Effective Date: March 24, 2026 · Last Updated: August 26, 2026 · Document Version: 2.4
PortFlow is a maritime operations platform for port agencies. This policy covers two things: the public site at www.portflow.tech, and the application at app.portflow.tech. It describes what is actually collected today, not what we intend to build.
PortFlow is the controller for data about its own account holders, waitlist contacts and site visitors. For the data an agency loads into the application, including crew, client contacts and port calls, the agency is the controller and PortFlow is the processor acting on its instructions.
Some of the people described in this policy, in particular seafarers, are not PortFlow users and never see this page. Section 1.6 and section 1.7 set out exactly what is held about them, so that the agency responsible for them can tell them.
Questions about anything below: info@portflow.tech.
The crew module holds a full identity file on each seafarer an agency records. This is personal data about people who are not our users. The agency that entered it is the controller.
Passport number, nationality, date of birth and gender marker are encrypted at the application layer with AES-256-GCM before they are written to the database, with a blind index so that search still works without decrypting the column.
Two parts of the product hold data that relates to a named person's health. We are declaring them explicitly because they fall under Art. 9 GDPR and need a separate legal basis from the agency that records them.
PortFlow does not store diagnoses, clinical records, treatment details or the content of any medical examination. It stores the certificate metadata above and the event type.
PortFlow does not transmit anything to a port authority, to customs or to immigration. Preparing and submitting a declaration stays with the agency.
When a new account is created, PortFlow runs an automated assessment of the signup for internal lead triage. This is described in full in section 2.
Your data is used for the following purposes:
Providing, maintaining, and improving PortFlow. Processing vessel information and maritime operations. Generating quotations, disbursement accounts and invoices.
Understanding feature usage patterns. Identifying performance bottlenecks. Improving user interface and user experience.
Responding to support requests and technical issues. Troubleshooting account or service problems. Providing training and documentation.
Rate limiting by IP address, bot checks at registration, blocking disposable email domains, detecting unauthorized access and keeping an audit trail.
Complying with legal and regulatory requirements. Responding to lawful government requests. Maintaining records for audit purposes.
Sending service announcements and system updates. Notifying you of planned maintenance. Responding to your inquiries.
Assessing new signups and waitlist contacts to decide who we follow up with, and how. This includes the automated assessment described below.
Automated Assessment of New Signups
When an account is created, PortFlow sends the company name, the email domain, the phone number, the ports operated and the approximate location derived from your IP address to an Anthropic language model. The model returns a short internal note about the account, which we use to decide who to follow up with and how. It is stored against your agency and emailed to us, and it goes nowhere else.
It runs after the account already exists. It cannot block a signup, deny access, restrict features or reverse a registration, and it produces no legal effect for you. If the assessment fails for any reason the account is still created. To ask what was recorded about your account, or to contest it, write to support@portflow.tech.
What allows us to hold it
Data protection law asks us to say not only what we do with your data but on what grounds. For each purpose above, the ground is one of these four.
What you have to give us, and what is optional
Your name, email address and a password are required to create an account; we cannot open one without them. Phone number and ports operated are optional, and leaving them out costs you nothing except that the assessment above has less to work with. A waitlist sign-up needs only a name and an email. Everything your agency records about vessels, clients and crew is its own decision, not a requirement we impose.
We Do NOT:
No automatic purge is implemented
PortFlow does not run a scheduled job that deletes data when a period expires. Rather than publish retention periods that nothing enforces, the table below states what actually happens to each kind of data today. Deletion happens when a record or its parent is deleted, or when someone asks us and we do it by hand.
