Privacy Notice

Controller: GEXCAP INC, 2423 SW 147th Ave #4006, Miami, FL 33185-4082, United States · EIN 36-4969612

Contact: m.iorgu@gexcap.com

Platform: e-boat.co

Status: BETA

Version: 1.0 — DRAFT, not yet reviewed by counsel

Last updated: 2026-08-28

1. What this notice is

This notice describes what personal data the e-boat platform collects, why, on what legal basis, who else sees it, how long it is kept, and what you can require us to do about it. It is written from what the platform actually does — the fields it stores, the third parties it calls, the logs it writes — rather than from a template. Where something has not been settled, this notice says so instead of implying that it has.

It applies to e-boat.co and to everything reachable from it. It does not apply to what an Operator does with your details after a booking: once a Trip is booked, the Operator receives what they need to carry it out and is a controller in their own right for that use.

2. Who the controller is, and a limitation you should know about

The controller is GEXCAP INC, a company established in the United States. The platform serves guests and Operators in the European Union, which means personal data collected here is transferred to and processed by a controller outside the EU.

Note. Flagged for professional advice, not resolved. The transfer mechanism for EU personal data to this US controller — and whether an EU representative under Article 27 GDPR is required — has not been determined. This is recorded here because a privacy notice that quietly omits it would be worse than one that names it. It must be settled before the platform processes real bookings at volume.

3. What we collect, why, and on what basis

Account data

Name, email address, phone number, password (stored only as a bcrypt hash — we never hold the password itself), profile photograph if you upload one, and the role you hold (guest, Operator, staff).

Why: to create and operate your account, sign you in, and let the other side of a booking know who they are dealing with. Basis: performance of a contract (Art. 6(1)(b) GDPR).

Identity verification documents (KYC)

Where verification is required — principally for Operators — an identity document, and the verification decision recorded against your account.

Why: to confirm that the person listing a vessel is who they claim to be, and to meet our obligations against fraud and misrepresentation. Basis: performance of a contract and our legitimate interest in a platform where vessels are not listed by impostors (Art. 6(1)(b) and (f)). An identity document may reveal data in a special category (for example, an image showing racial or ethnic origin); we do not use it for any purpose other than confirming identity.

How it is held: in a private storage area, never in the public one, written with owner-only file permissions. It is served only to a signed-in staff account that holds the specific permission to decide verification — not to every staff role, and never over a public URL.

Bookings, trips and payments

The vessel, dates, times, number of guests, the price and its components, the status of the booking, and the payment records associated with it.

Why: to operate the booking, to settle Operators, to handle cancellations, refunds and disputes, and to keep the accounting records we are required to keep. Basis: performance of a contract, and legal obligation for the accounting records (Art. 6(1)(b) and (c)).

Note. During beta, no card payments are processed. The platform is not connected to a live card processor, so no card number, expiry date or security code is collected by the platform or by anyone on its behalf. When card processing goes live, card details will be handled by the payment provider and will not reach our servers; this notice will be updated before that happens.

Messages and reviews

The content of messages you exchange with the other side of a booking, and any review you write.

Why: to deliver the message, to show reviews to other users, and to investigate a dispute or a report of abuse. Basis: performance of a contract, and our legitimate interest in a platform that can act on abuse (Art. 6(1)(b) and (f)).

The on-site assistant

If you use the assistant, your question and its answer are stored, together with the conversation it belongs to and the IP address the conversation was opened from. You do not need an account to use it, so please do not type anything into it you would not want stored.

Why: to answer the question, and so an operator can later read what the assistant actually said — which is how a wrong answer gets found and corrected. Basis: legitimate interest (Art. 6(1)(f)).

Who else sees it: the question, the conversation so far, and the reference material the assistant is allowed to draw on are sent to our AI provider (see section 4) to generate the answer.

Technical and security data

IP address and browser user-agent recorded against each active session; one access-log line per request containing the time, method, path, status, duration and IP. Query strings and request bodies are deliberately excluded from that log, because they carry tokens, one-time codes and search terms.

