← Back to portflow.tech

Data Privacy Policy

Effective Date: March 24, 2026 · Last Updated: August 26, 2026 · Document Version: 2.4

PortFlow is a maritime operations platform for port agencies. This policy covers two things: the public site at www.portflow.tech, and the application at app.portflow.tech. It describes what is actually collected today, not what we intend to build.

PortFlow is the controller for data about its own account holders, waitlist contacts and site visitors. For the data an agency loads into the application, including crew, client contacts and port calls, the agency is the controller and PortFlow is the processor acting on its instructions.

Some of the people described in this policy, in particular seafarers, are not PortFlow users and never see this page. Section 1.6 and section 1.7 set out exactly what is held about them, so that the agency responsible for them can tell them.

Questions about anything below: info@portflow.tech.

1. What Data We Collect

1.1 Account & Authentication Data

  • · Full name, email address, phone number
  • · Login credentials (username, password hash)
  • · Company name and role within the agency
  • · Organization membership and access permissions
  • · Multi-factor authentication state and active session records
  • · Audit log entries recording who did what and when, including the IP address seen at the time

1.2 Operational Data

  • · Vessel information (name, IMO number, flag state, vessel type)
  • · Vessel specifications (tonnage, dimensions, capacity)
  • · Port call and operations data (arrival and departure times, cargo quantities)
  • · Service requests (bunkering, water supply, provisions, crew boat, repairs)
  • · Quotations, rate cards and pricing information
  • · Client records, which normally contain the name, email address and phone number of a person at that company

1.3 Transaction & Financial Data

  • · Invoices, disbursement accounts and payment records
  • · Transaction amounts and currency
  • · Billing address and tax identification numbers
  • · Subscription state, and any customer or subscription identifiers issued by Lemon Squeezy where online billing is used
  • · We never receive or store payment card numbers. Card details are entered on Lemon Squeezy and never reach PortFlow.

1.4 Communication Data

  • · Support tickets and correspondence with our team
  • · Email communications regarding your account or services
  • · Feature requests and feedback
  • · Conversations with the in-application assistant, stored in full against your user account and your agency

1.5 Technical & Usage Data

  • · Device type, browser type, and operating system
  • · IP address and approximate location derived from it (city and country level)
  • · Your IP address is used, in clear, as the counter key for rate limiting on our hosted Redis service
  • · Pages visited, features used, time spent in the application
  • · Error reports sent to our error monitoring provider, with a filter applied to strip personal fields
  • · Session identifiers and cookies
  • · For a small number of captain portal links that we watch during a pilot, opening the link triggers an internal email to PortFlow containing the vessel name, the visitor IP address and the browser user agent

1.6 Seafarer Identity Data

The crew module holds a full identity file on each seafarer an agency records. This is personal data about people who are not our users. The agency that entered it is the controller.

  • · First and last name, date of birth, place of birth, gender marker, nationality
  • · Passport number, issuing country, date of issue and date of expiry
  • · Personal email address, where the agency records one
  • · Rank on board, vessel assignment, ports and dates of embarkation and disembarkation
  • · Identity documents recorded with number, issuing country, issuing authority and validity dates: passport, visa, seafarer identity and record book, national identity document, and STCW certificates
  • · Crew lists imported from a spreadsheet, which are sent in full to our file scanning provider before being parsed

Passport number, nationality, date of birth and gender marker are encrypted at the application layer with AES-256-GCM before they are written to the database, with a blind index so that search still works without decrypting the column.

1.7 Health-Related Data (Special Category, Art. 9)

Two parts of the product hold data that relates to a named person's health. We are declaring them explicitly because they fall under Art. 9 GDPR and need a separate legal basis from the agency that records them.

  • · Medical fitness certificates, including the STCW medical: the fact that one exists, its number, issuing authority, issue date, expiry date and derived validity status for a named seafarer
  • · Crew change events recorded with the type "medical evacuation", which links a named seafarer and a vessel to a medical event

PortFlow does not store diagnoses, clinical records, treatment details or the content of any medical examination. It stores the certificate metadata above and the event type.

1.8 Signature Data

  • · Signer name and title on a signed quotation or invoice
  • · The IP address recorded at the moment of signing, and the timestamp

1.9 Regulatory & Compliance Data

  • · IMO FAL forms 1, 2, 3, 5 and 7 generated from a port call, stored as content, PDF and XML against that port call
  • · Supporting evidence files uploaded against disbursement account lines, held in a private file store
  • · Audit trail records of who accessed or changed what, and when

PortFlow does not transmit anything to a port authority, to customs or to immigration. Preparing and submitting a declaration stays with the agency.

