photo, the time your phone recorded (marked as unverified) and the notes you write — notes stay with the record for as long as the record is kept, so describe the yacht, not people. Everyone with access to the trip can see the record. Sailcorner never sends it to the charter operator; you share it yourself if you want to.

We delete handover photos 120 days after the trip ends — later if a damage case for this trip is still open (until 30 days after it's resolved, at most a year after the trip). Download or print anything you want to keep. The trip owner can delete photos from a record that isn't sealed at any time, and a sealed record once the trip is over and no damage case is open. Travellers can remove their own photos only until the record is sealed.

Cookies

Sailcorner uses only functional cookies: currency, locale and promo_dismissed. They remember choices you made and are not used for tracking. If you use the chat, a chat cookie connects your browser to your conversation (see above). We do not use advertising cookies.

If you plan a trip or open one from a link, a __Host-saltline_trip cookie gives this browser access to it. It holds random secrets for up to 6 trips (we store only their hashes) and is removed when you sign out of a trip on this device.

On a trip's departure day pass you can choose to keep an offline copy on your device. It is saved in your browser's storage on that device only (with a small service worker that shows it when you have no signal) and is never sent anywhere. It is deleted when you sign out of the trip or of the account you opened the trip from, when you remove it, or when it expires; your browser may also delete it sooner.

If you sign in, these functional cookies are used as well. None of them is used for tracking:

  • __Host-customer_session: keeps you signed in. It holds a random secret (we store only its hash) and lasts as long as your session.
  • __Host-saltline_account: says only that this browser is signed in, so pages can show your account menu. It holds no personal data.
  • __Host-customer_signin: ties an email code to the browser that asked for it, for up to 15 minutes.
  • __Host-customer_oauth: protects a Google sign-in while it is in progress, for up to 10 minutes.
  • __Host-saltline_pass_clear: set only when signing out (or deleting the account, or signing in as someone else) also signed trips out on this browser. It lists those trips' public identifiers so their offline pass copies are removed from this device, and is deleted once that is done (at the latest after 24 hours).

How long we keep it

Booking request details are kept for as long as needed to handle the request and meet legal obligations, and then deleted. Technical logs are kept for up to 30 days.

Sign-in codes are deleted within about a day after they expire. A signed-in session ends after 30 days without use, and at the latest 180 days after you signed in, or straight away when you sign out; its record is deleted at the latest with your account. Your account and its favourites are kept until you delete the account. Sign-in events are kept as a security log; they hold no email address or IP address, and we will set a fixed deletion period for them before launch.

Deleting your account

You can delete your account yourself at any time on the security page of your account (for your protection you may be asked to sign in again first). This deletes your account, all of its sessions, its sign-in methods (including the Google connection), its saved favourites, the list of trips saved to it (the links between your account and those trips) and any pending sign-in codes, and signs out trips that were opened on a device from your account.

We keep: booking requests you sent (the operator and our team need them to handle the request; they follow the retention above); shared shortlist links you created (recipients use them too; they are no longer connected to any account); trips and their own access links (they never belonged to the account); and the sign-in events, which hold only a random identifier. If you sign in again later with the same email address, you start with a new, empty account.

Your rights

You can ask to see, correct, export or delete your personal data, or object to how we use it, by writing to hello@sailcorner.com. You can also complain to your local data protection authority.

Pre-launch notice. Sailcorner is in development. This policy describes how the service will handle data and will be reviewed before launch.