Legal

Privacy Policy

Effective Date: January 27, 2026 · Last Revised: January 27, 2026

1. Introduction

CharterXO, LLC (“CharterXO,” “we,” “us,” or “our”) operates a yacht charter marketplace platform accessible via our website at charterxo.com and our mobile applications for iOS and Android (collectively, the “Platform”). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our Platform.

By accessing or using CharterXO, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our practices, please do not use our Platform.

Data Controller

CharterXO, LLC

801 S Miami Ave, Unit 1501

Miami, FL 33130

United States

Privacy Inquiries: privacy@charterxo.com

Legal Inquiries: legal@charterxo.com

2. Scope and Applicability

This Privacy Policy applies to:

  • Our website at charterxo.com
  • Our iOS mobile application
  • Our Android mobile application
  • All services provided through the Platform

This Privacy Policy covers all user types on our Platform, including:

  • Customers who search for and book yacht charters
  • Boat Owners who list vessels and manage bookings
  • Captains who operate vessels and manage schedules
  • Crew Members who support charter operations

This Privacy Policy does not apply to third-party websites, applications, or services that may be linked from our Platform. We encourage you to review the privacy policies of any third-party services you access.

Jurisdiction-Specific Rights: If you are a California resident or a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, please see Sections 8.2 and 8.3 for information about your additional privacy rights.

3. Personal Information We Collect

3.1 Information You Provide Directly

Account Registration (All Users)

InformationPurpose
First and last nameIdentity verification, personalization, communications
Email addressAccount access, notifications, communications
Phone numberOTP verification, SMS notifications, trip coordination
Date of birthAge verification (18+ requirement for accounts)
Profile photoPersonalization, identity recognition
Home townPersonalization

Boat Owners (Additional Information)

InformationPurpose
Business name and DBABusiness operations, legal compliance
Business addressTax compliance, payout processing
Articles of incorporationBusiness verification
FWC permit documentationRegulatory compliance
Tax receiptTax compliance
Insurance documentationRisk management, trust and safety
Bank account information (via Stripe)Payout processing

Captains and Crew (Additional Information)

InformationPurpose
Captain's license numberCredential verification
License issuing authorityCredential verification
License expiration dateCompliance monitoring
Insurance provider and policy numberRisk management
Identity verification documentsTrust and safety
Bank account information (via Stripe)Payout processing

Booking Guests

InformationPurpose
NameCharter agreement, waiver execution
Email addressBooking communications, waiver delivery
Phone numberTrip coordination, emergency contact
Electronic waiver signatureLegal protection, safety compliance

Communications: When you contact us or communicate through our Platform, we collect the content of your messages, including messages exchanged with boat owners, captains, crew members, customer support, and our AI-powered features.

3.2 Information Collected Automatically

Device and Technical Information

  • Device type and model
  • Operating system and version
  • Browser type and version
  • IP address
  • Unique device identifiers
  • App version and platform (iOS, Android, Web)

Usage Information

  • Pages and screens viewed
  • Features used and interactions
  • Search queries and filters applied
  • Booking flow activity
  • Time spent on the Platform
  • Referral sources

Location Information

For Captains During Active Charters: When a captain begins a booked charter trip, we collect real-time GPS location data including:

  • Latitude and longitude coordinates
  • Speed (in knots)
  • Heading (direction)
  • Altitude
  • Timestamps
  • Anchor point locations and duration

This voyage tracking data is collected for safety, insurance, and service quality purposes. GPS tracking is active only during booked charter trips and can be paused by the captain.

For All Users: With your permission, we may collect general location information to provide location-based search results and services.

3.3 Information from Third-Party Sources

Social Login Providers

If you choose to register or log in using a social account, we receive information from that provider:

  • Google Sign-In: Email address, name, profile photo
  • Apple Sign-In: Email address, name (if you choose to share)

Affiliate and Referral Partners

If you access our Platform through a referral or affiliate link, we may receive attribution information including referral source, campaign information, and affiliate identifiers.

