Privacy & Data Retention
Last updated: 2026-07-21. This page is maintained by the Cruise and Vote organising team to explain how registration data is handled.
Who is the data controller
The Cruise and Vote organising team is the data controller for this site. The site collects a small amount of contact information for the sole purpose of gauging interest in a cruise from Cyprus to Israel around the October 2026 Israeli election, and — if the cruise proceeds — coordinating with registrants.
What we collect
- Full name
- Email address
- Phone number (with country code)
- Number of passengers
- Preferred landing port (Haifa, Ashdod, or either)
- Whether you'd like organised transport from the port
- Your interface language and explicit consent to processing
- Verification metadata (timestamps, hashed one-time codes)
Legal basis
We process your data only on the basis of your explicit consent (GDPR Art. 6(1)(a)). You may withdraw consent at any time by requesting deletion — see below.
How we use the data
Registration data is used strictly to:
- estimate demand and viability of the crossing;
- contact registrants with schedule, boarding, and transport information;
- verify that a registration belongs to a real, reachable person via one-time code.
We do not sell, rent, share, or use your data for marketing, analytics profiling, or any other purpose.
Retention policy
All personal data collected through this site is permanently deleted on election day, October 27, 2026.
- Cruise registrations (name, email, phone, passengers, port, transport preference, language, consent, verification status): deleted no later than end of day October 27, 2026 (Israel local time).
- One-time verification codes (SMS/email OTP records): expire after 10 minutes and are purged automatically; consumed codes are deleted together with the retention sweep.
- Server and provider logs generated by our hosting and SMS provider are retained only as long as those providers' own policies require for security and abuse-prevention.
You may request earlier deletion at any time via /delete-my-data.
Your rights (GDPR)
Under GDPR you have the right to:
- access the data we hold about you;
- correct inaccurate data;
- erase your data (right to be forgotten);
- withdraw consent at any time;
- lodge a complaint with your national data protection authority.
The fastest way to exercise access, correction, or erasure is to use the self-service deletion page. Verification is done by one-time code sent to the email or phone number on the registration, so no account or password is needed.
Data processors
- Hosting and database — Lovable Cloud (backed by Supabase).
- Email delivery of verification codes — Supabase Auth.
- SMS delivery of verification codes — Lovable Cloud built-in SMS / Supabase Auth.
Security
Data is stored encrypted at rest with row-level security policies restricting access to the registrant and the organising team. One-time verification codes are generated and validated by Supabase Auth; they are not stored in our database.
Contact
For any privacy question that isn't answered here, or to raise a complaint about how your data has been handled, reply to any message you receive from the organising team, or use the deletion page linked above.