Legal
Last updated: 19 July 2026
YachtApply ("we", "us") operates the website and service at yachtapply.com. For the purposes of the EU/UK General Data Protection Regulation (GDPR) and South Africa's Protection of Personal Information Act (POPIA), we are the controller / responsible party for the personal information described in this policy.
Operator detail to complete: insert the registered legal entity name, registration number, and registered address here before this policy is relied upon publicly. If you process data of South African residents, POPIA requires a registered Information Officer — name and contact details for that person go here too.
Account & profile. Email address, a hashed password (we never store your password itself), full name, phone number, gender (used only to filter role-appropriate listings), your CV file, and structured data our system extracts from it (roles, certifications, regions, skills).
Job preferences. Target roles, work types, regions, certifications, skills, and minimum salary you set to control matching and auto-apply.
Email connection metadata. If you connect Gmail or Outlook, we store the connection's encrypted OAuth tokens and your connected address only. We request send-only permission (gmail.send / Mail.Send) — we cannot and do not read your inbox, contacts, or any other mail.
Billing. Subscription status and transaction records. Card details are entered directly with Stripe and never touch our servers.
Job listings. To build the job feed, we process posts from public Facebook groups to identify genuine vacancies. See section 4 for how this works and what we do with the posts of people who are not YachtApply users.
Some listings on YachtApply are identified from posts made in public Facebook groups by people who are not YachtApply users and have not interacted with us directly. We take the following steps to limit what we retain about them:
If you posted in one of these groups and want a listing sourced from your post removed, contact us (section 9) and we will remove it.
We use the following processors to run the service. None of them are permitted to use your data for their own purposes.
| Provider | Purpose | What they receive |
|---|---|---|
| Amazon Web Services (Lightsail) | Hosting, EU (Ireland) | All account and application data |
| Cloudflare (R2) | CV file storage | Your uploaded CV file |
| Stripe | Payment processing | Billing/payment details — never your card number, direct to Stripe |
| Apify | Public Facebook group scraping | No personal data about you — only public post content |
| Google (Workspace / Cloud) | Transactional email, Gmail OAuth, AI matching | Your email address; send-only mailbox access if connected |
| Microsoft | Outlook OAuth | Send-only mailbox access, only if you connect Outlook |
Under GDPR and POPIA you have the right to access, correct, delete, and export your personal data, and to object to or restrict how we process it. In practice:
Passwords are hashed, never stored in plain text. OAuth tokens for connected mailboxes are encrypted at rest. The site is served entirely over HTTPS. Access to production systems is limited to the operator.
For any question about this policy or to exercise a data right, email info@yachtapply.com.
We'll update the date at the top of this page when this policy changes. Material changes will be communicated by email where we hold one for you.