Privacy Policy
NaviBoss is unusual for a web product: the planner runs entirely in your browser, so almost everything it knows about your voyage never reaches us at all. This page says exactly what does, who else sees it, and how to make it stop. It describes what the code actually does — not what a template says.
§The short version
- The planner has no back end. Your ports, routes, saved voyages, settings and trial clock live in your own browser's storage and are never uploaded. We could not read them if we wanted to.
- We receive an email address only if you sign in or buy, and a name and payment amount only if you pay us in pesos through /PHcheckout. Nothing else is asked for anywhere.
- We set no cookies of our own. The one third-party tag on the site — the Meta (Facebook) pixel — loads only if you say yes, and never before.
- You can withdraw that yes at any moment, from the link in the footer of every page. Turning it off also deletes the cookies it set.
- No adverts are served inside the product, and we do not sell, rent or trade personal data. There is no data broker in this stack.
1Who we are, and how to reach us
NaviBoss (“we”, “us”) operates naviboss.app and is the data controller for the personal data described here, within the meaning of the UK and EU General Data Protection Regulation.
Our registered address is West Boxhill, Talisay City, Cebu, Philippines.
Everything on this page — questions, requests, complaints, and any of the rights in §9 — goes to support@naviboss.app, and email is much the fastest way to reach us. We are not required to appoint, and have not appointed, a statutory Data Protection Officer; that address reaches the people who make these decisions.
2What stays on your device — which is most of it
The planner is a static web application. Once the page and its chart data have loaded, routing, chokepoint blocking, zone checks, playback and file export all run on your own machine, with no request back to us. That is a performance decision first — it is what makes NaviBoss usable on ship internet — but the privacy consequence is real and it is the most important thing on this page.
These are stored in your browser's localStorage, under keys
beginning naviboss., and are never transmitted:
- your saved voyages, the voyage you are currently building, and the passages you have blocked;
- your settings — vessel details if you entered any, units, coordinate format, clock, default departure, which chart layers start on;
- the day/night theme, the sidebar width, and which overlays are showing;
- the date your free trial started, which is how the trial is clocked without an account;
- your answer to the cookie banner (
naviboss.consent), so we do not ask again; - your sign-in session token, if you signed in.
Clearing your browser storage erases all of it, including the trial clock and your saved voyages. There is no copy on our side to restore from. If you share a voyage by link, the whole voyage is encoded in the link itself — it is not uploaded, and we never see who you sent it to.
3What actually reaches us
Your email address — only if you sign in or buy
Sign-in is passwordless: you give an email address, we send a sign-in link, and clicking it proves the address is yours. We store the address so we can look up whether it has an active subscription. There is no password to leak and no profile behind it.
A manual-payment claim — only if you use /PHcheckout
Filipino seafarers often hold no international card, so there is a second payment door: pay in pesos by GCash or bank transfer, and we match the payment and unlock the account by hand. Filing that claim sends us the name on the sending account, an email address, the amount, and which of the two methods you used. We deliberately do not ask for a reference number, an ID document, or anything else; if you send us a receipt screenshot over Facebook Messenger, that conversation is held by Meta under its own terms, not ours.
Ordinary server logs
The site is served by Cloudflare Pages, and our sign-in service runs on Cloudflare Workers. Like any web host, they process the IP address, request time, page requested and user-agent of each request, for delivery, caching and abuse prevention. We do not build these into profiles and we do not run server-side analytics over them.
What we never collect
No account passwords. No payment card numbers — those go to our payment provider and never touch our systems. No location or GPS data: NaviBoss does not ask for your position, and the ports in your voyage are typed by you and stay in your browser. No AIS or vessel-tracking data about your ship. No contact list, no camera, no microphone.
4Cookies, storage and the Meta pixel
We set no cookies of our own. The things listed in
§2 use localStorage, not cookies. They
are strictly necessary for a service you asked for — a planner that forgets
your voyage on every reload is not the service — so under the ePrivacy rules
they do not require consent, and they cannot be used to track you across
other websites.
There is exactly one third-party tag on this site, and it is optional:
| what | set by | purpose | lasts |
|---|---|---|---|
_fbp |
Meta pixel | Identifies this browser to Meta so we can measure which adverts brought people here, and so Meta can build advertising audiences. | 3 months |
_fbc |
Meta pixel | Records the advert click that led you here, when you arrive from a Facebook or Instagram link. | 3 months |
naviboss.consent |
us (localStorage, not a cookie) | Remembers your answer to the banner, and when you gave it, so we neither ask again nor lose the record. | until you clear storage |
Nothing loads from Meta until you accept. If you have not answered, or you declined, Meta's script is not requested, no cookie is written, and Meta is not told you were here. There is no invisible tracking image anywhere on this site that could fire regardless — we checked, because that is the usual way this promise gets broken.
