VesselMark
TermsPrivacyDPASubprocessorsContact

Privacy Policy

Last updated: August 6, 2026

VesselMark is operated by Stratiback LLC (Louisiana, USA). This policy describes what personal data we collect when you use vesselmark.com, why, and the choices you have. The short version: we collect what the service needs to function, we sell nothing, and there is no third-party advertising or tracking on this site.

What we collect

Account data: your name (if provided), work email address, and a salted hash of your password — never the password itself. Multi-factor authentication secrets are stored encrypted. Signup context: the IP address used at registration, kept for abuse prevention. Content you add: the compliance material your organization puts into the service — controls, risks, notes, evidence files — which may incidentally contain personal data your organization chooses to include. Operational records: an append-only audit trail of actions in your workspace (who did what, when), and server logs kept for security and troubleshooting.

What we use it for

Operating the service, authenticating you, sending the emails the service depends on (verification links, task and deadline reminders, billing notices), preventing abuse, and providing support when you contact us. We send no marketing email without separate consent. We do not sell or share personal data for advertising.

Who else touches your data

We use a small number of service providers: Stripe (payment processing — we never see your card number), Postmark (transactional email delivery), and US-based hosting infrastructure operated by Stratiback LLC. These providers process data only as needed to provide their service to us. We disclose data if required by law, and we will tell you when we are permitted to.

Cookies

Essential cookies, always set: a session cookie to keep you signed in. We also store your cookie choice itself in your browser’s local storage so we don’t ask again.

Analytics and advertising cookies from Google Analytics and Google Ads, used to measure which campaigns bring people here. We load Google’s tag only after you accept. Until you choose, and if you decline, the tag is never loaded at all — so no cookies are written, no advertising identifiers are collected, and nothing about your visit is sent to Google, not even a cookieless page view. Declining changes nothing about how the product works. You can change your choice at any time:

Accepting means Google receives your IP address and page-view information and may use it to attribute advertising. Google acts as an independent controller for that data; see Google’s own privacy policy for what it does with it. If you accept and then decline again, the tag stops loading from that point on; a tag already running on the page you are looking at is told to deny all storage immediately, and is gone on your next page view.

We also keep the tag out of your workspace. It loads only on our public pages and on the billing page — never on the pages holding your vessels, controls, risks or evidence — so those addresses, which contain your record identifiers, are never sent to Google.

Retention

Account and workspace data is retained while your account exists and for a reasonable period afterwards to allow reactivation and export. Evidence files are special: they are stored in write-once storage under a one-year compliance retention lock, and cannot be deleted by anyone — including us — until that lock expires. If you ask us to erase your data, we will delete or de-identify everything within our control and confirm the date on which locked evidence will be destroyed. Database backups are retained for 14 days.

Security

Every account requires multi-factor authentication. Customer workspaces are isolated at the database layer with row-level security. Evidence is content-hashed and stored write-once. The audit trail is append-only and cannot be modified even by our own application. Data is encrypted in transit; MFA secrets are encrypted at rest.

Your rights

You can access and export your organization’s data at any time from within the service. You may request correction or deletion of personal data, subject to the evidence retention lock described above. If you are in the UK, EU, or another jurisdiction with statutory data rights, we will honor access, rectification, erasure, portability, and objection requests as those laws provide. Contact us via the contact form — it is the fastest route to a human.

International transfers

The service is hosted in the United States. If you use it from elsewhere, your data is processed in the US. Customers needing a data processing agreement for their own compliance obligations can request one via the contact form.

Changes

We will update this policy as the service evolves and note the date above. Material changes will be announced by email or in-app notice before they take effect.

Compliance management software. Not legal advice. Regulatory readiness is the operator's responsibility.