Privacy Policy

Last updated: August 30, 2026

Sealinn holds insurance paperwork belonging to companies that are not our customers — your subcontractors. That makes this page worth writing properly rather than generating. Retention periods controlled by Sealinn software are tied to the constants it enforces; provider-controlled defaults and periods that still require legal review are identified separately. Every company known to receive data is named.

1. Who we are

Sealinn provides subcontractor compliance and certificate-of-insurance tracking for general contractors. For the data in your workspace you are the controller and we are the processor: it is your subcontractor list, and we hold it to run the service you asked for. For your own account and billing details we are the controller.

This page is written to be read, not to be survived. It is general information about how the software behaves and is not legal advice.

2. What we collect

  • Account data — the name, email address and role of each person on your team, and the workspace they belong to.
  • Compliance data — your subcontractors and their contacts, your projects, the requirements you set, and the certificates of insurance uploaded under the current product scope, together with values your authorized reviewers record. Authorized historical records can also retain certificates of insurance, W-9s, licenses, safety cards, custom documents, and values or extraction context created under an earlier workflow.
  • Producer and supplier response data — invited producer or supplier names and business contact details, the suppliers and projects within an invitation’s scope, requests, comments, submissions and change notices. Supplier intake can also hold legal and trade names, contact details, tax classification, license and safety information, questionnaire answers, supporting documents, revision history and the recorded consent scope and version.
  • Requirement, source and reference data — contract excerpts and citations, extracted requirement candidates, customer-approved templates and questionnaire revisions; source-check queries, authorities, results, timestamps and freshness status; and vendor, spend or other operational reference rows imported from files you provide, including source-file hashes, mappings and your review disposition.
  • Evidence, reconciliation, and value data — customer work and payment decisions, handoff snapshots, reconciliation history, evidence-packet manifests and digests, selected evidence-room scope and activity, and the time, cost, currency and override assumptions used to generate value receipts.
  • Communications — the email addresses and phone numbers reminders are sent to, and a record of what was sent and when.
  • Usage and diagnostic data — which pages are used, and error reports when something breaks. Tied to a user and workspace identifier so a problem can be traced to the account it happened in. Separately, Google Analytics is planned for allow-listed public marketing pathnames only, after an explicit browser opt-in, without a user or workspace identifier. It is not active in production today.
  • Security and abuse-prevention data — an IP address or a derived rate-limit key, request timing, and related technical details used to protect public forms, upload links, and authenticated actions.
  • Billing data — your billing contact and plan. Card details go to Stripe directly; we never see or store a card number.

Much of the personal data in Sealinn is not about our customers at all — it is about their subcontractors and those subcontractors’ agents. We hold it on your instructions. Requests about workspace data are handled with the workspace customer as controller; Sealinn does not decide them on that customer’s behalf.

3. Why each category is processed

The legal basis depends on the confirmed contracting party, the person involved, the jurisdiction, and the particular use. Those facts require owner and counsel confirmation before Sealinn intentionally offers the service in a market. The operational purposes are:

  • Providing the service — account, workspace, document, compliance, response-workspace, requirement, source, reference, operational-proof, value, billing, and customer-requested communication data.
  • Operating and protecting it — limited usage, diagnostic, security, and abuse-prevention data. We do not use it to build an advertising profile.
  • Respecting communication choices — a portal-submitted SMS preference and the minimum email or phone record needed to keep a STOP or unsubscribe request working across workspaces. The applicable legal basis and retention period for that cross-workspace suppression record still require counsel to apply the law to Sealinn’s confirmed operator and markets.
  • Earlier requested follow-up — the retired signed-out reading flow could use an address to send one requested message and keep its unsubscribe control resolvable. That public reader is now unavailable. A retained request does not opt the visitor into a marketing sequence.

We do not sell personal data, we do not share it for cross-context behavioral advertising, and there is no advertising technology anywhere on this site or in the product.

4. What we do with it

We accept COI uploads, keep the original file available for human review, let authorized reviewers record values and decisions, send reminders before manually recorded supported expiry dates pass, and keep a record of key review actions such as approvals and rejections when the audit write succeeds. Automated AI field extraction, confidence routing, and automatic requirement checks are currently unavailable. At your direction, the product can also collect scoped producer and supplier responses, record source-check attempts, turn contract excerpts into customer-reviewed requirement candidates, reconcile file-imported reference rows, record customer work and payment decisions, generate evidence packets and value receipts, and expose an exact selected packet scope through a revocable evidence-room link. We also use product-usage events associated with a user and workspace identifier to troubleshoot flows and decide what to build next; we do not include uploaded document contents in those analytics events.

