BoatLog — Sign in. Row safe. Log out.

Privacy Policy

Last updated 10 August 2026

BoatLog is a digital boat sign-out book for rowing clubs, operated by Civil Digital at app.boatlog.civildigital.co.uk. This policy explains what personal data BoatLog handles, who is responsible for it, and what you can ask us to do about it.

Who is responsible for your data

Civil Digital acts in two different roles, depending on which data is involved. This is not a contradiction — it reflects two kinds of processing:

  • Civil Digital is the data controller for the BoatLog platform itself: account and sign-in data, billing and subscription records, security and audit logging, and the operation and improvement of the service.
  • Civil Digital is a data processor for the information your club enters — member records, outings, bookings, damage reports and safety records. For that data your club is the controller: it decides what to record and why, and Civil Digital processes it on the club's instructions.

All enquiries, including data-subject requests, safeguarding questions and complaints, go to info@civildigital.co.uk. If your request concerns data your club entered, we may need to pass it to your club administrator, since the club is the controller for that data.

What BoatLog holds

  • Account data — your email address, and a password held only as a hash by Firebase Authentication. We never see your password.
  • Member records — name, contact details, the roles you hold in your club, whether you appear on the boating roster, and for under-18s a link to a parent or guardian who holds the contact details.
  • Activity records — outings (which boat, who signed it out, crew, destination, times), bookings, and damage or repair reports, including any photograph you attach to a damage report. Embedded metadata is removed from those photographs too — see Photographs and documents you upload.
  • Kiosk PINs — a 4-digit PIN used to identify you at a shared boathouse tablet, stored only as a salted scrypt hash. We cannot show you your PIN; a club administrator can issue a new one.
  • Safety records — whether an outing was logged while a safety flag was in force, and any incident record your club creates. Anyone in the club can file an incident report, because the person who saw something is the person who should be able to record it — but the report itself is readable only by your club's captain, committee, safety officer and administrators. It is not shown to other members and is never shown on a shared boathouse tablet.
  • Billing data — your club's subscription state. Card details are handled entirely by Stripe; Civil Digital never receives or stores them. Whether a card is on file, when the subscription renews, and your club's payment-provider reference are visible only to the people who manage your club's billing — its membership secretary and administrators. Every member can see the parts the app needs to work, which is the plan and whether the subscription is active.

Activity records reference people by an internal identifier rather than storing names inside them, so names live in one place and can be corrected or erased without rewriting the club's history.

Who can see your name in the club

When you are booked into a boat, signed out on an outing, or listed as part of a crew, your name is shown to other members of your club within BoatLog. This is so the club can see who is on the water, run outings safely, and meet its safety obligations (including British Rowing RowSafe duties).

  • Your name appears on the booking or outing record for a boat and on in-club views used by authorised people — for example coaches, the club captain and safety officers viewing who is on the water or which outings are overdue.
  • The full club roster is not browsable by ordinary members. Only coaches, captains and administrators can search the roster or assign crew seats.
  • Where a crew boat is signed out without a coach or captain present, only the person who signed it out is named. The occupant list is not necessarily a complete record of everyone aboard — it records who took responsibility for the boat.
  • Only members of your club can see this information. Other clubs cannot. Civil Digital can access it where necessary to support or operate the service, acting as your club's processor.
  • Where an outing was logged while a safety flag was in force, your name may appear in the club's internal safety and red-flag audit records.

Shared boathouse tablets

A club may run BoatLog on a shared tablet in the boathouse. That tablet is signed in as a device, not as a person, and it does not hold your club's roster — it cannot list or search your members.

You identify yourself there by typing your PIN, and the screen shows your name so you can confirm it is you before a boat is signed out in your name. So that this still works when the boathouse has no signal, the tablet remembers the name of each person who has used that particular tablet — nothing else about them, and only for 28 days after their last use. It never downloads the club list. The remembered names are erased when the tablet is unpaired.

