CruiseFeed ← Back to site

Privacy Policy

Last updated 7 August 2026.

This policy explains what personal data CruiseFeed collects, why we collect it, who we share it with, how long we keep it, and what rights you have. It covers the CruiseFeed website at cruisefeed.io, the CruiseFeed API and dashboard, and the business-to-business marketing emails we send. If you received a cold email from us and want to know where your details came from, go straight to section 9.

1.Who we are

CruiseFeed is a cruise-inventory data feed and API (“CruiseFeed”, “we”, “us”). Our registered company details are available on request from [email protected].

We are the controller of the personal data described in this policy. For privacy questions, requests or complaints, email [email protected].

Note that the cruise data we sell — cruise lines, ships, sailing dates, itineraries, ports and prices — is commercial inventory data. It is not personal data and is not covered by this policy. Our Terms of Service govern use of that data.

2.What we collect and why

2.1 Account data

When you create an account we collect your email address, and — if you supply them — your company name and a short description of your intended use case. Authentication is handled by Clerk, which holds your login credentials and email address; we also store a copy of the email address against your API key so we can identify your account for support and billing. We store your API key only as a hash, plus a short non-secret prefix used to display it and to attribute requests.

2.2 API request logs (IP address and User-Agent)

Every request to the CruiseFeed API and dashboard is logged. Each log entry records:

We use these logs to secure the service, investigate abuse and errors, enforce rate limits and plan quotas, and answer support questions about what a given key did. Health and internal operational routes are not logged.

2.3 Cookies and analytics

See section 4 for the full detail. In short: we run no analytics product and no marketing cookies. The only cookies set on this site are the strictly necessary ones our authentication provider uses to keep you signed in.

2.4 Contact form enquiries

If you use the enquiry form on our home page, we collect your name, work email address, company, the plan you are interested in, your desired refresh cadence, the cruise lines and regions you care about, and whatever you write in the free-text message field. We use this to reply to you and to discuss a plan.

Please note: this form is submitted directly from your browser to Web3Forms (api.web3forms.com), a third-party form-relay service, which forwards the submission to us by email. Your submission passes through Web3Forms' systems. Do not put sensitive personal data in the message field. If you would rather not use the form, email us instead at [email protected].

2.5 Billing data

Payments are processed by Stripe. Stripe collects and holds your card or other payment details and its own billing information — we never see or store your card number. What we store is your Stripe customer id, your subscription id and status, and which plan tier you are on, so we can provision the right level of access.

2.6 Marketing attribution

If you arrive from a tagged link — for example one in a marketing email — that link carries campaign parameters such as utm_source and utm_campaign in its URL. While you move from that landing page to the sign-up page, those parameters are carried along in the address bar. Nothing is stored on your device to do this.

If you then create an account, the utm_source and utm_campaign values are recorded against your account, so we can tell which campaign brought you to us. Only those two values are kept, and only at sign-up. If you never sign up, nothing is retained. If you would rather not pass them on, delete the utm_ parameters from the URL before you continue, or navigate to cruisefeed.io directly.

2.7 Email we send you

We send transactional email — sign-up verification, welcome and billing messages — through Proton Mail's SMTP service. This requires your email address to be transmitted to and processed by Proton.

2.8 Business prospect data

Separately from all of the above, we collect business contact details about people we have not yet done business with, in order to send B2B marketing email. Because that data is not collected from you directly, it has its own section — see section 9.

3.Legal bases for processing

Under the UK GDPR and EU GDPR we must have a lawful basis for each use of your personal data. Ours are:

WhatLegal basis
Account creation, API key issuance, delivering the service, supportContract (Art. 6(1)(b)) — necessary to provide the service you signed up for
Billing and subscription managementContract (Art. 6(1)(b)), and legal obligation (Art. 6(1)(c)) for tax and accounting records
API request logging: IP, User-Agent, path, statusLegitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse, debugging, and enforcing plan limits
Contact form enquiriesLegitimate interests (Art. 6(1)(f)), or steps prior to entering a contract (Art. 6(1)(b)) where you are asking about a plan
Authentication session cookies (section 4)Contract (Art. 6(1)(b)) — necessary to sign you in and keep you signed in. Exempt from the ePrivacy/PECR consent requirement as strictly necessary to provide a service you requested
Recording utm_source / utm_campaign against a new accountLegitimate interests (Art. 6(1)(f)) — understanding which marketing activity works. No information is stored on your device, so the PECR cookie rules do not apply
B2B prospecting email (section 9)Legitimate interests (Art. 6(1)(f)) — direct marketing to business contacts at organisations whose role is relevant to our product

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is proportionate — the data involved is limited, business-context, and not sensitive. You can object at any time (see section 8), and we will stop unless we have compelling grounds not to. For direct marketing, we will always stop on request.

