Privacy Policy | Seafarer Consulting Skip to main content
Seafarer Consulting, gold ship's wheel logo
Legal

Privacy Policy

What the Sea Portal handles, why, who else touches it, and how long we keep it. We handle financial information for a living, so we treat privacy as part of the work.

Effective: August 5, 2026 Last updated: August 5, 2026 Terms of Service →

Seafarer Consulting LLC ("Seafarer", "we", "us") provides accounting services and an online client portal (the "Sea Portal"). This policy explains what personal information the Portal and our website handle, why, who else sees it, and how long we keep it. Questions: info@seafarerconsulting.com.

1. Who this policy covers

  • Client users: people at a client business who are given access to the Portal.
  • Seafarer staff: our employees and leadership.
  • Visitors to our public website, including anyone who submits a contact or quote form.

Portal accounts are created by Seafarer, by invitation only. There is no public sign-up.

2. What we collect

2.1 What you or your organization give us

Enquiry details
Name, work email, phone if you give one, company name, the services you are interested in, and anything you write in a message field on our website.
Account details
Name, work email, role, and the client entities you may access.
Authentication data
Passkey and authenticator-app enrolment, plus sign-in events.
Documents you upload
Statements, tax documents, contracts, and correspondence. If you become a client, also the entity, banking, invoice, payroll, and tax records needed to deliver the engagement.
Messages and tasks
Questions, replies, task titles, and notes you write.
Meeting bookings
The times you book and any note you add.

2.2 What we generate or retrieve to provide the service

Accounting data
Financial records retrieved from your accounting system on your behalf and presented as statements, reports, and KPIs. The Portal is designed to read only, never to write to your books. Where a live connection to your accounting system is not yet enabled for your engagement, we work from the records you provide.
Billing records
Invoices, amounts, and payment status.
Meeting records
Recordings and transcripts of meetings, where recording has been agreed.
Correspondence metadata
For mail sent to our shared address: sender, recipients, subject line, and the preview line the mail provider generates. We do not retrieve or store message bodies.
Staff calendars
For Seafarer staff only: meeting times from work calendars. Where an event is marked private we store only that the person is busy, and the title is never transmitted to us.
Access logs
Who opened or downloaded which document, when, and from what address, including attempts that were refused.
Technical logs
Error reports and operational logs needed to run the service securely, plus standard web logs such as IP address, browser, and referring page.

2.3 What we deliberately do not collect

  • Card and bank details. Payments run entirely through Stripe's hosted checkout. Card numbers never reach our systems; we store only Stripe's identifiers and the payment status.
  • The contents of your email. We never ask you to connect your mailbox, and we cannot read it.
  • Message bodies from our own shared inbox, as above.
  • Special category data. The Portal is not designed to hold health, biometric, or similar sensitive data, and you should not upload it.

3. Why we use it

  • To respond to your enquiry, prepare a quote, and schedule a consultation.
  • To deliver the services in your engagement letter: closing your books, preparing statements and forecasts, filing returns, and advising you.
  • To operate, secure, and support the Sea Portal, prevent unauthorized access, and keep audit records.
  • To send service communications such as close reminders, document requests, and deadline notices.
  • To send occasional updates and insights, only where you opted in. Every marketing email has an unsubscribe link.
  • To bill and collect fees, to meet our legal and professional record-keeping obligations, and to improve reliability and fix faults.

We do not sell personal information, and we do not share it for advertising.

4. Your financial records

When we become your back office, your financial records stay yours. We hold them as a service provider, we use them only to perform the engagement, and we keep them confidential. We do not use client financial data to train third-party models, and we do not disclose your figures to anyone outside your engagement team without your instruction, unless the law requires it.

5. Automated decisions and AI

No automated decision produces a legal or similarly significant effect about you.

The Portal does not expose an AI assistant to client users. Where meeting transcripts are summarized, that summarization is performed by our meeting provider, the output is visible only to Seafarer staff, and any resulting action is created by a person who decided to create it. A person is always in the loop.