Why: to keep your session working across devices, to let you see and end your own sessions, to apply rate limits, to detect a stolen session token, and to investigate an incident. Basis: legitimate interest in the security of the service (Art. 6(1)(f)).

Cookies

The platform sets two cookies, both strictly necessary:

• e-boat_at — your short-lived access token, valid for 15 minutes.

• e-boat_rt — your refresh token, valid for 30 days, which is what keeps you signed in.

Both are HttpOnly (unreadable by scripts in your browser), SameSite=Lax, and marked Secure in production so they never travel over an unencrypted connection.

There are no analytics, advertising, profiling or third-party tracking cookies, and no tracking pixels or tag managers. Because the only cookies are strictly necessary for a service you asked for, no consent banner is required for them — and none is shown, rather than a banner that asks for consent it does not need.

4. Who else receives your data

We do not sell personal data and we do not share it for anyone else's marketing.

• The other side of your booking. An Operator receives what they need to carry out the Trip; a

Guest sees the Operator and the skipper details for the vessel they booked.

• Our AI provider. The assistant is powered by Groq. Your question, the conversation so far, and

the reference material are sent to Groq to generate an answer. Do not enter personal details of other people into the assistant.

• Our payment provider. Not yet engaged — see the beta note in section 3. When card processing

goes live, the provider will receive what it needs to take the payment.

• Hosting. The platform runs on a server rented from a hosting provider, who has the access to

the underlying machine that any hosting provider necessarily has.

• Authorities, where we are legally required to disclose, and only to the extent required.

5. How long we keep it

• Account data: for as long as the account exists. If you ask us to delete the account, the

personal fields are anonymised and the account is marked deleted.

• Bookings, payments and invoices: retained after the account closes, for as long as accounting

and tax law requires them to be retained.

• Identity documents: kept while verification is valid. A replacement document retires the one

it replaces.

• Messages and reviews: for as long as the account exists. A review may remain visible with the

author's name removed, because deleting one side of a public record misrepresents the other.

• Sessions: a refresh token expires after 30 days, or immediately when you sign out, sign out

everywhere, or change your password.

• Assistant conversations: kept so an operator can review what was answered.

• Backups: a copy of the database is taken every hour and kept for 14 days, so data you delete

may persist in a backup for up to that long before it ages out.

6. Your rights

Under the GDPR you may ask us to:

• Access the personal data we hold about you, and receive a copy.

• Correct it where it is wrong — most of it you can correct yourself in your account.

• Delete it. Note that we cannot delete records we are required by law to keep, such as the

accounting record of a completed booking.

• Restrict or object to processing we carry out on the basis of legitimate interest.

• Port the data you gave us, in a machine-readable form.

• Withdraw consent, where we relied on consent — which today is nowhere in the list above.

Write to m.iorgu@gexcap.com. We will answer within one month. You do not have to go through us first: you may complain directly to the data protection authority in the EU country where you live or work.

Automated decision-making. Search results are ranked and vessels are matched to a request by software, which is a convenience and not a decision about you. No decision producing a legal or similarly significant effect on you is made by automated means alone.

7. How we protect it

Passwords are stored only as bcrypt hashes. Session cookies are HttpOnly and Secure, and a refresh token is single-use — a replayed one ends every session on the account rather than being honoured. Identity documents are written to a private area with owner-only permissions and are served only to the staff role that decides verification. The site is served over HTTPS only, with HSTS. Uploads are identified by inspecting their actual bytes, not by trusting the filename or the declared type.

No system is perfectly secure, and this one is in beta. If you believe an account or a document has been exposed, write to the address above.

8. Children

The platform is not intended for anyone under 18, and an account may not be created by one.

9. Changes

We will update this notice when the platform changes — in particular when card processing goes live and when the transfer question in section 2 is resolved. The date at the top is the date of the version you are reading.