DOCKY PRIVACY POLICY
Privacy, data use, and U.S. consumer rights
United States Privacy Notice
Effective Date: September 22, 2026
Version: 3.0
This Privacy Policy explains how DOCKY USA LLC ("Docky," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information through Docky's websites, mobile applications, communications, and marina-booking services (the "Platform"). It also explains privacy choices and rights.
This policy applies to Visitors, Annual Berth Holders, Marina personnel, Direct Listing providers, prospective users, and people who contact us. A Marina may separately process information under its own privacy notice.
IMPORTANT
Please read this document carefully. It contains legally binding terms and, where applicable, provisions concerning risk allocation, limitations of liability, dispute resolution, and individual arbitration.
1. Who Is Responsible for Your Information
For U.S. Platform activities, DOCKY USA LLC is responsible for the personal information it determines how and why to process. Docky may use affiliates and service providers.
For Marina operations, admission, dockage, security, and legal compliance, the Marina may independently determine how and why it processes information. Docky and the Marina are not automatically joint controllers, partners, or agents. A signed Marina Partner Agreement may assign specific data-processing roles.
2. Information We Collect
Depending on your role and use, we may collect:
Account and identity information
Name, date of birth, username, profile photo, email, phone number, mailing address, language, account identifiers, login information, and authentication records.
Verification information
Government identification, proof of address, authority documents, business information, sanctions or fraud-screening results, and verification status. We seek to avoid retaining full identity documents longer than needed.
Vessel and boating information
Vessel name, photographs, make, model, type, registration or documentation number, length, beam, draft, air draft, displacement, propulsion, home port, equipment, utilities, owner or operator information, safety credentials, and intended use.
Insurance information
Insurer, policy number, coverage dates, limits, certificate or declarations page, claims contact, and verification status. Docky does not determine whether a policy will cover a particular event.
Marina and berth information
Marina identity, personnel, address, location, berth numbers, dimensions, utilities, rules, prices, assignments, contract dates, approval status, absence periods, availability, and operational messages.
Booking and transaction information
Searches, requests, approvals, booking dates, arrival and departure, pricing, fees, taxes, deposits, cancellations, refunds, disputes, chargebacks, incentives, and transaction identifiers.
Payment information
Payment tokens, card type and last digits, billing address, payout status, and payment-provider responses. Full payment-card numbers are generally collected directly by the payment provider and not stored by Docky.
Communications and support
Messages between users and Marinas, support requests, call or chat records, survey responses, incident reports, attachments, and communications preferences.
Device, usage, and technical information
IP address, device and browser type, operating system, app version, identifiers, language, time zone, referral source, pages and features used, clicks, crash logs, security events, cookies, and similar technologies.
Location information
Approximate location derived from IP address and, only with device permission, precise device location used for maps, search, check-in, verification, fraud prevention, or location-based features. Device permissions can be changed in operating-system settings, although some features may stop working.
Content
Listings, photos, reviews, uploaded documents, profile content, and other material submitted to the Platform.
Inferences
Compatibility results, fraud or risk indicators, likely preferences, and analytics derived from other information. Docky does not use solely automated decisions to produce legal or similarly significant effects unless separately disclosed and legally permitted.
3. Sources of Information
We collect information:
- directly from you;
- from a Marina, Annual Berth Holder, Visitor, vessel owner, captain, or authorized representative;
- automatically from devices and Platform use;
- from payment, identity, fraud, communications, mapping, analytics, cloud, and support providers;
- from public vessel, company, sanctions, professional, or governmental records where lawful;
- from insurers, advisors, authorities, or other parties involved in an incident or dispute.
