AIS Trail

Features

Use Cases

Pricing

FAQ

Docs

Live Map

Sign in

Get started

AIS Trail

Docs

  • Quickstart
  • API reference
  • Errors
  • Data sources

Legal

  • Terms of service
  • Privacy policy
    • 1. Who is responsible
    • 2. What we collect
    • 3. Why we use it and our legal bases
    • 4. How long we keep it
    • 5. Who we share it with
    • 6. International transfers
    • 7. Cookies
    • 8. Personal data in AIS data
    • 9. Security
    • 10. Your rights
    • 11. Children
    • 12. Changes to this policy
    • 13. Contact

Draft pending legal review. Highlighted values in brackets are placeholders that AIS Trail will complete before this policy takes effect.

Legal

Privacy policy

Effective date: [Effective date]. Last updated 10 October 2026. Contact: hello@aistrail.com.

This policy explains what personal data AIS Trail collects when you visit aistrail.com, use the dashboard at app.aistrail.com, open the live map at map.aistrail.com or call the API at api.aistrail.com, why we use it, how long we keep it and which rights you have. We describe legal bases and rights in the terms of the EU General Data Protection Regulation (GDPR); other data protection laws may also apply: [Applicable data protection law].

1. Who is responsible

The controller of your personal data is [Company legal name], [Registered address], registered under number [Company registration number] ("AIS Trail", "we", "us").

  • Privacy questions and requests: [Data protection contact], or hello@aistrail.com.
  • Representative in the EU, if one is required: [EU representative].

2. What we collect

Your account

To create an account you give us your email address and a password; your name and company are optional. We store your email address, your password only as a salted one-way hash (PBKDF2-HMAC-SHA256), never the password itself, the name and company if you give them, your plan, the times you created the account, confirmed your email address and accepted the terms, and whether the account has been disabled. You can change or remove your name and company on the Settings page.

Sign-in sessions

When you log in to the dashboard we create a session. We store a hash of the session token, the IP address and browser user agent at sign-in, and when the session was created, last used and expires. A session ends when you log out, after 30 days without use, and at the latest 90 days after sign-in. Changing your password ends your other sessions; resetting it ends all of them.

Email links

Links to confirm your email address (valid for 48 hours) and to reset your password (valid for 1 hour) work once. We store only a hash of each link's token, with its type and times. Requesting a new reset link cancels older ones.

API keys and usage

For each key we store a hash of the key, its first 16 characters so you can recognise it, the name you give it, its plan and when it was created and revoked. The full key is shown only once, when you create it. We count your successful requests per key and calendar month for quotas and billing; this counter stores numbers only, not what you requested.

Upgrade requests, billing and messages

When you request a paid plan in the dashboard, we store your email address, name, company, current and requested plan and the note you write, and send these details to our team mailbox so we can set up billing. For paid plans we keep the details needed for invoicing. [Billing data to confirm] When you write to us, we receive your email address and your message.

Server logs

Our API and dashboard servers log, for each request, the client IP address, time, method, path without the query string, status code, response size and duration. A path can contain the identifier (MMSI or IMO number) of a vessel you asked for. Application logs also record account events such as sign-up, email confirmation, key creation and revocation, upgrade requests, password changes and account deletion; they identify the account by an internal number, not by email address. API keys and email-link tokens are masked in logs and passwords are never logged. If an email cannot be delivered, we log the recipient's domain and the subject.

Abuse protection

To limit sign-in, sign-up and password-reset attempts and the rate of API requests, we keep short-lived counters keyed by IP address (for IPv6, the /64 network), email address, account or API key. They exist only in server memory, expire within about an hour and are lost when the server restarts.

This website

aistrail.com is a static website hosted on Cloudflare Pages. It has no forms, sets no cookies and uses no analytics or advertising trackers. Cloudflare, which delivers our pages, may measure page load times with its cookieless Real User Monitoring beacon (for example /cdn-cgi/rum); it reports timings and the page address, not who you are. Its fonts and scripts, including the open-source scrolling library Lenis, are served from aistrail.com itself, so reading these pages does not make your browser contact any other service. Cloudflare processes your IP address and request details to deliver the pages.

Live map

The public live map at map.aistrail.com needs no account. It shows AIS positions from the sources listed on the Data sources page and from community feeds (aisstream.io and Open Waters AIS) that are not part of the API. When you open it, your browser loads map tiles, the map style and map label fonts from OpenFreeMap (tiles.openfreemap.org), the open-source map libraries MapLibre GL JS and three.js from unpkg.com, and the Inter font from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Your browser connects to these services directly, which shows them your IP address and browser details; they process this data under their own terms. The map keeps two settings in your browser's local storage, your day or night view and the ship types you hide in its filters; they stay on your device and are never sent to us. Our server logs the map's requests like any other request (see Server logs above). The map sets no cookies.

