Privacy

Controller

André Ralf Palmen
Plochinger Str. 62
73760 Ostfildern
Deutschland

Email: [email protected]

This policy covers the same service under its German name Kursblick and international name Vesselbird.

Website delivery and security

Vesselbird uses no analytics or advertising scripts. Connection data, including IP address, request time, requested address, browser information and response status, is processed to deliver the website and protect its availability and accounts. The legal basis is Article 6(1)(f) GDPR; the legitimate interests are reliable delivery and prevention of misuse.

The reverse proxy rotates access logs weekly and retains four rotated versions in addition to the current log. Error logs rotate weekly with ten retained versions in addition to the current log. Older versions are removed through this rotation. Retention therefore follows the rotation schedule and the time of the request; it is not a fixed number of days for every entry.

Cloudflare acts as a delivery and security provider and receives connection and security data. Processing may take place outside the European Economic Area. Cloudflare publishes its processing terms, safeguards for international transfers, including the EU Standard Contractual Clauses, and information on obtaining those safeguards in its Data Processing Addendum. Further information about processing and retention is in its privacy policy. Cloudflare’s retention depends on the service and security data concerned; it is separate from the reverse proxy’s log rotation.

Functional cookies

The following host-only cookies support features you request. They are not used for advertising or cross-site tracking. You can remove them in your browser; this ends a session or resets the settings concerned. Necessary device storage is based on Section 25(2)(2) of the German TDDDG.

Guest filters and favourites

Without signing in, filters and favourite lists are stored only in functional cookies in this browser. Cookie contents are technically transmitted with requests, but guest lists are not stored in the account database. Limited cookie capacity means a larger collection may need an account. These settings provide the collections and filters you request; the legal basis for personal-data processing is Article 6(1)(b) GDPR. Older guest favourites may be migrated once from this host’s localStorage into cookies; the old copy is removed only after successful migration.

Your Vesselbird account

Registration requires a username and password, not an email address. We store the account ID, username, creation time, secured password value, secured recovery code, filters and favourite lists. Passwords, recovery codes and session keys are not stored in plain text. Account data and preferences remain until you delete the account. Sessions expire after 30 days. Signing out ends the current session; password recovery and account deletion end all of that account’s sessions.

You can export your account settings as a file from the account dialog. You can also delete your account after confirming your password; this removes its settings and active sessions from the account database. Data is held in the server’s persistent volume. The account database has its own daily backup, separate from AIS backups. These copies are retained for up to seven days; deleted accounts and preferences may remain in a protected backup until it expires. Restoring a backup must also reapply deletion requests made since that backup. The purpose is to provide your collections across devices; the legal basis is Article 6(1)(b) GDPR. An account is optional: without it, the map and local guest settings remain available.

To prevent automated login attempts, the application uses temporary counters in memory, based on hashes of IP addresses or account identifiers. It does not store plain-text IP addresses for these counters. The rate-limit windows are one minute, 15 minutes or one hour. Expired counters are removed at the next cleanup, which runs hourly, or on restart. The legal basis is Article 6(1)(f) GDPR; the legitimate interests are account security and service availability. This does not change the separate processing of IP addresses by the reverse proxy or Cloudflare.

Maps, photos and support

Map tiles are loaded directly from OpenStreetMap and, when the seamark layer is enabled, OpenSeaMap. Available ship photos are loaded from Wikimedia when you open ship details. These providers receive connection data, including your IP address and the requested map or image address. Map tiles can reveal the area being viewed. Provider information: OpenStreetMap, OpenSeaMap and Wikimedia. These requests provide the map and photos you ask to view; the legal basis is Article 6(1)(f) GDPR, with the legitimate interest of displaying maritime information. International processing may also occur at these providers; their linked information describes their safeguards.

Buy Me a Coffee and ShipSpotting are ordinary external links, not embedded widgets. Their websites are contacted only when you open a link. A payment is governed by the support provider’s terms and privacy information.

Your device location

Your location is displayed only after you press the location button and grant your browser permission. It remains in browser memory and is not automatically transmitted to the Vesselbird server or stored in ship history. Focusing on it loads map tiles for the visible area from the map provider. A map view is saved in a filter only if you explicitly select that option when saving. Its centre can then correspond to the device location previously displayed.

Public ship information

Ship history comes from the public AIS services listed under Data sources. We normalise, combine and archive the received data to display maritime traffic and make historical vessel movements understandable. AIS identifiers and positions may relate to individuals, especially on private vessels. Where the data is personal, processing is based on Article 6(1)(f) GDPR, with the legitimate interests of providing this public information service and documenting vessel traffic; individual interests and justified objections must also be considered.

Positions are recorded at a maximum resolution of one position per minute and source and currently retained up to 365 days; the configured period is visible in History. Older positions are removed through routine cleanup. Up to seven daily AIS database backups are retained, so removed positions can remain in a backup until it is replaced. Contact the controller above for questions, corrections, justified objections or removal requests concerning a vessel linked to you. Each request is assessed individually.

Your rights

Subject to the applicable legal conditions, you may request access, correction, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests for reasons relating to your particular situation. Contact the controller above. You may also complain to a competent data protection supervisory authority. No automated decisions with legal or similarly significant effects are made about users. Details of these rights are in the GDPR.