1.10 Public Site Data

  • · Waitlist sign-ups: the name and email address you type are held on our hosted Redis service for 24 hours pending email confirmation, then discarded from that store. On confirmation, a notification containing your name and email is emailed to our own inbox.
  • · Assistant conversations on this site are sent to Anthropic to generate a reply and are not stored in a database by us
  • · Aggregated traffic measurement on this public site through Vercel Analytics, described in section 8
  • · Your IP address as a rate limiting key on the waitlist and assistant endpoints

1.11 Signup Assessment Data

When a new account is created, PortFlow runs an automated assessment of the signup for internal lead triage. This is described in full in section 2.

  • · Sent to the model: company name, email domain, phone number, ports operated, and the approximate country, region and city derived from your IP address by our hosting provider
  • · Stored against your agency: a short internal note about the account, used to decide who we follow up with and how
  • · A notification containing the same information is emailed to our own inbox

2. How We Use Your Data

Your data is used for the following purposes:

Service Delivery

Providing, maintaining, and improving PortFlow. Processing vessel information and maritime operations. Generating quotations, disbursement accounts and invoices.

Analytics & Improvement

Understanding feature usage patterns. Identifying performance bottlenecks. Improving user interface and user experience.

Customer Support

Responding to support requests and technical issues. Troubleshooting account or service problems. Providing training and documentation.

Security & Abuse Prevention

Rate limiting by IP address, bot checks at registration, blocking disposable email domains, detecting unauthorized access and keeping an audit trail.

Legal & Compliance

Complying with legal and regulatory requirements. Responding to lawful government requests. Maintaining records for audit purposes.

Communications

Sending service announcements and system updates. Notifying you of planned maintenance. Responding to your inquiries.

Lead Triage

Assessing new signups and waitlist contacts to decide who we follow up with, and how. This includes the automated assessment described below.

Automated Assessment of New Signups

When an account is created, PortFlow sends the company name, the email domain, the phone number, the ports operated and the approximate location derived from your IP address to an Anthropic language model. The model returns a short internal note about the account, which we use to decide who to follow up with and how. It is stored against your agency and emailed to us, and it goes nowhere else.

It runs after the account already exists. It cannot block a signup, deny access, restrict features or reverse a registration, and it produces no legal effect for you. If the assessment fails for any reason the account is still created. To ask what was recorded about your account, or to contest it, write to support@portflow.tech.

What allows us to hold it

Data protection law asks us to say not only what we do with your data but on what grounds. For each purpose above, the ground is one of these four.

  • · To provide what you signed up for. Your account, your agency's records, the documents the platform produces and the support we give you. Without this data there is no service to deliver.
  • · Because the law requires it. Financial records and the audit trail, which we keep even when you would rather we did not.
  • · Because we have a legitimate interest. Keeping the platform secure, stopping abuse, and deciding which new signups to follow up with. We use the least data that achieves it, and if you think we have the balance wrong you can object under section 4.
  • · Because your agency instructed us. For crew, client contacts and everything else an agency loads, the agency decides the grounds and we act on its instructions. Health-related records need a separate ground from that agency, which is why section 1.7 sets them out on their own.

What you have to give us, and what is optional

Your name, email address and a password are required to create an account; we cannot open one without them. Phone number and ports operated are optional, and leaving them out costs you nothing except that the assessment above has less to work with. A waitlist sign-up needs only a name and an email. Everything your agency records about vessels, clients and crew is its own decision, not a requirement we impose.

We Do NOT:

  • · Sell your data to third parties
  • · Use your vessel, crew or transaction data for marketing purposes
  • · Share your operational data with competitors or other maritime companies
  • · Buy personal data about you from data brokers or enrichment services
  • · Use your crew, vessel, financial or operational data to train any AI model

3. Data Retention

No automatic purge is implemented

PortFlow does not run a scheduled job that deletes data when a period expires. Rather than publish retention periods that nothing enforces, the table below states what actually happens to each kind of data today. Deletion happens when a record or its parent is deleted, or when someone asks us and we do it by hand.

