This policy describes how Goose Yard Sailing AB (“Goose Yard”, “we”) processes personal data when you use Nordic Stars, the sailing performance and navigation service at nordicstars.ai, or visit our website.
1. Data controller
Goose Yard Sailing AB, a Swedish limited company (aktiebolag), org. nr. 559489-8594, with its registered office in Sweden, is the data controller for the processing described here — except for personal data inside your team’s telemetry and tracking data, where your organisation is the controller and we process on its behalf under the Data Processing Agreement.
Privacy contact: privacy@nordicstars.ai
2. What data we collect
2.1 Account data
Name, email address, organisation name and your role in it, authentication identifiers (we use Google Cloud Identity Platform; with Google sign-in we receive your Google account email), and account settings.
2.2 Billing data
Billing contact, country and VAT ID where applicable, and subscription history. Card details are collected and processed by Stripe — they never touch our servers.
2.3 Telemetry and race content
The instrument logs your team uploads, the telemetry Race Control streams live from on board, and the analytics derived from them (positions, speeds, wind, boat state over time), race events, and fleet tracking data retrieved from providers at your instruction. These recordings can embed personal data — for example GPS traces of crewed boats, competitor names or sail numbers in official feeds. Your organisation controls this content; we process it under the DPA.
2.4 Video metadata
Onboard video never uploads — the player links files on your own machine. We store only file fingerprints, names, durations and alignment offsets so clips re-attach across sessions.
2.5 Usage and security data
Server logs (IP address, timestamps, requests), session records and audit events — used to run and secure the Service.
2.6 Support and communication data
Emails you send us and our replies.
2.7 Website visitors
The marketing site sets no analytics or marketing cookies; see the Cookie Policy. If you allow the analytics category, we measure how the marketing pages are used through Plausible — a cookieless service that records aggregate usage: the page, where you arrived from, country and device type, and when a visit clicks a link off the site, downloads a file or submits a form. It records no field you fill in, builds no profile of you and follows you to no other website. It never runs in the app. Standard web-server logs (IP, user agent) apply.
3. Legal bases
| Processing | Legal basis (GDPR Art. 6) |
|---|---|
| Account, sign-in, providing the Service | Contract performance (6(1)(b)) |
| Billing and invoicing via Stripe | Contract performance; legal obligation (6(1)(b), (c)) |
| Security monitoring, abuse prevention, audit logs | Legitimate interest (6(1)(f)) — keeping the Service secure |
| Service emails (invites, receipts, notices) | Contract performance (6(1)(b)) |
| Bookkeeping records | Legal obligation (6(1)(c)) — Swedish accounting law |
| Telemetry and race content | Processed on your organisation’s behalf under the DPA — the organisation holds the legal basis |
We do not use personal data for marketing without consent, and we do not make automated decisions with legal effect.
4. Sharing and subprocessors
We do not sell personal data and we do not share it with advertisers. We use a small set of subprocessors to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform (incl. Google Cloud Identity Platform) | Infrastructure, storage, sign-in | EU — europe-north1 (Finland) |
| Stripe | Payments, invoicing, tax | EU / US (SCCs, EU-US Data Privacy Framework) |
| Twilio SendGrid | Transactional email (invites, notices) | EU / US (SCCs, EU-US Data Privacy Framework) |
| Plausible Analytics | Marketing-site analytics — cookieless, only with your consent, never in the app | EU — Germany |
Race tracking providers are data sources, not subprocessors: when your organisation connects its own provider credentials (currently GEORACING), we retrieve fleet data from the provider at your instruction. The provider processes your relationship with it under its own terms.
Third-party content your browser loads: in the signed-in app, your browser fetches some content directly from third parties. They receive your IP address and standard request data, and nothing else from us: no Customer Data, no account details. They are not subprocessors and we store nothing with them.
- OpenFreeMap — the base map on every map in the app (race plans, marks, weather, routing).
- Kartverket (Norway) and NOAA(United States) — official chart images, only while the official chart layer is switched on in the race plan editor. It is off by default and the choice is remembered in your browser.
- YouTube — its video player, only in a debrief where your team has linked a YouTube video. The player loads in YouTube’s privacy-enhanced mode (youtube-nocookie.com) and sets no cookies until you press play. YouTube’s own privacy policy applies to that player.
Weather, sea-model and chart files download from Google Cloud Storage in the EU, listed above.
We may disclose data where required by law (with notice to you unless prohibited) and in a merger or acquisition (with notice).
5. International transfers
The Service runs in the EU (Google Cloud europe-north1, Finland). Where a subprocessor involves transfers outside the EU/EEA (Stripe, SendGrid), we rely on adequacy decisions including the EU-US Data Privacy Framework and on EU Standard Contractual Clauses.
6. Retention
| Data | Retention |
|---|---|
| Account data | Account lifetime + 30 days after deletion |
| Telemetry and race content | Until your organisation deletes it or the account closes (30-day export window, then deletion) |
| Billing records | 7 years (Swedish accounting law) |
| Security and server logs | 12 months |
| Support correspondence | 3 years |
7. Your rights
Under the GDPR you can:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have data erased where the conditions apply (Art. 17);
- restrict processing during verification or objection (Art. 18);
- receive your data in a machine-readable format (Art. 20);
- object to processing based on legitimate interest (Art. 21) — an absolute right for direct marketing;
- withdraw consent at any time, without affecting prior processing.
Write to privacy@nordicstars.ai. We respond within 30 days (extendable by 60 for complex requests) and may need to verify your identity. If your request concerns data inside an organisation’s telemetry or race content, we will refer it to that organisation as controller.
You can also lodge a complaint with the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden — imy.se, imy@imy.se.
8. Security
- Encryption in transit (TLS) and at rest (AES-256, Google Cloud default encryption).
- Per-organisation data isolation enforced in the application and database layer.
- Role-based access on the principle of least privilege; administrative access requires recent re-authentication.
- Continuous monitoring and audit logging of administrative actions.
- Personal-data breaches are notified to the supervisory authority within 72 hours where required, and affected customers are informed without undue delay.
9. Children
The Service is not directed to children under 16, and we do not knowingly process their data outside organisation-controlled content. If you believe a child under 16 has created an account, contact privacy@nordicstars.ai and we will delete it promptly.
10. Cookies
See the Cookie Policy — one strictly necessary first-party session cookie, and cookieless analytics on the marketing pages once you allow them.
11. Changes
We will announce material changes to this policy by email or in-Service notice at least 30 days before they take effect, and update the date above.
12. Contact
Goose Yard Sailing AB
Privacy: privacy@nordicstars.ai
General: hello@nordicstars.ai