AIS data

The vessel data the Service and the live map show can contain personal data in some cases; section 8 explains how we handle it.

3. Why we use it and our legal bases

PurposeDataLegal basis
Create and run your account, sign you in, issue keys, apply plan limits and show your usageAccount, sessions, email links, keys, usagePerformance of our contract with you (Art. 6(1)(b))
Send service emails: email confirmation, password reset, password-changed notice, and a notice when someone tries to sign up with your addressEmail addressContract (Art. 6(1)(b)); our legitimate interest in account security (Art. 6(1)(f))
Handle upgrade requests, billing and invoicingUpgrade requests, billing detailsSteps you ask for before a contract, and the contract (Art. 6(1)(b)); legal obligations for accounting and tax records (Art. 6(1)(c))
Keep the Service secure, prevent abuse and fix errorsServer logs, session IP address and user agent, rate-limit countersOur legitimate interest in a secure and reliable service (Art. 6(1)(f))
Keep a record that you accepted the terms; establish, exercise or defend legal claimsAccount timestamps, logs, correspondenceOur legitimate interest (Art. 6(1)(f))
Answer your messagesEmail address, messageOur legitimate interest (Art. 6(1)(f)), or the contract where your message concerns your account
Deliver this websiteIP address, request detailsOur legitimate interest in delivering the website (Art. 6(1)(f))
Comply with the law and with requests from authoritiesAs required in each caseLegal obligation (Art. 6(1)(c))

We do not sell personal data, use it for advertising or send marketing emails. We make no decisions about you based solely on automated processing that have legal or similarly significant effects; automatic quotas and rate limits only hold back requests until the limit resets. Where we rely on our legitimate interest, you can object (section 10).

4. How long we keep it

DataHow long
Account detailsWhile your account exists. Deleted when you delete your account on the Settings page.
Sign-in sessionsUntil you log out, the session expires (30 days without use, 90 days at most) or your account is deleted. Expired sessions are removed within about ten minutes.
Email-link tokensDeleted one day after they are used or expire, or when your account is deleted.
API key records and monthly request countsKept after a key is revoked and after your account is deleted, as usage and billing history. They hold an internal account number and the key's first 16 characters, name, plan, dates and counts, but not your email address. [Retention period for key and usage records]
Upgrade requestsNot removed automatically when you delete your account. We delete them on request, and at the latest [Retention period for upgrade requests].
Billing and invoicing records[Statutory retention period for accounting records]
Server logsUp to 30 days.
Rate-limit countersIn server memory only, for about an hour at most.
Emails you send us[Retention period for correspondence]
Backups[Backup location and retention to confirm]

5. Who we share it with

We use the service providers below to run AIS Trail. Providers marked as processors handle personal data only on our instructions and under data processing terms. [Hosting/processor list to confirm]

ProviderWhat it doesPersonal data
Cloudflare (processor)DNS, hosting of aistrail.com (Cloudflare Pages), and the encrypted tunnel that carries all traffic to the API, the live map and the dashboard.IP addresses and request data, and the content of requests and responses in transit
Contabo (processor)The virtual server that runs the API, the dashboard and their database. Location: [Server location to confirm]All account, key, usage, upgrade-request and log data described above
[Email delivery provider] (processor)Sends account emailsEmail address and the content of the email
[Mailbox provider for hello@aistrail.com] (processor)Receives the emails you send us and upgrade-request notificationsEmail address, name, company and message content
OpenFreeMap, unpkg.com, Google FontsServe the map tiles and style, the open-source map libraries and a font for the live map (not for aistrail.com). Your browser connects to them directly; they process this data under their own terms.IP address and browser details

We do not take online payments today. If we start, we will name the payment provider here before then.

We may also disclose personal data to authorities when the law requires it, to professional advisers bound by confidentiality, and to a company that takes over the Service, which must continue to protect it as this policy describes.

6. International transfers

Our server is located in [Server location to confirm]. Some providers listed above, such as Cloudflare and the services that serve the live map's tiles, libraries and font, operate global networks and may process data in other countries, including outside the European Economic Area (EEA). Where personal data goes to a country without an adequacy decision, we rely on [Transfer safeguards to confirm, e.g. Standard Contractual Clauses]. You can ask us for a copy of these safeguards.

