๐Ÿ”’ Security & trust

Your data is protected โ€” and always yours.

We run a marina's money, its customer records and โ€” when owners connect their boats โ€” live position data. We take that seriously. Here's plainly how navdeck protects it, who we share it with, and why leaving is always easy.

๐Ÿ’ณ Payments

your money never flows through us

Your own Stripe account

Marinas take card payments through their own Stripe account (Stripe Connect). Funds settle directly to your bank โ€” navdeck is never in the middle of your cash flow.

We never see card numbers

Card data is entered on Stripe's PCI-DSS Level 1 infrastructure and never touches our servers. We store only a payment reference and status.

No markup

You pay Stripe's standard processing rates. navdeck adds nothing on top of them.

๐Ÿ”“ Data ownership

no lock-in, ever

It's your data

Berths, vessels, contracts, invoices, payments, routes and the boat profile are yours. Full export to CSV / GPX / files on every plan, any time โ€” no "export request" ticket.

The boat identity transfers

A boat's equipment, documents and service history follow the boat to its next owner. Selling a boat shouldn't erase its story.

Downgrading never deletes

Drop to a lower plan and your data stays intact. Leaving should be easy โ€” that's what makes staying meaningful.

๐Ÿ‡ช๐Ÿ‡บ Privacy & GDPR

built on an EU base

EU-based operator

navdeck is operated from Malta, in the EU, under the GDPR. See our Privacy Policy for the full detail on data we process and why.

Your rights, honoured

Access, correction, export and deletion of personal data on request. For marinas we act as your data processor for the customer data you hold.

Owner-controlled sharing

Boat owners choose exactly what a marina or fleet can see โ€” from position-only up to full history โ€” and can revoke it instantly. Scopes are enforced server-side on every read.

๐Ÿ›ก๏ธ Platform security

the boring, important parts

Encrypted in transit

All traffic is HTTPS/TLS. The public edge runs on Cloudflare; a single hardened API gateway is the only door into our services.

Authenticated access

Logins are handled by a dedicated identity provider (Authentik, OIDC). Devices authenticate with per-device tokens, hashed at rest and revocable.

Isolation by design

Each service has its own database and every organisation's data is scoped to its account. Internal service endpoints are never exposed to the internet.

Who we share data with (subprocessors)

We keep this list short and honest. We use trusted infrastructure providers to run the platform; each processes data only to deliver their part of the service:

The current, authoritative list lives in our Privacy Policy. If a subprocessor changes, we update it there.

Reporting a vulnerability

Found a security issue? We want to hear about it. Email info@navdeck.io with the details and we'll respond quickly. Please give us reasonable time to fix an issue before disclosing it publicly โ€” we're a small team and we take reports seriously.

Questions about security or data protection?

We're happy to walk any marina or fleet through exactly how their data is handled.

Contact Privacy