Skip to main content

What information of mine was involved?

What was copied, why notices differ from person to person, and what was not taken.

Your security notice lists what applied to you. It is not the same for everyone, and that is deliberate.

This page is about Yacht Week records. If you also travelled with Ski Week, that is a separate company holding separate records, and its answers are at help.theskiweek.com.

Why your notice may differ from a friend's

We checked each record individually rather than sending one generic warning. Some people had passport details on file, others did not. Some had payment records, others only contact details. If you and someone you travelled with received different notices, both are correct.

This also means that if a field was filled in oddly when you registered, your notice reflects what was actually in the database rather than what we assume should have been there.

What was copied

Depending on your record, the data copied may have included:

  • Identity details given for charter and border requirements — passport number, date of birth, place and country of birth, nationality and sex

  • Contact details — name, email address, phone number, postal address, and next-of-kin where you gave one

  • A stored card reference — a token held on our side, along with the card type, expiry and last four digits

What was not taken

No passport scans, photographs, signatures or machine-readable strips. What we held was text typed into database fields, not images of your document. This matters: a scan carries your photograph and signature, and a number does not.

No card security codes. We never store CVV or PIN numbers, and none were taken.

No usable card numbers in the ordinary case. The card reference held against your booking is a token. It cannot be used to take a payment.

Yacht Week account passwords were not copied. The Ski Week answer is different — see Do I need to change my Yacht Week password? if you hold both.

What was not compromised

The intrusion was confined to an internal reporting tool. The Yacht Week platform itself was not compromised — there was no unauthorised administrative access, no account takeover, and no service disruption. Nothing in your booking was altered or deleted; the access was read-only throughout.

If you want the detail specific to you

We can tell you what your individual record contained. See How do I find out exactly what data you hold about me?

Did this answer your question?