Privacy
Scope and controller
This proposed policy covers SeaWeb websites, accounts, MCP/API tools, publisher tools, and booking-request features. [COUNSEL: legal entity, notice address, controller role, and supported jurisdictions].
Proposed data inventory
Potential data includes website/security logs; account, authentication, API-key, support, and quota data; MCP queries, tool arguments, and returned identifiers; publisher listings and contacts; and booking-request information. SeaWeb should not receive raw card numbers. Stripe may process checkout data only if separately enabled and reviewed.
Subprocessors and partners
Verify actual vendors and data flows before publication. Candidate providers include hosting, Supabase, Cloudflare, Google, PostHog, Stripe, Inc., and booking partners. Partners may control their own reservation/payment activity.
Retention and deletion
Proposed targets pending verification: security logs 30 days; query/telemetry 90 days; active publisher data plus 30 days; backups up to 30 days. Publish request, identity-verification, deletion, and exception procedures only after operational review.
Analytics and security
Analytics must remain off until consent, opt-out, event inventory, and vendor settings are verified. This draft makes no claim that all stored data is encrypted; verify transport encryption, at-rest protection, access controls, and incident process before publication.
US-first publication process
This draft has no effective date. Counsel and an accountable owner must approve data inventory, processors, retention/deletion, analytics, security, payments, partners, legal entity, jurisdiction, and contacts before publication.