4. How We Use Information
We use personal information to:
- create, authenticate, secure, and support accounts;
- verify identity, authority, vessel, insurance, and documents;
- connect Marinas, Annual Berth Holders, and Visitors;
- manage berth assignments, absence periods, availability, requests, and Bookings;
- calculate compatibility, prices, fees, taxes, and operational status;
- facilitate payments, payouts, refunds, disputes, and accounting;
- send transactional, safety, access, support, and legal communications;
- prevent fraud, abuse, chargebacks, sanctions violations, security incidents, and unlawful activity;
- investigate incidents, enforce terms, resolve disputes, and protect people and property;
- maintain, troubleshoot, analyze, and improve the Platform;
- develop new features, analytics, matching, and forecasting using aggregated, deidentified, or appropriately protected data where feasible;
- comply with law, legal process, tax, insurance, recordkeeping, and regulatory obligations;
- market Docky where permitted and honor communication choices.
We do not use personal information for materially different purposes without appropriate notice or consent where required.
5. When We Disclose Information
We may disclose information to:
Marinas
For admission, verification, berth assignment, access, safety, payment, operations, incident response, and compliance.
Other transaction participants
To the limited extent reasonably necessary to complete a Booking, coordinate an absence, communicate, or resolve a dispute. Annual Berth Holder details should not be used to create a direct sublease relationship.
Service providers and processors
Payment processing, cloud hosting, data storage, authentication, identity verification, fraud prevention, mapping, analytics, communications, customer support, document management, cybersecurity, and professional services. Providers are authorized to process information for contracted purposes and must protect it as required by contract and law.
Payment networks and financial partners
To process charges, payouts, refunds, reserves, disputes, chargebacks, fraud controls, and compliance.
Authorities and safety recipients
Law enforcement, courts, regulators, emergency services, the Coast Guard, port authorities, insurers, and affected parties when reasonably necessary and legally permitted for safety, legal process, fraud, claims, or protection of rights.
Corporate transactions
Potential or actual investors, lenders, buyers, sellers, advisors, and successors in connection with financing, reorganization, merger, acquisition, asset transfer, insolvency, or similar transaction, subject to appropriate confidentiality and legal safeguards.
At your direction
When you request, authorize, or intentionally publish the disclosure.
6. Sale, Sharing, Targeted Advertising, and Analytics
Docky does not sell personal information for money. We may use analytics, measurement, or advertising technologies that some state laws define as "sharing," "sale," or targeted advertising, depending on configuration and use.
Where legally required, Docky will provide a "Do Not Sell or Share My Personal Information" or equivalent mechanism and honor recognized opt-out preference signals, including Global Privacy Control, for the browser or device sending the signal.
We do not knowingly sell or share personal information of anyone under 18 for targeted advertising.
7. Cookies and Similar Technologies
We may use:
- strictly necessary technologies for login, security, payments, preferences, and core functions;
- functional technologies for language, maps, and user settings;
- analytics technologies for performance, crashes, and feature use;
- advertising or measurement technologies only as disclosed and subject to required choices.
Browser and device settings may block some technologies, but core features may be affected. Where required, a consent tool will permit choices before non-essential technologies operate.
8. Communications
We send transactional communications for accounts, security, verification, bookings, access, payments, support, incidents, and legal notices. These are not marketing and may be necessary to provide the service.
Marketing emails include an unsubscribe method. Marketing texts require the consent mandated by law and may be stopped using the stated instruction. Opting out of marketing does not stop necessary transactional or safety communications.
9. Retention
We retain information only as reasonably necessary for the purposes described, including service delivery, safety, fraud prevention, dispute resolution, insurance, accounting, tax, legal compliance, and enforcement.
Retention depends on the record. Account and Booking records may be retained for the account relationship and applicable limitation, tax, or dispute periods. Identity and insurance documents may be retained for shorter verification periods unless an incident or law requires longer retention. Security logs and backups are retained under operational schedules and then deleted or deidentified when reasonably practicable.
Deletion requests are subject to legal and operational exceptions. We may retain a minimal record to document the request and prevent re-creation of deleted data.
10. Security
We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information, including access controls, authentication, encryption in transit where appropriate, logging, backups, vendor controls, and incident response.
