Privacy policy
Last updated: 5 August 2026
1. Who we are
Sail is club management software for sailing and watersports clubs. It is owned and operated by Aurelia Technology Consulting Limited, a company registered in England and Wales, company number 14957218, registered office Collingwood Buildings, Collingwood Street, Newcastle Upon Tyne, England, NE1 1JF.
In this policy, "we", "us" and "our" mean Aurelia Technology Consulting Limited. "Sail" means our software and the websites at sailapp.cloud, app.sailapp.cloud, and the club websites we host on our subdomains.
For anything about this policy or your personal data, contact privacy@sailapp.cloud.
2. The most important thing in this policy
For most of the personal data inside Sail, we are not the ones who decide what happens to it.
- When a club uses Sail to manage its members, the club is the data controller. It decides what to collect and why. We are its data processor: we hold and handle that data on the club's instructions, and we do not use it for our own purposes. If you are a club member and want to know how your details are used, ask your club.
- When you deal with us directly, by running a club and holding a Sail account, filling in our enquiry form, subscribing to our newsletter, contacting support, or browsing sailapp.cloud, we are the data controller, and the rest of this policy tells you what we do.
Section 6 covers what we do as a processor.
3. What we collect when we are the controller
3.1 If you run a club and hold a Sail account
| What | Why | Lawful basis |
|---|---|---|
| Name, email address, club role and title | To give you an account, sign you in, and show the right parts of the console | Contract |
| Your club's name, address and configuration | To provide the service | Contract |
| Billing details and subscription history | To bill you and meet our tax obligations | Contract; legal obligation |
| Records of support requests you send us | To answer them and improve the product | Legitimate interests (running a support desk) |
| Product usage and technical error reports | To keep the service working and fix faults | Legitimate interests (a reliable service) |
We do not handle card numbers. Card details go directly to Stripe (section 5).
3.2 If you enquire, or subscribe to updates
- Enquiry form: your name, email address and message, so we can reply. Lawful basis: legitimate interests, or steps towards a contract at your request.
- Newsletter and founding-club list: your email address, and only after you confirm by clicking a link in a confirmation email. We keep the timestamp of that confirmation as the record of your consent. Lawful basis: consent. Every email has an unsubscribe link and unsubscribing is immediate.
- Demo booking: handled by Calendly, which collects the details you give it to schedule the call.
3.3 If you just visit the website
See the Cookies policy. In short: nothing that identifies you is collected unless you accept cookies, and declining leaves the site fully usable.
4. What we do not do
- We do not sell personal data. To anyone, ever.
- We do not use a club's member data to advertise to those members, or to build any profile of them.
- We do not use club data to train AI models. Where Sail uses AI, data is sent to answer a specific request and is not used for model training.
- We do not use automated decision-making that produces legal or similarly significant effects.
5. Who else is involved
We use other companies to run Sail. Each is bound by a contract restricting them to acting on our instructions. Each is listed here so a club can carry out its own due diligence.
| Provider | What they do | Where data is processed |
|---|---|---|
| Supabase | Hosts the database and handles sign-in | United Kingdom (London) |
| Netlify | Hosts the websites and runs the application code | Global content network |
| Stripe | Takes payments. Card details go straight to Stripe and never reach us | UK, EU and US |
| Brevo | Sends email: sign-in links, notifications, and the emails clubs send their members | European Union |
| Sentry | Records technical errors so we can fix faults | Germany |
| Zendesk | Runs our support desk. If you contact support, your message and contact details are held there | United States |
| Anthropic | Powers Sail's AI features. Data is sent to answer a specific request and is not used to train models | United States |
| Microsoft 365 | Our own email | UK and EU |
| Google Analytics | Measures how our marketing website is used, and only if you accept cookies | United States |
All club and member data in the Sail database is held in the United Kingdom. Google Analytics runs on our marketing website only. It does not run in the Sail application and never sees club or member data.
Where a provider processes data outside the UK, the transfer is covered by the UK adequacy regulations for the European Economic Area, or for the United States by the UK Extension to the EU-US Data Privacy Framework or by standard contractual clauses with the UK Addendum, as set out in each provider's terms.
