Back

Privacy Policy

Effective date: March 24, 2026 · Last updated: August 26, 2026 · Version 2.2

This policy covers the PortFlow application at app.portflow.tech. It describes what the product actually collects and does today, not what we intend to build. Where a control does not exist, it says so.

The public site at www.portflow.tech has its own policy at portflow.tech/privacy, which also covers the waitlist and the assistant on that site.

1. Who We Are, and Who Controls What

PortFlow is a maritime agency management platform operated by Jeffry Valerio, based in Costa Rica.

PortFlow is the controller for data about its own account holders. For the data an agency loads into the application, meaning crew, client contacts, vessels, port calls and invoices, the agency is the controller and PortFlow is the processor acting on its instructions.

Some of the people described below, in particular seafarers, are not PortFlow users and will never read this page. Sections 2.6 and 2.7 set out exactly what is held about them, so that the agency responsible for them can tell them.

Contact: info@portflow.tech

2. What Data We Collect

2.1 Account and authentication data

  • Full name, email address, phone number
  • Password, stored as a bcrypt hash we cannot read
  • Company or agency name, and your role within it
  • Organization membership and access permissions
  • Multi-factor authentication state, including recovery codes stored as hashes
  • Active session and refresh token records
  • Audit log entries recording who did what and when, including the IP address seen at the time

2.2 Operational data

  • Vessel information: name, IMO number, flag state, type, specifications
  • Port calls and operations: arrival and departure times, cargo quantities
  • Service requests: bunkering, water supply, provisions, crew boat, repairs
  • Quotations, rate cards and pricing
  • Client records, which normally contain the name, email address and phone number of a person at that company

2.3 Transaction and financial data

  • Invoices, disbursement accounts and payment records
  • Transaction amounts and currency
  • Billing address and tax identification numbers
  • Commercial agreement status and the billing or customer identifiers required for accounting and support
  • We never receive or store payment card numbers. When a payment processor is used, card details remain with that processor and never reach PortFlow.

2.4 Communication data

  • Support requests and correspondence with our team
  • Transactional email we send you about your account
  • Conversations with the in-app assistant, stored in full against your user account and your agency

2.5 Technical and usage data

  • Device type, browser and operating system
  • IP address, and the approximate country, region and city our host derives from it
  • Your IP address is used, in clear, as the counter key for rate limiting on our hosted Redis service
  • Error reports sent to Sentry, with a filter applied to strip the email address and IP address first
  • Session cookies and identifiers
  • For a small number of captain portal links that we watch during a pilot, opening the link triggers an internal email to PortFlow containing the vessel name, the visitor IP address and the browser user agent. Only tokens on an explicit watch list trigger this.

2.6 Seafarer identity data

The crew module holds a full identity file on each seafarer an agency records. This is personal data about people who are not our users. The agency that entered it is the controller.

  • First and last name, date of birth, place of birth, gender marker, nationality
  • Passport number, issuing country, date of issue and date of expiry
  • Personal email address, where the agency records one
  • Rank on board, vessel assignment, ports and dates of embarkation and disembarkation
  • Identity documents recorded with number, issuing country, issuing authority and validity dates: passport, visa, seafarer identity and record book, national identity document, and STCW certificates
  • Crew lists imported from a spreadsheet, which are sent in full to our file scanning provider before being parsed

Passport number, nationality, date of birth and gender marker are encrypted by the application with AES-256-GCM before they are written to the database, with a blind index so that search still works without decrypting the column.

2.7 Health-related data (special category)

Two parts of the product hold data that relates to a named person's health. We declare them explicitly because they need a separate legal basis from the agency that records them.

  • Medical fitness certificates, including the STCW medical: the fact that one exists, its number, issuing authority, issue date, expiry date and derived validity status for a named seafarer
  • Crew change events recorded with the type “medical evacuation”, which links a named seafarer and a vessel to a medical event

PortFlow does not store diagnoses, clinical records, treatment details or the content of any medical examination. It stores the certificate metadata above and the event type.