No system is perfectly secure. Users must protect credentials and promptly report suspected compromise. Do not send full payment-card information or unnecessary sensitive documents through ordinary messages.
11. Data Incidents
Docky maintains procedures to investigate and respond to suspected data incidents. We will notify affected individuals, regulators, Marinas, or other parties as required by applicable law and contracts.
Marinas and service providers must promptly report incidents involving Docky data and cooperate with containment, investigation, remediation, and legally required notice.
12. Your Privacy Rights
Depending on residence and applicable law, you may have rights to:
- confirm whether we process your personal information;
- access and obtain a portable copy;
- correct inaccuracies;
- delete information;
- opt out of sale, sharing, targeted advertising, or qualifying profiling;
- limit certain uses of sensitive personal information;
- withdraw consent where processing depends on consent;
- appeal a refusal of a privacy request;
- receive equal service and pricing without unlawful discrimination for exercising rights.
To submit a request, email contact@docky.com with the subject "Privacy Request." We may provide an online request method. Describe the right, state of residence, and account email. We will verify identity and authority proportionately. An authorized agent may submit a request where permitted, but we may require proof of authorization and direct identity confirmation.
We will respond within the period required by applicable law. If we deny a request, we will explain the basis and any available appeal process. Appeals may be sent to contact@docky.com with the subject "Privacy Appeal."
13. U.S. State Privacy Disclosures
For the preceding 12 months, the categories collected may include identifiers; customer and transaction records; protected-class information only if voluntarily provided and legally relevant; commercial information; internet or network activity; approximate or precise geolocation with permission; audio, visual, and electronic content; professional information; sensitive information such as government identification, login credentials, precise location, and insurance details; and inferences.
We collect and disclose these categories for the business purposes described in this policy. Recipient categories include Marinas, transaction participants, payment and fraud providers, cloud and technology providers, professional advisors, authorities, and corporate transaction recipients.
Docky does not use sensitive personal information to infer characteristics unrelated to providing, securing, and improving the service. Where a state law applies and requires additional controls, Docky will honor them.
California residents may have rights under the CCPA/CPRA, including access to categories and specific pieces, correction, deletion, portability, opt-out of sale or sharing, limitation of certain sensitive-information uses, and non-discrimination. Applicable metrics and additional notices will be published if legally required.
Florida residents may have rights under the Florida Digital Bill of Rights if and when its applicability thresholds and conditions cover Docky. Regardless of threshold, Docky will use reasonable efforts to honor verified access, correction, deletion, and portability requests, subject to lawful exceptions.
14. Children
The Platform is intended only for persons 18 or older and is not directed to children. We do not knowingly collect personal information online from children under 13. If we learn that such information was collected without legally sufficient authorization, we will delete it as required.
Contact contact@docky.com if you believe a child provided information.
15. International Users and Transfers
This policy is the U.S. version. Information may be processed in the United States and other countries where Docky, affiliates, Marinas, or service providers operate. Those countries may have different privacy laws.
Separate regional terms or legally required transfer safeguards may apply to European, UK, or other non-U.S. users. This U.S. policy does not waive mandatory rights under another applicable law.
16. Third-Party Links and Services
The Platform may link to Marina sites, maps, payment providers, app stores, social media, and other services. Their privacy practices are governed by their policies. Docky is not responsible for independent third-party practices.
17. Deidentified and Aggregated Information
We may create and use aggregated or deidentified information for analytics, capacity planning, forecasting, research, product improvement, and business reporting. Where required by law, we will maintain deidentified information in deidentified form and will not attempt to reidentify it except to test permitted safeguards.
18. Changes to This Policy
We may update this policy for legal, security, operational, or product reasons. We will post the new effective date and provide additional notice when required or when changes are material. We will obtain consent where legally required for a new use.
19. Contact
DOCKY USA LLC
11 Broadway, Suite 1155
New York, NY 10004, United States
Privacy requests: contact@docky.com
Privacy appeals and legal notices: contact@docky.com
General support: support@docky.com