4. How We Use Your Information

To Provide and Operate Our Services

  • Create and manage your account
  • Facilitate yacht charter bookings
  • Process payments and payouts
  • Enable communications between users
  • Provide customer support

To Verify Identity and Credentials

  • Verify your identity through OTP verification
  • Verify captain licenses and certifications
  • Verify business entity documentation for owners
  • Prevent fraud and unauthorized access

To Process Payments

  • Process booking payments from customers
  • Distribute payouts to boat owners, captains, and crew
  • Manage security deposits
  • Handle refunds and disputes
  • Maintain transaction records for tax and legal compliance

To Ensure Safety and Compliance

  • Track voyage routes for safety and insurance purposes
  • Send weather alerts and safety notifications
  • Facilitate electronic waiver signing
  • Monitor for policy violations
  • Respond to emergencies

To Improve Our Platform

  • Analyze usage patterns and trends
  • Develop new features and services
  • Conduct research and analytics
  • Train and improve our AI-powered features

To Communicate With You

  • Send booking confirmations and updates
  • Deliver trip reminders and notifications
  • Respond to your inquiries
  • Send marketing communications (with your consent)
  • Notify you of policy changes

AI-Powered Features

Our Platform includes AI-powered features to enhance your experience:

  • AI Concierge: Helps customers find and book charters through natural language conversation
  • XO Sidekick: Assists owners with fleet management and analytics
  • Dispute Analysis: Helps analyze and resolve booking disputes
  • Weather Analysis: Provides trip safety recommendations
  • Smart Messaging: Monitors communications for safety concerns
These AI features are powered by Google Gemini. When you use AI features, your messages and relevant context are sent to Google's servers for processing. Google processes this data in accordance with their privacy policy and does not retain your message content after processing.

6. How We Share Your Information

6.1 Service Providers

CategoryInformation SharedPurpose
Cloud Infrastructure ProvidersAccount data, bookings, messagesDatabase hosting, authentication, cloud storage, serverless functions
Payment ProcessorsName, email, payment information, bank account detailsPayment processing, payout distribution
Communication ProvidersUser ID, email address, phone number, notification preferencesPush notifications, SMS messages, email delivery, OTP verification
Analytics ProvidersAnonymized user ID, usage events, screen viewsPlatform analytics and improvement
AI Service ProvidersChat messages, relevant contextAI-powered features (Concierge, Sidekick, dispute analysis)
Mapping and Location ProvidersLocation queries, coordinatesInteractive maps, geolocation services
Electronic Signature ProvidersGuest name, emailElectronic waiver and agreement signing
Attribution and Linking ProvidersUser ID, referral dataAffiliate tracking, deep linking

All service providers are contractually obligated to protect your information and use it only for the purposes for which it was disclosed. For specific inquiries about our service providers, please contact privacy@charterxo.com.

6.2 Other Users

  • When you book a charter: Your name, contact information, and booking details are shared with the boat owner and assigned captain
  • When you list a boat: Your business name and contact information are visible to potential customers
  • Group bookings: Guest names are shared with other guests in the booking for coordination purposes

6.3 Legal and Safety Disclosures

We may disclose your information when we believe it is necessary to:

  • Comply with applicable laws, regulations, or legal processes
  • Respond to lawful requests from government authorities, including law enforcement
  • Protect the rights, property, or safety of CharterXO, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues
  • Respond to emergencies involving potential threats to safety

6.4 Business Transfers

If CharterXO is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

6.5 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

6.6 We Do Not Sell Your Personal Information

CharterXO does not sell your personal information to third parties for monetary or other valuable consideration. We do not share your personal information with third parties for their direct marketing purposes.

7. Data Retention

Data TypeRetention PeriodReason
Active user accountsUntil you request deletionService provision
Financial and transaction records7 yearsTax and legal compliance
Completed booking records3 yearsDispute resolution, service improvement
Voyage GPS tracking data2 yearsInsurance, safety records
Analytics data1 yearPlatform improvement
AI conversation logs90 daysService improvement
Admin audit logs7 yearsCompliance, security
OTP verification codes10 minutesSecurity

When your information is no longer needed, we will securely delete or anonymize it.

8. Your Privacy Rights

8.1 Rights for All Users

Regardless of where you are located, you have the following rights:

  • Access your information: View and download the personal information we hold about you
  • Update your information: Correct or update your account information at any time
  • Manage notifications: Control your notification preferences in your account settings
  • Request deletion: Contact us at privacy@charterxo.com

8.2 California Residents (CCPA Rights)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request information about the categories and specific pieces of personal information we have collected
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions
  • Right to Opt-Out of Sale: CharterXO does not sell personal information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To Exercise Your CCPA Rights: Email privacy@charterxo.com. We will respond within 45 days.

California “Shine the Light” Law: California residents may also request information about our practices related to disclosing personal information to third parties for their direct marketing purposes.

