Privacy Policy
Last updated 8 August 2026.
This policy explains what personal data CruiseFeed collects, why, who we share it with, how long we keep it, and what rights you have. It covers our website, API and dashboard, and the business-to-business marketing email we send. If we emailed you first and you want to know why, go straight to section 8.
1.Who we are
CruiseFeed is a cruise-inventory data feed and API (“CruiseFeed”, “we”, “us”), operated as an independent business trading under that name. We are the controller of the personal data described here. For any privacy question, request or complaint — and for our full business and contact details — email [email protected].
The cruise data we sell — lines, ships, sailing dates, itineraries, ports and prices — is commercial inventory data, not personal data, and is not covered by this policy. Our Terms of Service govern use of it.
2.What we collect and why
- Account data — your email address and, if you supply them, your company name and intended use case. We store API keys only as hashes, alongside a short non-secret prefix used to display them and attribute requests.
- Technical request data — we log requests to the API and dashboard, including the IP address, browser or client identifier, what was requested and the outcome. We use this to keep the service secure and available, investigate abuse and errors, enforce plan limits, and answer support questions.
- Enquiries and support — whatever you send us through our enquiry form or by email, so we can reply. The enquiry form is delivered to us by a third-party form service, so please don't put sensitive personal data in it; email us directly if you would rather not use it.
- Billing data — our payment processor handles your card details. We never see or store your card number. We keep only the customer and subscription references we need to bill you and provision the right plan.
- Marketing attribution — if you arrive from a tagged link, the campaign name it carries in the URL is recorded against your account if you sign up. Nothing is stored on your device to do this, and nothing is retained if you don't sign up.
- Business prospect data — business contact details of people we haven't done business with yet, used for B2B marketing email. Because that isn't collected from you, it has its own section — see section 8.
3.Legal bases for processing
Under the UK GDPR and EU GDPR we must have a lawful basis for each use of your personal data:
- Contract (Art. 6(1)(b)) — creating your account, issuing API keys, delivering the service, support, billing, and keeping you signed in.
- Legal obligation (Art. 6(1)(c)) — retaining tax and accounting records.
- Legitimate interests (Art. 6(1)(f)) — securing the service and preventing abuse, enforcing plan limits, responding to enquiries, understanding which marketing works, and B2B marketing to relevant business contacts.
Where we rely on legitimate interests we have weighed our interest against your rights and concluded the processing is proportionate — the data involved is limited, business-context and not sensitive. You can object at any time (section 7), and we will stop unless we have compelling grounds not to. For direct marketing we will always stop on request.
4.Cookies and analytics
We run no analytics product and set no advertising, marketing or tracking cookies. We do not track you across sites and do not build a profile of you.
The only cookies set on this site are the strictly necessary ones our authentication provider uses to sign you in and keep you signed in. Under the ePrivacy Directive and UK PECR (reg. 6(4)) these are exempt from the consent requirement — which is why this site has no cookie banner. There is nothing to consent to or refuse. If that ever changes, we will ask for your consent first and update this policy. You can block these cookies in your browser, but signing in will not work if you do.
5.Who we share data with, and where it goes
We do not sell personal data. We share it only with service providers who process it on our instructions to run the service, in these categories:
- authentication and account management;
- payment and subscription billing;
- cloud hosting, database and content delivery;
- transactional and marketing email delivery, and enquiry-form relay;
- sourcing and verifying business contact data (section 8).
We can tell you which providers we currently use — just ask at [email protected]. We may also disclose personal data where legally required, or to establish or defend legal claims. If the business is ever sold or merged, account data may transfer to the buyer, who would remain bound by this policy.
Some of these providers are established outside the UK and EEA, mainly in the United States, so your data is transferred internationally. No data is transferred for analytics or advertising purposes. Where such transfers happen we rely on the Standard Contractual Clauses (with the UK International Data Transfer Addendum where UK data is involved), or on a provider's certification under the EU–US Data Privacy Framework and its UK extension. Ask us and we will explain the safeguards applied to a particular transfer.