Members under 18

Every member recorded as under 18 must be linked to a parent or guardian, who holds the contact details and is recorded as the emergency contact. The young person's name is visible to authorised club members on crew lists and who's-on-the-water views, in the same way as any other member.

Consent is a matter between the young person's parent or guardian and the club, which is the controller for that data. Contact your club administrator or welfare officer to see, correct, withdraw consent for, or erase a young person's information.

Qualifications, checks and certificates

Your club can record what its members are qualified for — a swim test, a capsize drill, a DBS check, a safeguarding course — with the date, any expiry, and optionally a certificate or other document as evidence. Your club decides which of these it records; the list is its own.

Who can see them. The record itself (which check, its dates, whether it has been verified) is visible to your club's coaches, captain, committee, safety officer, membership secretary and administrators, and to you for your own record. The evidence document is narrower still: only your club's safety officer and administrators can open one, or you for your own. There is no screen anywhere in the app that simply displays these documents — opening one goes through a check on who is asking, and every access is recorded, including who opened whose and when.

How long they are kept. A certificate is kept for as long as your club keeps the record it belongs to, and is deleted when the member's record is erased or the club is deleted. Civil Digital does not apply an automatic expiry to DBS certificates; your club is the controller and decides when a check no longer needs to be held. If you want a certificate removed sooner, ask your club administrator or safety officer — the app lets them delete it.

A member can supply their own evidence, and it is recorded as unverified until somebody with the authority to check it says otherwise. Nobody can verify their own.

Emergency contacts and health information

You can record the details your club would need if you were hurt or taken ill: one or more emergency contacts (each with a name, an optional relationship to you such as "Mother" or "Partner", a phone number and an email), in the order you want them tried; plus your home address, any allergies, illnesses or medical conditions, other medical information, and anything else you want the club to know about your health. All of it is optional, you enter it yourself on your Me tab, and you can add, reorder, change or remove any of it at any time.

The contacts are people you name, so their details are their personal data as well as yours. Tell them you have listed them — the club may ring them, and BoatLog has no way to ask them first.

This is health data — special-category data under UK GDPR Article 9 — and it is treated accordingly. Civil Digital relies on your explicit consent for it: you provide it voluntarily, for the single purpose of being cared for in an emergency, and withdrawing it is as simple as clearing the fields.

Who can see it. Only your club's coaches, captain, safety officer and administrators — the people who would be dealing with an emergency — and you, for your own. Other members cannot see it. Nor can your club's committee or membership secretary, even though they can otherwise administer members: being able to edit the roster does not carry the right to read somebody's medical conditions. It is never shown on a shared boathouse tablet.

Every time somebody opens your details, it is recorded — who opened whose, and when — in the same way as an evidence document. Opening it is a deliberate press on a button that says so beforehand, not something that happens because somebody looked at your record for another reason.

Where it is held. Separately from the rest of your member record, in a place that no app screen and no member's device can read directly. In particular it is never copied onto anybody's phone or tablet for offline use, as the rest of the club roster is — it is fetched only when somebody with permission asks for it, and it is gone again when they close the screen.

How long it is kept. For as long as you keep it there. It is deleted when your record is erased and when the club is deleted, and it is included in full if you ask for a copy of your data.

BoatLog is a record of what you chose to tell your club. It is not a medical record, it is not shared with the emergency services automatically, and nobody is monitoring it.

Photographs and documents you upload

Photographs have their embedded metadata removed automatically before they leave your device. A phone photograph normally carries the exact location the photograph was taken and an identifier for the device that took it. BoatLog re-encodes the picture on your device, which discards all of it, and only then stores or uploads it. This applies to RowSocial posts and profile pictures, damage-report photographs, and kit-order pictures.

The removal happens the moment you choose the photo, not when it uploads. That matters on the water: a damage-report photograph taken with no signal waits on your device until you are back in range, and it has already had its location stripped while it waits. If a photograph cannot be processed, BoatLog refuses the photograph rather than uploading the original — your report still goes through without it.