4.Cookies and analytics

4.1 We use no analytics and no marketing cookies

This site runs no analytics product — no Google Analytics, no alternative analytics tool, no tag manager. We use no advertising cookies, no remarketing, no social pixels and no other ad-tech. We do not track you across sites, and we do not build a profile of you.

We also store nothing on your device for marketing purposes. Campaign parameters travel in the URL for the length of your visit and are read from it at sign-up (see section 2.6); no cookie, localStorage entry or similar identifier is written to do it.

4.2 The only cookies on this site

The only cookies set are those our authentication provider, Clerk, needs to sign you in and keep you signed in across pages. They are set on the sign-in, sign-up and dashboard pages and on our home page, which loads the sign-in component.

Set byPurposeCategory
Clerk (authentication) Maintains your login session and protects against session hijacking and cross-site request forgery Strictly necessary

Strictly necessary cookies are those without which a service you have asked for cannot work — you cannot have an account area without a way to know you are signed in. Under the ePrivacy Directive and the UK PECR (reg. 6(4)) these are exempt from the consent requirement.

This is why you are not asked to accept cookies on this site. A consent banner is required for cookies and similar storage that are not strictly necessary. We set none, so there is nothing for you to consent to or refuse. If that ever changes, we will ask for your consent before setting anything, and this policy will say so.

You can still clear or block these cookies in your browser settings; if you block them, signing in will not work.

4.3 Third-party assets

Loading a page on this site makes no requests to any third party. The fonts, icons, stylesheets and images our pages use are all served from our own domain. Requesting a file from someone else's content delivery network would necessarily disclose your IP address and User-Agent to that network before you could object, so we host them ourselves instead.

The exceptions are things you actively choose to do, and only at the moment you do them: signing in or creating an account contacts Clerk, submitting the enquiry form sends it to Web3Forms, and starting a subscription contacts Stripe. Each is described in section 5.

5.Who we share data with

We do not sell personal data. We share it only with the service providers below, each of which processes it on our instructions to run part of the service:

ProviderWhat they do for usData involved
ClerkAuthentication and account managementEmail address, login credentials, session data
StripePayments and subscription billingPayment details, billing contact, subscription records
SupabaseManaged PostgreSQL — our primary data storeAccount records, API key metadata, request logs
Amazon Web ServicesS3 object storage and Lambda functions for the data pipeline; hostingStored datasets and operational logs
CloudflareCDN and DNS in front of the site, R2 object storage, and Workers hosting our MCP serverRequest metadata including IP address and User-Agent
Web3FormsRelays enquiry-form submissions to us by emailEverything you put in the enquiry form
ProtonTransactional email deliveryRecipient email address and message content
Instantly / SmartleadSends our B2B marketing email (see section 9)Prospect business contact details and engagement data
Apify and email-verification providersSourcing and verifying business contact data (see section 9)Publicly listed business contact details

We may also disclose personal data where we are legally required to — for example in response to a valid legal request — or to establish or defend legal claims. If the business is ever sold or merged, account data may transfer to the buyer, who would remain bound by this policy.

6.International transfers

Most of the providers above are established in the United States, and some operate globally. Using them means your personal data is transferred outside the UK and the EEA.

These transfers now all arise from running the service itself — authentication, billing, hosting, email. No data is transferred for analytics or marketing-measurement purposes, because we no longer run an analytics product. Since our fonts, icons and images are served from our own domain, simply loading a page no longer discloses your IP address to any overseas provider.

Where that happens, we rely on the Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where UK data is involved), incorporated into our data processing agreements with those providers, together with their own technical and organisational safeguards. Where a provider is certified under the EU–US Data Privacy Framework and its UK extension, we may rely on that instead. You can ask us for details of the safeguards applied to a particular transfer by emailing [email protected].

7.How long we keep data

We keep personal data only for as long as we need it for the purposes described in this policy. How long that is depends on the type of data and why we hold it, so instead of a single fixed period we apply the criteria below. We may keep data for longer where the law requires it, or where we need it to establish, exercise or defend a legal claim.

