1. Introduction
This Privacy Policy applies to CrewPost and the website operated by MarSoft AI (“we”, “us”, “our”). CrewPost is a yacht crew job board and direct recruitment platform. Our sister product CrewRef — for digitally verifiable crew references — is linked from this site but has its own privacy policy.
We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR), applicable Greek and EU data protection laws, and international privacy standards.
2. Data Controller
MarSoft AI is the data controller for all personal data processed through CrewPost.
3. Data We Collect
3.1 Account Data
- Full name and email address
- Professional title, rank, or position
- Company name (for employers/captains, optional)
- Profile photo (if provided via Google OAuth or upload)
- Phone number (optional, where applicable)
- Authentication data (hashed passwords, OAuth tokens)
3.2 CrewPost-Specific Data
Depending on how you use CrewPost, we may collect:
- Job postings: Position title, department, yacht name, yacht type, location, salary range, contract type, posting status, and expiry date
- Applications: Applicant name, email, phone, nationality, experience, CV uploads, cover letters, and reference contact details
- Crew profiles: Job seeker profile data, saved searches, matching preferences, and application history
- Agency directory: Public crewing agency names, websites, and board URLs (publicly listed). Recruiter contact details are admin-only and never displayed publicly.
3.3 Technical Data
- IP address and approximate geolocation
- Browser type, version, and device information
- Usage patterns and page interactions (via analytics)
- Error reports and performance data (via Sentry)
- Cookies and session identifiers
3.4 Payment Data
Where payments are involved (e.g. purchasing post credits), processing is handled entirely by Stripe. We never store your full credit card number, CVV, or banking details. We receive only: transaction ID, amount, currency, and payment status.
4. How We Use Your Data
- Service delivery: Publishing job postings, processing applications, connecting captains with crew candidates, and maintaining the platform.
- Account management: Authentication (including Google OAuth), profile management, and dashboard functionality.
- Communication: Transactional emails (verification, application notifications, confirmations). We will never send unsolicited marketing emails without explicit consent.
- Security: Fraud prevention, abuse detection, and maintaining platform integrity.
- Analytics: Understanding usage patterns to improve user experience and fix issues.
- Legal compliance: Meeting obligations under applicable laws and regulations.
5. Legal Basis for Processing (GDPR)
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Services you requested.
- Legitimate interests (Art. 6(1)(f)): Platform security, fraud prevention, analytics, and service improvement.
- Consent (Art. 6(1)(a)): Where explicitly obtained.
- Legal obligation (Art. 6(1)(c)): Where required by applicable law.
6. Data Sharing & Sub-Processors
- Supabase — database & authentication (EU-hosted)
- Vercel — hosting & deployment
- Resend — transactional email delivery
- Stripe — payment processing (PCI-DSS Level 1)
- Sentry — error monitoring
- Google OAuth — authentication
- Google Analytics — anonymized usage data
We do not sell, rent, or trade your personal data. We do not share data for advertising or third-party marketing. No data brokers, no recruiters, no third parties.
7. Public Content
Job postings published on CrewPost are publicly accessible. Application data is shared only with the posting captain. You may unpublish or delete your content at any time from your dashboard.
8. Data Retention
- Account data: Retained until you request account deletion.
- Job postings & applications: Retained until you delete them or request account deletion.
- Technical/analytics data: Up to 12 months for analytics; up to 90 days for error reports.
- Payment records: Retained as required by law (typically 7 years).
Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
9. Your Rights (GDPR)
- Access — Request a copy of your personal data
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion (“right to be forgotten”)
- Restriction — Request limitation of processing
- Portability — Receive your data in a structured format
- Objection — Object to processing based on legitimate interests
- Withdraw consent — At any time, without affecting prior processing
To exercise any right, email crewpost@marsoft.ai. We will respond within 30 days.
10. Data Security
We implement encryption in transit (TLS/HTTPS) and at rest, row-level security policies, OAuth 2.0 authentication, regular security reviews, and the principle of least privilege. Passwords are hashed using bcrypt. No system is 100% secure, but we take all reasonable measures.
11. International Data Transfers
Where data is transferred outside the EEA, we ensure appropriate safeguards including Standard Contractual Clauses (SCCs) or adequacy decisions.
12. Cookies & Tracking
We use essential cookies (authentication, session management) and analytics cookies (usage understanding). We do not use advertising cookies or trackers. You may opt out via browser settings.
13. Children's Privacy
Our Services are not intended for individuals under 16. We do not knowingly collect data from children.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or prominent notice on our Services.
15. Supervisory Authority
You may lodge a complaint with the Hellenic Data Protection Authority (HDPA): www.dpa.gr