One deliberate exception: evidence documents. A certificate uploaded for a qualification or check is stored exactly as you supplied it, unaltered, because it is a record your club may later need to rely on. Those are covered by Qualifications, checks and certificates above, and are the most tightly restricted thing BoatLog holds.

RowSocial

RowSocial is your club's own news feed. It is an optional feature: it is available to clubs on a paid plan, your club's committee can switch it off entirely, and no member is part of it until they have agreed to its terms in the app. If you never agree, nothing about you is processed by it and you cannot see it.

What is processed. Posts (a title, text and up to two photographs), comments and replies, reactions, and reports of content to your club's moderators. Each post and comment carries the name your club holds for you, saved onto it at the moment you post. If your club later changes the name on your record, posts you have already made keep the name they were published with.

The lawful basis is consent, given by you in the app, and you can withdraw it at any time from your RowSocial settings. Withdrawing does not close your BoatLog account or affect anything else you do in it.

Who can see it. Only members of your own club who have themselves agreed to RowSocial. It is never visible to another club, never public, and never indexed by a search engine.

Members under 18. A young person can only take part if their parent or guardian gives a separate consent for RowSocial specifically — the safeguarding consent already given for rowing does not cover it. That consent states in plain words that their name will be visible, that they may post text and photographs, that other members may post photographs which include them, and that posts are moderated after they appear rather than before. Withdrawing the safeguarding consent also withdraws this one. A guardian's consent stops applying when the young person turns 18, and they are asked to agree for themselves before posting again.

Photographs. Photographs posted to RowSocial have their embedded metadata removed before they leave your device — see Photographs and documents you upload, which applies the same treatment everywhere in BoatLog. Photographs posted by other members may include you or your child; if you want one taken down, report it and your club's moderators can remove it.

Moderation and reports. Your club's committee, captain and admins act as its moderators — your club is the controller, so moderation decisions are your club's, not ours. A report records who made it and what they said, and is visible only to those moderators — never to other members, and never to the person whose content was reported. When content is removed, we log who removed it and when, using internal identifiers and a reason code only, never the content itself.

What withdrawal and erasure actually do. Your name is removed from everything you posted — it is replaced with "Former member" — and your reactions are deleted. Your posts and comments themselves stay up. We do not delete conversations that other members took part in because one person left them. This is worth knowing before you post: withdrawing removes your name, not the words. Anything anonymised this way cannot be reversed, and text you wrote may still mention you by name, which nothing can fix automatically — ask your club's moderators to remove such a post.

Lawful bases

  • Legitimate interests — recording outings, crews and safety flags so that a club can operate on-water activity safely and account for its boats; keeping security and audit logs.
  • Consent — RowSocial, which no member takes part in until they agree to it in the app, and which they can withdraw at any time.
  • Contract — providing the service to your club and administering its subscription.
  • Legal obligation — retaining records where we are required to.

How long data is kept

When a member leaves a club, their personal details are anonymised six weeks later: name, contact details and PIN are erased, and the internal identifier is kept so the club's outing history stays intact as an anonymous record. This means erasure removes who you were, not that a boat went out.

Safety and incident records are retained by the club for as long as its safety obligations require. Billing records are retained as long as required for accounting purposes.

If a club stops subscribing, its BoatLog data is permanently deleted 28 days after access is paused. That covers everything the club recorded — members, outings, bookings, damage reports and safety records. An administrator can export it all at any point during those 28 days, and we email the club's administrators before the deadline. Resubscribing stops the clock. After the deadline the deletion is permanent and cannot be reversed.

Where your data is stored

BoatLog's database, files and server-side processing run in Google Cloud's London region (europe-west2) — your club's data is stored in the United Kingdom. Some sub-processors listed below may process limited data outside the UK under their own safeguards.

Sub-processors

  • Google Ireland Ltd / Google Cloud (Firebase) — authentication, database, file storage, hosting, server-side functions, push notifications and operational logging.
  • Stripe — subscription billing and card payments. Card details go directly to Stripe; Civil Digital never receives them.
  • Resend — delivery of service emails, such as overdue-boat alerts.

