← Back
Trust & Compliance

Privacy Policy

Last updated · 1 June 2026

GuestVoyages is the post-booking guest portal used by your charter operator. This policy explains what personal information passes through the platform, why it is collected, and the controls you have over it.

Who we are

GuestVoyages is a software platform operated for the benefit of luxury charter operators — yacht charter companies, charter brokers, luxury villa operators and similar hospitality businesses. We provide the technology; your charter operator is the party that holds the commercial relationship with you and is the data controller for your personal information. GuestVoyages acts as a data processor on their behalf.

What we collect

The platform processes the categories of information you provide to your operator through your portal, including:

  • Identity & contact: full legal name, date of birth, nationality, email and mobile number.
  • Travel documents: passport number, issuing country, expiry, and an uploaded copy of the passport page (PDF or photograph).
  • Hospitality preferences: dietary requirements, allergies, medical notes you choose to share for your safety, beverage and amenity preferences.
  • Logistics: arrival and departure flights, transfer requirements, special-occasion notes.
  • Concierge requests: messages and bookings you ask your operator to arrange.
  • Authentication: hashed passwords, sign-in timestamps and security events. We never store passwords in plain text.
  • Technical: a session cookie, the browser session token, and minimal device information needed to keep you signed in safely.

We do not collect advertising identifiers, location tracking data, or profile you across third-party services.

Why we collect it

  • To deliver your charter experience — itinerary, transfers, concierge, documents and on-board personalisation.
  • To meet international travel and maritime compliance obligations the operator must satisfy on your behalf (passenger manifests, port clearance, insurance).
  • To keep your account secure and prevent unauthorised access to your information.
  • To allow your operator to communicate with you about your booking through a private, auditable channel.

Lawful basis for processing

Under UK GDPR and EU GDPR (Article 6) we rely on the following bases:

  • Performance of a contract — to deliver the charter you have booked with your operator.
  • Legal obligation — to satisfy maritime, immigration and tax requirements that apply to chartered voyages.
  • Legitimate interests — to keep the platform secure, detect fraud and improve service quality. We balance these interests against your rights and do not use this basis for marketing.
  • Consent — for any optional cookie categories (functional, analytics) and for processing of special-category data such as medical or dietary information that reveals sensitive details. You may withdraw consent at any time.

Who has access

  • Your charter operator and the specific crew or shoreside team they assign to your voyage.
  • GuestVoyages engineering staff strictly for the purpose of running and maintaining the platform — under a confidentiality agreement and only when access is necessary for support or security.
  • Sub-processors that provide the underlying cloud infrastructure (hosting, encrypted object storage, transactional email). A current list is available on request to your operator.
  • Authorities, only where legally required and after notifying your operator unless that notification is itself prohibited by law.

We do not sell personal information. We do not share information with advertisers or data brokers.

How long we keep data

  • Account and charter records — for the duration of your relationship with your operator plus the period required by their finance, tax and maritime record-keeping obligations (typically 6–7 years).
  • Passport copies — held only as long as your operator needs them to deliver the charter and meet manifest obligations. Operators may request earlier secure deletion via their admin tools.
  • Hospitality preferences — retained between charters with your operator unless you ask for them to be removed, so you do not have to re-enter them every voyage.
  • Security and audit logs — retained for up to 12 months to detect and investigate misuse.
  • Anonymised analytics — retained indefinitely; this data cannot be linked back to you.

How we protect it

  • All traffic is encrypted in transit using TLS 1.2 or higher.
  • Passport files and uploaded documents are stored in an access-controlled object store with encryption at rest.
  • Passwords are hashed using bcrypt with a per-account salt — never stored in plain text.
  • Sign-in attempts are rate-limited and brute-force attacks trigger temporary lockouts.
  • Role-based access controls separate operator, crew and guest visibility.
  • Production access is restricted to a minimum number of named engineers under multi-factor authentication.
  • Backups are encrypted and stored separately from the live database.

Your rights

Because your charter operator is the controller of your data, requests under UK GDPR and EU GDPR are made through them. They will use GuestVoyages tooling to action your request. You have the right to:

  • Access the personal data held about you.
  • Have inaccurate data corrected.
  • Have your data erased once it is no longer required for the charter or by law.
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw any consent you have given (this does not affect processing already carried out under that consent).
  • Complain to the supervisory authority in your country — in the United Kingdom this is the Information Commissioner's Office (ico.org.uk); in the EU your national data protection authority.

Contact

For privacy requests relating to a specific charter, please contact your charter operator directly — they hold your booking record and will action the request through the GuestVoyages platform.

For questions about the platform itself, technical issues or to report a vulnerability, you may also contact the GuestVoyages team via your operator. We aim to respond within 30 calendar days of a complete request.