Data TypeWhat happens today
Account and agency dataKept for as long as the account exists. There is no scheduled deletion after cancellation and no recovery countdown; removal is a manual request.
Operational data (vessels, port calls, services)Kept for as long as the agency keeps the record. Deleting a port call deletes the FAL documents generated from it.
Crew and identity documentsKept until the agency deletes the crew member. Deleting a crew member deletes their identity documents with them.
Invoices, disbursement accounts and financial recordsKept indefinitely. Billing snapshots are historical and immutable by design, and tax law in the agency's own country normally requires several years.
Audit logKept indefinitely. It is the tamper evidence record of who did what, and nothing purges it.
Assistant conversations in the applicationKept for as long as the account exists. No expiry is applied.
Sessions and refresh tokensExpired session rows are pruned when the same account next refreshes a token.
Error reportsHeld by our error monitoring provider under its own retention schedule, which we do not control.
Waitlist sign-ups pending confirmationHeld on our hosted Redis service for 24 hours, then dropped by the store itself.
Confirmed waitlist contactsHeld in our own mailbox as email until we delete it.

When you ask us to delete data, we do it manually and confirm when it is done, within the statutory deadline set out in section 4. We do not currently have an anonymization routine, so where a record cannot be deleted for a legal reason we will tell you that it is being retained and why, rather than claim it has been anonymized.

4. Your Privacy Rights (GDPR & Similar Regulations)

If you are located in the EU or in a country with similar privacy laws, you have the rights below. All of them are available to you. None of them is self service: PortFlow has no privacy dashboard, no export-my-account button and no account deletion screen. Every request is handled by a person.

Who to ask depends on the data. If you are a seafarer or a client contact whose details an agency loaded into PortFlow, that agency is the controller and your request goes to them; we assist them in answering it. If you are a PortFlow account holder, a waitlist contact or a visitor to this site, the request comes to us.

Right to Access (Art. 15)

A copy of the personal data held about you, the purposes of the processing, the recipients and the criteria used to set retention. We assemble the extract by hand from the relevant records.

Right to Rectification (Art. 16)

Correction of inaccurate or incomplete records, including crew details and identity document data. There is no self-service profile page, and editing a user account inside the application is restricted to an agency administrator, so send us the correction and we will apply it.

Right to Erasure (Art. 17)

Deletion of your personal data, carried out manually by our team. Two things normally survive: financial records the agency must keep under its own tax law, and audit log entries, which exist as the record of who did what. We will tell you exactly what was kept and why.

Right to Data Portability (Art. 20)

The application exports per module, in CSV or XLSX: audit log, invoices, payments, quotations, vessels, port services, provisions, water supply and client account statements. Those are reports scoped to an agency, not an extract for one individual, so a portability request for a single person is assembled by hand.

Right to Object (Art. 21)

An objection to direct marketing stops that processing once we receive it. Our emails carry no unsubscribe header and there is no preference centre, so the way to object is to write to us and we will stop. For analytics on this public site there is no consent gate today, so browser level blocking is the only technical opt out.

Right to Restrict Processing (Art. 18)

Processing limited while accuracy is verified or a dispute is resolved. There is no restriction flag in the product, so we apply this as an operational hold agreed with you in writing.

How long we take

The deadline is the statutory one in Art. 12(3) GDPR: one month from receipt of the request, extendable by two further months for complex or numerous requests, in which case we tell you within the first month and explain why. PortFlow does not publish a faster service level than the law requires, because it has not measured one.

To exercise any of these rights, write to support@portflow.tech. Tell us which right you are exercising and give us enough information to identify your records. We will ask you to confirm your identity before we act, and we will confirm in writing when the request is complete.

If we get it wrong, you can complain about us. You have the right to lodge a complaint with the data protection authority where you live, where you work, or where you believe something went wrong, and you do not have to come to us first. We would rather you did, because we can usually fix it faster than a regulator can, but that is a preference of ours and not a condition on your right.

5. Data Sharing & Sub-Processors

These are the third parties that process data on our behalf today. Regions reflect the current default configuration and are not contractual.

PortFlow has no signed Data Processing Agreement with its customers. Each provider below is used under its own standard terms and data processing addendum. A contractual right to be notified of changes to this list, and to object to them, exists only once a DPA is executed. See the compliance page for where that stands.

Neon Postgres

Application database · United States (default region)

Stores all application data, including crew identity and financial records.

Vercel

Hosting and CDN · Global edge network

Hosts the application, the API and this public site. Supplies the approximate location headers derived from your IP address.

Vercel Blob

Private file storage · United States

Stores disbursement account evidence files in a private store.

Auth0 (Okta)

Identity provider · United States

Handles sign-in for the agencies enrolled in the Auth0 pilot, and receives their email address and authentication events. Agencies outside the pilot sign in against PortFlow directly and their credentials never reach Auth0.

Upstash Redis

Rate limiting and short-lived state · United States (default region)

Holds your IP address in clear as a rate limiting counter key, and holds a waitlist name and email for 24 hours pending confirmation.

