Privacy Policy — YSS (Your Sailing Stats)

Draft notice. This document is a working draft prepared from the YSS codebase to accurately describe the platform's current data practices. It is not legal advice and must be reviewed and adapted by qualified legal counsel (and localized for your target jurisdictions) before it is published or relied upon. Bracketed [...] values are placeholders that must be completed.

This Privacy Policy explains how DEEPSPACEOTTERS LLC ("YSS", "we", "us") collects, uses, shares, and protects personal data when you use the YSS sailing/GPS analytics service — the mobile app, website, and backend API (together, the "Service") available at https://your-sailing-stats.net.

For the purposes of the EU/UK General Data Protection Regulation (GDPR), DEEPSPACEOTTERS LLC is the data controller for the personal data described here. If you are in the EU/UK, our representative is [EU/UK Representative] and our Data Protection Officer (if appointed) can be reached at [DPO contact].

1. Summary

2. Personal data we collect

2.1 Account and profile data

2.2 Authentication and device/session data

2.3 Location and activity data (sensitive)

When you upload or record an activity, we process:

2.4 Health data — we do not store it

Activity files often include heart-rate measurements, because the devices that record them write heart rate into the same file as the track.

We do not keep it. When your file is processed, heart-rate samples are discarded, and they are not written to our storage in any form. They are not in the track data our app reads, and they are not in the archive you get if you export your data. We do not hold heart rate, so there is nothing of that kind for us to disclose, share, or lose.

This is a deliberate choice rather than a technical limit: not holding health data is simpler and safer for you than holding it well. See Section 9.

Two honest qualifications:

2.5 Uploaded files — we do not keep the file itself

2.6 Social and community data

2.7 Derived and aggregate data

2.8 Technical and usage data

We use personal data for the following purposes. Where GDPR applies, the corresponding legal basis is shown.

PurposeExamplesLegal basis (GDPR)
Provide the ServiceCreate/authenticate your account; store and analyze your tracks; show your statsPerformance of a contract
Sharing you controlShow tracks to the audience you select (public/friends/group/fleet)Contract, and your consent/choice via privacy settings
Process sensitive dataPrecise location analysis. Heart rate is not collectedYour explicit consent (see Section 9)
Account & transactional emailEmail verification, password reset, security noticesContract; legitimate interests (account security)
Security & abuse preventionRate limiting, session management, fraud/abuse mitigationLegitimate interests
Reliability & improvementOperational metrics/traces, debuggingLegitimate interests
Legal complianceResponding to lawful requests; record-keepingLegal obligation

We do not use your personal data for third-party advertising or profiling that produces legal or similarly significant effects.

4. How we share personal data

4.1 With other users — according to your settings

Your tracks are shared with other people only as you direct:

4.2 With service providers (sub-processors)

We use the following categories of providers to operate the Service. Each processes personal data only to provide services to us, under contract.

Sub-processor (category)What it doesData involved
[Hosting provider] / databaseRuns our servers and PostgreSQL databaseAll stored account, activity, and social data
Amazon Web Services — S3 & CloudFrontStores processed track files and delivers them via time-limited signed URLsProcessed track data blobs; the request that fetches them
[SMTP / email provider]Sends transactional emailYour email address; verification/reset codes
Google (Sign-In)Optional social sign-inProfile data we receive from Google when you connect (email, name, picture) plus the sign-in access token
Garmin (import)Optional, user-initiated import of your activity archivesThe archive you provide
OpenWeatherMap and Visual CrossingOptional wind/weather enrichment of a trackWe send track coordinates and timestamps to retrieve historical wind/weather
Rate-limit store (Redis)Short-lived request countersAccount identifier or IP for the counter key
Monitoring (self-hosted OpenTelemetry → VictoriaMetrics / VictoriaLogs / VictoriaTraces)Operational metrics, logs, and tracingTechnical telemetry; may include an account identifier. We use no third-party product-analytics, advertising, or crash-reporting SDKs

Note on weather providers: to add wind/weather to a track we transmit the track's location coordinates and time to the weather provider(s). No account identifier is required for this lookup. Weather responses may be cached to improve performance and reduce repeat lookups.

The specific legal names, locations, and contact details of these providers should be listed and kept current here: [Sub-processor list / DPA references].

