PortPal
Menu

Privacy Policy

Effective 7 September 2026

This Privacy Policy explains how PortPal (“PortPal”, “we”, “us”) collects, uses, shares and protects information when you use the PortPal mobile app and the website at portpal.io (together, the “Service”). It applies from 7 September 2026. By using the Service you agree to the practices described here.

Summary

  • We do not sell, rent or trade your personal information.
  • We collect what the app needs to work: your account, your sailing, your bookings, and what you post or send to other passengers.
  • Your address book, calendar and location are read only when you use the feature that needs them, and your contacts never leave your phone.
  • Excursion operators receive only what they need to run your booking. Card details go to a payment processor and never touch our servers.
  • You can see, correct, export or delete your data by emailing us, and delete your account from inside the app.

The full policy follows. Nothing in the summary limits it.

1. Who we are

The Service is operated by PortPal LLC (“PortPal”), which is the data controller for the personal information described in this policy.

2108 N St, Ste N, Sacramento, CA 95816, USA

You can reach us about anything in this policy at team@portpal.io.

2. Information we collect

2.1 Information you give us

  • Account details: your name, the display handle other passengers see, and either an email address and password or an identifier from Apple if you use Sign in with Apple. Passwords are stored only as a salted hash.
  • Your sailing: the ship and sail date, and, if you choose to add them, your cabin number and a short bio.
  • Bookings: the excursions you save, book, join a waitlist for or cancel; the departure you choose; the number of adults and children in your party; and the name and email address on the ticket.
  • Content: posts and replies on your sailing's feed, messages to your party, to others on the same excursion and to your cabin, questions you ask about an excursion, and reviews you write.
  • Safety records: the passengers you mute, block or report, so that the block keeps working and the report can be acted on.
  • Waitlist: the email address you enter on this website to be told when PortPal launches.

2.2 Information collected automatically

Product events inside the app — exactly this list, kept in the app's own words so this page cannot describe a different set of events than the app actually sends:

  • You open an excursion's details.
  • You pick a time for an excursion.
  • You set how many adults and children are booking.
  • You tap to book an excursion.
  • You join the waitlist for a sold-out time.
  • You accept a waitlist seat that opened up.
  • You send a running-late notice for a booking.
  • A booking is confirmed.
  • A booking is declined.
  • A booking hands off to the operator's own booking flow.
  • You share a booking confirmation.
  • You join the chat for a booking.
  • You view your list of excursions.
  • You start planning a port day.
  • You start planning a day an operator gave back.
  • You view a booking's ticket.
  • A booking is cancelled, and why.
  • A booking's date or party size is amended.
  • You are checked in for an excursion.
  • You submit a review.
  • The app is opened.
  • The app is put in the background, and for how long that use lasted.

Each event is tied to the excursion or booking and the action itself, not to an advertising identifier, and there is no third-party analytics or advertising SDK in the app.

  • Server logs: when your device talks to our servers, the servers record the request, the time and the network address it came from, as every web service does.
  • This website's visit log: one line per page you open, with the page, the time, the network address your device connects from and the country and city it maps to, the page that linked you here, and your browser and language. If you act on the site, such as opening a question or joining the waitlist, the action is logged too. The log is ours, kept for a short period by our host, and used only to see how the site is used. It sets no cookie and no identifier in your browser, and nothing on this site loads a third-party analytics script, a tracking pixel or an advertising network.
  • A push notification token, if you allow notifications. It identifies the app on your device so we can deliver a notification; it does not identify you.

2.3 Information from your device, with your permission

  • Contacts: if you use the feature that finds which of your contacts are already aboard, the app reads display names from your address book and compares them on your device with the people already on your sailing. No contact, no number and no hash of either is sent to us, and closing the screen discards what was read.
  • Calendar: if you add an excursion to your calendar, the app writes one event to the calendar you choose. It does not read your other events.
  • Location: the app can ask for your position to answer one question, whether you can make it back to the ship from where you are. It asks only when you use that feature and only while the app is open. Your position is used on the device and is not stored or shared by us.

Each of these permissions can be withdrawn at any time in your phone's Settings, and the app keeps working without them.

2.4 Payment information

Card details never touch our servers. They are entered into and held by a payment processor, and we keep only the processor's reference for the payment method and the last four digits, so the card can be named in a list. Refunds are issued through the same processor.

3. How we use information

  • To run the Service: sign you in, show the ports and hours of your sailing, and work out which excursions fit them.
  • To make and manage bookings: take payment through the processor, send tickets and receipts, handle waitlists, changes, cancellations and refunds.
  • To let passengers on the same sailing find and talk to each other, within the audience settings you choose.
  • To send notifications you have asked for: booking confirmations, reminders timed to your port call and the excursion's check-in time, and messages.
  • To keep the Service safe: enforce mutes and blocks, act on reports, prevent abuse and secure accounts.
  • To understand how the booking flow is used and improve it, using the product events described above.
  • To meet legal obligations, such as keeping records of transactions.

We do not sell, rent or trade personal information. We do not use an advertising identifier, and we do not profile you across other apps or websites.

4. Accuracy of cruise, port and excursion data

Port stops, docking and all-aboard times, meeting points and excursion details come from published schedules, our own datasets and the operators who run the excursions. Any of it can be wrong or can change on the day. Where a time is estimated rather than published, or a meeting point is approximate, the app says so on the screen. PortPal is a planning tool; being back on board before your ship sails remains your responsibility, as the Terms explain. If you spot an error, tell us at team@portpal.io and we will correct it.