7. Cookies

aistrail.com and the live map set no cookies. [Confirm: no Cloudflare cookies, such as __cf_bm, on any of our domains] The API sets none either: it identifies you by the API key in the Authorization header. The dashboard at app.aistrail.com sets two cookies, both strictly necessary for it to work:

CookiePurposeDuration
ast_sessionKeeps you signed in. It holds a random token; we store only its hash. HttpOnly, Secure, SameSite=Lax.Up to 90 days; removed when you log out
ast_csrfProtects the sign-up, log-in and password forms against cross-site request forgery. HttpOnly, Secure, SameSite=Strict.Until you close your browser

Because these cookies are strictly necessary for a service you ask for, we do not ask for consent to them. Neither the website nor the dashboard stores anything else in your browser. The live map keeps only the two display settings described in section 2 (Live map) in your browser's local storage; you can clear them in your browser settings.

8. Personal data in AIS data

The Service distributes AIS data: positions and vessel and voyage details that vessels broadcast by radio and that public authorities publish under open licences (see Data sources). It includes identifiers such as the MMSI, IMO number, vessel name and call sign. The public live map shows the same kind of data for recent positions. For most vessels this is not personal data, but for some, such as small private craft or vessels operated by an individual, it can relate to an identifiable person.

  • Source. The public authorities listed on the Data sources page.
  • Purpose and legal basis. We process this data to provide the Service, based on our legitimate interest in making published maritime data available in a clean, usable form (Art. 6(1)(f)). [Legal review: legal basis for AIS data]
  • No identification. We do not combine AIS data with other information to identify persons, and we hold no owner, crew or passenger details. Our terms forbid customers from using the data to identify, profile or track private persons without a legal basis.
  • Retention. We keep AIS data in a rolling window, currently 365 days; older days are deleted automatically.
  • Your rights. If you believe AIS data in the Service relates to you, contact us (section 10). The original data stays published by the source authority.

9. Security

We protect personal data with measures that include encrypted connections (HTTPS); application servers that are reachable only through an encrypted tunnel; passwords stored as salted PBKDF2 hashes; API keys, session tokens and email-link tokens stored only as hashes; HttpOnly and Secure cookies with protection against cross-site request forgery; limits on sign-in and password-reset attempts; and masking of keys and tokens in logs. No method is completely secure. If a personal data breach is likely to put your rights at risk, we will inform you and the authorities as the law requires.

10. Your rights

Depending on the law that applies to you, you have the right to:

  • access the personal data we hold about you and get a copy of it;
  • have inaccurate data corrected;
  • have your data deleted;
  • restrict how we use your data;
  • receive the data you gave us in a portable format;
  • object to processing based on our legitimate interest;
  • complain to a data protection authority, in particular where you live or work or where an alleged breach took place. Our lead authority: [Supervisory authority].

You can change your name and company and delete your account yourself on the Settings page of the dashboard. For anything else, including changing your email address or getting a copy of your data, write to [Data protection contact] or hello@aistrail.com from the email address on your account. We may ask you to confirm your identity. We reply within one month; where the law allows, we can extend this when a request is complex, and we will tell you if we do.

11. Children

AIS Trail is a service for professional users and is not directed at children. You must be at least [Minimum age] years old to create an account. We do not knowingly collect personal data from children; if you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We update this policy when our processing changes, for example when we add a service provider. The effective date at the top shows which version applies. If a change materially affects how we use your personal data, we email account holders before it takes effect.

13. Contact

[Company legal name]
[Registered address]
Data protection contact: [Data protection contact]
Email: hello@aistrail.com

AIS Trail

AIS Trail is a vessel data API. We turn raw AIS broadcasts into clean, consistent ship tracks, so developers, analysts and maritime teams can look up vessels, replay voyages and follow traffic without running their own receivers or data pipelines.

Product

FeaturesUse CasesPricingLive Map

Developers

API referenceQuickstartData sourcesErrors

Company

ContactTermsPrivacySign in

© 2026 AIS Trail. All rights reserved.

AIS Trail

AIS Trail is a vessel data API. We turn raw AIS broadcasts into clean, consistent ship tracks, so developers, analysts and maritime teams can look up vessels, replay voyages and follow traffic without running their own receivers or data pipelines.

Product

FeaturesUse CasesPricingLive Map

Developers

API referenceQuickstartData sourcesErrors

Company

ContactTermsPrivacySign in

© 2026 AIS Trail. All rights reserved.

AIS Trail

AIS Trail is a vessel data API. We turn raw AIS broadcasts into clean, consistent ship tracks, so developers, analysts and maritime teams can look up vessels, replay voyages and follow traffic without running their own receivers or data pipelines.

Product

FeaturesUse CasesPricingLive Map

Developers

API referenceQuickstartData sourcesErrors

Company

ContactTermsPrivacySign in

© 2026 AIS Trail. All rights reserved.

AIS Trail
FeaturesUse CasesPricingFAQDocsLive MapSign in
Get started