Privacy Policy
Last updated 7 August 2026.
This policy explains what personal data CruiseFeed collects, why we collect it, who we share it with, how long we keep it, and what rights you have. It covers the CruiseFeed website at cruisefeed.io, the CruiseFeed API and dashboard, and the business-to-business marketing emails we send. If you received a cold email from us and want to know where your details came from, go straight to section 9.
1.Who we are
CruiseFeed is a cruise-inventory data feed and API (“CruiseFeed”, “we”, “us”). Our registered company details are available on request from [email protected].
We are the controller of the personal data described in this policy. For privacy questions, requests or complaints, email [email protected].
Note that the cruise data we sell — cruise lines, ships, sailing dates, itineraries, ports and prices — is commercial inventory data. It is not personal data and is not covered by this policy. Our Terms of Service govern use of that data.
2.What we collect and why
2.1 Account data
When you create an account we collect your email address, and — if you supply them — your company name and a short description of your intended use case. Authentication is handled by Clerk, which holds your login credentials and email address; we also store a copy of the email address against your API key so we can identify your account for support and billing. We store your API key only as a hash, plus a short non-secret prefix used to display it and to attribute requests.
2.2 API request logs (IP address and User-Agent)
Every request to the CruiseFeed API and dashboard is logged. Each log entry records:
- the IP address the request came from;
- the User-Agent string sent by your client or browser;
- the HTTP method, path and query string;
- the response status code and how long the request took;
- the prefix of the API key used, and the account id behind the key or dashboard session (blank for anonymous, ops and gateway traffic).
We use these logs to secure the service, investigate abuse and errors, enforce rate limits and plan quotas, and answer support questions about what a given key did. Health and internal operational routes are not logged.
2.3 Cookies and analytics
See section 4 for the full detail. In short: we run no analytics product and no marketing cookies. The only cookies set on this site are the strictly necessary ones our authentication provider uses to keep you signed in.
2.4 Contact form enquiries
If you use the enquiry form on our home page, we collect your name, work email address, company, the plan you are interested in, your desired refresh cadence, the cruise lines and regions you care about, and whatever you write in the free-text message field. We use this to reply to you and to discuss a plan.
Please note: this form is submitted directly from your browser to Web3Forms (api.web3forms.com), a third-party form-relay service, which forwards the submission to us by email. Your submission passes through Web3Forms' systems. Do not put sensitive personal data in the message field. If you would rather not use the form, email us instead at [email protected].
2.5 Billing data
Payments are processed by Stripe. Stripe collects and holds your card or other payment details and its own billing information — we never see or store your card number. What we store is your Stripe customer id, your subscription id and status, and which plan tier you are on, so we can provision the right level of access.
2.6 Marketing attribution
If you arrive from a tagged link — for example one in a marketing email — that link carries
campaign parameters such as utm_source and utm_campaign in its URL. While
you move from that landing page to the sign-up page, those parameters are carried along in
the address bar. Nothing is stored on your device to do this.
If you then create an account, the utm_source and utm_campaign values
are recorded against your account, so we can tell which campaign brought you to us.
Only those two values are kept, and only at sign-up. If you never sign up, nothing is retained. If
you would rather not pass them on, delete the utm_ parameters from the URL before you
continue, or navigate to cruisefeed.io directly.
2.7 Email we send you
We send transactional email — sign-up verification, welcome and billing messages — through Proton Mail's SMTP service. This requires your email address to be transmitted to and processed by Proton.
2.8 Business prospect data
Separately from all of the above, we collect business contact details about people we have not yet done business with, in order to send B2B marketing email. Because that data is not collected from you directly, it has its own section — see section 9.
3.Legal bases for processing
Under the UK GDPR and EU GDPR we must have a lawful basis for each use of your personal data. Ours are:
| What | Legal basis |
|---|---|
| Account creation, API key issuance, delivering the service, support | Contract (Art. 6(1)(b)) — necessary to provide the service you signed up for |
| Billing and subscription management | Contract (Art. 6(1)(b)), and legal obligation (Art. 6(1)(c)) for tax and accounting records |
| API request logging: IP, User-Agent, path, status | Legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse, debugging, and enforcing plan limits |
| Contact form enquiries | Legitimate interests (Art. 6(1)(f)), or steps prior to entering a contract (Art. 6(1)(b)) where you are asking about a plan |
| Authentication session cookies (section 4) | Contract (Art. 6(1)(b)) — necessary to sign you in and keep you signed in. Exempt from the ePrivacy/PECR consent requirement as strictly necessary to provide a service you requested |
Recording utm_source / utm_campaign against a new account | Legitimate interests (Art. 6(1)(f)) — understanding which marketing activity works. No information is stored on your device, so the PECR cookie rules do not apply |
| B2B prospecting email (section 9) | Legitimate interests (Art. 6(1)(f)) — direct marketing to business contacts at organisations whose role is relevant to our product |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is proportionate — the data involved is limited, business-context, and not sensitive. You can object at any time (see section 8), and we will stop unless we have compelling grounds not to. For direct marketing, we will always stop on request.
