Skip to main content

Key points — plain language

  • We never sell your personal data to third parties.
  • Your email is used for account notifications only — opt-in for marketing.
  • You can request deletion of your account and data at any time.
  • Payments are processed by Stripe; we do not store card numbers.
  • AI diagnostic data is processed by Google Vertex AI.

Privacy Policy

Last updated: July 2, 2026. This policy explains how Boatable handles your data.

1. Information We Collect

We collect several categories of information depending on how you use the platform.

  • Account information — name, email address, avatar photo, and authentication credentials (managed by Supabase)
  • Profile information — display name, bio, experience level, boating interests, and home location coordinates (latitude and longitude, entered during profile setup)
  • Vessel information — make, model, year, engine type, length, weight, home port coordinates, photos, and descriptions
  • GPS and trip data — full-precision GPS coordinates, waypoints, and route tracks recorded during opt-in trip recording sessions
  • AI diagnostic session data — symptom text you submit, AI-generated responses, diagnostic findings, confidence scores, and model version metadata
  • Vessel telemetry and IoT data — engine temperature, battery voltage, RPM, fuel level, bilge pump status, and GPS fix data received from connected marine instruments
  • Uploaded media and photos — images and files you upload, stored on Amazon Web Services (AWS) S3
  • Community content — condition reports, community posts, comments, and reactions
  • Service marketplace data — service requests, quotes, job records, invoices, and payment transactions
  • Business profile data — business name, category, phone, email, website, service area, and Stripe Connect account information
  • Activity audit logs — data mutations are logged with actor identity and action taken for security and compliance
  • Payment data — transaction amounts and payment status (card numbers handled exclusively by Stripe, never stored by Boatable)
  • Device and browser data — IP address, browser type, user agent, and device characteristics
  • Usage analytics — page views and feature usage events (first-party only, no third-party analytics)

2. GPS and Location Data

Boatable collects GPS coordinates only when you explicitly start a trip recording or submit a condition report with location. Location tracking is not passive — it requires your active opt-in each time.

Your home location coordinates (if provided during profile or vessel setup) are used to show nearby points of interest, service providers, and community content. You can remove your home location at any time in your profile settings.

Full-precision GPS tracks are stored for your personal trip history. When you share a trip publicly, coordinates are downsampled to approximately 111-meter precision (3 decimal places) to protect your exact location.

You can delete your trip data at any time through the My Trips page. GPS data is not sold to third parties.

3. How We Use Your Information

We use your information to: operate and improve the platform, match service requests with providers, generate community intelligence (aggregated condition reports, fuel prices, wait times), power AI diagnostic features, send notifications you have opted into, process payments, and prevent fraud.

We use aggregated, anonymized data for fleet analytics (average fuel burn by vessel type, popular routes) that is never attributable to individual users.

4. Third-Party Service Providers

We share data with the following service providers, each for a specific purpose:

  • Supabase — authentication, session management, and database hosting
  • Stripe — payment processing, Connect onboarding, and payout disbursement
  • Google Cloud Platform (GCP) — application hosting and server infrastructure (us-central1)
  • Google Vertex AI / Gemini — AI diagnostic text processing; symptom descriptions are sent to Google generative AI models
  • Google Maps Platform — geocoding and Places API for location search
  • Amazon Web Services (AWS) S3 — storage of uploaded photos and media (us-east-1)
  • AWS SES — transactional email delivery (us-east-1)
  • CARTO — base map tiles; your browser sends viewport coordinates to CARTO tile servers when viewing maps
  • NOAA — weather and tide data retrieval (no personal data shared)
  • Sentry — error tracking and performance monitoring; receives IP addresses, user agent strings, request identifiers, and DOM recordings during Session Replay sessions (sampled). Used exclusively for debugging.
  • Upstash — rate limiting via Redis (no personal data stored beyond short-lived counters)

5. Vessel Data Ownership

You own your vessel data. Boatable uses vessel information you provide (make, model, year, engine) to power fitment-based service matching and community fleet analytics.

You may export your vessel data at any time through the Profile > Vessels page. You may delete your vessel records, which will remove them from all platform features.

Aggregated vessel statistics (e.g., 'average fuel burn for a 2020 Yamaha 242') are derived from community data and do not identify individual vessels or owners.

6. Analytics and Web Vitals

Boatable uses first-party analytics to measure page views, feature usage, and Core Web Vitals (page load performance). We do not use third-party analytics services like Google Analytics, Facebook Pixel, or similar tracking platforms.