Resend

Email delivery · United States

Sends transactional email: verification, password reset, captain portal links, waitlist confirmations and internal notifications.

Zoho Mail

Hosted mailboxes · United States

Hosts the PortFlow mailboxes that receive support and general correspondence. It is not used as a CRM.

Anthropic

AI assistant and signup assessment · United States

Generates assistant replies, and runs the automated signup assessment described in section 2. Crew, vessel and financial records are not sent to it.

Cloudmersive

File scanning · United States

Receives the raw bytes of every crew list or capability spreadsheet you upload, before it is parsed, in order to scan it. Those files routinely contain passport numbers.

Cloudflare Turnstile

Bot check at registration · Global edge network

Verifies that a registration comes from a human. Receives a challenge token and your IP address.

Lemon Squeezy

Payments and subscriptions · United States

Merchant of record for online subscription billing. Where used, it handles checkout and card details, which never reach PortFlow, and returns customer and subscription identifiers.

Sentry

Error monitoring · United States

Receives production error reports. A filter is applied to strip personal fields before an event is sent.

6. Data Protection & Encryption

Data in Transit

Communications use TLS. HTTPS is enforced on all PortFlow domains, and the database connection verifies the server certificate.

Data at Rest

The database provider encrypts data at rest. On top of that, crew passport number, nationality, date of birth and gender marker are encrypted by the application with AES-256-GCM before they reach the database.

Access Controls

Each agency is isolated in the database with row level security. Multi-factor authentication is available, admin actions are written to an audit log, and production database access is restricted.

Network Security

A content security policy restricts what the browser may load. Requests are rate limited by IP address, and registration is behind a bot check.

Vercel and Neon hold SOC 2 Type II reports for their own services. PortFlow holds no certification of its own, has not been independently audited, and inherits nothing from its providers.

7. Data Location & Residency

Default: All application data is stored in a single Neon Postgres database in the United States. The application and this site run on the Vercel edge network.

EU Data Residency: Not deployed. PortFlow runs one shared database with a single connection string and has no per region routing, so there is no environment we can point at an EU region today. Neon and Vercel both offer EU regions, so it is technically possible, but nothing has been provisioned or tested and no customer runs on one. Treat it as a scoping conversation, not a feature. To scope it, write to info@portflow.tech.

Data Transfers: In the default configuration, personal data is processed in the United States. Those transfers currently rest on the Standard Contractual Clauses and data processing terms of each provider listed in section 5. PortFlow has no SCCs of its own signed with customers, because no DPA has been executed yet.

8. Cookies & Tracking

No third party tracking runs on this site. Google Analytics was removed from both this site and the application in August 2026, and no advertising or social pixel has ever been used. What remains is Vercel Analytics, which is first party, aggregated and cookieless. There is nothing here to consent to, which is why you were not asked to click a cookie banner.

Essential CookiesRequired

Required for login, session handling and security. Cannot be disabled.

Preference CookiesOptional

Your choices for language and display settings.

Analytics, first party CookiesNo cookies

Vercel Analytics on this public site. Aggregated page view measurement that sets no cookie and does not identify you.

The application at app.portflow.tech runs no analytics at all. No Facebook Pixel, advertising pixel or social tracker is used on either the site or the application, and no advertising network receives anything from us.

9. Data Breach Notification

If PortFlow becomes aware of a security breach that compromises personal data, we commit to:

  • · Notify affected customers without undue delay, and notify the competent supervisory authority within 72 hours of becoming aware where Art. 33 GDPR requires it
  • · Provide details about what data was affected
  • · Explain steps you should take to protect yourself
  • · Provide information about remediation measures

To report a vulnerability or a suspected incident, write to security@portflow.tech.

10. Age Requirement

PortFlow is a business tool and is not intended for anyone under 18. Account holders must be at least 18 years of age or act on behalf of a business entity, which matches the age requirement in our Terms and Conditions. We do not knowingly collect personal data from anyone under 18 as an account holder. If we learn that we have, we will delete it. This does not apply to crew records, which an agency may hold about a seafarer of any lawful working age as part of its own regulatory duties.

11. Changes to This Policy

We update this page when what the product does changes. The version number and the last updated date at the top of the page tell you which text you are reading. Material changes are announced to account holders by email.

Contact Us

For privacy-related questions or to exercise your data rights:

Privacy and data rights: support@portflow.tech

General enquiries: info@portflow.tech

Security issues: security@portflow.tech

PortFlow © 2026 · All Rights Reserved · Document Version 2.4