We limit what our error monitoring receives: it is sent internal reference numbers rather than names or email addresses, it does not receive request contents or sign-in details, and session recording is switched off so that nothing on a club's screen is captured.
6. When we are a processor: club member data
Clubs put a lot into Sail, and some of it is sensitive:
- members' names, addresses, contact details and dates of birth;
- emergency contacts;
- health and dietary information, where a member chooses to share it. This is special category data under UK GDPR Article 9;
- safeguarding records, including DBS checks, which are criminal offence data under Article 10;
- records about children, including guardian details and consents;
- incident and accident reports, which may describe injuries;
- qualifications, duties, bookings and payment history.
For all of this:
- The club is the controller and we are the processor. We act only on the club's documented instructions.
- Our Data Processing Agreement forms part of our contract with every club and sets out the Article 28 terms: confidentiality, security, sub-processors, assistance with data subject rights, breach notification, and deletion or return at the end.
- Members should contact their club, not us, to exercise their rights. Sail includes a request process that routes a member's deletion request to their club for a decision, because the decision is the club's to make. If a member contacts us directly we will tell them so, and tell their club.
- Safeguarding, medical and incident records remain readable and exportable at all times, including if a club's subscription lapses.
7. How long we keep things
| What | How long |
|---|---|
| Financial records: invoices, payments, subscription history | 6 years from the end of the relevant accounting period, as UK tax and company law requires |
| Your Sail account, after you stop subscribing | Long enough for you to export what is yours, then deleted |
| A club's member data, after the club leaves | Long enough for the club to export it, then deleted or returned on the club's instruction |
| Newsletter subscription | Until you unsubscribe |
| Enquiries and support correspondence | While it is useful to answer follow-ups and identify recurring problems |
| Technical error reports | While they are useful for diagnosing faults |
Where we have not given a fixed period above, we keep data only as long as we need it for the purpose it was collected for, and review it against that purpose rather than keeping it by default.
Two things sit outside that table:
- Safeguarding and DBS records belong to the club's own retention policy, not ours. They often carry statutory or governing-body expectations, and we will not delete them on our own initiative. If your club is unsure how long to keep them, ask your national governing body.
- Records we are legally required to keep are held in restricted form, are not used for anything else, and are deleted at the end of the period.
Six years applies to what is genuinely a financial record. It is not a reason to keep an entire membership database, including health and safeguarding information, for six years after a club leaves. That would not be proportionate, and we do not do it.
8. Your rights
Under UK GDPR you have the right to: be informed; get a copy of your data; have inaccurate data corrected; have data erased in some circumstances; restrict or object to processing; portability; and to withdraw consent at any time where consent is the basis.
To exercise any of these with us, email privacy@sailapp.cloud. We will respond within one month. We do not charge, unless a request is manifestly unfounded or excessive.
If you are a club member, please go to your club first. They are the controller and the decision is theirs. We will help them respond.
You can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We would rather you raised it with us first, but you do not have to.
9. Security
- All traffic is encrypted in transit, and data is encrypted at rest by our hosting provider.
- The database enforces access rules at the data layer, so a club can only reach its own records and each person sees only the parts of their club they have been granted.
- Changes to your club's records are logged. Revealing a staff member's National Insurance number or bank details is logged separately, each time.
- Access to production systems by our staff is limited to those who need it.
- Errors are monitored so faults are found by us rather than reported by you, and what our monitoring receives is limited as described in section 5.
No system is perfectly secure. If a breach occurs that risks people's rights and freedoms, we will report it to the ICO within 72 hours and tell those affected without undue delay. Where a club is the controller, we will notify the club without undue delay so it can meet its own duty.
10. Children
Sail holds records about under-18s because clubs teach and race with juniors. Those records are entered by the club, under the club's own safeguarding policy and consents. We are the processor.
We do not knowingly collect data directly from children through our own website, and our marketing is aimed at club officers, not at children.
11. Changes
We will update this policy when what we do changes. If a change materially affects you, we will tell account holders by email rather than quietly changing the page. The date at the top always shows the current version.
12. Contact
Aurelia Technology Consulting Limited, Collingwood Buildings, Collingwood Street, Newcastle Upon Tyne, England, NE1 1JF. Company number 14957218.