Cookies, analytics and what's stored on your device

BoatLog sets no cookies at all. Not advertising cookies, not analytics cookies, not “essential” ones — none. There is also no analytics and no tracking of any kind: no Google Analytics, no third-party measurement, no behavioural monitoring. We don't build a profile of you, and there is nothing to opt out of.

That is also why you have never seen a cookie banner here, and won't. Everything BoatLog keeps on your device is strictly necessary — remove any of it and something you asked for stops working — and consent isn't required for that. Asking anyway would just train people to click past banners that do matter.

Signing out clears your club's copy from that device. BoatLog keeps a local copy of your club — its boats, outings, bookings and repairs, and the member list if your role lets you see it — so the app works with no signal. When you sign out, that copy is deleted, along with the record of which club you were in. This matters on a shared computer or a club laptop: the next person to sign in starts from nothing and sees only what their own role allows.

The one thing sign-out keeps is work that has not reached the server yet — a sign-out or a repair you recorded with no signal. That is your own record of something you were told was saved, so it is kept and sent when you next sign in, and it is not shown to or submitted by anyone else who uses that browser in the meantime.

Here is the complete list:

WhatWhereWhy it's necessaryHow to clear it
Your sign-in sessionfirebaseLocalStorageDbIndexedDBKeeps you signed in between visits. Without it you would re-enter your password on every page load.Signing out, or clearing site data in your browser.
Your club's offline copyboatlog-{clubId}IndexedDBHolds your club's boats, outings, bookings and repairs, plus anything you've done that hasn't synced yet, so the app works with no signal. This is the offline-first product, not an optimisation.Signing out, which clears everything except work still waiting to sync — that is kept for you and sent when you next sign in. Clearing site data removes it all, including unsynced work.
Which club you last usedboatlog.activeClubIdlocalStorageOpens the app on the club you were last in, instead of asking every time. Only matters if you belong to more than one club.Signing out, or clearing site data.
Boathouse tablet: remembered namesboatlog-{clubId} (kioskIdentities)IndexedDBOn a paired kiosk only: lets someone who has used that tablet identify by PIN with no signal. Expires after 28 days (AR-3).Unpairing the tablet, which erases it.
Boathouse tablet: tile sizeboatlog.kiosk.densitylocalStorageRemembers whether the club chose larger or more tiles on that tablet.Clearing site data.
Dismissed the orientation tipboatlog.orientationDismissedlocalStorageRemembers that you closed the welcome tip, so it doesn't reappear every visit.Clearing site data.
Notification setup for this devicefirebase-messaging-databaseIndexedDBOnly present if you turn on notifications. Holds the token the push service uses to reach this device — without it there is nothing to send a notification to.Turning notifications off for this device on the Me screen, which also removes it from your account. Signing out removes it from your account too. Clearing site data removes the local copy.
Which sections you collapsedboatlog.collapsible.localStorageRemembers which expandable sections you closed on the admin screens, so a long list you folded away stays folded.Clearing site data.

Your rights

You can ask for access to your data, correction, erasure, restriction, or to object to processing, and you can ask for a copy of your record in a portable form. BoatLog includes a data-request route in the app under Me → Your data.

Requests about data your club entered are handled by your club as controller; write to your club administrator, or to info@civildigital.co.uk and we will route it. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

BoatLog is a record-keeping tool, not a safety system

BoatLog records what a club logs. It does not monitor the water, detect danger, summon help, or guarantee that anyone is where a record says they are. Overdue alerts and safety flags are conveniences built on what people have entered; they are not a rescue or emergency service, and they can be wrong or delayed if a record was not entered, was entered incorrectly, or could not be synchronised. Your club's own safety procedures remain the thing that keeps people safe.

Changes to this policy

We will update this page when the service changes, and the date at the top will change with it. For anything unclear, write to info@civildigital.co.uk.