Privacy Policy
Last updated: August 1, 2026
1. Who we are
Sealinn provides subcontractor compliance and certificate-of-insurance tracking for general contractors. For the data in your workspace you are the controller and we are the processor: it is your subcontractor list, and we hold it to run the service you asked for. For your own account and billing details we are the controller.
This page is written to be read, not to be survived. It is general information about how the software behaves and is not legal advice.
2. What we collect
- Account data — the name, email address and role of each person on your team, and the workspace they belong to.
- Compliance data — your subcontractors and their contacts, your projects, the requirements you set, and every document uploaded: certificates of insurance, W-9s, licenses, safety cards and anything else you ask for. Plus the values read off each one.
- Communications — the email addresses and phone numbers reminders are sent to, and a record of what was sent and when.
- Usage and diagnostic data — which pages are used, and error reports when something breaks. Tied to a user and workspace identifier so a problem can be traced to the account it happened in.
- Billing data — your billing contact and plan. Card details go to Stripe directly; we never see or store a card number.
Much of the personal data in Sealinn is not about our customers at all — it is about their subcontractors and those subcontractors’ agents. We hold it on your instructions, and if one of them contacts us we will point them to you and help you answer.
3. Why we are allowed to hold it
Two grounds, and no others:
- To perform the contract — account data, compliance data and communications. Without them there is no service.
- Legitimate interests — usage, diagnostic and security data, to keep the service working, find bugs, and detect abuse. Narrow, and we do not use it to build a profile of you.
We do not sell personal data, we do not share it for cross-context behavioral advertising, and there is no advertising technology anywhere on this site or in the product.
4. What we do with it
We read the fields off each document you upload, check them against the requirements you set, show you what does not meet them, send reminders before coverage lapses, and keep a record of every approval and rejection. We also use aggregate, non-identifying usage patterns to decide what to build next.
5. When a document is read by AI
Sealinn sends an image of each uploaded document to OpenAI to read the fields off it. Three things are true about that, all from OpenAI’s published API policy rather than from us: your documents are not used to train their models; they keep a copy for up to 30 days for abuse monitoring and then delete it; and we do not have zero-data-retention in place — it must be applied for and approved, and we have not been approved.
Because we send an image, everything visible on the document is transmitted. Sealinn deliberately never reads or stores a taxpayer number from a W-9 — it records only that one is present — but the number is visible in the image. The full statement, with every other company that receives data, is on subprocessors.
7. How long we keep things
Your workspace data is kept for as long as your workspace exists. When you ask for it to be deleted, this is what happens:
- Workspace deletion — 30 days, then permanent. Ask to delete from Settings and the workspace keeps working for 30 days, visibly marked, and anyone with billing permission can cancel. After that a scheduled job erases every record and every stored file. It cannot be recovered afterwards, by you or by us. If you need it gone sooner than that, write to privacy@sealinn.com and a person will handle it.
- A rejected document — 3 days. Recoverable in the app during that window, then the record and the file are both erased.
- Generated reports — 3 days (1 if the report failed). They are cheap to regenerate, so they do not linger.
- An upload link — 7 days. The link a subcontractor receives stops working after that, and can be revoked sooner.
- An abandoned upload — 24 hours. A file that starts uploading and never finishes is swept away.
- A workspace you opened without signing up — 7 days. Anything you try before creating an account lives in a temporary workspace. It is erased in full when the time is up — records and documents, not just hidden — and there is no grace period, because nobody is relying on it yet. Sign up before then and the same workspace becomes your account with nothing moved or lost. The look-around sandbox on our demo page is shorter still, at 24 hours.
- Operational records — 30 days. The ledger that stops a payment or account event being processed twice.
- The audit log — the life of the workspace. This one is deliberately not on a timer. The record of who approved what is the thing you would need years later, so it is kept until the workspace is deleted and then erased with it. Export it whenever you want, including after you cancel.
Backups roll off on their own schedule, so a record can survive in a backup for a short period after it is deleted from the live system. It is not restored into the service.
8. Where the data is
The database is in the United States. Uploaded documents are in Cloudflare R2 with a location preference for Eastern North America, which is a region that also includes Canada and is a best-effort placement rather than a guarantee. Both were read back from the running system rather than taken from a diagram, and the exact values are named on subprocessors. If you or your subcontractors are in the UK or the EEA, using Sealinn means that data is transferred out of your region, and our providers carry the standard contractual clauses for it.
9. Security
Each workspace is isolated at the database row level rather than by application code, documents are reachable only through short-lived links rather than public URLs, and every approval, override and rejection is written once to a log the application has no permission to change or delete. That last one is worth being precise about: the application cannot alter the log, and the database is what refuses it. The mechanisms, and how they were verified, are on the security page.
10. Your rights
Wherever you are, you can see everything in your workspace, correct it, export it, and delete it. Exports need no request: certificates download in bulk and the compliance ledger and full audit log export to PDF, Excel or CSV from inside the product, on any plan, including after you cancel.
If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and to a copy in a portable form. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.
If you are in the UK or the EEA, you additionally have the right to object to processing based on legitimate interests, to ask us to restrict processing, and to complain to your supervisory authority.
Write to privacy@sealinn.com. We will ask enough to be sure it is really you, and answer within the time the applicable law allows.
11. If you are a subcontractor
You were probably sent an upload link by a contractor you work for. Your details are in their workspace, they decide what is held there, and requests about that data should go to them first. If you cannot reach them, write to privacy@sealinn.com and we will help. If you are not sure a link you received is genuine, this explains how to check.
13. Children
Sealinn is a tool for businesses and is not directed at anyone under 16. We do not knowingly collect data from children; if you believe we have, write to privacy@sealinn.com and we will delete it.
14. If something goes wrong
If personal data in your workspace is exposed, we will tell you without undue delay and with what we actually know at the time — what happened, what was affected, and what we are doing about it — rather than waiting until the picture is tidy. Where the law requires notifying a regulator, we will.
15. Changes to this policy
When this policy changes we update the date at the top. If a change is material — a new category of data, a new purpose, or a shorter retention period — we will email account owners before it takes effect rather than relying on you to re-read the page.
16. Contact
Privacy requests and questions about this page: privacy@sealinn.com. Anything else about the product: hello@sealinn.com. Every channel is listed on contact, and every legal document — including the data processing addendum — is indexed on the legal page.
Looking for a different document? They are all listed on the Legal page.