DataHow long we keep it
API request logs (IP, User-Agent, path, status)A limited period only, for security monitoring, abuse prevention and troubleshooting — deleted once no longer needed for those purposes
Account data (email, company, use case, API key hash and prefix)For as long as you have an account with us, and for a limited period afterwards so we can deal with billing queries, disputes and reinstatement requests
Billing and transaction recordsFor as long as tax, accounting and company law require us to keep them
Enquiry-form submissions and support emailFor as long as we need them to answer you and to keep a reasonable record of our correspondence
Prospect data used for B2B marketing (section 9)Until you ask us to stop, or until the data is no longer relevant to our business-to-business marketing — whichever comes first
Suppression / do-not-contact listIndefinitely — we keep the minimum needed (your email address) precisely so we do not contact you again
utm_source / utm_campaign recorded at sign-upFor as long as the account exists — it is a field on the account record, not separate storage

You can ask us how long we hold a particular category of data, or ask us to delete it, by emailing [email protected] — see section 8.

8.Your rights

If the UK GDPR or EU GDPR applies to you, you have the right to:

How to exercise them: email [email protected]. Tell us what you want and, if you are a customer, which email address your account uses. We will respond within one month. We may ask you to confirm your identity before we act — enough to be sure we are not disclosing your data to someone else, and no more. We do not charge for this, unless a request is manifestly unfounded or excessive.

9.Business prospect data — if we emailed you first

CruiseFeed runs an outbound business-to-business email programme. If you received a message from us and did not sign up or contact us first, this section is the notice we owe you under Article 14 of the GDPR, which covers personal data obtained from somewhere other than you.

9.1 What we hold

Business contact details only: your name, job title or role, employer or company, work email address, your company's website domain, your LinkedIn profile URL, your general business location, and our record of whether an email to you was delivered, opened, replied to, or bounced. We do not seek or store personal email addresses, home addresses, phone numbers of a personal nature, or any special-category data.

9.2 Where we got it

From publicly accessible sources — professional networking and business-listing profiles, company websites and public business directories — collected through third-party data-sourcing tools (principally Apify and its published scrapers) and checked with commercial email-verification services. We do not buy contact lists compiled by data brokers.

9.3 Why, and on what basis

We use it to send a small number of relevant business emails about CruiseFeed to people whose role suggests our cruise data may be useful to their organisation. Our legal basis is legitimate interests (Art. 6(1)(f)) — promoting a B2B product to relevant business contacts at their work address. We have carried out a balancing assessment: the data is limited to the professional sphere, obtained from sources you or your employer made public, and messaging is low-volume and role-relevant. Where local law requires consent for marketing email, we do not send without it.

Marketing email is sent through a third-party cold-email platform (Instantly / Smartlead) and from a separate sending domain, not from cruisefeed.io. Replies still reach us.

9.4 How to make it stop

Any of these works, and none of them requires you to explain yourself:

On request we suppress your address — we add it to a permanent do-not-contact list and remove the rest of your record from our prospecting data. Keeping the address on the suppression list is the only way to guarantee we never contact you again; if you would prefer full erasure instead, say so and we will do that too. You can also ask us at any time what we hold about you and where specifically it came from, and we will tell you.

10.California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, use and disclose; to request deletion of it; to request correction of inaccurate information; and not to be discriminated against for exercising those rights. The categories we collect and our purposes are set out in sections 2 to 7 above.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. We run no advertising or remarketing technology on this site. We have not sold or shared personal information in the preceding 12 months, including that of anyone we know to be under 16.

We do not use or disclose sensitive personal information beyond the purposes permitted under the CCPA, so there is nothing to limit under the "Limit the Use of My Sensitive Personal Information" right.

To exercise any of these rights, email [email protected]. You may use an authorised agent; we will ask for proof of their authority. We will verify your request by matching the details you give us against what we already hold.

11.Children

CruiseFeed is a business-to-business service. It is not directed at children, we do not market to them, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, email [email protected] and we will delete it.

12.Security

API keys are stored as hashes, never in plain text. Traffic to the site and API is served over HTTPS. Access to production systems is limited to those who need it. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the data we hold. If you believe you have found a security or privacy issue, please tell us at [email protected].

13.Complaints

If you are unhappy with how we have handled your personal data, please raise it with us first at [email protected] — we would rather fix it.

You also have the right to complain to a data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113). If you are in the EEA, you may complain to the supervisory authority in the country where you live or work, or where you believe the problem occurred.

14.Changes to this policy

We may update this policy as the service changes or the law does. When we do, we will update the “last updated” date above. If a change materially affects how we use your personal data, we will give active customers reasonable notice by email before it takes effect.

15.Contact

Privacy questions, rights requests and marketing opt-outs: [email protected].
Anything else: [email protected].

If you need a postal address to serve a formal notice or a data-protection request, ask at [email protected] and we will provide it.