Schengen Crew

Privacy Policy

Last updated 5 October 2026

Who we are

Schengen Crew is a tool for yacht-management companies to track crew compliance with the Schengen 90/180 rule. It is operated by Cailiac FZE LLC (trade licence no. 2628913647888), CWS-1V-228062, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates, contactable at info@schengencrew.com.

Schengen Crew is provided to yacht-management companies. The company that uses it to track its crew decides what is recorded and why: it is the data controller, and we process the data on its behalf.

For the little we collect for ourselves — enquiries sent through our website, billing, and keeping accounts secure — Cailiac FZE LLC is the controller.

What we store

  • Your account. Name, email address, profile photo and an identifier from the provider you sign in with (Google or Microsoft), plus the date you last signed in.
  • Your nationality and passport. Because the 90/180 rule only applies to non-EU/EEA/Swiss nationals, the calculation cannot be done without it — the citizenship of the passport you travel on. A passport number and a date of birth, when given, are kept for the crew list a yacht hands to a port, an agent or immigration, and are shown only to you and your fleet's Admins.
  • Your trips. Entry and exit dates, the countries visited, whether the trip counts toward the limit, and any note attached to it.
  • Your place in a fleet. Which company and yacht you belong to, your role, and whether you are currently aboard or have left.
  • A record of changes. Who changed a crew member's trips or role, and when. This exists so a compliance record can be accounted for.
  • Images you upload. A company logo, a yacht photo, a crew photo.
  • Notification subscriptions, if you switch on push notifications for a device or the phone app.
  • A private calendar link, if you add your days to your phone's calendar. It works like a password; you can replace it at any time from Settings.
  • Billing details for a company's plan: the company name, a billing email and the plan. Card details are entered on Stripe's page and never reach us.
  • Demo requests from our website: your name, work email, company, region, fleet size, the plan you're interested in and your message.

We do not use advertising, and we do not sell or share personal data with anyone for their own purposes. To see how the site is used and how fast it loads, we count visits with Vercel Web Analytics and Speed Insights — anonymously and in aggregate, without cookies and without anything that identifies you. Pages are counted by their kind (a crew member's page), never by whose they are.

Why we use it

  • To run the service for a company — counting days, planning rotations, sending the alerts and summaries its admins switch on. We do this on the company's instructions, under its contract with us.
  • To keep accounts secure and the service working — sign-in, preventing misuse, fixing faults. This is our legitimate interest in running a safe service.
  • To bill a plan, under the contract and the tax law that applies to it.
  • To answer a demo request — only to reply to you and, if you ask, prepare a quote. We don't add you to a mailing list.

The 90/180 count is automatic, but it is a planning figure: it never makes a decision about anyone on its own.

Who can see it

Within a fleet, managers and administrators can see the crew records they are responsible for — that is the purpose of the product, and every change is logged with who made it. Crew members see their own days and their yacht's calendar, and cannot see each other's records.

Google and Microsoft access

Connecting a spreadsheet or a calendar is optional, and only a yacht's manager can do it. We ask for the narrowest access each feature needs, and only when that feature is switched on:

  • Google Sheets — drive.file, which reaches only the spreadsheets Schengen Crew itself creates in your Drive and nothing else there. A sheet you already keep is connected by sharing it with your fleet's own address, which you can remove at any time.
  • Google Calendar — calendar.readonly and calendar.events, asked for only when a manager connects a calendar. We read the events of the one calendar they choose for a yacht, and keep it and the yacht's board in step both ways: the yacht's own events (charters, owner visits, yard periods entered in Schengen Crew) are added to that calendar and updated or removed when they change; an event of ours moved, renamed or deleted in the calendar is changed the same way in Schengen Crew; and, if the manager turns it on, events made in that calendar are copied onto the yacht's board (their name, dates and description). Otherwise the calendar's own events are shown to the yacht's managers and held in memory for a few minutes, not stored. We never change or delete an event in the calendar we didn't add, apart from the name and dates of one copied onto the board when a manager edits it there. We keep which calendar was chosen, which events were hidden, and the ids of the events we added or copied.
  • Microsoft — Files.ReadWrite.All, Calendars.ReadWrite and offline_access, asked for only when a manager connects Excel or Outlook Calendar, with their own Microsoft account. Microsoft has no equivalent of Google's per-file grant, so Files.ReadWrite.All is the narrowest scope that can open a workbook shared with you; Calendars.ReadWrite keeps the one Outlook calendar they choose for a yacht in step with its board exactly as described for Google Calendar above.
  • Signing in — openid, profile and email, to identify you.

We read only the sheet you point us at, and we write only to a worksheet we create and own by name — the tabs your office maintains are never written to. Google user data obtained through these scopes is used solely to provide the spreadsheet-sync and calendar features you switched on; it is not used for advertising, not sold, not shared with third parties, and not used to train any AI or machine-learning model. Schengen Crew's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect at any time from Settings, which deletes the stored credential, and you can revoke our access from your Google or Microsoft account at any time.

Where it is kept, and how

Data is stored in MongoDB Atlas. Credentials for connected spreadsheets — the tokens that let us reach your file — are encrypted before they are written to the database. Traffic to the app is over HTTPS.

Our processors are: MongoDB Atlas (database hosting), Vercel (application hosting), Zoho (sending invitation, alert and summary emails), Stripe (payments), Expo with Apple and Google's push services (notifications on the phone app), your browser's push service (notifications on the web), and Google and Microsoft (sign-in and, if you connect one, spreadsheets and calendars).

Some of them store or process data outside your country, including in the European Union and the United States. Where personal data leaves the EU, EEA or UK, the transfer relies on an adequacy decision or the European Commission's Standard Contractual Clauses.

Access inside a fleet is by role, every change to a crew record is logged with who made it, stored credentials are encrypted, and all traffic is over HTTPS.

How long we keep it

Crew records are kept for as long as the fleet using Schengen Crew keeps them, because a 90/180 calculation depends on trips from the previous 180 days and a compliance record may need to be produced later. A personal account's data is kept until you ask us to delete it. A deleted record is kept in a recoverable bin, so a mistake can be undone, and is removed for good when the company asks us.

Demo requests are kept for up to two years unless you become a customer. Billing records are kept for as long as tax law requires.

Cookies

We use one cookie, which keeps you signed in, and keep a few interface preferences in your browser — for example, which tips you have already dismissed. Both are needed for the service to work. There are no advertising or tracking cookies — visits are counted without any — which is why there is no cookie banner.

Children

Schengen Crew is a tool for working crew and the companies that employ them. It is not meant for children, and we do not knowingly collect data about anyone under 16.

Your rights

If you are in the EU, EEA or UK, you have the right to access, correct, export, or request deletion of your personal data, to object to or restrict its processing, and to complain to your local data protection authority. In the United Arab Emirates you have similar rights under Federal Decree-Law No. 45 of 2021. Write to info@schengencrew.com and we will respond within 30 days. If your data was entered by a yacht-management company, we may need to refer your request to them, and we will tell you if so.

Changes

If this policy changes in a way that affects how your data is used, we will say so on this page and update the date above.