Privacy Policy
Last updated: May 19, 2026
Boat Partner ("we," "us," or "our") is a boat partnership management app for yacht owners in Newport Beach, California. This privacy policy explains what information we collect, how we use it, and your choices regarding your data.
We are a small, independently operated service. We do not sell your data. We collect only what is needed to make the app work for you and your boat partners.
1. Information We Collect
Account Information
When you create an account, we collect your name and email address. These are used for login, identification within your boat partnership, and to send you important notifications about your boat.
Photos and Videos
You can upload photos and videos to your boat's shared gallery. These files are stored in our database and are visible to other partners on the same boat. You choose what to upload — we do not access your camera roll without your permission.
Location Data (Optional)
If you grant permission, photos may include location metadata (GPS coordinates) for tagging where they were taken. Location access is optional and can be disabled in your device settings at any time.
Cruise Logs and Reports
When you submit cruise logs or boat reports, the information you provide (dates, engine hours, notes, issues) is stored to maintain a shared record for your partnership.
Banking Information (Optional)
If you choose to link a bank account, we collect bank account names, account types, balances, and transaction history through Plaid. We do not collect or store your bank login credentials. See Section 5 for full details.
Forum Posts and Messages
Messages and forum posts you create through the app are stored so they can be delivered and displayed to your boat partners.
Usage Data
We collect basic usage analytics to understand how the app is used and to improve it. This may include screen views, feature usage, and crash reports. We may also collect data related to ad impressions if ads are displayed in the app.
2. Subscription and Payment Information
When you subscribe to Boat Partner through an in-app purchase, payment is processed entirely by Apple through the App Store. We do not collect, store, or have access to your credit card number, billing address, or other payment method details.
We do store subscription-related information necessary to operate the service, including:
- Your subscription status (active, expired, or none)
- The subscription plan you selected
- Apple transaction identifiers for purchase verification
- Subscription start and renewal dates
This information is used solely to grant you access to premium features and to verify your subscription status.
3. How We Use Your Information
- Authenticate your account and manage login sessions
- Display your name and information to your boat partners
- Store and serve photos, videos, and messages within your partnership
- Send notifications about calendar assignments, cruise logs, and reports
- Improve the app based on usage patterns
- Display relevant advertisements, if applicable
- If you choose to link a bank account, import and display transactions for the financial management of your yacht-partnership LLC
4. Third-Party Services
We use a small number of trusted third-party services to operate the app:
- Supabase — Database hosting and authentication. Data is stored on servers in the United States. See Supabase Privacy Policy.
- Apple — The mobile app is distributed through Apple TestFlight and the App Store. Apple may collect its own analytics. See Apple Privacy Policy.
- Plaid — Bank account linking and transaction data, for users who choose to connect a bank account. See Plaid Privacy Policy. Full details in Section 5 below.
- Microsoft Azure — Website hosting. See Microsoft Privacy Statement.
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
5. Banking Connections (Plaid)
Some Boat Partner accounts — primarily boat managers running yacht-partnership LLCs — choose to link a business bank account so the app can automatically import transactions for partnership bookkeeping. This is an optional feature. If you do not link a bank account, none of this section applies to you.
What Plaid is
We use Plaid Inc. ("Plaid") to securely connect your bank account to Boat Partner. Plaid is a financial-services company that specializes in linking bank accounts to third-party apps. When you choose to connect a bank account, Plaid (not Boat Partner) handles the login to your bank, and Plaid returns account and transaction information to us so we can display and categorize it inside Boat Partner.
Plaid is a separate company with its own privacy practices. Plaid's own privacy policy applies to your use of Plaid in addition to ours. You can read it here: https://plaid.com/legal/#end-user-privacy-policy.
What Plaid product we use
We use the Plaid Transactions product. This gives us:
- The names and types of the bank accounts you connect (for example, "Bank of America Business Checking — ...4321")
- The current balance of those accounts
- The history of transactions on those accounts (date, amount, description, merchant, category)
We do not use Plaid to move money, initiate payments, verify your identity for KYC, or pull credit reports.