4.Cookies and analytics
4.1 We use no analytics and no marketing cookies
This site runs no analytics product — no Google Analytics, no alternative analytics tool, no tag manager. We use no advertising cookies, no remarketing, no social pixels and no other ad-tech. We do not track you across sites, and we do not build a profile of you.
We also store nothing on your device for marketing purposes. Campaign parameters travel in the
URL for the length of your visit and are read from it at sign-up (see section
2.6); no cookie, localStorage entry or similar identifier is written
to do it.
4.2 The only cookies on this site
The only cookies set are those our authentication provider, Clerk, needs to sign you in and keep you signed in across pages. They are set on the sign-in, sign-up and dashboard pages and on our home page, which loads the sign-in component.
| Set by | Purpose | Category |
|---|---|---|
| Clerk (authentication) | Maintains your login session and protects against session hijacking and cross-site request forgery | Strictly necessary |
Strictly necessary cookies are those without which a service you have asked for cannot work — you cannot have an account area without a way to know you are signed in. Under the ePrivacy Directive and the UK PECR (reg. 6(4)) these are exempt from the consent requirement.
This is why you are not asked to accept cookies on this site. A consent banner is required for cookies and similar storage that are not strictly necessary. We set none, so there is nothing for you to consent to or refuse. If that ever changes, we will ask for your consent before setting anything, and this policy will say so.
You can still clear or block these cookies in your browser settings; if you block them, signing in will not work.
4.3 Third-party assets
Loading a page on this site makes no requests to any third party. The fonts, icons, stylesheets and images our pages use are all served from our own domain. Requesting a file from someone else's content delivery network would necessarily disclose your IP address and User-Agent to that network before you could object, so we host them ourselves instead.
The exceptions are things you actively choose to do, and only at the moment you do them: signing in or creating an account contacts Clerk, submitting the enquiry form sends it to Web3Forms, and starting a subscription contacts Stripe. Each is described in section 5.
5.Who we share data with
We do not sell personal data. We share it only with the service providers below, each of which processes it on our instructions to run part of the service:
| Provider | What they do for us | Data involved |
|---|---|---|
| Clerk | Authentication and account management | Email address, login credentials, session data |
| Stripe | Payments and subscription billing | Payment details, billing contact, subscription records |
| Supabase | Managed PostgreSQL — our primary data store | Account records, API key metadata, request logs |
| Amazon Web Services | S3 object storage and Lambda functions for the data pipeline; hosting | Stored datasets and operational logs |
| Cloudflare | CDN and DNS in front of the site, R2 object storage, and Workers hosting our MCP server | Request metadata including IP address and User-Agent |
| Web3Forms | Relays enquiry-form submissions to us by email | Everything you put in the enquiry form |
| Proton | Transactional email delivery | Recipient email address and message content |
| Instantly / Smartlead | Sends our B2B marketing email (see section 9) | Prospect business contact details and engagement data |
| Apify and email-verification providers | Sourcing and verifying business contact data (see section 9) | Publicly listed business contact details |
We may also disclose personal data where we are legally required to — for example in response to a valid legal request — or to establish or defend legal claims. If the business is ever sold or merged, account data may transfer to the buyer, who would remain bound by this policy.
6.International transfers
Most of the providers above are established in the United States, and some operate globally. Using them means your personal data is transferred outside the UK and the EEA.
These transfers now all arise from running the service itself — authentication, billing, hosting, email. No data is transferred for analytics or marketing-measurement purposes, because we no longer run an analytics product. Since our fonts, icons and images are served from our own domain, simply loading a page no longer discloses your IP address to any overseas provider.
Where that happens, we rely on the Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where UK data is involved), incorporated into our data processing agreements with those providers, together with their own technical and organisational safeguards. Where a provider is certified under the EU–US Data Privacy Framework and its UK extension, we may rely on that instead. You can ask us for details of the safeguards applied to a particular transfer by emailing [email protected].
7.How long we keep data
We keep personal data only for as long as we need it for the purposes described in this policy. How long that is depends on the type of data and why we hold it, so instead of a single fixed period we apply the criteria below. We may keep data for longer where the law requires it, or where we need it to establish, exercise or defend a legal claim.
| Data | How long we keep it |
|---|---|
| API request logs (IP, User-Agent, path, status) | A limited period only, for security monitoring, abuse prevention and troubleshooting — deleted once no longer needed for those purposes |
| Account data (email, company, use case, API key hash and prefix) | For as long as you have an account with us, and for a limited period afterwards so we can deal with billing queries, disputes and reinstatement requests |
| Billing and transaction records | For as long as tax, accounting and company law require us to keep them |
| Enquiry-form submissions and support email | For as long as we need them to answer you and to keep a reasonable record of our correspondence |
| Prospect data used for B2B marketing (section 9) | Until you ask us to stop, or until the data is no longer relevant to our business-to-business marketing — whichever comes first |
| Suppression / do-not-contact list | Indefinitely — we keep the minimum needed (your email address) precisely so we do not contact you again |
utm_source / utm_campaign recorded at sign-up | For as long as the account exists — it is a field on the account record, not separate storage |
You can ask us how long we hold a particular category of data, or ask us to delete it, by emailing [email protected] — see section 8.