Authorized Agents: You may designate an authorized agent to make a request on your behalf. We may require verification of the agent's authority.

8.3 EEA, UK, and Swiss Residents (GDPR Rights)

If you are a resident of the European Economic Area, United Kingdom, or Switzerland, you have the following additional rights:

  • Right of Access (Article 15)
  • Right to Rectification (Article 16)
  • Right to Erasure (Article 17)
  • Right to Restrict Processing (Article 18)
  • Right to Data Portability (Article 20)
  • Right to Object (Article 21)
  • Right to Withdraw Consent (Article 7)

To Exercise Your GDPR Rights: Email privacy@charterxo.com. We will respond within 30 days.

Data Protection Authority: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

International Data Transfers: We use Standard Contractual Clauses (SCCs) approved by the European Commission to safeguard your data when transferred outside the EEA.

9. SMS and Text Message Consent

By providing your phone number, you may receive the following types of text messages:

  • OTP verification codes
  • Booking confirmations and reminders
  • Trip status updates
  • Weather alerts
  • Captain and customer coordination

Consent: By providing your phone number and opting in, you consent to receiving text messages from CharterXO. Consent is not a condition of purchase.

Message Frequency: Message frequency varies based on your activity and preferences.

Message and Data Rates: Standard message and data rates may apply depending on your carrier and plan.

Opt-Out: You can opt out of SMS messages at any time by replying STOP to any message, adjusting your notification preferences in Settings, or emailing privacy@charterxo.com.

10. Cookies and Local Storage

Our Platform uses cookies and local storage technologies to enhance your experience.

Storage Types We Use

TypePurposeDuration
Session StorageTemporary session data, form stateBrowser session
Local StorageUser preferences, authentication tokensUntil cleared
Firebase Auth TokensAuthentication state persistenceUntil logout or expiry

Google Analytics Cookies

CookiePurposeDuration
_gaDistinguishes unique users2 years
_ga_*Maintains session state2 years
No Third-Party Advertising Cookies: CharterXO does not use third-party advertising cookies or tracking pixels. We do not participate in advertising networks or allow third parties to place cookies for advertising purposes.

11. Security

We implement appropriate technical and organizational measures to protect your personal information.

Authentication and Access Control

  • Phone-based OTP verification for account access
  • Social login integration (Google, Apple) with OAuth 2.0
  • Role-based access controls within the Platform
  • Secure session management

Data Protection

  • Encryption in transit (TLS/SSL)
  • Encryption at rest for sensitive data
  • Secure payment processing through Stripe (PCI DSS compliant)
  • Regular security assessments

Monitoring and Auditing

  • Administrative action audit logging
  • Automated security monitoring
  • Incident response procedures
No Absolute Security: While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.

12. Children's Privacy

Our Platform is not directed to children under the age of 18. You must be at least 18 years old to create an account on CharterXO.

Minors between the ages of 13 and 17 may participate as passengers on charter trips booked by an adult. In these cases, the booking adult is responsible for providing consent and managing any information related to the minor.

We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us at privacy@charterxo.com.

13. Account Deletion

You may request deletion of your account and associated data by contacting us at privacy@charterxo.com.

Permanently Deleted

  • Profile information and photos
  • Notification preferences
  • Saved searches and favorites
  • AI conversation history
  • Active session data

Anonymized and Retained

DataReasonRetention Period
Financial recordsTax and legal compliance7 years
Booking recordsDispute resolution3 years
Voyage tracking dataInsurance and safety2 years
Audit logsCompliance and security7 years

14. International Data Transfers

CharterXO is based in the United States, and your information is processed and stored on servers located in the United States.

If you are located outside the United States, please be aware that your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.

EEA/UK/Switzerland: We use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure appropriate safeguards for data transferred outside the EEA.

UK: We also rely on the UK International Data Transfer Agreement (IDTA) where applicable.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

Notification of Changes: We will notify you of material changes by posting the updated Privacy Policy on our Platform and updating the “Last Revised” date.

30 Days Notice: For material changes that significantly affect your rights or obligations, we will provide at least 30 days' notice before the changes take effect.

Your Continued Use: Your continued use of the Platform after any changes to this Privacy Policy constitutes your acceptance of the updated policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy Inquiries: privacy@charterxo.com

Legal Inquiries: legal@charterxo.com

CharterXO, LLC

Attn: Privacy Team

801 S Miami Ave, Unit 1501

Miami, FL 33130

United States