1. About this policy
This Privacy Policy explains how Procursea (“Procursea”, “we”, “us” or “our”) collects,
uses, shares, and protects personal data when you use the Procursea platform, our websites
at procursea.com and procursea.app, and any related services
(together, the “Service”).
We are committed to protecting your privacy and to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU GDPR.
2. Who we are (data controller)
For the purposes of UK data protection law, the data controller for personal data processed through the Service is:
Procursea Ltd
United Kingdom
Email: info@procursea.com
3. Personal data we collect
We collect the following categories of personal data:
- Account data — name, email address, role or job title, vessel assignment, profile photograph, hashed password, and authentication tokens.
- Operational data you create — inventory entries, photographs of equipment and parts, supplier details, requests for quotation, quotations, purchase orders, invoices, approvals, audit log entries, and any free-text notes you add.
- Communications data — emails sent to or received from suppliers through a mail account you have connected (Microsoft Outlook or Google Gmail), and support correspondence with us.
- Device and usage data — IP address, browser type, device type, operating system, pages viewed, actions taken, timestamps, and approximate location derived from IP address.
- Payment data — billing contact details, subscription tier, and transaction history. Card details are handled directly by our payment processor, Stripe, and we never receive or store full card numbers.
4. Data we do not collect
The following are outside the scope of the Service. We record them here so that the limits of our processing are explicit.
- Cardholder data. Primary account numbers, card verification values and cardholder names are never transmitted to or stored on Procursea systems. Payment collection is performed entirely by Stripe.
- Special category data. Procursea is a procurement and inventory platform. We do not ask for, and the Service is not designed to hold, data revealing health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation. Our Terms of Service prohibit customers from uploading such data, including crew medical certificates, passports and seafarer identity documents.
- Biometric identifiers and physical location tracking. We do not collect biometric data and we do not track the physical position of users or vessels.
- Children’s data. The Service is intended for adult professional crew and shore-based staff. We do not knowingly collect personal data from anyone under 18.
5. How we classify and protect your data
We classify every category of data we hold into one of four protection levels, and apply controls according to that level. The full scheme is set out in the Procursea Information Security Policy.
- Restricted. Applies to password hashes, session identifiers, the OAuth access and refresh tokens for any mailbox you connect, and message content retrieved from a connected Gmail or Outlook mailbox at the point of retrieval. These are encrypted at the application layer using AES-256-GCM before storage, in addition to encryption at rest. They are never written to application logs or error traces, and never transmitted to any third party other than the provider the credential belongs to. They are deleted when you disconnect the integration or close your account.
- Confidential. Applies to your name, email address, role and permissions; vessel identity; supplier quotations, negotiated pricing, purchase orders and invoices, including quote data extracted from mailbox content into a procurement record; and payment data retained by us, being your billing contact details, subscription tier, transaction history and Stripe customer and subscription identifiers. These are encrypted in transit using TLS 1.2 or 1.3 and at rest using AES-256. Access is governed by role-based access control and enforced separation between vessels, so that users on one vessel cannot see another vessel’s data.
- Internal. Applies to inventory records, part numbers, stock levels, maintenance history, uploaded photographs, and application logs. These are encrypted in transit and at rest. Access requires authentication and is subject to role-based access control. Logs are configured not to contain credentials, tokens or mailbox content.
- Public. Applies to published content on
procursea.com, including this policy. No confidentiality controls apply. Changes are made only through our normal publication process.
6. How we use your personal data and our lawful bases
Under UK GDPR Article 6, we rely on one of the following lawful bases for each processing activity:
- Performance of a contract — to create and manage your account, deliver the Service, process subscriptions, and provide customer support.
- Legitimate interests — to secure the Service, prevent fraud and abuse, improve our product, generate aggregated analytics, and communicate service updates. We balance these interests against your rights and freedoms.
- Legal obligation — to keep accounting records, respond to lawful requests from regulators, and comply with tax law.
- Consent — for optional cookies, marketing emails, and any processing where consent is the appropriate basis. You may withdraw consent at any time.
7. Sharing with third parties
We share personal data only with vetted service providers acting as our processors under contract, and only to the extent necessary to provide the Service:
- Stripe, Inc. — payment processing.
- Neon, Inc. — managed PostgreSQL database hosting.
- Replit, Inc. — application hosting and deployment.
- Cloudinary Ltd — storage and delivery of uploaded photographs and documents.
- Resend — transactional email and notification delivery.
