Legal
Privacy Policy
Effective date: 12 July 2026
Last updated: 12 July 2026
This Privacy Policy explains how Shaun Holman, an individual resident in Ireland ("Ancora", "we", "us", "our"), collects and uses personal data when you use the Ancora Vessel Management desktop application, the Ancora Vessel Management mobile app, and the ancora-yacht.com website (together, the "Service").
Ancora is designed to keep as little personal data as possible. Most of what you record inside the Service is operational vessel data — equipment, maintenance history, defects, spares, tasks, checklists, certificates and voyage records. This policy focuses on the personal data that necessarily sits alongside that: who you are, and what actions you took.
1. Who is the data controller
The data controller for personal data processed through the Service is:
Shaun Holman, individual
Ireland
Email: hello@ancora-yacht.com
Because Ancora is currently operated by an individual and not a formally-registered business, and does not conduct large-scale or systematic monitoring of personal data, no Data Protection Officer is appointed under Article 37 of the GDPR. Privacy questions and data subject requests are handled directly by Shaun Holman at the email above.
2. What personal data we collect
Account data. When your captain invites you to a vessel, or you sign up directly, we collect your name, email address and role on the vessel (captain, chief engineer, engineer, deck, interior, etc.). We also store an encrypted password hash — we never see or store your plaintext password.
Activity data. The Service records who did what and when: which user reported a defect, closed a task, ran a checklist, adjusted a stock count, and so on. This audit trail is a core operational requirement of a vessel management tool and cannot be disabled.
Photos. When you log a defect from the mobile app you may attach photos. These are stored in encrypted object storage and are only accessible to signed-in crew of the same vessel.
Technical data. When you use the apps our infrastructure providers (see Section 5) log standard connection metadata: IP address, timestamp, and the API request. This is used to keep the Service secure and available, and is retained for a short period only.
Marketing data. If you email us via the "Book a demo" or "Request early access" links on the website, we retain the email thread until the enquiry is closed and for a reasonable period afterwards in case you get back in touch.
3. Why we process personal data (legal bases)
We rely on the following legal bases from Article 6 of the GDPR:
- Contract (Art. 6(1)(b)). Providing you with access to the Service, storing the vessel data you enter, syncing it between your devices, and letting your crew see it — this is necessary to perform the contract we have with you or your vessel operator.
- Legitimate interests (Art. 6(1)(f)). Keeping the Service secure, preventing abuse, debugging errors, and responding to support requests. Our legitimate interests are balanced against your privacy expectations — we log only what we need to run the Service safely.
- Legal obligation (Art. 6(1)(c)). Where we are required to retain records for tax, accounting or other statutory purposes.
4. Who can see your data
Other crew of your vessel. Ancora is a shared operational tool. Any active crew member of your vessel can see the vessel's records, including who created or updated each item. Row-level security in our database enforces vessel-scoped access — crew of one vessel cannot see the data of another vessel.
Us. Shaun Holman may access personal and vessel data only where necessary to provide support, investigate a fault, or comply with a legal obligation.
No sale or advertising. Ancora does not sell personal data. Ancora does not use personal data for targeted advertising. Ancora does not share data with data brokers.
5. Third-party processors
The Service is built on infrastructure operated by the following processors. Each is bound by a Data Processing Agreement that requires them to protect your data to at least the standard set out in this policy.
- Supabase, Inc. — database, authentication and file storage. Your account, vessel data and defect photos are hosted here.
- PowerSync (JourneyApps). — offline-first data synchronisation between the server and your devices.
- Apple Inc. and Google LLC — mobile app distribution via the App Store and Play Store. They may collect their own analytics under their own privacy policies.
- GitHub, Inc. — hosts the ancora-yacht.com marketing site (GitHub Pages).
Where these processors are established outside the EEA, transfers of personal data are protected by Standard Contractual Clauses adopted by the European Commission or an equivalent safeguard under Article 46 of the GDPR.
6. How long we keep your data
-
Account data — for as long as your account is active
on a vessel. If you leave a vessel via the mobile app's "Leave vessel"
action, your row is deactivated immediately (
is_active = false) with a timestamp. The captain may reinstate you within 30 days; after that period we may hard-delete the row. - Vessel data — for the operational lifetime of the vessel on the Service. The captain can export or permanently delete all vessel data at any time from Settings › Data & Privacy in the desktop app.
- Photos — for as long as the parent defect record exists. Deleted with the defect.
- Technical logs — typically 30 to 90 days at our infrastructure providers.
- Marketing enquiries — until closure, plus up to 24 months.
- Tax / accounting records — as required by Irish law (currently 6 years for VAT-related records).
7. Your rights
Under the GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data ("right to be forgotten"). Note that operational audit records may need to remain in the vessel's history to preserve the integrity of the record, but your identifying details can be pseudonymised.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable format. Captains can export the full vessel dataset as .xlsx at any time from the desktop app.
- Objection — object to processing based on legitimate interests.
- Complaint — lodge a complaint with the Irish Data Protection Commission if you believe we have not handled your data correctly. Their website is dataprotection.ie.
To exercise any of these rights, email hello@ancora-yacht.com. We will respond within one month, as required by Article 12(3) of the GDPR.
8. Security
All traffic between your devices and our servers is encrypted with TLS. Data is encrypted at rest on our infrastructure providers. Access to production systems is restricted to Shaun Holman and requires multi-factor authentication. Passwords are hashed with bcrypt and never stored or transmitted in plaintext. Row-level security enforces that users can only see data for vessels they belong to.
9. Children
Ancora is a professional tool for adults working in the yacht industry. The Service is not intended for use by anyone under 16 years of age, which is the age of digital consent in Ireland. We do not knowingly collect data from children under 16. If you become aware that a child has provided personal data to the Service, please contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be communicated by email to active users at least 30 days before they take effect.
11. Contact
For any privacy question, data subject request, or complaint, email hello@ancora-yacht.com.
You can also contact the Irish Data Protection Commission directly at dataprotection.ie if you wish to raise a concern with the supervisory authority.