App Privacy Policy (Boat Data)
Last updated: 2026-08-24
1. Controller
Fabian Fisahn
Dietrich-Bonhoeffer-Str. 28
10407 Berlin
Germany
Email: info@boatdata.app
2. Scope
This policy applies to the Boat Data mobile/desktop app itself (Ionic/Capacitor builds), including data processed in-app, in local device storage, through connected marine data sources, and by third-party service providers used by app features.
3. Data Categories Processed By The App
- Connection data: configured server URL, port, protocol, and connection preferences.
- Authentication data: Signal K login/token information as configured by the user.
- Vessel and navigation data: incoming NMEA/Signal K values, AIS targets, route and tide data.
- Device context: platform/device identifiers used for technical functionality.
- Notification data: local and server-side alert states, including MOB alert handling.
- Subscription status: premium entitlement and transaction validation metadata.
- Support/debug data shown in-app for troubleshooting when enabled by the user.
4. Purposes And Legal Bases (GDPR)
| Purpose | Example Data | Legal Basis |
|---|---|---|
| Provide app functionality | Live marine data streams, route and instrument settings | Article 6(1)(b) GDPR (service provision) |
| Secure operation and resilience | Connection state, token/session handling, technical logs | Article 6(1)(f) GDPR (legitimate interest) |
| Persist user preferences locally | Layout, view preferences, app settings, alarm settings | Article 6(1)(b) and 6(1)(f) GDPR |
| Handle premium subscriptions | Store product status, verified entitlement state | Article 6(1)(b) GDPR |
| Optional notifications and permissions | Notification permissions, location when requested | Article 6(1)(a) and/or 6(1)(b) GDPR |
5. Storage, Security, And Local Processing
The app stores significant parts of operational data locally on the device (for example settings, views, local caches, and history) using Ionic Storage and localStorage.
Sensitive Signal K credentials/tokens configured in app settings are encrypted before persistence, where the platform Web Crypto API is available.
If cryptographic platform APIs are unavailable in specific environments, certain values may be stored with reduced protection. In such cases, device-level security controls become especially important.
6. Permissions And Device Features
- Location: used for own-ship position fallback and selected map/navigation features.
- Local notifications: used for alarm/alert display on-device.
- Network access: required to connect to Signal K/NMEA sources and fetch map content.
- File/share access: used for backup export and restore features when initiated by the user.
- Motion sensors: may be used by dedicated navigation/chart features when enabled.
7. Third-Party Services Used By App Features
| Service | Why It Is Used | Typical Data Involved |
|---|---|---|
| Mapbox | Map rendering, styles, map tiles | Technical request metadata (such as IP/device/network metadata) and map requests |
| Apache ECharts / ngx-echarts | In-app chart and gauge rendering | Processed locally in-app; chart rendering itself does not require direct ECharts cloud services |
| Apple App Store / Google Play Billing | Subscription purchase and restore | Store transaction and entitlement metadata handled by platform providers |
| Iaptic validator | Receipt/subscription validation | Purchase validation data required to verify active subscription status |
Third-party providers act under their own privacy terms for provider-side processing. Please review provider documentation for complete details.
8. Subscription And Premium Information
Premium access is purchased and managed through Apple App Store or Google Play, depending on platform. Boat Data does not directly process payment card details.
- Subscriptions may auto-renew unless canceled in your Apple or Google account settings before the current period ends.
- Billing, cancellations, refunds, taxes, and receipt handling are managed by the respective app store.
- The app receives product, offer, transaction, and entitlement state needed to unlock premium access.
- Receipt/subscription validation may use a validation provider such as Iaptic for status accuracy.
- If you restore purchases, the app asks the relevant store to re-check your existing entitlements.
Availability, pricing, and feature access can vary by region, platform, and store policy.
9. Data Transfers Outside The EEA
Where third-party services process data outside the EEA, transfers should rely on lawful safeguards, such as adequacy decisions or Standard Contractual Clauses, as applicable.
10. Data Retention
- On-device settings and caches remain until deleted by user actions, resets, or uninstall.
- Authentication/session data is retained only as needed for connectivity and renewal logic.
- Subscription validation data is retained as needed to confirm premium access state.
- Backups exported by the user are stored where the user saves/shares them.
11. Your GDPR Rights
- Access (Article 15 GDPR)
- Rectification (Article 16 GDPR)
- Erasure (Article 17 GDPR)
- Restriction (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objection (Article 21 GDPR)
- Withdrawal of consent (Article 7(3) GDPR)
- Complaint to a supervisory authority
12. Children
The app is not specifically intended for children where parental consent would be required by law.
13. Changes To This Policy
This policy may be updated when app features, legal requirements, or integrated providers change. The latest version should be published with the app's legal documents.
Note: This text is a detailed practical template. For complete legal certainty, especially around subscription handling and international data transfers, obtain professional legal advice.