Privacy

Privacy Policy

EquIP is an independent marine-equipment intelligence platform. This policy explains what personal data we collect, why we hold it, who helps us process it, and the rights you have over it.

Please note. This is a good-faith, plain-English policy describing how the platform works today. It is a starting point, not legal advice — have it reviewed against your obligations before you rely on it. Last updated 10 August 2026.

1. Who we are

“EquIP” (“we”, “us”) operates this platform and is the data controller for the personal data described below. For any privacy question, or to exercise the rights in section 7, contact us at Admin@equipyourship.com and we will respond.

2. What we collect

We keep the collection of personal data deliberately narrow:

  • Account data — the email address you sign in with, and, for makers and admins, the role assigned to your account.
  • Access-request and contact data — the name, work email, organisation and free-text message you submit when you request access or contact us.
  • Maker profile data — where you represent a maker, the company and product information you enter for your own profile.
  • Technical logs — limited server logs (such as timestamps and error records) kept to operate and secure the service.

We do not use advertising or tracking cookies, and we do not sell personal data to anyone. Ever.

3. Why we use it, and our legal basis

  • To provide the platform and your account — performance of a contract with you.
  • To review access requests, verify makers and respond to enquiries — our legitimate interest in operating a trustworthy, neutral platform, and your request itself.
  • To send transactional email (sign-in links, access-request notifications and confirmations) — necessary to deliver the service you asked for.
  • To keep the service secure and prevent abuse — our legitimate interest in protecting the platform and its users.

4. Who processes data on our behalf

We rely on a small number of carefully chosen sub-processors, and share only what each needs to do its job:

  • Supabase — database, authentication and hosting. Data is stored in the European Union (AWS, Frankfurt / eu-central region).
  • Resend — delivery of transactional email (sign-in links, access-request notifications and confirmations).

These providers act only on our instructions under their own data-processing terms. We do not otherwise disclose your data except where the law requires it.

5. International transfers

We aim to keep personal data within the European Union. Where a provider processes data outside the EU/EEA or Switzerland, that transfer is covered by an appropriate safeguard (such as the EU Standard Contractual Clauses) offered by that provider.

6. How long we keep it

Account data is kept for as long as your account is active. Access-request and contact submissions are kept for as long as needed to review and follow up on them, and then archived or deleted. You can ask us to delete your data sooner — see below.

7. Your rights

Under Swiss data-protection law and, where it applies, the EU GDPR, you have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to object to or restrict certain processing, and to receive a copy in a portable form. To exercise any of these, email Admin@equipyourship.com. You also have the right to complain to your data-protection authority.

8. How we protect it

Access to data is enforced at the database level through row-level security, so each account can reach only the data it is entitled to. Traffic is encrypted in transit, secrets are held outside the codebase, and administrative access follows a least-privilege model. No system is perfectly secure, but security is a first-order design goal of this platform, not an afterthought.

9. Changes to this policy

We may update this policy as the platform evolves. Material changes will be reflected here with a new “last updated” date.