Controller and contact
The controller and operator of SoloCruz is YAS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office at ul. Szlak 77/222, 31-153 Kraków, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS 0001166122, NIP 6793327784 and REGON 541401303. Privacy requests can be sent to [email protected].
Data we process
We process account and security data; profile and optional photo data; cruise searches, listings and interests; messages, blocks and reports; booking-support records; consent records; and technical data such as IP-related security signals, browser, session and referral information.
Health or accessibility information is optional special-category data. We process it only after separate explicit consent. It is never displayed publicly; the user may keep it undisplayed or share it only with a traveler whose cabin-mate request the user accepts.
Purposes and legal bases
We process data necessary to provide accounts, listings, matching, chat and requested booking support under the contract; to secure the service, prevent abuse and resolve claims based on legitimate interests; and to comply with legal obligations.
Public profile publication, health information, optional analytics, session recordings, the AI assistant and marketing are based on separate consent where consent is required. Consent can be withdrawn without affecting earlier lawful processing.
Public data and recipients
A published search may show the first name, age, gender, smoking, alcohol and sleep preferences, practical notes, listing details and an enabled profile photo. Health and accessibility information is excluded from public listings. Search engines and anyone online may copy public information, so users should not publish contact, payment, document or precise location data.
Processors may include hosting, email, security, Google sign-in, Google Analytics, Microsoft Clarity, Airep24 and AI infrastructure, and cruise-data providers. Cruise or payment providers process booking data under their own terms when users choose their services. We do not sell personal data.
International transfers and retention
Where a provider processes data outside the EEA, SoloCruz relies on an applicable adequacy decision, Standard Contractual Clauses or another lawful safeguard and assesses supplementary protections where required.
Account and active product data is retained while needed to provide the service. Consent evidence, security logs, reports and records needed for legal claims may be retained for applicable limitation periods. Deleted public content may remain in third-party caches beyond our control.
Rights
Depending on the legal basis, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent in profile or Privacy settings and complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or another competent EEA authority.
Account settings provide editing and deletion controls. We may verify identity before completing a request. Privacy notice version: 2026-08-12.2. Last updated: 12 August 2026.