Analytics events are stored in our database and used to improve the platform. They are not shared with advertising networks or data brokers.

7. Cookies and Local Storage

Boatable uses the following cookies and browser storage mechanisms:

  • Authentication cookies (Supabase session) — required for login functionality
  • Referral attribution cookie (boatable_ref) — tracks referral codes, expires after 30 days, requires consent
  • Browser localStorage — used for trip recorder crash recovery, onboarding wizard progress, and UI preferences; data remains on your device
  • No third-party advertising or tracking cookies are used
  • A cookie consent banner is displayed on your first visit to capture your consent preferences

8. Data Retention

We retain different categories of data for different periods:

  • Account and profile data — retained while account is active; deleted within 30 days of account deletion
  • GPS tracks and trip data — retained until you delete them or until account deletion
  • AI diagnostic sessions — retained for 1 year after session date; deleted on account deletion
  • Condition reports and community posts — retained while on platform; deletable by author
  • Audit logs — retained for 3 years; user identity disassociated on account deletion
  • Sentry error data — retained for 90 days per Sentry default policy
  • Payment and transaction records — retained for 7 years per tax and financial regulations
  • Uploaded photos — deleted from AWS S3 within 30 days of account deletion
  • Anonymized aggregated data — may be retained indefinitely as it is not attributable to individuals

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

  • Right to know — request what personal information we collect and how it is used
  • Right to delete — request deletion of your personal information, subject to legal exceptions
  • Right to correct — request correction of inaccurate personal information
  • Right to opt out of sale or sharing — Boatable does not sell personal information or share it for cross-context behavioral advertising
  • Right to limit use of sensitive personal information — GPS location data qualifies as sensitive personal information under CPRA
  • Right to non-discrimination — we will not discriminate against you for exercising privacy rights

Exercising Your California Rights

To exercise these rights, contact us at privacy@boatable.app or through Settings. You may designate an authorized agent to submit requests on your behalf with written authorization.

We will acknowledge your request within 10 business days and respond within 45 calendar days, extendable to 90 days with notice.

Visit our Do Not Sell or Share page for more information.

10. GDPR Rights (European Users)

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR:

  • Right of access (Article 15) — request a copy of your personal data
  • Right to rectification (Article 16) — request correction of inaccurate data
  • Right to erasure (Article 17) — request deletion of your personal data
  • Right to restriction of processing (Article 18) — request restricted processing during disputes
  • Right to data portability (Article 20) — receive your data in a machine-readable format
  • Right to object (Article 21) — object to processing based on legitimate interests
  • Right to withdraw consent (Article 7(3)) — withdraw consent at any time for consent-based processing

Exercising Your GDPR Rights

To exercise these rights, contact privacy@boatable.app. We will respond within 30 days.

Account deletion cascades to remove your profile, vessels, trips, diagnostic sessions, and condition reports. Audit log entries are retained but anonymized. Payment records retained for 7 years.

You may lodge a complaint with your local data protection supervisory authority.

11. Legal Basis for Processing (GDPR)

For users in the EEA, UK, and Switzerland, we process personal data under these legal bases:

  • Contractual necessity — account management, payment processing, service coordination
  • Legitimate interest — analytics, fraud prevention, error tracking, platform improvement
  • Consent — GPS tracking, marketing emails, non-essential cookies, AI diagnostic processing
  • Legal obligation — tax record retention, audit logs, regulatory compliance

12. International Data Transfers

Boatable is operated from the United States. Your data is processed in the following regions: Supabase (us-east-1), Google Cloud Platform (us-central1), and AWS (us-east-1).

For EEA/UK/Swiss users, we rely on Standard Contractual Clauses (SCCs) for data transfers to the United States. Contact privacy@boatable.app for a copy of applicable transfer safeguards.

13. Breach Notification

In the event of a data breach likely to affect your rights, we will notify affected users within 72 hours as required by GDPR Article 33 and comply with applicable state breach notification laws.

If you believe your account has been compromised, contact privacy@boatable.app immediately.

14. Children's Privacy (COPPA)

Boatable is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

16. Contact

For privacy questions or data rights requests, contact us at:

  • Email: privacy@boatable.app
  • Legal entity: Boatable, Inc.
  • Mailing address: 2136 Ford Parkway #5564, Saint Paul, MN 55116

EU Supervisory Authority

EEA residents may lodge complaints with their local data protection authority. A list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

Privacy Policy — Boatable