Cookie and Similar Technologies Policy
Mermaid stores or reads information on your device only for disclosed purposes. Strictly necessary technologies operate without consent where the law allows; analytics, advertising and cross-service tracking stay switched off until you have given valid prior consent. The website mermaid.navy currently sets no cookies at all.
1. Who this Policy applies to
This Policy explains how Krone Consulting s.r.o. ("Krone", "Mermaid", "we"), Mlynské Nivy 5, 821 09 Bratislava, Slovakia, info@mermaid.navy, stores or accesses information on a user's device through mermaid.navy and related sites; the Mermaid Crew web app and the Mermaid Base portal; the Mermaid iOS and Android apps; embedded authentication, payment, support and media components; and emails or links where similar technology is used. Storing or reading such information needs your consent unless it is strictly necessary to provide a service you asked for (Article 5(3) of Directive 2002/58/EC and Section 109(8) of Slovak Act No. 452/2021 Coll. on electronic communications). The Privacy Notice explains what happens to personal data obtained this way.
2. What counts as a cookie or similar technology
A cookie is a small text file placed by a browser or device. Similar technologies include HTML local storage and session storage; IndexedDB and local databases; service workers and progressive-web-app caches; app files, secure storage and device identifiers; software development kits (SDKs), pixels, tags and mobile analytics identifiers; push-notification subscription endpoints and device tokens; temporary protected-asset access tokens; email pixels and link parameters; and any other technique that stores or reads information on terminal equipment. The rules apply to personal and non-personal information and to websites and apps alike; where personal data is processed, the GDPR applies in addition.
3. Categories and what is in use today
3.1 Strictly necessary
Essential to provide a feature you expressly requested, to secure the Service or to transmit communications. In use today: on the Crew web app and Mermaid Base, the session and sign-in token, anti-forgery and security tokens, rate-limit identifiers, your language and display preferences, the offline copy of your charter (roster, galley board, shopping list, safety cards and kitty entries made offline), the service-worker cache that lets the app open without a connection, short-lived protected-asset grants, and the push subscription you enabled; in the mobile apps, sign-in, settings, downloaded charts and forecasts, the logbook and evidence on the device, and the push token issued by Apple or Google. The website sets nothing: fonts, icons and images are served from our own domain and no third-party resource is loaded. Necessary storage operates without consent; we still explain it and use it only for the necessary purpose.
3.2 Preferences and functionality
Optional conveniences such as remembering your persona (captain or charter base), map layer, units or recent boat between visits. Your selected language is treated as necessary storage for the requested locale. Not in use on the website today; we ask before adding any.
3.3 Analytics and performance
Identifiers that measure how the website or app is used, diagnose performance or count visitors and sessions. Not in use today. Any non-essential analytics is consent-based and blocked until consent (section 5), unless a narrowly configured tool is clearly exempt.
3.4 Marketing and cross-service tracking
Campaign and install attribution, partner and affiliate identifiers, the operating system's advertising identifier, profiling or retargeting. Not in use today. Any marketing technology is off by default, described separately and activated only after valid consent. Boating position is never used for advertising.
3.5 Embedded third-party content
Maps, videos, support widgets, social components or payment frames can let a third party access your device. The website embeds none. If we ever embed such content, it is loaded only after you accept the relevant category or through a click-to-load control.
4. How we measure the website today, without cookies
We want to know where visitors come from and what they use. We do this on our server from the request your browser sends anyway: the page requested, the site or campaign link that referred you (the referrer and campaign parameters in the link), your browser language, the class of device and browser from the user agent, and your IP address, which we shorten before storing so that it no longer identifies you. Nothing is stored on your device and no identifier follows you between visits, so no consent is needed; the legal basis is our legitimate interest in understanding and marketing the Service (Privacy Notice, section 6). Records are kept for 12 months and aggregated statistics indefinitely.
5. Consent standard for anything we add
We plan to measure marketing more precisely: which campaign or partner brought a visitor who later installed the app, which locale and device they used, and how visitors move through the site. Whenever this needs an identifier stored on or read from your device, we ask first, through a consent banner on the website and, in the apps, through the operating system's tracking prompt. We then ask before setting or accessing anything non-essential; give clear, specific information about purposes and providers; offer accept-all and reject-all with equal prominence at the first layer; allow a separate choice for each category; never treat a pre-ticked box, scrolling, inactivity or continued use as consent; keep consent separate from acceptance of the Terms; record the choice and the version of the information shown; make withdrawal as easy as consent; and ask again when purposes or providers change materially or after 13 months. Before any category goes live, the specific cookies, identifiers and providers will be listed in section 10 with name, purpose, provider and lifetime. Refusing has no effect on your use of Mermaid, and consent to a category does not authorise every later use of personal data: each purpose needs its own GDPR basis.
6. How to change your choice
Once a consent banner exists, a "Cookie settings" link in the website footer and the privacy menu in the apps let you change your choice at any time; withdrawal applies from then on and we delete the identifiers we hold for you within 30 days. Your browser lets you delete or block cookies and site data; blocking necessary storage signs you out of the Crew web app and Mermaid Base, removes offline drafts and makes the app download its data again. On iOS you control tracking under Settings › Privacy & Security › Tracking; on Android you can reset or delete the advertising ID under Settings › Privacy › Ads. Operating-system controls do not delete data already sent to a provider, so use the in-app controls as well.