2.8 Signature data

  • Signer name and title on a signed quotation or invoice
  • The IP address recorded at the moment of signing, and the timestamp

2.9 Regulatory and compliance data

  • IMO FAL forms 1, 2, 3, 5 and 7 generated from a port call, stored against that port call
  • Supporting evidence files uploaded against disbursement account lines, held in a private file store
  • Audit trail records of who accessed or changed what, and when

PortFlow does not transmit anything to a port authority, to customs or to immigration. Preparing and submitting a declaration stays with the agency.

2.10 Signup assessment data

When a new account is created, PortFlow runs an automated assessment of the signup for internal lead triage. Section 4 describes it in full.

3. How We Use Your Data

  • Service delivery. Running the platform, processing port calls, generating quotations, disbursement accounts and invoices.
  • Customer support. Answering support requests and troubleshooting account problems.
  • Security and abuse prevention. Rate limiting by IP address, a bot check at registration, blocking disposable email domains, detecting unauthorized access and keeping an audit trail.
  • Legal and compliance. Meeting legal obligations, responding to lawful requests and keeping records for audit.
  • Communications. Service announcements, system updates and replies to your enquiries.
  • Lead triage. Assessing new signups to decide who we follow up with, and how. This includes the automated assessment in section 4.

What allows us to hold it

Data protection law asks us to say not only what we do with your data but on what grounds. For each purpose above, the ground is one of these four.

  • To provide what you signed up for. Your account, your agency's records, the documents the platform produces and the support we give you. Without this data there is no service to deliver.
  • Because the law requires it. Financial records and the audit trail, which we keep even when you would rather we did not.
  • Because we have a legitimate interest. Keeping the platform secure, stopping abuse, and deciding which new signups to follow up with. We use the least data that achieves it, and if you think we have the balance wrong you can object under section 6.
  • Because your agency instructed us. For crew, client contacts and everything else an agency loads, the agency decides the grounds and we act on its instructions. Health-related records need a separate ground from that agency, which is why section 2.7 sets them out on their own.

What you have to give us, and what is optional

Your name, email address and a password are required to create an account; we cannot open one without them. Phone number and ports operated are optional, and leaving them out costs you nothing except that the assessment in section 4 has less to work with. Everything your agency records about vessels, clients and crew is its own decision, not a requirement we impose.

We do not:

  • Sell your data to third parties
  • Use your vessel, crew or transaction data for marketing
  • Share your operational data with competitors or other maritime companies
  • Buy personal data about you from data brokers or enrichment services
  • Use your crew, vessel, financial or operational data to train any AI model

4. Artificial Intelligence in PortFlow

PortFlow uses one AI provider, Anthropic, in two places that touch your data. Both are described here in full rather than summarized as “AI features”.

4.1 The in-app assistant

The assistant answers questions about how to use PortFlow. What you type, and the conversation that follows, is sent to Anthropic to generate the reply, and the whole conversation is stored against your user account and your agency in our database. It is limited to 30 messages per hour per user.

The assistant has no access to your database. It cannot read your vessels, crew, quotations or invoices, and none of those records are sent to Anthropic. It works from a fixed product guide plus, for trial accounts, how many days remain in the trial. The only data of yours that reaches Anthropic is the text you type into it.

4.2 Automated assessment of new signups

When an account is created, PortFlow sends the company name, the email domain, the phone number, the ports operated and the approximate country, region and city derived from your IP address to an Anthropic model. The model returns a short internal note about the account, which we use to decide who to follow up with and how. The note is stored against your agency and sent to our own inbox, and it goes nowhere else.

It runs after the account already exists. It cannot block a signup, deny access, restrict features or reverse a registration, and it produces no legal effect for you. If the assessment fails for any reason the account is still created. To ask what was recorded about your account, or to contest it, write to support@portflow.tech.

4.3 What the AI does not do

  • It does not read, summarize or classify your crew, vessel, port call, quotation or invoice records.
  • It does not price your quotations or make any financial calculation.
  • It does not generate your FAL forms, invoices or PDFs. Those are produced by ordinary code from your own data.
  • Nothing you put into PortFlow is used to train a model, ours or anyone else's.
  • No AI system decides anything about you that has a legal or similarly significant effect.

5. Data Retention and Deletion

There is no automatic purge.

PortFlow does not run a scheduled job that deletes data when a period expires. Rather than publish retention periods that nothing enforces, the table below states what actually happens to each kind of data today. Deletion happens when a record or its parent is deleted, or when someone asks us and we do it by hand.