5. Third-party services

We use a small number of service providers to run the Service. Each processes information only on our instructions and under its own privacy policy.

  • Amazon Web Services hosts our servers, database and files in the United States and delivers the emails we send.
  • Vercel hosts this website.
  • Formspree receives the waitlist form on this website.
  • Apple provides Sign in with Apple and the Apple Push Notification service; Expo relays push notifications to Apple.
  • Mapbox draws the maps. When a map is on screen Mapbox receives requests for the map tiles of that area, and when the app draws the walk from the pier to a meeting point it sends Mapbox those two coordinates. Neither is your location.
  • A payment processor takes card payments and issues refunds.
  • Sentry receives a report when the app, our servers or this website fails: the error, where in our code it happened, the device or browser and its operating system, and the page or screen. It does not receive your name, email address, card details or location, and we use it only to find and fix defects.

We do not integrate advertising networks, data brokers or third-party analytics services, and no such service receives information from the app or this website.

6. How we share information

6.1 Other passengers

Your cabin number, your bio and the excursions you are doing each carry their own audience setting, and the narrowest is Nobody. Set a thing to Nobody and it is withheld from other passengers entirely, without any sign that you withheld it. Your party sees what you share with your party; other passengers on your sailing see what you share with the sailing; nobody outside your sailing sees any of it.

6.2 Excursion operators

When you book, the operator running the excursion receives what they need to run it and take you on it: the name on the ticket, the size of your party, the date and departure, and your ship. They do not receive your cabin number, your bio, your other bookings or who else is in your party.

6.3 Legal requirements and safety

We disclose information if a court or authority with jurisdiction requires it, or where necessary to protect someone's safety or the integrity of the Service. We will tell you unless the law prevents it.

6.4 Business transfers

If PortPal is sold, merged or reorganised, your information may be transferred as part of that transaction, under this policy, and you will be told before it happens.

7. Data retention

  • Account, profile, sailing, posts, messages and inbox notifications: for as long as your account exists. Deleting the account removes them, along with the in-app usage and product-event records described in section 2.2.
  • Bookings, receipts and refunds: for as long as consumer and tax law require a record of the transaction, then deleted. That record holds the booking, not your profile.
  • Mutes, blocks and reports: for as long as needed to keep the block working and to act on the report.
  • Push tokens: until you turn notifications off, sign out of the device or delete the account.
  • The waitlist address: until the launch email has been sent, or until you ask us to remove it.
  • Server logs and this website's visit log: a short period set by the host, then discarded.
  • Deleting your account removes it from what the app and our servers show immediately. Our database keeps a point-in-time backup for up to 35 days after any change, including a deletion, so it can recover from a fault; a deleted account is not restored from that backup, and it ages out on its own within that window.

8. Data storage, deletion and your choices

Your account and booking data are stored on our servers in the United States. Anything read from your contacts or your location stays on your device and is not stored by us.

  • Delete your account from inside the app. This removes your profile, sailing, bookings, posts and messages as described in section 7.
  • If you signed in with Apple, also revoke PortPal in your Apple ID settings.
  • Turn notifications, contacts, calendar or location access off at any time in your phone’s Settings.
  • Change what other passengers can see in the app's audience settings.
  • Email us to have your waitlist address removed, or to have any of your data corrected or deleted.

9. Security

Everything between your device and our servers travels over TLS. Passwords are stored as salted hashes. Card numbers are never stored by us. Access to our systems is limited to the people who operate PortPal. No system is perfectly secure; if a breach affects your information we will notify you, and any regulator we are required to, without undue delay.

10. International transfers

PortPal is operated from the United States and its servers are there. If you use the Service from the European Economic Area, the United Kingdom or elsewhere, your information is transferred to and processed in the United States. Where the law requires, we rely on standard contractual clauses or an equivalent safeguard for those transfers.

11. Your rights

Wherever you live, you can ask what information we hold about you, have it corrected, have it deleted, receive a copy of it, object to a particular use of it, or withdraw consent you gave earlier. Write to team@portpal.io. There is no charge and no form, and we respond within a month or sooner.

11.1 European Economic Area and United Kingdom

Our legal bases are: performance of our contract with you, for account, sailing, booking and messaging data; your consent, for notifications, contacts, calendar and location; and our legitimate interests in keeping the Service secure and understanding how it is used. You have the rights above under the GDPR and UK GDPR, and the right to lodge a complaint with your data protection authority.

11.2 California

California residents have the right to know what personal information we collect, use and disclose, to request its deletion, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we have not done so in the preceding twelve months.

12. Children's privacy

The Service is not directed at children under 13, and we do not knowingly collect personal information from them, in line with the Children's Online Privacy Protection Act (COPPA). A parent or guardian books for children by giving a count of children in the party; we do not ask for a child's name or any other detail. If you believe a child has given us personal information, contact us at team@portpal.io and we will delete it.

13. Changes to this policy

We may update this policy as the Service changes. When we do, we post the new version here with a new effective date, and for material changes we email account holders and the waitlist rather than change it quietly.

14. Contact

Questions, requests and complaints about this policy go to team@portpal.io and reach a person.