Legal
Privacy Notice
Last updated
Who we are
Farshore Labs (“Farshore”, “we”) operates the platform available at farshorelabs.com and the services in its catalog. For privacy questions, contact privacy@farshorelabs.com.
Personal data we collect
We collect only data needed to operate the platform, bill you accurately, and keep the service secure.
- Account data: email address, hashed password (Argon2id), optional TOTP secret, display name, and email-verification state.
- Authentication signals: session identifiers (in a
__Host-sessioncookie), IP address, user agent, login timestamps, and MFA events. Used for security and fraud prevention. - Billing data: Stripe customer ID, the last four digits and brand of the card, and billing-country. Raw card numbers are stored only by Stripe.
- Subscription state: which services you have activated, activation/deactivation timestamps, and quota counters.
- API request metadata: API key prefix, service ID, request count per UTC month, and the timestamp of the last call. Used to enforce per-service quotas and to surface usage to you.
- Service input/output: queries you submit (e.g. SKU/region for availability lookups, names for sanctions screening) and the response we return. Retained per the schedule below.
- Operational telemetry: structured application logs, error traces, and aggregated performance metrics. Personal data in logs is minimised and scrubbed where feasible.
We do not knowingly collect data from children under 16. We do not use marketing trackers, advertising cookies, or third-party analytics that profile visitors.
Why we use it (lawful bases)
For customers in the EEA, UK, and Switzerland, our processing is based on one or more of the following Article 6 GDPR bases:
- Performance of a contract (Article 6(1)(b)) — to create your account, run subscriptions, answer API/web requests, and bill you.
- Legitimate interests (Article 6(1)(f)) — to keep the platform secure, prevent abuse, enforce rate limits, debug failures, and maintain backups. We balance these interests against your rights and freedoms.
- Legal obligation (Article 6(1)(c)) — for tax, accounting, and lawful requests from competent authorities.
- Consent (Article 6(1)(a)) — only where explicitly requested (e.g. optional product-update emails).
Who we share data with
We share personal data with a small set of vetted subprocessors listed on the Subprocessors page (Microsoft Azure for hosting, Stripe for payments, an email provider for transactional mail). Each subprocessor is bound by a data processing agreement consistent with Article 28 GDPR.
We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose data to law enforcement only when compelled by a valid legal process and only to the extent legally required.
International transfers
The platform is hosted in Microsoft Azure regions. By default, customer data is stored in the region closest to the operator entity (currently eastus2 primary, westus3 DR). Transfers out of the EEA, UK, or Switzerland to the United States rely on the EU-U.S. Data Privacy Framework (where the recipient is certified) and the European Commission’s Standard Contractual Clauses (2021/914), supplemented by encryption in transit and at rest with customer-managed keys.
A copy of the safeguards is available on request from privacy@farshorelabs.com.
How long we keep data
- Account & auth data: for the life of your account, then deleted within 30 days of closure (except records required for legal/accounting purposes).
- Session records: 90 days, then automatically purged.
- API usage counters: reset monthly; historical aggregates retained for 13 months for billing reconciliation.
- Service input/output: request bodies are not persisted beyond the lifetime of the request unless required to debug a specific failure (max 30 days). Aggregated, non-identifying usage statistics may be kept indefinitely.
- Operational logs: 30 days hot, then aggregated and pseudonymised.
- Billing records: seven (7) years, to satisfy tax and accounting law.
How we protect it
The platform runs on Microsoft Azure with a hardened baseline: TLS 1.2+ for all traffic, encryption at rest with customer-managed keys (Azure Key Vault), private endpoints for PaaS services, managed identities (no static secrets in code), HS256-signed JWTs, Argon2id password hashing, and optional TOTP MFA. Security posture is described on the Security page.
Your rights
Depending on your location you may have the right to access, correct, delete, port, or restrict our processing of your personal data, and to object to processing based on legitimate interests. See the GDPR & data rights page for the full list and how to exercise them. You also have the right to lodge a complaint with your local data protection authority.
Cookies
We use one strictly necessary first-party cookie (__Host-session) to keep you signed in. We do not use advertising, analytics, or cross-site tracking cookies. Full details are on the Cookie Notice.
Changes to this notice
We will publish a new “last updated” date at the top of this page when we change it. For material changes we will notify the email address on your account before the change takes effect.