Why we use it
The purpose is internal financial management of the yacht-partnership LLCs that operate boats on Boat Partner. Importing transactions lets boat managers see income and expenses, allocate costs to partners, and produce statements without retyping data from a bank website.
How banking data flows
- You choose to connect a bank account in the app.
- Plaid opens its own secure login screen. You enter your bank credentials directly into Plaid — Boat Partner never sees, stores, or has access to your bank username or password.
- After you authorize the link, Plaid gives Boat Partner an "access token." We store this token in our database in encrypted form (AES-256-GCM).
- Boat Partner uses the access token to ask Plaid for account information and transactions. Plaid returns the data, and we store it alongside the other records in your boat's partnership.
- Banking data is visible only to people on that boat's partnership who have permission to see financial records (typically the boat manager and designated partners). It is never shared with other boats, sold, or used for advertising.
Retention of banking data
Financial transaction records are kept for at least seven (7) years after the transaction date. This is a US recordkeeping practice for business tax records and is longer than the retention period we apply to other personal data.
The Plaid access token itself is treated differently: it is encrypted at rest and is destroyed immediately when you disconnect a bank account inside Boat Partner, when your account is deleted, or when an LLC ends its use of Boat Partner. Once the access token is destroyed, Boat Partner can no longer reach your bank through Plaid and no further data is imported.
Your choices and your rights
- Disconnect at any time. You can remove a linked bank account from inside Boat Partner. This destroys the Plaid access token and stops all future syncs. Past transactions that were already imported remain in our records for the retention period above, because they are part of the LLC's financial history.
- Delete your Boat Partner account. When you request account deletion (see Section 8, "Your Rights"), the Plaid access token associated with your account is destroyed and future syncs stop. Historical financial records belonging to a partnership LLC may be retained by that LLC for tax and recordkeeping purposes.
- Ask Plaid directly. Plaid offers its own end-user portal at https://my.plaid.com where you can see and manage every app you have connected to Plaid, including Boat Partner, and revoke access there as well.
Security
The Plaid access token is encrypted at rest using AES-256-GCM with a key that is never stored in our codebase. The connection between Boat Partner and Plaid uses TLS. Banking data inside our database is protected by the same row-level security and authentication that protects all other partnership data.
6. Data Storage and Security
Your data is stored in secure, hosted databases in the United States. We use industry-standard security practices including encrypted connections (TLS), row-level security policies on our database, and secure authentication. However, no system is 100% secure, and we cannot guarantee absolute security.
7. Data Retention
We retain your account data and content for as long as your account is active. If you leave a boat partnership or request account deletion, we will delete your personal data within 30 days. Photos and messages shared with a partnership may be retained for the benefit of remaining partners unless you specifically request their removal. Financial transaction records imported via Plaid are an exception: they are retained for at least seven (7) years from the transaction date as part of the LLC's business recordkeeping, even if you disconnect the bank or delete your account. The Plaid access token used to fetch this data is destroyed when you disconnect the bank or delete your account.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and personal data
- Withdraw consent for optional data collection (such as location)
- Export your data in a portable format
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
If you have linked a bank account through Plaid, you can disconnect it at any time inside Boat Partner. You can also manage your Plaid connections directly at my.plaid.com. Disconnecting destroys the encrypted access token and stops all future data imports.
9. Children's Privacy
Boat Partner is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Cookies
The Boat Partner mobile app does not use cookies. The website uses minimal cookies necessary for authentication and session management. We use Google Analytics to understand website traffic, which may set its own cookies. You can control cookie behavior through your browser settings.
11. California Privacy Rights (CCPA)
If you are a California resident, you have the right under the California Consumer Privacy Act (CCPA) to:
- Know what personal data we collect and how it is used
- Request deletion of your personal data
- Request a portable copy of your personal data
- Not be discriminated against for exercising your privacy rights
To make a request, contact us at support@boatpartner.co. We will verify your identity and respond within 45 days.
12. Changes to This Policy
We may update this privacy policy from time to time. If we make significant changes, we will notify you through the app or by email. The "last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
If you have any questions about this privacy policy or your data, reach out: