Privacy Policy
Last updated: 3 August 2026
1. Who we are and our roles
Seamdex is operated by [Company Legal Name], [Company Address], [Country]. For the account data of the people who sign in to Seamdex we act as data controller. For the content brands put into the platform, including personal data in supplier records, repair requests from consumers and passport scan statistics, we process that data on the brand's behalf: the brand is the controller and we are the processor.
2. Data we collect
- Account data. Name, email address and a password hash, managed by our authentication system. Session cookies keep you signed in.
- Organization content. Everything your team enters or imports: business and billing details, product and purchase order data, supplier records (which may include contact names, emails and phone numbers of supplier staff), certificates, images and files. Uploaded files are stored with our hosting provider and served over public URLs.
- Repair requests. When a consumer submits the repair form on a public passport, we store the name, email address and message they provide so the brand can respond. Replies the brand sends from Seamdex are stored with the request.
- Passport scan statistics.When someone opens a public passport page we record a scan event for the brand's statistics. This is designed to be privacy preserving: IP addresses are not stored (a salted hash is used to group repeat visits), location is kept at a coarse level, and we record device type and language rather than anything that identifies a person.
- Audit trail.Actions performed in the app are logged with the acting user's name and email so organizations can review changes.
- Integration credentials. If you connect your own SMTP server or the SPY ERP, the passwords and tokens you enter are stored encrypted and used only to provide those features.
3. Cookies
We use essential cookies only: they keep your session signed in. There are no advertising or third party tracking cookies, on the marketing pages or in the app. Public passport pages set no cookies for consumers.
4. How we use data
- to provide and secure the service,
- to send transactional email such as invitations, notifications you enabled, and replies you compose,
- to invoice the subscription,
- to help you when you contact support.
We do not sell personal data and we do not use it for advertising.
5. Who processes data for us
The service runs on a small set of infrastructure providers:
- Vercel - application hosting and file storage,
- MongoDB Atlas - database hosting,
- Google (Gmail) - delivery of platform transactional email,
- Stripe - subscription billing, card payments and invoicing. Card details go directly to Stripe and never touch Seamdex.
- Google (Tag Manager, Analytics) and Microsoft (Clarity) - aggregate usage analytics that help us understand how the site and app are used.
If your organization connects the SPY ERP, we call the SPY API on your instruction using the token you supplied. If you configure your own SMTP server, repair replies are sent through it. These providers may process data in regions outside the EEA; where that happens, transfers rely on the safeguards those providers offer, such as EU standard contractual clauses.
6. Retention
- Account and organization data is kept while the account is active.
- Brands can delete products, suppliers, repair requests and other content at any time; deletion removes it from the live service.
- After termination, data is deleted following the export window described in the Terms of Service.
7. Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, object to or restrict processing, and lodge a complaint with a supervisory authority. Write to [privacy contact email]. If your request concerns data a brand collected through its passports, for example a repair request you submitted as a consumer, contact the brand; we support them in answering such requests as their processor.
8. Security
Traffic is encrypted in transit. Integration credentials such as SMTP passwords and ERP tokens are encrypted at rest. Access to organization data is scoped per tenant, and actions are recorded in an audit trail.
9. Children
The service is a business tool and is not directed at children.
10. Changes
We update this policy when the service changes. Material changes are announced to account owners. The date above shows the latest revision.
11. Contact
Privacy questions and requests: [privacy contact email].