- Microsoft and Google — only where you choose to connect a mailbox for supplier communications.
- OpenAI, Anthropic and Google — for the AI inventory scanner, item identification, and assistant features, using product and inventory data and images. Inputs are sent on a per-request basis and are not used to train these providers’ models. Content from a connected Gmail or Outlook mailbox is never sent to these AI providers.
We do not sell your personal data and we do not share it for third-party advertising.
8. Google and Microsoft mailbox data
Connecting a mailbox is optional. If you choose to connect a Google (Gmail) account, Procursea requests two permissions:
- Send email on your behalf (gmail.send) — used only to send the requests for quotation and purchase order emails that you compose and send from within Procursea, so that suppliers receive them from, and reply to, your own email address.
- Read-only access to Gmail (gmail.readonly) — used only to retrieve suppliers’ replies in the specific email threads that Procursea created, so that quotations and their attachments appear back in Procursea against the correct request. Procursea does not scan, index or read the rest of your mailbox.
Google access and refresh tokens are encrypted using AES-256-GCM before storage and are deleted when you disconnect the integration. Email content we retrieve is used solely to populate the corresponding request inside your Procursea account.
Limited Use
Procursea’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- we do not use Google user data for serving advertisements;
- we do not allow humans to read this data, except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised for internal operations in line with our privacy obligations;
- we do not sell this data;
- we do not use it to develop, improve or train generalised or non-personalised AI or machine learning models; and
- we do not transfer it to third parties except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition.
Microsoft Outlook mailbox data, where you connect an Outlook account, is handled on the same principles: used solely to send your procurement emails and retrieve supplier replies, never sold, never used for advertising, and never used to train AI or machine learning models.
9. International data transfers
Some of our processors are located outside the United Kingdom and European Economic Area, principally in the United States. Where we transfer personal data outside the UK or EEA, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, together with appropriate technical and organisational safeguards.
10. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected.
- Account data — for the life of your account, and up to 12 months after closure for legal and dispute-resolution purposes.
- Mailbox credentials (OAuth access and refresh tokens) — only while the integration is connected. Deleted when you disconnect the mailbox or close your account.
- Supplier replies retrieved into a procurement record — a quotation or attachment that has been retrieved into a request for quotation, purchase order or invoice forms part of that record. Message content that is not written into a procurement record is not retained after retrieval.
- Procurement records (requests for quotation, purchase orders, invoices) — for the life of your account. On termination these are deleted in accordance with our Terms of Service. Our own invoices to you and the associated accounting records are retained for six years to meet UK accounting and tax record-keeping requirements.
- Audit logs — up to 24 months.
- Support correspondence — up to 36 months.
- Backups — encrypted and retained on a rolling basis for up to 90 days, after which deleted data is no longer recoverable.
11. Your rights under UK GDPR
You have the following rights in respect of your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion of your personal data, subject to the legal retention obligations set out above.
- Restriction — limit how we use your data while a query is being resolved.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection — object to processing carried out on the basis of legitimate interests.
- Withdraw consent — at any time, where we rely on consent.
- Complain — lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk.
To exercise any of these rights, email info@procursea.com with the subject line “Privacy request”. We will respond within one month.
12. Cookies and similar technologies
We use strictly necessary cookies for authentication, session management and security. We do not use third-party advertising cookies. Where we use analytics cookies to understand usage, we request your consent, and you can decline without affecting your access to the Service. Full detail of what this website stores, and the control to change your choice, is in our Cookie Policy.
13. Security
We protect personal data with technical and organisational measures appropriate to the protection level set out in section 5. These include TLS encryption in transit, AES-256 encryption at rest for the database and backups, AES-256-GCM application-layer encryption of connected-mailbox tokens, bcrypt password hashing, role-based access control, enforced separation between vessels, audit logging, and least-privilege access for our engineers.
The platform is assessed annually against the Cloud Application Security Assessment (CASA) framework, which is based on the OWASP Application Security Verification Standard.
If you believe you have found a security vulnerability in Procursea, please report it in accordance with our Vulnerability Disclosure Policy. No system can be guaranteed completely secure, but we review and improve our controls continually.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be notified to you by email or by an in-product banner before they take effect.
15. Contact us
For any privacy-related question, request or concern, contact Procursea at info@procursea.com using the subject line “Privacy request”.
Procursea Ltd
United Kingdom
Email: info@procursea.com
Copyright © 2026 Procursea Ltd. All rights reserved.