StarboardLog Privacy Policy

Version 1.0 · Effective Date: 26 September 2026

Download PDF

This Policy explains which personal data is processed to run StarboardLog, the difference between our own controller activities and Customer-directed Workspace processing, and how Guests, Documents and optional Google Drive use affect those roles.

1 Who we are

StarboardLog is operated by Sándor Levente Szabó e.v., 9400 Sopron, Semmelweis utca 10., Hungary; individual entrepreneur registration number 61070435; Hungarian tax number 91404451-1-28; EU VAT number HU91404451. Privacy and rights requests: starboardlog@gmail.com. We use StarboardLog, we and us for this operator. The Hungarian National Authority for Data Protection and Freedom of Information (NAIH) is a relevant supervisory authority.

2 Scope and roles

This Policy covers website visitors, Account holders, invited Users, Customers, booking-linked Guests, people identified in Workspace records and support contacts. StarboardLog is an independent controller for its own Accounts, contracts, subscriptions, invoices, service security, support, legal evidence and compliance. For Customer-selected operational data in a Workspace, the Customer ordinarily determines purposes and legal basis and StarboardLog acts as processor under the DPA. One identifier may be processed in both capacities for different purposes. A Guest is neither a Workspace member nor automatically a direct contracting Customer.

3 Personal data categories

Controller-side data may include name, email and optional contact information; Account and authentication identifiers; Workspace administration; contract, subscription and manual-billing details; Terms version, affirmative acceptance source and server-generated UTC time; support messages; transactional email metadata; and proportionate security and audit events. Limited technical context such as IP address or user agent may arise in infrastructure security logs, distinct from the contractual acceptance record.

Customer-selected Workspace data may include members and roles; Customer records and contact details; vessels and bookings; Guest Access issuance, expiry, revocation and guest issue reports; usage and counter readings; components, maintenance requirements and events; issues and assignments; ownership shares; operational expenses, allocation rules, currency-specific Owner Balances and Settlement records; Documents or their metadata and references; timeline and audit history; and exports or Vessel Record Packs. Free-text fields and Documents may incidentally contain personal data selected by the Customer. The Service does not require health or special-category data or criminal-offence data, and Customers should not submit these without a separately documented lawful basis and safeguards.

Optional Google Drive processing includes the connected Google email and account identifier, drive.file authorization scope, protected tokens or credentials, vessel file identifiers, metadata and folder references, and the specific document bytes accessed transiently to supply the selected workflow. The underlying file bytes remain in the connected Customer-controlled Drive rather than a StarboardLog document store.

4 Purposes and legal bases for our own data

We administer Accounts and the agreed Service and take requested pre-contract steps under GDPR Article 6(1)(b). We manage invoices, tax records and legally required disclosures under Article 6(1)(c), with contract performance where relevant. We protect security, investigate abuse, keep proportionate legal evidence, support users, administer service communications and defend claims under Article 6(1)(f), subject to balancing. Certain support and service communications may also be necessary to perform the contract under Article 6(1)(b). If a future optional purpose requires consent, we will request separate consent and enable withdrawal. Google authorization is a technical permission and does not itself decide every GDPR legal basis.

We do not infer legal vessel ownership from an Ownership Share, provide a payment account through Owner Balances or automatically convert currencies. We do not currently use Google Analytics, Meta Pixel, advertising cookies, marketing pixels, newsletter tracking or solely automated decisions producing legal or similarly significant effects.

5 Processing for a Customer

The Customer decides which Workspace records to enter, whom to invite, which Guest Access links to issue and which information is visible in a booking context. The Customer must provide privacy notices and lawful bases to its vessel owners, customers, crew, guests and other affected people and answer rights requests. We process Workspace Personal Data on documented instructions and help the Customer under the DPA. We may process a limited request record independently to verify identity, secure the Service and document our response.

6 Guest Access and recipients

A booking-linked Guest Access link may expose the relevant vessel and booking details, known guest-visible Issues and a means to report an Issue. It expires or can be revoked, and does not give owner financial information, other bookings, Workspace administration, private Documents or Google Drive access. The Customer controls delivery, visibility and revocation; the Service retains the context and audit data needed to secure and administer the link.

