DOCUMENT — LEGAL

Privacy Policy

Last updated 15 February 2025

Introduction

Sailhouse respects your privacy and is committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you use our services and tell you about your privacy rights and how the law protects you.

Personal Data We Collect

When you use our services, we may collect and process the following data about you:

  • Information you give us. This is information (including identity, contact, and business details) you consent to giving us about you by filling in forms on the Sailhouse platform or by corresponding with us (by phone, email or otherwise). It includes information you provide when you register to use our services, subscribe to our services, or report a problem with our services.
  • Information we collect about you and your device. Each time you visit our Sailhouse platform we may automatically collect information including the following: technical information, including the type of device you’re using, the IP address, browser and operating systems being used, and other technical information; information about your visit, including what pages you visit and how long you spend on each page.
  • Information we receive from other sources. We work closely with third parties (including, for example, business partners, sub-contractors in technical services, advertising networks, analytics providers, and search information providers) and may receive information about you from them.

Use of Your Information

  1. Purposes:
    • We use your information for contract performance, legitimate interests (such as improving the service, preventing fraud), and legal compliance.
  2. Anonymisation:
    • We may anonymise or aggregate your data for internal analytics and service improvement.

Disclosure of Your Information

We will not disclose your personal information to any other party other than in accordance with this Privacy Policy and in the circumstances detailed below:

  • In the event that we sell any or all of our business to a buyer.
  • Where we are legally required by law to disclose your personal information.
  • To further fraud protection and reduce the risk of fraud.
  • With service providers necessary for operating the service. A list of sub processors is shared below.

Storage of Personal Data

All information you provide to us is stored on our secure servers. We have implemented necessary measures, including encryption and access controls, to ensure that your data is treated securely and in accordance with this privacy policy.

In the event of a data breach, we will notify affected users within 72 hours and take immediate action to mitigate the breach.

We retain your data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations.

Your Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These rights include the right to:

  • Request access to your personal data.
  • Request correction of your personal data.
  • Request erasure of your personal data.
  • Object to processing of your personal data.
  • Request restriction of processing your personal data.
  • Request transfer of your personal data.
  • Right to withdraw consent.

You can exercise your data protection rights by contacting us via email. We will respond to your request within 30 days. We aim to respond to all data-related inquiries within the timeframe required by applicable law.

Cross-Border Transfers

If we transfer your data outside the UK, we will ensure that appropriate safeguards are in place, such as standard contractual clauses.

Changes to This Policy

Any changes we may make to our privacy policy in the future will be posted on this page. Please check back frequently to see any updates or changes to our privacy policy.

Data Sub Processors

SubprocessorPurposeUsage
Clerk Inc.Authentication PlatformUsed for managing user authentication and authorization, including sign-ups, sign-ins, password management, and possibly two-factor authentication, ensuring secure access to Sailhouse’s services.
PlanetScaleData StoreServes as the primary database, offering scalable, MySQL-compatible databases focused on reliability and easy management for storing application data, user profiles, transaction records, and more.
Fly.ioApplication HostingProvides global server hosting for the Sailhouse application, supporting distributed, containerized applications for low-latency access and enhanced performance and reliability.
GrafanaObservability & MonitoringIntegrated for monitoring and visualizing metrics, logs, and traces from Sailhouse’s infrastructure, helping in system health observation, performance metrics, and setting up alerts for anomalies or performance issues.
SentryApplication Error MonitoringUsed for real-time error tracking and monitoring to identify, diagnose, and fix crashes and bugs in Sailhouse’s application, offering insights into error frequency, severity, and user impact.
PaddlePayments ProcessingActs as a payment and billing processor, managing subscription billing, invoices, and global payments, simplifying the handling of various payment methods, currencies, and tax compliance.
NetlifyApplication HostingUsed alongside Fly.io for hosting static sites and web applications, facilitating continuous integration and deployment with features like serverless functions, edge computing, and CDN services.
AxiomObservability & MonitoringUsed alongside Grafana for monotiring and visualizing logs from Sailhouse’s application and infrastructure.
PostmarkTransactional emailsUsed to send transactional communication to users related to their use of the platform.

Contact

Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to hello@sailhouse.dev.