Privacy Policy
Effective Date: January 27, 2026 · Last Revised: January 27, 2026
1. Introduction
CharterXO, LLC (“CharterXO,” “we,” “us,” or “our”) operates a yacht charter marketplace platform accessible via our website at charterxo.com and our mobile applications for iOS and Android (collectively, the “Platform”). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our Platform.
By accessing or using CharterXO, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our practices, please do not use our Platform.
Data Controller
CharterXO, LLC
801 S Miami Ave, Unit 1501
Miami, FL 33130
United States
Privacy Inquiries: privacy@charterxo.com
Legal Inquiries: legal@charterxo.com
2. Scope and Applicability
This Privacy Policy applies to:
- Our website at charterxo.com
- Our iOS mobile application
- Our Android mobile application
- All services provided through the Platform
This Privacy Policy covers all user types on our Platform, including:
- Customers who search for and book yacht charters
- Boat Owners who list vessels and manage bookings
- Captains who operate vessels and manage schedules
- Crew Members who support charter operations
This Privacy Policy does not apply to third-party websites, applications, or services that may be linked from our Platform. We encourage you to review the privacy policies of any third-party services you access.
3. Personal Information We Collect
3.1 Information You Provide Directly
Account Registration (All Users)
| Information | Purpose |
|---|---|
| First and last name | Identity verification, personalization, communications |
| Email address | Account access, notifications, communications |
| Phone number | OTP verification, SMS notifications, trip coordination |
| Date of birth | Age verification (18+ requirement for accounts) |
| Profile photo | Personalization, identity recognition |
| Home town | Personalization |
Boat Owners (Additional Information)
| Information | Purpose |
|---|---|
| Business name and DBA | Business operations, legal compliance |
| Business address | Tax compliance, payout processing |
| Articles of incorporation | Business verification |
| FWC permit documentation | Regulatory compliance |
| Tax receipt | Tax compliance |
| Insurance documentation | Risk management, trust and safety |
| Bank account information (via Stripe) | Payout processing |
Captains and Crew (Additional Information)
| Information | Purpose |
|---|---|
| Captain's license number | Credential verification |
| License issuing authority | Credential verification |
| License expiration date | Compliance monitoring |
| Insurance provider and policy number | Risk management |
| Identity verification documents | Trust and safety |
| Bank account information (via Stripe) | Payout processing |
Booking Guests
| Information | Purpose |
|---|---|
| Name | Charter agreement, waiver execution |
| Email address | Booking communications, waiver delivery |
| Phone number | Trip coordination, emergency contact |
| Electronic waiver signature | Legal protection, safety compliance |
Communications: When you contact us or communicate through our Platform, we collect the content of your messages, including messages exchanged with boat owners, captains, crew members, customer support, and our AI-powered features.
3.2 Information Collected Automatically
Device and Technical Information
- Device type and model
- Operating system and version
- Browser type and version
- IP address
- Unique device identifiers
- App version and platform (iOS, Android, Web)
Usage Information
- Pages and screens viewed
- Features used and interactions
- Search queries and filters applied
- Booking flow activity
- Time spent on the Platform
- Referral sources
Location Information
For Captains During Active Charters: When a captain begins a booked charter trip, we collect real-time GPS location data including:
- Latitude and longitude coordinates
- Speed (in knots)
- Heading (direction)
- Altitude
- Timestamps
- Anchor point locations and duration
This voyage tracking data is collected for safety, insurance, and service quality purposes. GPS tracking is active only during booked charter trips and can be paused by the captain.
For All Users: With your permission, we may collect general location information to provide location-based search results and services.
3.3 Information from Third-Party Sources
Social Login Providers
If you choose to register or log in using a social account, we receive information from that provider:
- Google Sign-In: Email address, name, profile photo
- Apple Sign-In: Email address, name (if you choose to share)
Affiliate and Referral Partners
If you access our Platform through a referral or affiliate link, we may receive attribution information including referral source, campaign information, and affiliate identifiers.
4. How We Use Your Information
To Provide and Operate Our Services
- Create and manage your account
- Facilitate yacht charter bookings
- Process payments and payouts
- Enable communications between users
- Provide customer support
To Verify Identity and Credentials
- Verify your identity through OTP verification
- Verify captain licenses and certifications
- Verify business entity documentation for owners
- Prevent fraud and unauthorized access
To Process Payments
- Process booking payments from customers
- Distribute payouts to boat owners, captains, and crew
- Manage security deposits
- Handle refunds and disputes
- Maintain transaction records for tax and legal compliance
To Ensure Safety and Compliance
- Track voyage routes for safety and insurance purposes
- Send weather alerts and safety notifications
- Facilitate electronic waiver signing
- Monitor for policy violations
- Respond to emergencies
To Improve Our Platform
- Analyze usage patterns and trends
- Develop new features and services
- Conduct research and analytics
- Train and improve our AI-powered features
To Communicate With You
- Send booking confirmations and updates
- Deliver trip reminders and notifications
- Respond to your inquiries
- Send marketing communications (with your consent)
- Notify you of policy changes
AI-Powered Features
Our Platform includes AI-powered features to enhance your experience:
- AI Concierge: Helps customers find and book charters through natural language conversation
- XO Sidekick: Assists owners with fleet management and analytics
- Dispute Analysis: Helps analyze and resolve booking disputes
- Weather Analysis: Provides trip safety recommendations
- Smart Messaging: Monitors communications for safety concerns
5. Legal Bases for Processing (For EEA/UK Users)
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Performance of contract |
| Booking and payment processing | Performance of contract |
| OTP verification | Performance of contract |
| Communications between users | Performance of contract |
| GPS voyage tracking | Legitimate interest (safety and insurance) |
| Usage analytics | Legitimate interest (service improvement) |
| Marketing communications | Consent |
| AI-powered features | Consent |
| Fraud prevention | Legitimate interest (security) |
| Financial record retention | Legal obligation |
| Responding to legal requests | Legal obligation |
You may withdraw your consent at any time for processing activities based on consent. This will not affect the lawfulness of processing conducted prior to withdrawal.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Active user accounts | Until you request deletion | Service provision |
| Financial and transaction records | 7 years | Tax and legal compliance |
| Completed booking records | 3 years | Dispute resolution, service improvement |
| Voyage GPS tracking data | 2 years | Insurance, safety records |
| Analytics data | 1 year | Platform improvement |
| AI conversation logs | 90 days | Service improvement |
| Admin audit logs | 7 years | Compliance, security |
| OTP verification codes | 10 minutes | Security |
When your information is no longer needed, we will securely delete or anonymize it.