| Data Type | What happens today |
|---|---|
| Account and agency data | Kept for as long as the account exists. There is no scheduled deletion after cancellation and no recovery countdown; removal is a manual request. |
| Operational data (vessels, port calls, services) | Kept for as long as the agency keeps the record. Deleting a port call deletes the FAL documents generated from it. |
| Crew and identity documents | Kept until the agency deletes the crew member. Deleting a crew member deletes their identity documents with them. |
| Invoices, disbursement accounts and financial records | Kept indefinitely. Billing snapshots are historical and immutable by design, and tax law in the agency's own country normally requires several years. |
| Audit log | Kept indefinitely. It is the tamper evidence record of who did what, and nothing purges it. |
| Assistant conversations in the application | Kept for as long as the account exists. No expiry is applied. |
| Sessions and refresh tokens | Expired session rows are pruned when the same account next refreshes a token. |
| Error reports | Held by our error monitoring provider under its own retention schedule, which we do not control. |
| Waitlist sign-ups pending confirmation | Held on our hosted Redis service for 24 hours, then dropped by the store itself. |
| Confirmed waitlist contacts | Held in our own mailbox as email until we delete it. |
When you ask us to delete data, we do it manually and confirm when it is done, within the statutory deadline set out in section 4. We do not currently have an anonymization routine, so where a record cannot be deleted for a legal reason we will tell you that it is being retained and why, rather than claim it has been anonymized.
If you are located in the EU or in a country with similar privacy laws, you have the rights below. All of them are available to you. None of them is self service: PortFlow has no privacy dashboard, no export-my-account button and no account deletion screen. Every request is handled by a person.
Who to ask depends on the data. If you are a seafarer or a client contact whose details an agency loaded into PortFlow, that agency is the controller and your request goes to them; we assist them in answering it. If you are a PortFlow account holder, a waitlist contact or a visitor to this site, the request comes to us.
A copy of the personal data held about you, the purposes of the processing, the recipients and the criteria used to set retention. We assemble the extract by hand from the relevant records.
Correction of inaccurate or incomplete records, including crew details and identity document data. There is no self-service profile page, and editing a user account inside the application is restricted to an agency administrator, so send us the correction and we will apply it.
Deletion of your personal data, carried out manually by our team. Two things normally survive: financial records the agency must keep under its own tax law, and audit log entries, which exist as the record of who did what. We will tell you exactly what was kept and why.
The application exports per module, in CSV or XLSX: audit log, invoices, payments, quotations, vessels, port services, provisions, water supply and client account statements. Those are reports scoped to an agency, not an extract for one individual, so a portability request for a single person is assembled by hand.
An objection to direct marketing stops that processing once we receive it. Our emails carry no unsubscribe header and there is no preference centre, so the way to object is to write to us and we will stop. For analytics on this public site there is no consent gate today, so browser level blocking is the only technical opt out.
Processing limited while accuracy is verified or a dispute is resolved. There is no restriction flag in the product, so we apply this as an operational hold agreed with you in writing.
The deadline is the statutory one in Art. 12(3) GDPR: one month from receipt of the request, extendable by two further months for complex or numerous requests, in which case we tell you within the first month and explain why. PortFlow does not publish a faster service level than the law requires, because it has not measured one.
To exercise any of these rights, write to support@portflow.tech. Tell us which right you are exercising and give us enough information to identify your records. We will ask you to confirm your identity before we act, and we will confirm in writing when the request is complete.
If we get it wrong, you can complain about us. You have the right to lodge a complaint with the data protection authority where you live, where you work, or where you believe something went wrong, and you do not have to come to us first. We would rather you did, because we can usually fix it faster than a regulator can, but that is a preference of ours and not a condition on your right.
These are the third parties that process data on our behalf today. Regions reflect the current default configuration and are not contractual.
PortFlow has no signed Data Processing Agreement with its customers. Each provider below is used under its own standard terms and data processing addendum. A contractual right to be notified of changes to this list, and to object to them, exists only once a DPA is executed. See the compliance page for where that stands.
Application database · United States (default region)
Stores all application data, including crew identity and financial records.
Hosting and CDN · Global edge network
Hosts the application, the API and this public site. Supplies the approximate location headers derived from your IP address.
Private file storage · United States
Stores disbursement account evidence files in a private store.
Identity provider · United States
Handles sign-in for the agencies enrolled in the Auth0 pilot, and receives their email address and authentication events. Agencies outside the pilot sign in against PortFlow directly and their credentials never reach Auth0.