8.Your rights
If the UK GDPR or EU GDPR applies to you, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted, where we have no overriding reason to keep it (we must, for example, keep billing records for tax purposes).
- Restriction — have us pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Object — object to processing based on legitimate interests. If you object to direct marketing, we will stop, always and without question.
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing carried out before you withdrew. In practice we currently rely on consent for nothing: we set no non-essential cookies and run no analytics, so there is no consent to withdraw.
- Not be subject to automated decision-making that produces legal or similarly significant effects. We do not carry out any such decision-making.
How to exercise them: email [email protected]. Tell us what you want and, if you are a customer, which email address your account uses. We will respond within one month. We may ask you to confirm your identity before we act — enough to be sure we are not disclosing your data to someone else, and no more. We do not charge for this, unless a request is manifestly unfounded or excessive.
9.Business prospect data — if we emailed you first
CruiseFeed runs an outbound business-to-business email programme. If you received a message from us and did not sign up or contact us first, this section is the notice we owe you under Article 14 of the GDPR, which covers personal data obtained from somewhere other than you.
9.1 What we hold
Business contact details only: your name, job title or role, employer or company, work email address, your company's website domain, your LinkedIn profile URL, your general business location, and our record of whether an email to you was delivered, opened, replied to, or bounced. We do not seek or store personal email addresses, home addresses, phone numbers of a personal nature, or any special-category data.
9.2 Where we got it
From publicly accessible sources — professional networking and business-listing profiles, company websites and public business directories — collected through third-party data-sourcing tools (principally Apify and its published scrapers) and checked with commercial email-verification services. We do not buy contact lists compiled by data brokers.
9.3 Why, and on what basis
We use it to send a small number of relevant business emails about CruiseFeed to people whose role suggests our cruise data may be useful to their organisation. Our legal basis is legitimate interests (Art. 6(1)(f)) — promoting a B2B product to relevant business contacts at their work address. We have carried out a balancing assessment: the data is limited to the professional sphere, obtained from sources you or your employer made public, and messaging is low-volume and role-relevant. Where local law requires consent for marketing email, we do not send without it.
Marketing email is sent through a third-party cold-email platform (Instantly / Smartlead) and from a separate sending domain, not from cruisefeed.io. Replies still reach us.
9.4 How to make it stop
Any of these works, and none of them requires you to explain yourself:
- Reply to the email with “unsubscribe”, “remove me”, or anything to that effect.
- Use the unsubscribe link in the email.
- Email [email protected] and ask to be removed.
On request we suppress your address — we add it to a permanent do-not-contact list and remove the rest of your record from our prospecting data. Keeping the address on the suppression list is the only way to guarantee we never contact you again; if you would prefer full erasure instead, say so and we will do that too. You can also ask us at any time what we hold about you and where specifically it came from, and we will tell you.
10.California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, use and disclose; to request deletion of it; to request correction of inaccurate information; and not to be discriminated against for exercising those rights. The categories we collect and our purposes are set out in sections 2 to 7 above.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. We run no advertising or remarketing technology on this site. We have not sold or shared personal information in the preceding 12 months, including that of anyone we know to be under 16.
We do not use or disclose sensitive personal information beyond the purposes permitted under the CCPA, so there is nothing to limit under the "Limit the Use of My Sensitive Personal Information" right.
To exercise any of these rights, email [email protected]. You may use an authorised agent; we will ask for proof of their authority. We will verify your request by matching the details you give us against what we already hold.
11.Children
CruiseFeed is a business-to-business service. It is not directed at children, we do not market to them, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, email [email protected] and we will delete it.
12.Security
API keys are stored as hashes, never in plain text. Traffic to the site and API is served over HTTPS. Access to production systems is limited to those who need it. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the data we hold. If you believe you have found a security or privacy issue, please tell us at [email protected].
13.Complaints
If you are unhappy with how we have handled your personal data, please raise it with us first at [email protected] — we would rather fix it.
You also have the right to complain to a data protection supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113). If you are in the EEA, you may complain to the supervisory authority in the country where you live or work, or where you believe the problem occurred.
14.Changes to this policy
We may update this policy as the service changes or the law does. When we do, we will update the “last updated” date above. If a change materially affects how we use your personal data, we will give active customers reasonable notice by email before it takes effect.
15.Contact
Privacy questions, rights requests and marketing opt-outs:
[email protected].
Anything else: [email protected].
If you need a postal address to serve a formal notice or a data-protection request, ask at [email protected] and we will provide it.