Privacy Policy
This policy explains how TouchBase Maritime handles your personal data when you use the TouchBase Maritime app. It is written in plain English. Where a phrase has a specific legal meaning under UK GDPR or EU GDPR, the meaning is the one given in those regulations.
Who we are
TouchBase Maritime is operated by Werner Vietze as a sole trader. You can reach us about anything in this policy at privacy@touchbasemaritime.com.
TouchBase Maritime is separate from APRON Maritime. Some yachts and management companies use the APRON Maritime platform for their operations and, when you are connected to one of those employers, some of your TouchBase data flows over to them. That cross-platform flow is described in the Data flow with APRON Maritime section.
Controller or processor
For the data we hold about you personally — your TouchBase profile, your career record, your wellness data and the documents you upload to your own profile — TouchBase Maritime is the data controller (UK GDPR Article 4(7)).
For data that flows out to a yacht or management company that employs you and uses APRON Maritime, that employer is the controller in respect of the data they hold; TouchBase Maritime is the processor for the connected portion. Their privacy policy applies to their handling of that data once it leaves us.
What we collect
The app holds the data needed to be a seafarer’s working record:
- Identity and contact data: name, email, phone (optional), job title, employee identifier (where your employer uses one), your profile photo.
- Authentication data: a sign-in identifier issued by our authentication provider, session tokens, and a record of when and where you last signed in.
- Career data: sea-service records, vessels served, voyages assigned, ports visited, gangway entries (on or off the vessel), crew-change records, references given and received, and rotation blocks. This forms the spine of your career history across employers.
- Documents you upload to your own record: certificates, training, passports, visas, medical, contracts, and vessel-related documents.
- Work-and-rest data: the working and rest hours you enter yourself or that flow through from the vessel’s system, used for STCW/MLC recordkeeping and your own fatigue picture.
- Wellness data (where you choose to use the wellness features): daily check-ins, fatigue-risk scores derived from your work-and-rest data, wellness streak and badge state, optional wearable-device connection state, and any safety threshold alerts.
- Sharing records: profile shares, document shares and share packages you choose to send to employers, agents or recruiters, and what they did with those (open/download).
- Operational telemetry: error reports and basic request logs used to keep the app working. These are designed not to carry personal data fields — they identify the request, the route, the timing and the status code.
The current app does not collect live location-tracking data from your phone, voice recordings, or biometric data. Push-notification tokens are held to deliver notifications (see Push notifications, cookies and SDKs).
Your career data is yours
TouchBase is built around a simple promise: your seafaring career belongs to you, not to whichever vessel you happen to be on. When you change employers, your career record stays with you. When you leave a vessel that used APRON Maritime, your profile stays with you. We will not delete your record without your instruction (subject to the retention rules below) and we will not transfer it to anyone without your action.
You can export your full TouchBase record at any time from inside the app, and you can ask us to delete it. We will do so, subject to the retention minimums in the Retention section.
Wellness and work-and-rest data
Wellness data (daily check-ins, fatigue-risk scores, wearable connection state) is more sensitive than the rest of your profile. Three things follow from that:
- We only collect wellness data when you choose to use the wellness features. They are off by default for new accounts.
- By default your wellness data is visible to you only. You choose whether your employer (and which roles within it — for example the master, the DPA, or HR) can see any of it. The default is no visibility outside your account.
- The work-and-rest record itself is required by maritime law for your employer’s compliance, so the work-and-rest entries you make through the app may be shared with the employer that is legally entitled to keep that record, where you have entered them as part of that employment.
Sharing with employers and recruiters
TouchBase lets you share specific parts of your record (your CV, a single certificate, a share package) with another person — usually a recruiter, a crewing agent, or a yacht owner. You choose what to share and with whom. We record the share so you can revoke it later. We do not sell your data to recruiters and we do not put your profile in any directory without your instruction.
Why we process it
The app exists to do four things, and we process data for each:
- Let you keep your career record up to date and accessible throughout your career at sea.
- Support the recordkeeping the maritime regulations require for a working seafarer (work-and-rest under STCW/MLC, certificate expiry, sea-service evidence).
- Help employers that use APRON Maritime keep an accurate picture of you while you are on rotation with them (see Data flow with APRON Maritime).
- Operate, maintain and improve the app itself — error monitoring, performance work and security.