8. Your Privacy Rights
8.1 Rights for All Users
Regardless of where you are located, you have the following rights:
- Access your information: View and download the personal information we hold about you
- Update your information: Correct or update your account information at any time
- Manage notifications: Control your notification preferences in your account settings
- Request deletion: Contact us at privacy@charterxo.com
8.2 California Residents (CCPA Rights)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request information about the categories and specific pieces of personal information we have collected
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale: CharterXO does not sell personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To Exercise Your CCPA Rights: Email privacy@charterxo.com. We will respond within 45 days.
California “Shine the Light” Law: California residents may also request information about our practices related to disclosing personal information to third parties for their direct marketing purposes.
Authorized Agents: You may designate an authorized agent to make a request on your behalf. We may require verification of the agent's authority.
8.3 EEA, UK, and Swiss Residents (GDPR Rights)
If you are a resident of the European Economic Area, United Kingdom, or Switzerland, you have the following additional rights:
- Right of Access (Article 15)
- Right to Rectification (Article 16)
- Right to Erasure (Article 17)
- Right to Restrict Processing (Article 18)
- Right to Data Portability (Article 20)
- Right to Object (Article 21)
- Right to Withdraw Consent (Article 7)
To Exercise Your GDPR Rights: Email privacy@charterxo.com. We will respond within 30 days.
Data Protection Authority: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
International Data Transfers: We use Standard Contractual Clauses (SCCs) approved by the European Commission to safeguard your data when transferred outside the EEA.
9. SMS and Text Message Consent
By providing your phone number, you may receive the following types of text messages:
- OTP verification codes
- Booking confirmations and reminders
- Trip status updates
- Weather alerts
- Captain and customer coordination
Consent: By providing your phone number and opting in, you consent to receiving text messages from CharterXO. Consent is not a condition of purchase.
Message Frequency: Message frequency varies based on your activity and preferences.
Message and Data Rates: Standard message and data rates may apply depending on your carrier and plan.
11. Security
We implement appropriate technical and organizational measures to protect your personal information.
Authentication and Access Control
- Phone-based OTP verification for account access
- Social login integration (Google, Apple) with OAuth 2.0
- Role-based access controls within the Platform
- Secure session management
Data Protection
- Encryption in transit (TLS/SSL)
- Encryption at rest for sensitive data
- Secure payment processing through Stripe (PCI DSS compliant)
- Regular security assessments
Monitoring and Auditing
- Administrative action audit logging
- Automated security monitoring
- Incident response procedures
12. Children's Privacy
Our Platform is not directed to children under the age of 18. You must be at least 18 years old to create an account on CharterXO.
Minors between the ages of 13 and 17 may participate as passengers on charter trips booked by an adult. In these cases, the booking adult is responsible for providing consent and managing any information related to the minor.
13. Account Deletion
You may request deletion of your account and associated data by contacting us at privacy@charterxo.com.
Permanently Deleted
- Profile information and photos
- Notification preferences
- Saved searches and favorites
- AI conversation history
- Active session data
Anonymized and Retained
| Data | Reason | Retention Period |
|---|---|---|
| Financial records | Tax and legal compliance | 7 years |
| Booking records | Dispute resolution | 3 years |
| Voyage tracking data | Insurance and safety | 2 years |
| Audit logs | Compliance and security | 7 years |
14. International Data Transfers
CharterXO is based in the United States, and your information is processed and stored on servers located in the United States.
If you are located outside the United States, please be aware that your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.
EEA/UK/Switzerland: We use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure appropriate safeguards for data transferred outside the EEA.
UK: We also rely on the UK International Data Transfer Agreement (IDTA) where applicable.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Notification of Changes: We will notify you of material changes by posting the updated Privacy Policy on our Platform and updating the “Last Revised” date.
30 Days Notice: For material changes that significantly affect your rights or obligations, we will provide at least 30 days' notice before the changes take effect.
Your Continued Use: Your continued use of the Platform after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Privacy Inquiries: privacy@charterxo.com
Legal Inquiries: legal@charterxo.com
CharterXO, LLC
Attn: Privacy Team
801 S Miami Ave, Unit 1501
Miami, FL 33130
United States