7 Google Drive and third-party integration

An authorized Customer or User may optionally connect their own Google Drive for supported vessel-document workflows. The Customer remains responsible for its Google permissions, sharing and retention. We process only the connection information and specific file information required by the authorized workflow. Guest Access has no Google Drive access. Revoking a connection may prevent future access but does not itself remove Workspace records or Google-held files.

The integration requests drive.file, a limited Google Drive permission for files the user creates, opens with or selects for the Service. StarboardLog stores protected connection credentials, metadata and references. Removing a reference does not itself delete its underlying Drive file. Our use of Google API information follows the Google API Services User Data Policy, including its Limited Use requirements; we do not sell Google user data or use it for advertising.

8 Browser storage

The Service uses functional browser storage for authenticated sign-in, the session-only sign-in choice, selected Workspace, temporary administrative impersonation and welcome UI state, notice acknowledgement and the optional application-install prompt. Guest Access creates no guest-specific browser storage. The Cookie and Browser Storage Notice lists current values, purposes, duration criteria and user controls. No non-essential analytics or advertising storage is currently identified.

9 Service providers and disclosures

Lovable Labs Incorporated and its managed infrastructure chain provide hosting, database, authentication and security services. Plus Five Five, Inc. operating Resend sends transactional application email. Google Drive is an optional Customer-directed integration authorized through the Customer’s or User’s Google account. KBOSS.hu Kft. operating Számlázz.hu assists with the Provider’s manual invoices as a controller-side provider. Professional advisers and public authorities may receive limited data where lawful and necessary. Authorized Admins and Crew receive role-limited Workspace data; Guests see only their booking context. Details and safeguards appear in the Subprocessor and Service Provider Information document.

10 International transfers

The primary application data region is Ireland in the EU through the shared Lovable managed infrastructure. Lovable, Resend and their authorized provider chains may process limited information outside the EEA. Where required, we use an adequacy decision, Standard Contractual Clauses or another lawful mechanism and appropriate supplementary safeguards. Ireland as primary region does not imply all support, email and security processing occurs only in the EEA.

11 Retention and deletion

Account and subscription records are retained while the relationship is active and as needed afterward for account closure, disputes and legal obligations. Terms acceptance and material audit evidence may be retained for claims or security; invoice and tax records follow applicable Hungarian retention law. Support, email delivery and security records are retained as necessary to resolve matters and protect the Service. Protected provider backup copies may remain until their normal rotation or deletion.

Workspace Personal Data follows Customer instructions and the DPA. An approximately 30-day post-termination Read-Only retrieval opportunity may be provided where technically, legally and securely appropriate; active-system deletion or anonymization then follows the DPA and verified instructions. Closing an Account, removing membership, revoking Guest Access, deleting Workspace references and deleting files from a connected Google Drive are separate actions.

12 Security

We use HTTPS/TLS in transit, managed encrypted storage, Workspace and role checks, row-level policies, server-side secrets, protected financial writes, limited Google Drive permissions, audit records for sensitive changes and restricted elevated access with reason-logged impersonation. We review security events and coordinate response with providers. No absolute security, selective restoration, backup frequency or recovery time is promised. Customers manage their own roles, Guest links, Google Drive, exports and endpoints.

13 Rights and complaints

Subject to applicable law, people may request access, rectification, erasure, restriction and portability; object to legitimate-interest processing; withdraw consent where it applies; and complain to NAIH or another competent supervisory authority. Contact starboardlog@gmail.com. We may verify identity and authority. For Workspace data, the Customer normally decides the request while we assist under the DPA. NAIH: https://naih.hu/.

14 Required and optional data

Minimum Account, authentication and contract data are needed for access and billing. Optional Customer inputs, a Google connection and Guest Access depend on feature selection. Refusing optional data may prevent that specific feature without preventing unrelated use. We do not currently use newsletter distribution or advertising profiling.

15 Updates and contact

We publish a revised version and effective date when this Policy changes, with additional notice for material changes where appropriate. Privacy inquiries and verified closure or deletion requests: starboardlog@gmail.com. Postal correspondence: Sándor Levente Szabó e.v., 9400 Sopron, Semmelweis utca 10., Hungary; individual entrepreneur registration number 61070435; Hungarian tax number 91404451-1-28; EU VAT number HU91404451.