1. Controller and contact
The data controller is YAS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Szlak 77/222, 31-153 Kraków, Poland; KRS 0001166122, NIP/VAT PL6793327784, REGON 541401303. Privacy requests: [email protected]. Telephone: +48 571 938 389.
2. Data we collect
We collect account identity and contact data; destination inquiries, preferred dates, group size, phone number, sailing qualifications and preferences you choose to submit; the legal passenger details required for a booking; email-verification and session data; organiser, owner and payout-verification data; trip requests, charter dates, cabin assignments, payments and refunds; crew-chat messages, reports and moderation records; support messages; and security logs.
Organisers and boat owners may submit identity, business-registration and yacht-ownership evidence. CabinJoin encrypts those files before storing them and makes them available only to the protected owner console for verification, fraud prevention and dispute handling.
Payment card details are collected by Stripe, not stored in CabinJoin’s database. Google provides verified profile details only when you choose Google sign-in.
3. Why and on what basis
We process data to create and secure your account, assess and route destination inquiries to relevant independent providers, perform requested marketplace and booking services, route payments, provide crew communication, prevent fraud, handle disputes, comply with tax and legal duties, and improve service reliability.
The legal bases are performance of a contract or steps requested before a contract, legal obligations, legitimate interests in platform security and dispute prevention, and consent where the interface specifically asks for it. You can withdraw consent without affecting earlier lawful processing.
4. Who receives data
Approved participants see only limited crew information. After a deposit or booking is confirmed, the responsible organiser or boat operator receives the passenger phone and emergency contact needed for safe trip operations; other travellers never receive those protected details. Suppliers receive only the information required to assess and fulfil a request. Stripe processes payments and connected payouts; Google processes OAuth when selected; Microsoft Clarity processes optional usage and interaction analytics after consent. Hosting, email and professional advisers receive only what is necessary under appropriate duties.
We do not sell personal data. Crew messages are not sent to Airep24.
5. International transfers
Some providers may process data outside the EEA. Where required, we rely on an adequacy decision, approved contractual safeguards or another lawful transfer mechanism and make further information available on request.
6. Retention
Verification links expire after 24 hours; authentication rate-limit events are removed after 48 hours; normal sessions expire after 30 days. Account and operational booking data is kept while the account or booking is active and then only for the period needed for claims, safety and legal duties. Financial and tax records are kept for the statutory accounting period. Chat and moderation evidence may be retained for up to three years after the trip or longer while a dispute is active.
Destination inquiries are retained while they are being assessed or matched and then only for the period needed for consent records, claims, fraud prevention and legal duties. Verification evidence is retained only while needed to establish or defend the verified marketplace relationship, meet legal duties, prevent fraud or resolve a dispute. Rejected or superseded evidence is scheduled for deletion when those purposes no longer require it.
Deletion requests are applied to data that is no longer legally or operationally required; required records are restricted rather than used for new purposes.
7. Your rights
Depending on the basis and circumstances, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent and complain to the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych (UODO), or the authority in your EU country.
A signed-in user can download a machine-readable copy and submit a protected request from the CabinJoin account; requests may also be sent to [email protected]. We may verify identity before releasing or changing data.
8. Matching and automated decisions
CabinJoin may compare declared travel preferences to explain practical overlap with a trip. It is not a compatibility score and does not make a solely automated decision with legal or similarly significant effect. Organisers make participation decisions under their disclosed rules.
9. Cookies and security
CabinJoin uses essential cookies for the signed-in session and language choice. Optional CabinJoin and Microsoft Clarity analytics load only after consent, with advertising storage denied. We use hashed session tokens, access controls, rate limits, audit records and encrypted HTTPS transport, but no internet service can promise absolute security.
10. Changes
Material changes will be dated and, when they affect an existing account or booking, communicated through the account or email. A new consent is requested when required by law or when the purpose materially changes.