7. Crew web app and offline storage
The Crew web app uses a service worker, Cache Storage, local storage and IndexedDB to be installable and load its core files; to work with poor or no connectivity; to keep the charter-scoped session; to hold temporary drafts and pending uploads; to cache map, weather or field tiles within licence and expiry limits; to queue a push subscription; and to avoid downloading unchanged files again. Offline storage can contain charter data and is protected only by your device security; it can persist after the browser tab is closed. Remove the site data on a shared device and do not install the Crew web app on a device that unauthorised people can access. Necessary caches are versioned and expire when access ends, a code is revoked or content becomes stale; protected assets are not made public because they are cached locally.
8. Mobile app SDKs and device access
The apps use SDKs for sign-in, push, crash reporting, subscriptions and support. An SDK can collect data without a browser cookie, so we apply the same inventory, purpose limitation and consent analysis to SDKs. The apps request operating-system permissions for location, notifications, camera, photos, files or nearby devices contextually, when the feature is used, with an explanation; you can revoke them in device settings. Background location is used only for a feature you activated that genuinely needs it, the active anchor watch or trip recording, and never for advertising or unrelated profiling.
9. Push notifications
Push delivery involves a browser or operating-system permission, the Crew web app's service worker, a subscription endpoint or device token, the Apple Push Notification service or Google's push service, and Mermaid's event and delivery logs. Push permission is optional; disabling it prevents remote crew alerts but does not turn off the anchor alarm on the skipper's own device, and email fallback is used where described. A push token is treated as a security-sensitive identifier, is rotated or removed when no longer needed, and is never used for advertising.
10. Technology register
- Authenticated session identifier
- Crew web app and Mermaid Base sign-in and account security. Session or short fixed period, rotated on authentication. Strictly necessary.
- Anti-forgery token
- Protects state-changing requests. Session. Strictly necessary.
- Crew invitation and session code
- Scopes Crew web app access to one charter and role. Short-lived, revocable. Strictly necessary.
- Language and display preference
- Provides the selected locale and layout. Up to 12 months. Necessary for the requested locale.
- Service worker and static cache
- Installability, resilience and offline operation of the Crew web app. Versioned until update, access expiry or deletion. Strictly necessary.
- IndexedDB and local draft store
- Offline roster, galley board, shopping list, kitty entries and drafts. Until sync, submission, access expiry or manual deletion. Strictly necessary.
- Protected-asset grant
- Temporary access to protected map, weather or evidence files. Minutes to hours. Strictly necessary.
- Push subscription or device token
- Delivers the alerts you enabled. Until permission is revoked, the token is invalidated or the charter or account expires. Strictly necessary for the requested alerts.
- Security and rate-limit identifier
- Abuse and account protection. Short-lived. Strictly necessary.
- Consent record
- Remembers your category choices and the version shown, once a banner exists. Up to 13 months, then renewed. Strictly necessary for honouring your choice.
- Analytics identifier (planned)
- First-party visitor and session counting. Up to 13 months; aggregated reporting. Consent.
- Marketing and attribution identifiers (planned)
- Campaign, partner and install attribution, the OS advertising identifier in the apps. Up to 13 months; reporting to partners aggregated or pseudonymised. Consent.
The names describe functions; the exact keys and any third-party provider will be listed here before a planned entry goes live.
11. Email tracking
Transactional emails (invitations, statements, alerts, service notices) are sent without marketing tracking. If open pixels or uniquely tracked links are ever used for marketing analytics, they will be disclosed and activated only with consent where required. Security links, invitation codes and statement links contain unique parameters needed to authenticate or route the requested action; they are short-lived, scope-limited and must not be shared.
12. Browser signals
We treat a Global Privacy Control signal from your browser as a refusal of the marketing category and never use it to override a more protective choice you made in Mermaid. "Do Not Track" has no uniform legal meaning; we honour legally binding signals.
13. Third parties and transfers
The website loads no third-party resources and sets no third-party cookies. Apple and Google set their own cookies and identifiers when you use their sign-in, app stores or payment services under their own notices. A third-party technology we may add later would receive IP address, device information, an identifier and interaction data; it is enabled only after due diligence, data-processing terms, a transfer assessment, data-use restrictions and an update of section 10. The Privacy Notice explains recipients and international transfers.
14. Retention
Session and security storage: the session or the shortest workable security period. Consent preference: 13 months before a renewed choice. Server-side consent evidence: the reliance period plus 5 years. Analytics and marketing identifiers: no longer than 13 months and stated in the register. Crew web app offline data: until sync, charter access expiry, code revocation or deletion. Invalid push tokens: removed promptly after permanent delivery failure or permission withdrawal.
15. Changes
We update this Policy when technologies or the law change. A material new purpose or provider is not activated under an old consent where new consent is required. The version and date at the top tell you which text applies, and prior versions are kept.
16. Contact and complaints
Questions and requests: info@mermaid.navy, subject "Cookie privacy". In Slovakia, the Regulatory Authority for Electronic Communications and Postal Services (Úrad pre reguláciu elektronických komunikácií a poštových služieb, Továrenská 7, 828 55 Bratislava 24, teleoff.gov.sk) supervises the rules on storing information on terminal equipment, and the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk) supervises personal-data processing. You may also complain to the authority in your own country.