Legal

Privacy policy

Last updated: May 26, 2026

Who we are

Yachtxchange operates a yacht trading marketplace consisting of this website, the buyer mobile app, and the broker mobile app (collectively, “the Service”). This policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and your rights as a user. Questions: support@yachtxchange.app.

Data we collect

  • Account data: name, email, phone number, avatar, and password (handled by our authentication provider, never stored in plaintext on our servers).
  • Brokerage data: brokerage name, legal name, logo, business address, team roster, and Stripe billing identifier for brokers.
  • Listing data: vessel specs, photos, location, pricing, and the description text you write.
  • Activity data: listings you view, save, and compare; saved searches; messages exchanged with brokers; appointments you create or accept; closing pipeline state.
  • Device data: IP address, user-agent, mobile push token (only if you opt in to alerts), and approximate geographic region for fraud signals.
  • AI inputs and outputs: the prompts you submit to the listing copilot, semantic search, concierge, and matchmaker, plus the model responses returned to you. We retain these to debug bad responses and to bill metered usage.

How we use your data

  • To operate the Service (sign-in, listings, messaging, billing).
  • To deliver AI features you initiate.
  • To send transactional emails (lead notifications, appointment confirmations, billing receipts) and, with your consent, alerts from saved searches.
  • To prevent fraud, abuse, and platform-policy violations.
  • To comply with legal obligations.

Third parties who process your data on our behalf

We use the following processors. Each one provides equivalent or stronger contractual data protections than this policy describes:

  • Clerk– authentication, organization membership, session tokens.
  • Neon– managed Postgres database hosting.
  • Vercel– web and mobile API hosting; Vercel Blob for photo and document storage.
  • Vercel AI Gateway– routes AI feature requests to underlying model providers (Anthropic, OpenAI, Google). Prompts and outputs may transit those providers under their respective data-handling terms.
  • Stripe– subscription billing for broker tiers; card data never touches our servers.
  • Expo / EAS– mobile delivery, crash reporting, and push-notification routing.

Data we share publicly

Listings that you publish are intentionally public — vessel specs, photos, asking price, and the broker or seller's display name appear in our catalog and on partner search surfaces. Personal contact information (phone, email) is shown only when you choose to share it inside a lead conversation.

Retention

We retain account and listing data for as long as your account is active. When you delete your account (see below), we delete or anonymize personal data within 30 days. We retain a minimal transactional record (e.g., invoice ledger) where required by tax or anti-fraud law, but it no longer identifies you.

Your rights

  • Access– request a copy of the data we hold about you.
  • Correction– edit your profile and listings directly inside the Service.
  • Deletion– delete your account from Settings inside the web portal, or from the Account screen in the mobile apps. We process within 30 days.
  • Withdraw consent– turn off push notifications, saved-search alerts, and AI feature use at any time from the Service.
  • Complain– you can lodge a complaint with your local data protection authority. Where you are covered by GDPR or CCPA, we will respond to verifiable requests within statutory deadlines.

Children

The Service is intended for adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has submitted data to us, contact support@yachtxchange.app and we will delete it.

Security

We encrypt data in transit (HTTPS / TLS) and at rest (Neon and Blob default encryption). Access to production data is restricted to a small set of operators on audited least-privilege roles. No online service is perfectly secure — report suspected vulnerabilities to support@yachtxchange.app.

Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced in-app and by email at least 14 days before taking effect.

Contact

Email support@yachtxchange.app. We respond to privacy questions within five business days.

This document is a starting scaffold. Please have it reviewed by counsel before launch — we are not your lawyers.