Data typeWhat happens today
Account and agency dataKept for as long as the account exists. There is no scheduled deletion after cancellation and no recovery countdown; removal is a manual request.
Operational data (vessels, port calls, services)Kept for as long as the agency keeps the record. Deleting a port call deletes the FAL documents generated from it.
Crew records and identity documentsKept until the agency deletes the crew member. Deleting a crew member deletes their identity documents with them.
Invoices, disbursement accounts and financial recordsKept indefinitely. Billing snapshots are historical and immutable by design, and tax law in the agency’s own country normally requires several years of retention.
Audit logKept indefinitely. It is the record of who did what, and nothing purges it.
Assistant conversationsKept for as long as the account exists. No expiry is applied.
Sessions and refresh tokensExpired session rows are pruned when the same account next refreshes a token.
Error reportsHeld by Sentry under its own retention schedule, which we do not control.

Asking us to delete your data. There is no account deletion screen and no self-service export button. Write to support@portflow.tech and a person will do it and confirm when it is done, within the deadline in section 6.

We do not have an anonymization routine. Where a record cannot be deleted for a legal reason, we will tell you it is being retained and why, rather than claim it has been anonymized.

6. Your Rights

If you are in the EU, the UK or a country with similar privacy laws, you have the rights below. All of them are available to you. None of them is self-service: PortFlow has no privacy dashboard, no export-my-account button and no account deletion screen. Every request is handled by a person.

Who to ask depends on the data. If you are a seafarer or a client contact whose details an agency loaded into PortFlow, that agency is the controller and your request goes to them; we assist them in answering it. If you are a PortFlow account holder, the request comes to us.

  • Access. A copy of the personal data held about you, the purposes of the processing, the recipients and how long it is kept. We assemble the extract by hand from the relevant records.
  • Rectification. Correction of inaccurate or incomplete records, including crew details and identity document data. There is no self-service profile page, and editing a user account inside the application is restricted to an agency administrator, so send us the correction and we will apply it.
  • Erasure. Deletion of your personal data, carried out manually by our team. Two things normally survive: financial records the agency must keep under its own tax law, and audit log entries, which exist as the record of who did what. We will tell you exactly what was kept and why.
  • Portability. The application exports per module, in CSV or XLSX: audit log, invoices, payments, quotations, vessels, port services, provisions, water supply, billing exceptions and client account statements. Those are reports scoped to an agency, not an extract for one individual, so a portability request for a single person is assembled by hand.
  • Objection. An objection to direct marketing stops that processing once we receive it. Our emails carry no unsubscribe header and there is no preference centre, so the way to object is to write to us and we will stop.
  • Restriction. Processing limited while accuracy is verified or a dispute is resolved. There is no restriction flag in the product, so we apply this as an operational hold agreed with you in writing.

How long we take. One month from receipt of the request, extendable by two further months for complex or numerous requests, in which case we tell you within the first month and explain why. PortFlow does not publish a faster service level than the law requires, because it has not measured one.

To exercise any of these rights, write to support@portflow.tech. Tell us which right you are exercising and give us enough information to identify your records. We will ask you to confirm your identity before we act, and we will confirm in writing when the request is complete.

If we get it wrong, you can complain about us. You have the right to lodge a complaint with the data protection authority where you live, where you work, or where you believe something went wrong, and you do not have to come to us first. We would rather you did, because we can usually fix it faster than a regulator can, but that is a preference of ours and not a condition on your right.

7. Third Parties That Receive Your Data

These are the providers that process data on our behalf today. Regions reflect the current default configuration and are not contractual.

PortFlow has no signed Data Processing Agreement with its customers. Each provider below is used under its own standard terms and data processing addendum. A contractual right to be notified of changes to this list, and to object to them, exists only once a DPA is executed.

Neon

Application database (PostgreSQL) · United States

Stores all application data, including crew identity records and financial records.

Vercel

Hosting and CDN · Global edge network

Runs the application and the API. Supplies the approximate country, region and city derived from your IP address.

Vercel Blob

Private file storage · United States

Holds disbursement account evidence files in a private store. The files are not reachable by URL without a signed request from the application.

