1. Scope and contact
This Privacy Policy explains how Yachtbase handles information submitted through yachtbase.co and information processed when you use Yachtbase products and services, including connected business mailboxes.
For privacy questions or rights requests, email hello@yachtbase.co. Please do not send passwords, payment credentials or sensitive personal information by email.
2. Information we collect
Depending on how you use the website, we may receive your name, email address, phone number, company and message content when you contact us. We also process consent choices, basic device and request information, and security signals needed to protect the website.
3. Why we use information
We use this information to respond to enquiries, arrange product conversations, provide support, prevent abuse, protect the service, remember cookie choices and measure public-site use when optional analytics consent is granted.
4. Legal bases
Depending on the context, processing is based on responding to a request, taking steps at your request, legitimate interests in operating and securing the website, legal obligations, or consent for optional analytics and similar technologies.
5. Google Gmail data
When an authorized user chooses to connect a business Gmail mailbox to Yachtbase, Yachtbase uses Google OAuth and the Gmail API to access the Gmail data needed to provide the connected shared inbox. Depending on the mailbox settings and user actions, this may include the Gmail account email address, message and thread metadata, headers, message content, attachments, labels and Gmail history.
By connecting Google, you authorize Yachtbase to access and process Gmail data for the shared inbox features described in this Privacy Policy. Because this is a shared inbox, you also authorize Yachtbase to make synchronized conversations available to authorized members of the customer’s Yachtbase workspace according to workspace permissions. We use this information to synchronize and display business email conversations, provide Gmail search and folder views, send new emails and replies, manage drafts, and synchronize or apply mailbox labels and message states such as read, unread, archive and Trash.
Imported Gmail message content, metadata and selected attachments may be stored in the customer’s Yachtbase workspace. Yachtbase personnel do not routinely read Gmail message content; any exceptional access is limited to a user-requested support action involving specific data, security investigation, or legal compliance, with access controls. Disconnecting a mailbox stops future synchronization and removes the stored OAuth credentials. Users can also use Yachtbase’s mailbox controls to clear imported Gmail data.
6. Meta messaging data
When an authorized user chooses to connect a Facebook Page or Messenger account, Instagram professional account, or WhatsApp Business account to Yachtbase, Yachtbase uses Meta’s authorization tools, APIs and webhooks to access the data needed to provide the connected social inbox. Depending on the connected service and user actions, this may include account, Page, business, WhatsApp Business Account and phone identifiers; display names, usernames, profile names and business profile information; connection and permission metadata; message and conversation identifiers; sender and recipient identifiers; message content; timestamps; attachments or message payloads supplied by Meta; and delivery, read and error statuses.
By connecting Meta, you authorize Yachtbase to access and process Facebook Messenger, Instagram, and WhatsApp data for the social inbox features described in this Privacy Policy. We use this information to synchronize and display customer conversations in the authorized Yachtbase workspace, backfill recent conversations where supported, allow authorized team members to send replies, and show message delivery and read status. Meta webhook event records may be stored with the related conversation so that the inbox remains synchronized and auditable.
Meta message content, metadata and connection records may be stored in the customer’s Yachtbase workspace. Access is limited to authorized members of that customer workspace according to workspace permissions. Disconnecting a Meta channel stops future receiving and sending for that channel and clears its saved access token; existing conversations may remain in the workspace unless removed under the customer’s retention or deletion controls.
7. Sharing and disclosures
For Google Gmail data, transfers are limited to hosting, database, object-storage and background-processing providers acting on Yachtbase’s behalf only as necessary to provide the connected mailbox and shared inbox features, and only after the user’s affirmative consent; to security providers or personnel when necessary to investigate abuse or protect the service; to comply with applicable laws or regulations; or as part of a merger, acquisition or sale of assets after obtaining the user’s explicit prior consent. At the user’s direction and affirmative action, email content is transmitted to recipients selected by the user when an email is sent.
For Meta messaging data, we may use hosting, database, object-storage and background-processing providers acting on Yachtbase’s behalf only as necessary to provide the connected social inbox features. We also use carefully selected providers for website hosting, security, email delivery, CAPTCHA protection and optional analytics. Providers receive only the information needed for their service and are required to protect it under applicable agreements.
Yachtbase does not sell Google or Meta user data, use it for advertising or retargeting, use it for creditworthiness or lending decisions, or use it to train generalized artificial-intelligence or machine-learning models. We may disclose information when required by law or for security purposes. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
8. Retention and security
We keep information only for as long as needed for the purpose collected, a continuing relationship, legal requirements, dispute handling or security records. Customer workspace retention is generally controlled by the customer’s configuration and agreement with Yachtbase.
We use access controls, encrypted connections, encrypted credential storage and operational safeguards designed to protect information. No internet service can guarantee absolute security.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection to processing. Where processing relies on consent, you may withdraw it at any time. Contact hello@yachtbase.co and include enough information for us to understand the request.
10. Changes
We may update this policy when the website, products, providers or legal requirements change. The effective date above identifies the current published version.