Legal
Privacy Policy
How MarineDirect collects, uses, and protects your personal data.
Who we are
MarineDirect is operated by SEA LINE d.o.o., Slovenia (the "operator", "we"). We are the data controller for personal data processed through this website. You can reach us about anything in this policy via the contact page or by email at info@Marine-Direct.com.
Questions about your data? →What data we collect
We collect the data you give us and a small amount of technical data that keeps the site working:
- Account data — email address, password (stored as a secure hash), display name, and the role you choose (private seller, dealer, broker, charter).
- Listing data — the boats, equipment, rentals, events, news, and business profiles you publish, including photos, location, and the contact phone number you add to a listing.
- Messages — messages you send to sellers or receive from buyers through the site.
- Payment data — if you buy a subscription, payments are processed by Stripe. We never see or store your card number; we store your subscription tier, invoices, and Stripe customer reference.
- Technical data — server logs (IP address, time, requested page) kept briefly for security, and your saved preferences such as language and light/dark theme.
Why we process it (legal bases)
- To run your account and publish your listings — performance of a contract (GDPR Art. 6(1)(b)).
- To process subscription payments and keep invoices — contract and legal obligations (Art. 6(1)(b) and (c)).
- To keep the site secure, prevent abuse, and moderate junk content — our legitimate interest in a safe marketplace (Art. 6(1)(f)).
- To send account emails such as password resets and message notifications — contract. We do not send marketing email without your separate consent.
Who we share data with
We share personal data only with service providers who help us run the site, and only what they need:
- Stripe (payments and invoices) — card details go directly to Stripe.
- Our hosting and database provider, which stores the site and its data.
- Our email delivery provider, which sends account and notification emails.
- Google Translation services — listing texts and descriptions may be sent to Google to display them in the visitor’s language. Only the text itself is sent, never your account details.
We do not sell personal data and we do not show third-party advertising.
What is public
Listings are public by design. When you publish a listing, event, news post, or business profile, its content — including the photos, location, and any contact details you put in it — is visible to anyone on the internet and may appear in search engines. Your account email address is never shown publicly.
Cookies and local storage
We use only functional cookies and local storage: your login session, your language choice, and your theme preference. We set no advertising or cross-site tracking cookies, which is why the site shows no cookie banner.
How long we keep data
- Account and listing data — for as long as your account exists. If you delete a listing or your account, it is removed from the site; invoices are kept as long as tax law requires.
- Messages — until you or the other party delete them or the related account is deleted.
- Server logs — a short, rolling period used only for security and troubleshooting.
Your rights
Under the GDPR you can ask us at any time to:
- access a copy of the personal data we hold about you;
- correct inaccurate data or complete incomplete data;
- delete your data ("right to be forgotten") — you can also delete listings and your account yourself from the account pages;
- restrict or object to processing based on our legitimate interest;
- receive your data in a portable format;
- withdraw any consent you gave, without affecting processing before the withdrawal.
We answer within one month. If you believe we handle your data unlawfully, you can complain to your local supervisory authority or to the Slovenian Information Commissioner (Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si).
Questions about your data? →International transfers
Some providers (for example Stripe and Google) may process data outside the EU/EEA. Where that happens, the transfer is protected by the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
Children
MarineDirect is not directed at children. You must be at least 16 years old (or the age of digital consent in your country) to create an account.
Security
Connections to the site are encrypted (HTTPS), passwords are stored only as salted hashes, payment card data never touches our servers, and access to the database is restricted to the operator.
Changes to this policy
If we change this policy, the new version is published on this page with an updated date. Substantial changes will be announced on the site before they take effect.