If you accept, we tell Meta that a page was viewed, and separately when someone opens the planner, starts a checkout, or completes a purchase. We have switched Meta's automatic collection off, so the pixel does not read the contents of form fields — your name, email and payment amount on the /PHcheckout form are never sent to Meta by the pixel. What Meta then does with the visit is governed by its own Privacy Policy; on this we and Meta are joint controllers to the limited extent set out in Meta's controller addendum.
Withdrawing is one click, from the link in the footer of every page. Withdrawal takes effect immediately, stops further reporting, and deletes the two cookies above — it does not merely stop sending while leaving the identifier in place. It does not undo reporting that already happened; for that, use the deletion rights in §9 and Meta's own Accounts Centre controls.
5Who else is involved
A short list on purpose. Every one of these has a written data-processing agreement with us, and none of them is permitted to use your data for their own purposes except where the last column says so.
| who | what for | what they get |
|---|---|---|
| Cloudflare | Hosting the site, and running the sign-in service and its storage. | Request logs; your email address and subscription status. |
| Dodo Payments | Card checkout. They are the merchant of record — the sale is legally theirs, and they are a controller in their own right for it. | Your email, billing details and card data. We never see the card. |
| Resend | Delivering the sign-in link and payment-claim emails. | Your email address and the message we send you. |
| Meta Platforms | Advertising measurement and audiences — only with your consent, per §4. | That this browser visited, and which of a handful of named events occurred. |
We may also disclose data where the law requires it, or to establish or defend a legal claim. If NaviBoss is ever sold, personal data would pass to the buyer under this policy, and we would say so here first.
6Why we are allowed to (lawful bases)
- Performance of a contract — your email and subscription status, because you asked us to give you access to something you bought.
- Consent — the Meta pixel, and only the Meta pixel. Freely given, specific, informed, and as easy to withdraw as to give.
- Legitimate interests — server logs, keeping the service up, and preventing abuse of the sign-in and claim endpoints. We have weighed this against your interests; the data is minimal, is not profiled, and is not combined with anything else.
- Legal obligation — keeping records of payments for as long as tax and accounting rules require.
You are never required to give us personal data to use the planner. It is free, it needs no sign-up, and it works without an account.
7How long we keep it
- Sign-in and subscription records — for as long as the subscription is live, and for 12 months afterwards so that a returning customer is recognised. Then deleted.
- Manual-payment claims — 180 days after the claim is approved or refused, as the receipt trail for a payment that was matched by hand. Then deleted automatically.
- Payment and tax records — as long as the applicable tax law requires, typically several years, held by our payment provider.
- Server logs — the short retention our host applies, on the order of days, not months.
- Your consent record — in your browser only, until you clear it.
8When data leaves the EEA or the UK
We are not based in the EEA, and neither are all of the providers in §5. Where personal data of someone in the EEA or the UK is transferred outside it, that transfer is covered by the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies), which is the mechanism each of those providers offers. You may ask us for a copy of the relevant clauses.
9Your rights, and how to use them
If the UK or EU GDPR applies to you, you have the right to ask us for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how we use it, to have it sent to you or another provider in a portable form, and — where we rely on consent — to withdraw that consent at any time without affecting what was lawful before you did.
To use any of them, email support@naviboss.app. We answer within one month, free of charge. We will ask you to confirm you control the email address in question, because that address is the only identifier we hold — we cannot look you up any other way, and we will not accept a request to delete someone else's data.
Note the practical limit that follows from §2: your voyages and settings are not ours to export or delete. They are in your browser, and clearing its storage for this site removes them completely.
If you think we have handled your data badly, please tell us first — but you are entitled to complain directly to your national data protection authority. In the UK that is the Information Commissioner's Office; in the EEA it is the supervisory authority for the country you live or work in. In the Philippines it is the National Privacy Commission.
10Children
NaviBoss is a professional tool for people working at sea and ashore, and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to support@naviboss.app and we will delete it.
11Changes to this policy
If we change what we collect or who processes it, we will update the date and version at the top of this page. A change that adds a new tracker, or a new purpose for an existing one, will also re-ask for your consent — the banner comes back rather than quietly inheriting your old answer.
This policy sits alongside our Terms & Conditions, which govern your use of the product itself.