Lawful basis
For each category above we rely on one or more of: performance of a contract (Article 6(1)(b)) — the contract being the terms of use that apply when you use the app; compliance with a legal obligation (Article 6(1)(c)) — primarily maritime recordkeeping obligations affecting your employment; legitimate interests (Article 6(1)(f)) where we need to keep the app secure and reliable. For wellness data and any other health-related data, we rely on your explicit consent under Article 9(2)(a), and you can withdraw that consent at any time from inside the app.
Where your data lives
The primary database is a managed PostgreSQL instance in the European Union. Uploaded files (passport scans, certificates, receipts, photos) are stored in Amazon Web Services S3 in eu-central-1. The app itself runs in the European region for our deployments. Authentication is handled by our auth provider in the European region. When you install the native app on iOS or Android, parts of your record are also held on your device so the app works without connectivity, and these synchronise back when you are online.
We do not move personal data outside the European Economic Area for our own purposes. The exceptions are described in the Subprocessors and third-party SDKs and International transfers sections below.
Encryption
Connections to the app are protected with Transport Layer Security (TLS 1.2 or higher). The database and S3 storage are encrypted at rest by the underlying provider using AES-256. Sensitive fields (including health-related wellness data, passport numbers and contact details linked to next-of-kin) are held with additional safeguards in line with current good practice.
Subprocessors and third-party SDKs
We use a small number of third-party providers to actually run the service. Each is bound by a data-processing agreement that meets UK and EU GDPR Article 28 requirements:
- Supabase Inc. — authentication provider for your sign-in identity. Holds your sign-in identifier and session state.
- Neon Inc. (or equivalent managed Postgres) — managed PostgreSQL hosting in a European region.
- Amazon Web Services, Inc. — S3 file storage (eu-central-1) for documents you upload.
- Vercel Inc. — application hosting and CDN edge in the European region.
- Anthropic PBC — document analysis. Receives the image or PDF of a document at the moment you scan it, or when you ask for it to be analysed on upload, and returns the fields printed on it. Nothing else in your record is sent. See AI features.
- Upstash, Inc. — the rate limiting that stops sign-in and upload endpoints being hammered. Holds a short-lived counter keyed to your account identifier, or to your IP address before you are signed in. No profile data and no documents.
- Functional Software, Inc. (Sentry) — error monitoring, so a crash is visible to us without you having to report it. Receives the technical detail of the fault: the error, where in the code it happened, the browser or device, and the page path. It is deliberately configured to send no account identifier, no request contents, no document data and no wellness data, and it never records your screen.
- Resend, Inc. — transactional email delivery (sign-in links, vessel invitations, expiry reminders). Receives your email address, your name, and the content of the message.
- Google LLC (Firebase Cloud Messaging) — push notification delivery on Android.
- Apple Inc. (Apple Push Notification service) — push notification delivery on iOS.
- Capacitor / Ionic open-source libraries — the native app runtime that lets TouchBase run on iOS and Android. These run on your device; no personal data is sent to Ionic from your device.
We may add or replace subprocessors. Where we do so we will give you reasonable notice through the app, and we will only do so where the new provider offers equivalent data-protection safeguards. If you object on reasonable grounds you can stop using the affected feature, and in the limit you can request deletion of your account.
Data flow with APRON Maritime
APRON Maritime is a separate platform that operates a platform used by some yachts and management companies for their own operations. When you are employed on a vessel or fleet that uses APRON Maritime, specific parts of your record flow between TouchBase and that platform so the employer can keep accurate records for the vessel and your career stays consistent across both surfaces. Typical data moved: your identity and certifications, your work-and-rest entries, the training and document expiry dates relevant to your employment with that employer, and your voyage assignments. APRON Maritime’s own handling of that data is governed by its own privacy policy at https://apronmaritime.com/privacy.
Wellness data is not shared with APRON Maritime or with any employer except where you have explicitly enabled sharing of specific metrics with specific roles in your wellness-privacy settings. Per-checkin notes and mood data are never shared by default.
International transfers
Where any subprocessor processes data outside the United Kingdom or the European Economic Area, we rely on the standard contractual clauses adopted by the European Commission (the 2021 SCCs) and the United Kingdom International Data Transfer Addendum to those clauses, together with each processor’s own published data-protection practices. Push-notification delivery through Apple and Google passes through their respective worldwide infrastructure to reach your phone.