Auth0 (Okta)

Identity provider · United States

Handles sign-in for the agencies enrolled in the Auth0 pilot. Receives the email address and authentication events for those accounts. Agencies not in the pilot sign in against PortFlow directly and their credentials never reach Auth0.

Anthropic

AI assistant and signup assessment · United States

Generates the in-app assistant replies and runs the automated signup assessment. Section 4 sets out exactly what is sent.

Cloudmersive

File scanning · United States

Receives the raw bytes of every crew list or capability spreadsheet you upload, before it is parsed, to scan it for malicious content. Those files routinely contain passport numbers.

Upstash Redis

Rate limiting and short-lived state · United States

Holds your IP address in clear as a rate limiting counter key.

Resend

Email delivery · United States

Sends transactional email: account verification, password reset, captain portal links and internal notifications.

Cloudflare Turnstile

Bot check at registration · Global edge network

Verifies that a registration comes from a human. Receives a challenge token and your IP address.

Sentry

Error monitoring · United States

Receives production error reports. A filter strips the email address and IP address from the user record, the contexts and the breadcrumbs before an event is sent.

Zoho Mail

Hosted mailboxes · United States

Hosts the PortFlow mailboxes that receive support and general correspondence. It is not used as a CRM.

Beyond this list, we disclose data only where the law compels us to, and we do not sell or rent it to anyone.

8. Data Protection and Encryption

  • In transit. TLS on all PortFlow domains, and the database connection verifies the server certificate.
  • At rest. The database provider encrypts data at rest. On top of that, crew passport number, nationality, date of birth and gender marker are encrypted by the application with AES-256-GCM before they reach the database.
  • Passwords. Hashed with bcrypt at cost factor 12. We cannot read them, and neither can anyone with database access.
  • Access controls. Each agency is isolated in the database with row level security. Multi-factor authentication is available, admin actions are written to an audit log, and production database access is restricted.
  • Network. A content security policy restricts what the browser may load. Requests are rate limited by IP address, and registration is behind a bot check.

Vercel and Neon hold SOC 2 Type II reports for their own services. PortFlow holds no certification of its own, has not been independently audited, and inherits nothing from its providers.

9. Where Your Data Lives

All application data is stored in a single Neon Postgres database in the United States. The application runs on the Vercel edge network.

EU data residency is not deployed. PortFlow runs one shared database with a single connection string and has no per-region routing, so there is no environment we can point at an EU region today. Neon and Vercel both offer EU regions, so it is technically possible, but nothing has been provisioned or tested and no customer runs on one. Treat it as a scoping conversation, not a feature.

In the default configuration, personal data is processed in the United States. Those transfers currently rest on the standard contractual clauses and data processing terms of each provider in section 7. PortFlow has no clauses of its own signed with customers, because no DPA has been executed yet.

10. Cookies and Tracking

The application runs no analytics. Google Analytics was removed in August 2026, and no advertising or social pixel has ever been used here. Nothing in the application profiles you or follows you across sites, which is why you were not asked to click a cookie banner.

These are the cookies the application sets, all of them necessary:

  • auth_token: your session, as a secure HTTP-only cookie. Expires after 8 hours, or 30 minutes on a trial plan.
  • refresh_token: renews the session without a new login. Idle timeout of 30 days; every renewal pushes it forward.
  • __session: set only for accounts signing in through the Auth0 pilot.

11. Data Breach Notification

If we become aware of a security breach that compromises personal data, we will:

  • Notify affected customers without undue delay, and notify the competent supervisory authority within 72 hours of becoming aware where the law requires it
  • Tell you what data was affected
  • Explain what you should do to protect yourself
  • Describe what we have done to remediate it

To report a vulnerability or a suspected incident, write to security@portflow.tech.

12. Age Requirement

PortFlow is a business tool and is not intended for anyone under 18. Account holders must be at least 18 or act on behalf of a business entity, which matches the age requirement in our Terms of Service. We do not knowingly collect personal data from anyone under 18 as an account holder, and if we learn that we have, we will delete it. This does not apply to crew records, which an agency may hold about a seafarer of any lawful working age as part of its own regulatory duties.

13. Changes to This Policy

We update this page when what the product does changes. The version number and the last updated date at the top tell you which text you are reading. We announce material changes to account holders by email.

14. Contact