6.How long we keep data
We keep personal data only as long as we need it for the purposes above, so we apply criteria rather than one fixed period. In short: request logs are kept for a limited period for security and troubleshooting; account data for as long as you have an account and a short period afterwards for billing and reinstatement queries; billing records for as long as tax and accounting law require; enquiries for as long as needed to deal with them. If you ask us to stop marketing to you, we keep your email address on a do-not-contact list indefinitely — that is the only way to be sure we never contact you again. We may keep data longer where the law requires it or to defend a legal claim.
You can ask how long we hold a particular category of data, or ask us to delete it, at [email protected].
7.Your rights
If the UK GDPR or EU GDPR applies to you, you have the right to access your data, have it corrected or deleted, have processing restricted, receive it in a portable format, and object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time — in practice we rely on consent for nothing, as we set no non-essential cookies and run no analytics. We carry out no automated decision-making that produces legal or similarly significant effects.
To exercise any of these: email [email protected], telling us what you want and, if you are a customer, the email address on your account. We respond within one month. We may ask you to confirm your identity first — enough to be sure we are not disclosing your data to someone else, and no more. There is no charge unless a request is manifestly unfounded or excessive.
8.If we emailed you first
CruiseFeed runs an outbound B2B email programme. If you heard from us without signing up or contacting us first, this is the notice we owe you under Article 14 of the GDPR, which covers personal data obtained from somewhere other than you.
What we hold: business contact details only — your name, role, employer, work email address and related professional details, plus whether an email to you was delivered, opened, replied to or bounced. We do not seek or store personal email or home addresses, personal phone numbers, or any special-category data.
Where it came from: publicly accessible professional and business sources — networking and business-listing profiles, company websites and public directories — gathered using third-party data-sourcing tools and checked by commercial email-verification services. We do not buy contact lists from data brokers. You can ask us where your details specifically came from and we will tell you.
Why: to send a small number of relevant business emails to people whose role suggests our cruise data may be useful to their organisation. Our basis is legitimate interests (Art. 6(1)(f)), supported by a balancing assessment: the data is limited to the professional sphere, obtained from public sources, and messaging is low-volume and role-relevant. Where local law requires consent for marketing email, we do not send without it. Marketing email is sent through a third-party platform and from a separate sending domain, not from cruisefeed.io; replies still reach us.
To make it stop — reply “unsubscribe” to any message, use the unsubscribe link, or email [email protected]. No explanation needed. We will add your address to our do-not-contact list and remove the rest of your record. If you would rather we erase everything including the address, say so and we will.
9.California privacy rights (CCPA/CPRA)
California residents have the right to know what personal information we collect, use and disclose; to request its deletion or correction; and not to be discriminated against for exercising those rights. The categories and purposes are set out above.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising as the CCPA/CPRA define those terms, and have not done so in the preceding 12 months, including for anyone we know to be under 16. We do not use or disclose sensitive personal information beyond the purposes the CCPA permits, so there is nothing to limit under the “Limit the Use of My Sensitive Personal Information” right. To exercise these rights, email [email protected]; you may use an authorised agent, and we will ask for proof of their authority.
10.Children, security and complaints
CruiseFeed is a business-to-business service. It is not directed at children and we do not knowingly collect personal data from anyone under 16.
We take technical and organisational measures appropriate to the data we hold: API keys are stored as hashes and never in plain text, traffic is served over HTTPS, and access to production systems is restricted. No system is perfectly secure. If you believe you have found a security or privacy issue, please tell us at [email protected].
If you are unhappy with how we have handled your data, raise it with us first — we would rather fix it. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority where you live or work.
11.Changes and contact
We may update this policy as the service or the law changes, and will update the “last updated” date above. If a change materially affects how we use your personal data, we will give active customers reasonable notice by email first.
Privacy questions, rights requests and marketing opt-outs:
[email protected].
Anything else: [email protected]. If you need a postal
address to serve a formal notice, ask and we will provide it.