Retention
We retain your data as long as your account is active. If you delete your account, we delete or anonymise your personal data, subject to:
- Statutory minimums where another party (typically a previous employer’s maritime regulator) is legally required to hold a copy of certain records (for example STCW-mandated minimums for sea-service evidence and rest-hours records).
- A short backup-retention window after which residual copies in backups also expire.
You can export your data at any time before requesting deletion. We will confirm completion on request.
Your rights
Under UK GDPR Articles 15–22 you have rights to: access, rectification, erasure, restriction, data portability, and objection. Most rights are exercisable directly inside the app (profile editing, document deletion, export, account deletion); anything else can be requested from privacy@touchbasemaritime.com.
If you believe we have not handled your data properly you have the right to complain to the UK Information Commissioner’s Office (ICO) or to the data protection authority in your country of residence. Please give us a chance to fix the issue first — write to privacy@touchbasemaritime.com.
Anonymised and aggregated data
We may collect, use, retain, and publish aggregated and anonymised data derived from TouchBase for any lawful purpose, including service improvement, statistical analysis, research, security analytics, and reporting on the maritime industry. We will only do this where the result cannot reasonably be used to re-identify you, any employer, any vessel, or any other identifiable party. Anonymised and aggregated outputs are not personal data and are not subject to the rights in the section above.
AI features
TouchBase uses AI to read your documents for you. When you scan a document with the camera, the photograph is sent for analysis as part of scanning it. When you upload a file instead, nothing is sent until you press Analyze with AI (or, in bulk upload, the analyse button). Nothing else in your record — your profile, your sea service, your wellness entries, your messages — is ever sent to a model provider.
The analysis extracts the fields printed on the document, such as the document number, the issuing authority and the expiry date, so you do not have to type them. It runs at Anthropic PBC, a processor in the United States, under a data-processing agreement and the transfer safeguards described in International transfers. The image or PDF you scanned is sent, together with the extraction instructions. It is processed to return the result and is not used to train Anthropic’s models.
This matters because the documents in question are usually identity documents — a passport, a seafarer’s identity document, a visa. If you would rather no third party saw them, upload the file and fill the fields in yourself: the extraction step is never required to store a document.
Push notifications, cookies and SDKs
The native app uses your device’s push-notification system to deliver operational notifications (for example certificate expiry, a new share, a vessel assignment). On iOS this is Apple’s APNs; on Android this is Google’s Firebase Cloud Messaging. You can turn these off in your device settings or inside the app at any time.
The web version of the app uses strictly necessary cookies (sign-in session, cross-site request forgery token, and a light set of preferences). We do not set advertising or tracking cookies. When we add web analytics in the future, this section and a consent banner will be added at the same time.
For App Store privacy nutrition labels and Google Play data safety disclosures: TouchBase collects identifier data (name, email), contact data, fitness data (when wellness features are used), photos and videos (when uploaded as documents), diagnostic data (crash reports), and a push notification identifier. None of this data is used for third-party advertising. The categories are described in detail in the sections above.
Children
TouchBase is for working seafarers and is not directed at children. You must be 16 or older to use the app. If you believe a person under 16 has created an account, please tell us at privacy@touchbasemaritime.com and we will close it.
What the app is and is not
TouchBase records, organises and surfaces the data you put in. It is not the auditor, the inspector, the regulator, the master, the DPA, the flag-state filer, or any other authority. TouchBase does not certify any audit, inspection or regulatory outcome.
You are responsible for the accuracy of the data you enter about yourself. Your employer is responsible for the operational and compliance decisions taken from their side of the platform. We provide the tool; the decisions stay with the people qualified to make them.
Security incidents
We test for and monitor security incidents. If a personal data breach happens that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and (where required) tell you as soon as practicable. Security-relevant reports can be sent to security@touchbasemaritime.com.
Changes to this policy
We will update this policy when the app changes in a way that affects how we handle data. The "last updated" date at the top of the page reflects the most recent material change. We will tell active users about significant changes in-app and (if you have opted in) by push notification.
Contact
Privacy questions: privacy@touchbasemaritime.com.
Security questions: security@touchbasemaritime.com.
General app questions: support@touchbasemaritime.com.
Version 2026-09-06.