5. AI document reading

Automated AI document reading is currently unavailable. New uploads are not sent to OpenAI for field extraction. If that capability is deliberately enabled later, this policy and the in-product notice must continue to identify the provider and what is transmitted before processing begins.

Historical processing still matters. When automated reading previously ran, Sealinn sent an image of the document to OpenAI. Everything visible in that image was transmitted, including a taxpayer number visible on a W-9 even though Sealinn did not extract that number into its own fields. OpenAI’s published API default says data is not used to train models and abuse-monitoring logs may be retained for up to 30 days. Sealinn has not recorded a project-specific zero-data-retention readback, so historical processing must not be described as zero-data-retention. The full statement is on subprocessors.

6. Who else receives it

10 active companies, each named on the subprocessors page along with what it does and exactly what it receives. A unit test compares provider-specific credentials in the committed production environment template with that list. This catches new credentialed integrations; services configured through deployment dashboards or source-control integrations still require a manual disclosure review.

That page also retains 2 inactive providers for historical context and any future reviewed activation, and identifies one provider disclosed in advance but not active. A planned provider receives no data until the promised notice window has elapsed and its production integration is deliberately enabled.

Beyond those, we disclose data only when you tell us to, or when we are legally required to — and if we are legally required to hand over your workspace data we will tell you unless we are prohibited from doing so.

Customer-directed response-workspace and selected evidence-room links are bearer links: anyone who possesses the URL can act within its recorded supplier or project scope, or view the exact selected files and customer decisions, until revocation or expiry. Sealinn returns those links to the customer for manual delivery; it does not verify who ultimately opens one, and a recipient can forward it. Selected evidence-room activity records prove that the link was used, not the viewer’s identity or an electronic signature.

7. How long we keep things

Your workspace data is kept for as long as your workspace exists. When you ask for it to be deleted, this is what happens:

  • Workspace deletion — 30 days, then removed from the live service. Ask to delete from Settings and the workspace keeps working for 30 days, visibly marked, and anyone with billing permission can cancel. After that a scheduled job removes the workspace and its workspace-scoped database records, and requests deletion of each stored object it can enumerate. Storage deletion failures are logged, but failed object keys are not yet retained in a durable retry queue after the workspace rows are removed. The deleted workspace is no longer available in the live service; backup retention is described below. Questions about a deletion request can be sent to privacy@sealinn.com.
  • A rejected document — 3 days. Recoverable in the app during that window. After the grace period, a scheduled purge requests deletion of the stored file and removes the record only when that succeeds; a failed storage deletion leaves the record for a later retry. Provider backup copies follow the provider’s own retention schedule.
  • Generated reports — 3 days (1 if the report failed). They are cheap to regenerate, so they do not linger.
  • An upload link — 7 days. The link a subcontractor receives stops working after that, and can be revoked sooner.
  • An abandoned upload — 24 hours. A file that starts uploading and never finishes is swept away.
  • A producer or supplier response-workspace link — between 1 and 30 days. The customer chooses the lifetime within that range and can revoke the link sooner. The invitation, its scope and the response history remain with the workspace after the link stops working, until the workspace is deleted.
  • An evidence-packet ZIP — 24 hours. The downloadable ZIP stops being available after that delivery window and its expiry job requests deletion of the transient stored object. If storage deletion fails, the ready record is retained for another daily sweep. The immutable packet manifest and digest remain with the workspace. A selected evidence-room link cannot outlive the ZIP availability window and can be revoked sooner; the selected scope, revocation record and anonymous view, download and acknowledgment activity remain with the workspace until it is deleted.
  • An existing legacy workspace opened without signing up — 30 days after you last open it. Start Free no longer creates a new anonymous workspace; it asks the visitor to sign up. Workspaces created under the earlier guest flow can still exist during their retention window. Opening one restarts the 30-day clock, so a legacy workspace that remains in use is not deleted; one nobody opens for that long enters the same live-system deletion process described above. Signing up converts that same workspace into an account workspace. The current look-around sandbox on the demo page is fixed rather than rolling, and shorter, at 24 hours from when it is opened.
  • Operational records — 30 days. The ledger that stops a payment or account event being processed twice.
  • Retired certificate-reading requests — 730 days. The signed-out demo reader and its email-results flow are unavailable. A historical record from an earlier completed request can retain the address that was entered and the document kind for this period. It does not retain the certificate, its file, or its read values, and the earlier request did not enroll that address in a follow-up sequence. Its unsubscribe record remains resolvable without suppressing service messages for a workspace that separately uses the same address.
  • The audit log — the life of the workspace. This one is deliberately not on a timer. The record of who approved what is the thing you would need years later, so it is kept until the workspace is deleted and then erased with it. Export it whenever you want, including after you cancel.