Rate limiting and short-lived state · United States (default region)
Holds your IP address in clear as a rate limiting counter key, and holds a waitlist name and email for 24 hours pending confirmation.
Email delivery · United States
Sends transactional email: verification, password reset, captain portal links, waitlist confirmations and internal notifications.
Hosted mailboxes · United States
Hosts the PortFlow mailboxes that receive support and general correspondence. It is not used as a CRM.
AI assistant and signup assessment · United States
Generates assistant replies, and runs the automated signup assessment described in section 2. Crew, vessel and financial records are not sent to it.
File scanning · United States
Receives the raw bytes of every crew list or capability spreadsheet you upload, before it is parsed, in order to scan it. Those files routinely contain passport numbers.
Bot check at registration · Global edge network
Verifies that a registration comes from a human. Receives a challenge token and your IP address.
Payments and subscriptions · United States
Merchant of record for online subscription billing. Where used, it handles checkout and card details, which never reach PortFlow, and returns customer and subscription identifiers.
Error monitoring · United States
Receives production error reports. A filter is applied to strip personal fields before an event is sent.
Communications use TLS. HTTPS is enforced on all PortFlow domains, and the database connection verifies the server certificate.
The database provider encrypts data at rest. On top of that, crew passport number, nationality, date of birth and gender marker are encrypted by the application with AES-256-GCM before they reach the database.
Each agency is isolated in the database with row level security. Multi-factor authentication is available, admin actions are written to an audit log, and production database access is restricted.
A content security policy restricts what the browser may load. Requests are rate limited by IP address, and registration is behind a bot check.
Vercel and Neon hold SOC 2 Type II reports for their own services. PortFlow holds no certification of its own, has not been independently audited, and inherits nothing from its providers.
Default: All application data is stored in a single Neon Postgres database in the United States. The application and this site run on the Vercel edge network.
EU Data Residency: Not deployed. PortFlow runs one shared database with a single connection string and has no per region routing, so there is no environment we can point at an EU region today. Neon and Vercel both offer EU regions, so it is technically possible, but nothing has been provisioned or tested and no customer runs on one. Treat it as a scoping conversation, not a feature. To scope it, write to info@portflow.tech.
Data Transfers: In the default configuration, personal data is processed in the United States. Those transfers currently rest on the Standard Contractual Clauses and data processing terms of each provider listed in section 5. PortFlow has no SCCs of its own signed with customers, because no DPA has been executed yet.
No third party tracking runs on this site. Google Analytics was removed from both this site and the application in August 2026, and no advertising or social pixel has ever been used. What remains is Vercel Analytics, which is first party, aggregated and cookieless. There is nothing here to consent to, which is why you were not asked to click a cookie banner.
Required for login, session handling and security. Cannot be disabled.
Your choices for language and display settings.
Vercel Analytics on this public site. Aggregated page view measurement that sets no cookie and does not identify you.
The application at app.portflow.tech runs no analytics at all. No Facebook Pixel, advertising pixel or social tracker is used on either the site or the application, and no advertising network receives anything from us.
If PortFlow becomes aware of a security breach that compromises personal data, we commit to:
To report a vulnerability or a suspected incident, write to security@portflow.tech.
PortFlow is a business tool and is not intended for anyone under 18. Account holders must be at least 18 years of age or act on behalf of a business entity, which matches the age requirement in our Terms and Conditions. We do not knowingly collect personal data from anyone under 18 as an account holder. If we learn that we have, we will delete it. This does not apply to crew records, which an agency may hold about a seafarer of any lawful working age as part of its own regulatory duties.
We update this page when what the product does changes. The version number and the last updated date at the top of the page tell you which text you are reading. Material changes are announced to account holders by email.
For privacy-related questions or to exercise your data rights:
Privacy and data rights: support@portflow.tech
General enquiries: info@portflow.tech
Security issues: security@portflow.tech
PortFlow © 2026 · All Rights Reserved · Document Version 2.4