Privacy Policy
Last updated: 26 July 2026
This policy explains what TSD Shipmanagement ("we") does with personal data in SandraOps. It covers two different groups of people, and the difference matters:
- You, our customer. For your account data we are the data controller.
- The people you research and contact. For their data you are the controller and we are your processor — you decide who is searched for and who is contacted; we process it on your instructions.
1. Data about you
| What | Why |
|---|---|
| Email address, display name, password hash, preferred language | To create and secure your account |
| Business profile you fill in (what you sell, to whom, your positioning) | It is the context every AI search, analysis and draft is built from |
| Workspace and membership records | To scope your data to your workspace |
| Credit balance and transaction ledger | To bill correctly and show you where credits went |
| Stripe customer id | To connect your payments; card details are held by Stripe, never by us |
| Mailbox credentials or OAuth tokens you connect | To send outreach and sync replies. Passwords for SMTP are encrypted at rest |
| Server logs (IP address, request, timestamp) | Security, abuse prevention and debugging |
Our legal basis is performance of our contract with you, and our legitimate interest in keeping the Service secure and working.
2. Data about the companies and people you research
When you run a search, the Service collects business contact data from public sources — search engines, Google Places, and company websites — and stores it in your workspace together with the evidence of where each item came from. This can include business email addresses, phone numbers and the names of people in business roles, which is personal data.
We process this data on your behalf and on your instructions. You decide the search, you decide who to contact, and you are responsible for having a lawful basis to do so and for meeting your own transparency obligations toward those people. Our Terms of Service set this out in section 4.
Anyone contacted through the Service can unsubscribe using the link in the message; that sets do-not-contact status on the record and stops further outreach from your workspace. Requests to see, correct or delete such data should be directed to you as the controller; if one reaches us, we will pass it to you and assist you in answering it.
3. Calls
Where calling is enabled for your workspace, we store the call status, duration, cost, and — where the transport provides them — a transcript and the classified outcome. Recording and transcription of a call may require the other party's consent depending on where they are; obtaining it is your responsibility.
4. Who else processes the data
We use these processors. Data is shared with them only as needed to run the features you use:
- OpenAI — search planning, company analysis, message drafting, voice. API data is not used to train their models.
- Google — Places and Custom Search for discovery; Gmail OAuth if you connect a Google mailbox; Google sign-in if you use it.
- Web-search providers (Serper and equivalents) — B2B discovery.
- Twilio (and its speech providers) — telephony, where calling is enabled.
- Stripe — payments. We never see your card number.
- Our hosting provider — running the application and database.
Some of these process data outside the EEA. Transfers rely on the standard contractual clauses or an equivalent safeguard offered by the provider.
We do not sell personal data and we do not use your workspace data to train our own models.
5. Retention
Account, workspace and business data is kept while your account is open. When you ask us to delete your workspace, we delete it and the research data in it. Credit ledger entries and payment records are kept for as long as tax and accounting law requires. Server logs are kept for a limited period for security purposes.
6. Security
Traffic is served over TLS. Passwords are stored hashed, never in plain text. Mailbox passwords you provide are encrypted at rest. Data in each workspace is scoped to that workspace at the database-query level. Payment webhooks and telephony webhooks are verified by signature before they are accepted.
7. Your rights
Where the GDPR or a comparable law applies to you, you have the right to access, correct, delete and export your data, to object to or restrict processing, and to complain to your national data protection authority. To exercise any of these, write to [email protected] and we will respond within one month.
8. Cookies
We use a session cookie to keep you signed in and a "remember me" cookie if you choose it. Local storage holds your theme and language preference. There is no advertising or third-party analytics tracking on the Service.
9. Contact
TSD Shipmanagement — [email protected].