We may disclose personal data if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of our users, the public, or the Service.

4.4 Business transfers

If we are involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction; we will notify you and honor the commitments in this Policy.

4.5 No sale of personal data

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy laws (e.g. CCPA/CPRA).

5. International data transfers

The Service and its providers may process data in countries other than yours. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism. Details and a copy of the safeguards are available on request at support@your-sailing-stats.net. [Confirm hosting/CDN regions and transfer mechanisms.]

6. Data retention

We keep personal data only as long as needed for the purposes above, then delete or anonymize it.

DataRetention
Account, profile, and activity dataUntil you delete the item, or until your account is deleted (on request)
The file you uploadedNot retained. It is read on arrival and discarded; only the track points inside it are kept. Files uploaded before this change are still held, and are deleted with the track they belong to
Heart-rate measurementsNot retained. Discarded during processing and never written to storage. Values stored before this change are removed from derived track data at the next recalculation, and with the track on deletion
Track points (S3)Until the track is deleted. Held in two forms: the points as read from your upload, and the processed track the app displays
Processed track files (S3)Until the track is deleted; a track file is immutable — when a track is re-processed, split, or merged, a new file is written and the previous one is deleted
Refresh tokens (sessions)Become invalid after ~30 days, or when you sign out / sign out of all sessions; expired records are cleared on our maintenance cycle
Email verification / password-reset codesShort-lived (~10 minutes), then invalid; removed after use or on our maintenance cycle
Signed track/download URLsTime-limited (default ~1 hour); the link then expires and must be re-requested
Rate-limit countersEphemeral — expire automatically within the rate-limit window (seconds to about an hour)
Fleet-shared segmentsUntil the fleet or your participation is removed (see below)
Operational telemetryPer our monitoring retention configuration — [state period]

Deletion mechanisms.

7. How we protect personal data

We use technical and organizational measures appropriate to the sensitivity of the data, including:

No method of transmission or storage is completely secure; we cannot guarantee absolute security.

8. Your choices and rights

8.1 In-product controls

Depending on where you live, you may have the right to:

For residents of California and similar U.S. states (CCPA/CPRA): you have the right to know, access, delete, and correct your personal information, to opt out of any "sale"/"sharing" (we do neither), and to non-discrimination for exercising your rights. You may exercise these rights, including via an authorized agent, using the contact below.

8.3 How to exercise your rights

Use the in-product controls where available, or contact us at support@your-sailing-stats.net. We may need to verify your identity before acting. We respond within the timeframes required by applicable law.

9. Sensitive data

The Service processes one category of sensitive data:

We process it only with your explicit consent, given when you create an account and upload or record activities, and/or through a clear in-product consent where required. You can withdraw consent by deleting the relevant activities or your account.

Health data — we hold none. Heart-rate measurements are a special category of personal data, and our answer to that is not to keep them: samples found in an upload are discarded during processing and are never written to our storage. See Section 2.4 for what that means in practice, including for tracks imported before the change. You do not need to strip heart rate out of a file before uploading it, and there is no consent for us to ask for something we do not collect.

10. Children's privacy

The Service is not directed to children under [Minimum Age], and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact support@your-sailing-stats.net and we will delete it.

11. Cookies, local storage, and tokens

The YSS app and API authenticate you using access and refresh tokens (stored on your device), not third-party tracking cookies. The web-based administration panel uses a session cookie that is strictly necessary to keep an administrator signed in. We do not use advertising or cross-site tracking cookies. [If the website uses any analytics/cookies, list them here.]

12. Automated processing

We apply algorithmic processing to your tracks (e.g. filtering GPS noise, computing speeds, detecting maneuvers, and building statistics). This is analytics on your own data to produce the results you request. We do not make automated decisions that produce legal or similarly significant effects about you, and we do not perform behavioral profiling for such decisions.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Effective date" and, for material changes, provide additional notice as required by law. Your continued use of the Service after an update means you accept the revised Policy.

14. Contact us

Questions or requests regarding this Policy or your personal data:

If you are in the EEA/UK and believe we have not addressed your concern, you may lodge a complaint with your local supervisory authority. This Policy is governed by the laws of the Republic of Armenia.

← Back to home