6. Who else processes your information

We use service providers ("subprocessors"), each bound by contract to process data only on our instructions. The providers that handle client financial records or meeting content are named:

Supabase
Database and encrypted file storage.
Cloudflare
Application hosting and network security.
Stripe
Invoicing and payment processing.
Inngest
Scheduled and background processing.
Fireflies
Meeting recording and transcription.

We also use providers that do not hold your financial records, by category:

  • Sign-in, session management, and multi-factor authentication
  • Seafarer's own email and calendars
  • Notification email delivery
  • Error monitoring, configured so that text is masked and media is not captured
  • Operational log storage

A full, current list including these providers is available on request. We will tell affected clients before adding a subprocessor that handles client financial records or meeting content.

Some providers operate outside the United States. Where information is transferred internationally we rely on the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback, and we require appropriate safeguards.

7. Who can see what, inside Seafarer

Access is enforced by the system itself, not by policy alone:

  • Client users see only the entities they have been granted, and only their own organization's data.
  • Seafarer staff see only the clients they are assigned to. An unassigned employee has no access at all to a client's records, not reduced access.
  • Leadership can access all client records and the separate folder holding employee contracts. Leadership access to documents is logged the same way as everyone else's.
  • Meeting transcripts and internal notes are not visible to clients, including transcripts of the client's own meetings. These records hold our candid working assessments, and making them client-readable would destroy both their value and our candor.

Every document opened or downloaded is recorded, including refused attempts.

8. Security

  • Encrypted in transit and at rest.
  • Strong authentication is required for every account. Client and employee accounts require a passkey or an authenticator app; Leadership accounts require a passkey and an authenticator app. SMS codes are not used.
  • Uploaded files are checked by content, not by filename. Malware scanning is being deployed as a gate on downloads, so that a file which has not passed scanning cannot be downloaded by anyone, at any permission level. Until that gate is live in production, please treat uploads as you would any file exchange and send only documents you trust.
  • PDFs are stripped of active content before being served.
  • Access is separated at the database level, so one client's records cannot be returned in another client's session.
  • Independent security testing is carried out before real client data is onboarded.

Please send sensitive documents through the Sea Portal rather than by plain email. No system is perfectly secure. If a breach affects your information we will notify you and any required authority without undue delay.

9. How long we keep things

Documents
Until the retention date set for the record, then deleted on a scheduled sweep.
Meeting transcripts
A defined short period, then deleted automatically.
Staff calendar entries
90 days.
Shared-inbox metadata
365 days.
Access and audit logs
Retained longer than the records they describe, so the account of who accessed something survives the thing itself.
Account records
For the life of the engagement, plus any period we are required to keep them.

Accounting records may be subject to statutory retention periods that override the above.

10. Your rights

Depending on where you live, you may have the right to request access to your personal information, correct it, delete it, restrict or object to processing, receive a copy in portable form, or withdraw consent where we rely on it. We will not discriminate against you for exercising these rights.

To exercise any of these, email info@seafarerconsulting.com with the subject line "Privacy request." We verify identity before acting and respond within 30 days.

Two honest caveats:

  • Some records we are legally required to retain as an accounting practice, and we cannot delete those on request until that period expires.
  • Audit and access logs are deliberately immutable. They record who did what, and a log that could be edited would not be a record. We cannot amend them.
  • Where we hold information as a service provider on behalf of a client, we will refer your request to that client.

11. Cookies

The Portal uses only the cookies it needs to work: keeping you signed in and remembering which client entity you are currently viewing. On our public website we also use analytics to understand which pages are useful. We do not use advertising or cross-site tracking cookies. You can block or delete cookies in your browser, though blocking necessary cookies may stop parts of the Portal working.

12. Children

The Portal is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children.

13. Changes

If we make a material change we will update the date at the top and notify Portal users before it takes effect.

14. Contact

Seafarer Consulting LLC 9123 Lake Tower Lane, Fort Belvoir, VA 22060 info@seafarerconsulting.com +1 (202) 350-1703 Monday to Friday, 8 AM to 6 PM EST