โ† Back to portflow.tech
๐Ÿ”’

Data Privacy Policy

Effective Date: March 24, 2026 ยท Last Updated: March 24, 2026 ยท Document Version: 1.0

PortFlow is a maritime logistics SaaS platform designed for agencias portuarias (maritime agencies) throughout the Caribbean and Latin America. We understand that your data is critical to your business, and we treat it with the highest level of care and security.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have regarding your data. If you have any questions after reading this, please contact us at info@portflow.tech.

1. What Data We Collect

1.1 Account & Authentication Data

  • ยท Full name, email address, phone number
  • ยท Login credentials (username, password hash)
  • ยท Company name and role/job title
  • ยท Organization membership and access permissions
  • ยท Login history and IP address logs

1.2 Operational Data

  • ยท Vessel information (name, IMO number, flag state, vessel type)
  • ยท Vessel specifications (tonnage, dimensions, capacity)
  • ยท Port operations data (arrival/departure times, cargo quantities)
  • ยท Service requests (bunkering, water supply, provisions, repairs)
  • ยท Quotations and pricing information

1.3 Transaction & Financial Data

  • ยท Invoices and payment records
  • ยท Transaction amounts and currency
  • ยท Payment method type (we do not store payment card details directly)
  • ยท Billing address and tax identification numbers

1.4 Communication Data

  • ยท Support tickets and correspondence with our team
  • ยท Email communications regarding your account or services
  • ยท Feature requests and feedback

1.5 Technical & Usage Data

  • ยท Device type, browser type, and operating system
  • ยท IP address and general geographic location (city/country level)
  • ยท Pages visited, features used, time spent in application
  • ยท Error logs and system performance data
  • ยท Session identifiers and cookies

1.6 Regulatory & Compliance Data

  • ยท Port authority documentation references
  • ยท Customs declaration summaries
  • ยท Audit trail records of who accessed what data and when

2. How We Use Your Data

Your data is used exclusively for legitimate business purposes:

Service Delivery

Providing, maintaining, and improving PortFlow. Processing vessel information and maritime operations. Generating quotations and managing invoicing.

Analytics & Improvement

Understanding feature usage patterns. Identifying performance bottlenecks. Improving user interface and user experience.

Customer Support

Responding to support requests and technical issues. Troubleshooting account or service problems. Providing training and documentation.

Security & Fraud Prevention

Detecting and preventing unauthorized access. Identifying suspicious activity patterns. Protecting against security threats.

Legal & Compliance

Complying with legal and regulatory requirements. Responding to lawful government requests. Maintaining records for audit purposes.

Communications

Sending service announcements and system updates. Notifying you of planned maintenance. Responding to your inquiries.

We Do NOT:

  • ยท Sell your data to third parties
  • ยท Use your vessel or transaction data for marketing purposes
  • ยท Share your data with competitors or other maritime companies
  • ยท Combine your data with external data sources for profiling

3. Data Retention Periods

Data TypeRetention Period
Account data (active)Duration of subscription
Account data (deleted)30 days (recovery window)
Login logs30 days (security auditing)
Operational data (vessels, ports)7 years (maritime industry standard)
Transaction & financial data7 years minimum (legal requirement)
Support tickets3 years
Email correspondence1 year (unless related to disputes)
Application & session logs30 days
Error logs90 days

When you request deletion, we remove your data within 30 days. Data that cannot be deleted due to legal requirements will be anonymized.

4. Your Privacy Rights (GDPR & Similar Regulations)

If you are located in the EU or countries with similar privacy laws, you have the following rights regarding your personal data:

Right to Access

Request a copy of all personal data we hold about you, provided within 30 days in a portable, machine-readable format.

Right to Deletion

Request deletion of your personal data, except where we have a legal obligation to retain it (e.g., 7-year tax records). Completed within 30 days.

Right to Rectification

If your data is inaccurate or incomplete, request corrections. We will update your information promptly.

Right to Data Portability

Request your data in a standard format suitable for transfer to another service provider within 30 days.

Right to Object

Object to certain data processing activities, particularly marketing communications. Honored immediately.

Right to Restrict Processing

Request that we limit how we process your data while you resolve a dispute or we verify accuracy.

To exercise any of these rights, contact: privacy@portflow.tech. Include proof of your identity and specify which right you wish to exercise.

5. Data Sharing & Third Parties

PortFlow works with trusted service providers who process data on our behalf under strict Data Processing Agreements (DPAs):

Neon Postgres

DPA Signed

Database Provider ยท US (us-east-1); EU available

Storing all PortFlow databases

Vercel

DPA Signed

Hosting Provider ยท Global CDN

Hosting PortFlow frontend and API

Sentry

DPA Signed

Error Monitoring ยท US

Production error tracking and performance monitoring. PII filtered automatically.

Anthropic (Claude AI)

DPA Signed

Marina Chatbot AI ยท US

Processing chatbot queries. User queries only, not vessel data.

Zoho

DPA Signed

CRM & Support ยท US

Managing customer relationships and support tickets

6. Data Protection & Encryption

Data in Transit

All communications use TLS 1.3 encryption. HTTPS enforced on all PortFlow domains. Certificates issued by recognized certificate authorities.

Data at Rest

Database data encrypted using AES-256. Backup files are encrypted. Encryption keys managed separately from encrypted data.

Access Controls

Only authorized personnel can access customer data. Admin access is logged and audited. Production database access restricted to designated engineers.

Network Security

Firewalls restrict unauthorized network access. DDoS protection implemented. Regular security monitoring and intrusion detection.

7. Data Location & Residency

Default: All PortFlow data is stored in Neon Postgres on AWS us-east-1 (Northern Virginia, USA).

EU Data Residency: If your organization requires EU data residency for GDPR compliance, contact sales@portflow.tech. We can configure your environment to use Neon Postgres on AWS eu-west-1 (Ireland) and Vercel EU infrastructure.

Data Transfers: For organizations outside the US, data transfers comply with GDPR Standard Contractual Clauses (SCCs), adequacy decisions where available, and your country's data transfer requirements.

8. Cookies & Tracking

Essential CookiesRequired

Required for login and security. Cannot be disabled.

Preference CookiesOptional

Your choices for language and display settings.

Analytics CookiesOptional

Aggregated usage data via Vercel Analytics (first-party only). Can be disabled in settings.

We do not use third-party tracking cookies (e.g., Facebook Pixel, Google Analytics). Only first-party analytics through Vercel Analytics.

9. Data Breach Notification

If PortFlow experiences a security breach that compromises your personal data, we commit to:

  • ยท Notify you within 72 hours of discovery (or as required by law)
  • ยท Provide details about what data was affected
  • ยท Explain steps you should take to protect yourself
  • ยท Provide information about remediation measures
  • ยท Notify regulatory authorities as required by law

10. Children's Privacy

PortFlow is not designed for children under 16. We do not knowingly collect data from anyone under 16. If we become aware that a child has provided personal data, we will delete it immediately.

Contact Us

For privacy-related questions or to exercise your data rights:

Privacy: privacy@portflow.tech

General Support: info@portflow.tech

Security Issues: security@portflow.tech

PortFlow ยฉ 2026 ยท All Rights Reserved ยท Document Version 1.0