Backups roll off on their own schedule, so a record can survive in a backup for a short period after it is deleted from the live system. It is not restored into the service.

8. Where the data is

The database is in the United States. Uploaded documents are in Cloudflare R2 with a location preference for Eastern North America, which is a region that also includes Canada and is a best-effort placement rather than a guarantee. Both were read back from the running system rather than taken from a diagram, and the exact values are named on subprocessors. If you or your subcontractors are in the UK or the EEA, using Sealinn means that data is transferred out of your region. The applicable contracting party, processing location, and transfer mechanism must be confirmed from each provider's current terms; we identify any unverified transfer fact on the subprocessor page for owner and counsel review instead of asserting that a safeguard is in force by assumption.

9. Security

Each workspace is isolated at the database row level rather than by application code, and raw object-storage locations are not public browser addresses: signed-in previews use authenticated, workspace-scoped proxy routes, while downloads and direct views use short-lived signed links. Customer-directed response and evidence-room URLs are separate bearer credentials. Only their hashes are stored; every access rechecks expiry, revocation and recorded scope, and the public evidence-room resolver pins every joined row to the organization selected by that token. Sealinn attempts to record key review actions in an audit log. The ordinary tenant-facing database role cannot update or delete audit rows; a restricted maintenance role can administer the database, and a product action can still succeed if its separate audit write fails. The mechanisms, and how they were verified, are on the security page.

10. Your rights

Wherever you are, you can view and correct the workspace records the product exposes and request deletion of the workspace. Exports need no support request: the subcontractor roster and contact details, uploaded documents, compliance ledger, and audit log can be exported from inside the product, on any plan, including after you cancel.

Those self-serve exports do not claim to include every response-workspace, requirement, source, reference, reconciliation, value-receipt or evidence-room record described above. A request concerning a category the product does not expose or export can be sent to privacy@sealinn.com and may require identity or authority verification.

If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and to a copy in a portable form. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.

If you are in the UK or the EEA, you additionally have the right to object to processing based on legitimate interests, to ask us to restrict processing, and to complain to your supervisory authority.

Send requests to privacy@sealinn.com. A request may require identity or authority verification, and applicable law determines which rights and response deadline apply.

11. If you are a subcontractor

You were probably sent an upload link by a contractor you work for. Your details are in their workspace, they decide what is held there, and requests about that data should go to them first. If you cannot reach them, privacy@sealinn.com is the alternate contact route; that does not change who decides what is held in the workspace. If you are not sure a link you received is genuine, this explains how to check.

12. Cookies

Clerk uses cookies to maintain a signed-in session. The seeded demo, and any still-live workspace created under the earlier anonymous guest flow, use two first-party cookies: one random access token and one client-readable layout hint. Start Free no longer creates a new anonymous workspace. The signed-in product stores a few interface preferences in local storage. A supplier-response form can store unfinished progress as an AES-GCM-encrypted draft in that browser; it is not synced to the server or another device, and consent is excluded.

Current product analytics is cookieless. Google Analytics is disclosed in advance but is inactive in production: its environment value is empty, so no Google tag loads and no Google cookie is set. If activated after the notice window, it will run only on allow-listed public marketing paths after explicit opt-in, without query strings, fragments, referrers, signed-in app routes, bearer-link paths, user identifiers or workspace identifiers. Consent can be withdrawn from the persistent Privacy choices control, which also removes readable first-party _ga cookies. We do not currently use advertising or cross-site tracking cookies.

The cookies page names the two guest cookies and Sealinn local storage keys, explains their lifetimes and flags, and describes what happens if you clear or block them.

13. Children

Sealinn is a tool for businesses and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe child data is present, send the relevant details to privacy@sealinn.com so the request can be assessed under applicable law.

14. If something goes wrong

If personal data in your workspace is exposed, we will tell you without undue delay and with what we actually know at the time — what happened, what was affected, and what we are doing about it — rather than waiting until the picture is tidy. Where the law requires notifying a regulator, we will.

15. Changes to this policy

When this policy changes we update the date at the top. If a change is material — a new category of data, a new purpose, or a shorter retention period — we will email account owners before it takes effect rather than relying on you to re-read the page.

16. Contact

Privacy requests and questions about this page: privacy@sealinn.com. Anything else about the product: hello@sealinn.com. Every channel is listed on contact, and every legal document — including the data processing addendum — is indexed on the legal page.

Looking for a different document? They are all listed on the Legal page.