OpenStampsfor industry

← Back to site

Privacy Policy

OpenStamps for Furniture · Protosonic OÜ · Estonia · last updated 10 September 2026

Who is responsible depends on the surface. Protosonic OÜ (Estonia), trading as OpenStamps, is controller for this website, enquiries, accounts and payments, and processor for the hand-off mailbox and for filing deployments, where the buyer or operator is controller. Protosonic OÜ · reg. 16344167 · VAT EE103014252 · pilot@openstamps.com · security@openstamps.com
In short: stamp, verify and the due-diligence desk keep your files on your device; we never receive them. A farmer's record goes to the buyer who asked for it, through a mailbox we run for that buyer. Enquiry details you choose to send become a Lead in the CRM we operate (EspoCRM, hosted by Hetzner Online GmbH in Germany) and we reply from pilot@openstamps.com. Payments run through Stripe: we never see a card number or Revolut credentials. Checking a stamp is free, anonymous and involves no account, no server of ours and no blockchain.

1. Who is controller, surface by surface

The same person's data can sit on several surfaces with a different responsible party on each. This table is the map; the sections below give the detail. "Local" means the bytes never leave the device they were made on.

SurfaceControllerProcessorWhere the bytes areKept for
Farmer's record (field.html)the named buyer who requested itnone — nothing reaches us from the pagethe farmer's phone90 days on the phone; an unsent record is never pruned
Hand-off mailbox (/api/handoff)the buyerProtosonic; Netlify as sub-processorNetlify Blobs14 days by default (1–30), applied on touch; no sweep job
Due-diligence desk (dds.html)the operatornone — localthe operator's deviceuntil exported or cleared
Filing deployment (configured deployments)the operator; the European Commission for what it receivesProtosonic; Netlify as sub-processortransient in the functionnot retained; decommissioned at end of order
Account (account.html)ProtosonicNetlify; Netlify Identity (identity.netlify.com) as a page script on this page and the homepage; an e-mail provider if configured; Google as identity provider if you choose Continue with GoogleNetlify Blobsuntil the account is closed
Payments and subscriptionProtosonicStripe as payment processor; Stripe holds the customer record. Revolut Pay is a method on Stripe's pages, not a second processorStripe (EU) — we never receive a card number or Revolut credentialsStripe's own retention; tax records as law requires
API key (x-osfp-key)ProtosonicNetlifyNetlify Blobs — a SHA-256 hash of the key, never the keyuntil you revoke it or close the account
The meter (closed and one-sided counts)ProtosonicNetlifyNetlify Blobs, on the account recordcounts only — no record, no fingerprint, no content, ever
Enquiry e-mailProtosonicHetzner Online GmbH (Germany) hosts the CRM we operate; Netlify runs the same-origin doorEspoCRM we operate — not a third-party inbox productup to 24 months after last contact
Stamp, plot, Phone Sync, map tilesProtosonic for the hashed abuse counters onlyyour device; a digest passes through our relaynot retained; counters expire with the UTC day
Checking a stamp or a chainnobody — no personal data reaches anyoneyour device only; no server is on this pathnothing is created, so nothing is kept

2. The farmer's record — what a farmer is owed under Art. 13, in plain words

If you are a farmer, forest owner, cooperative officer or agent using the plot page from a buyer's link, this is what you should know before you press Send.

This notice is in English here; the plot page shows its short form in the language you chose.

3. The hand-off mailbox

Supplier hand-off (dds.html → field.html): a request link carries a random token; the supplier's phone posts the sealed plot record and its stamp to our same-origin /api/handoff/<token> mailbox (Netlify Blobs, strong consistency), where it waits for the buyer's desk to collect it. A request expires 14 days after it was made (the buyer can choose 1–30): after that, the next touch of that token — a post, a pull or a close — deletes the request and everything posted to it. There is no separate clean-up job: an expired entry that nobody touches again stays in the store, unread by us, until it is touched. The buyer's desk can close a request early, which deletes it at once. The mailbox holds the declared record and its seal; it cannot alter either and we do not read them. Only the buyer holding the token can collect. Posts are counted against a hashed per-IP daily limit.

Roles. The buyer whose desk created the link is the controller; Protosonic is the buyer's processor for the mailbox, under a data-processing agreement attached to the buyer's order, and Netlify, Inc. (United States) is our sub-processor for storage. Retention is the 14-day (1–30) expiry above, applied when the token is next touched. Limits: 256 KB per deposit, 20 deposits per request, 30 requests created, 40 posts and 120 reads per network per UTC day, declared-plot deposits only. Deposits are stored as posted, in the clear: "we do not read them" is a promise, not a lock, until deposits are encrypted to a key carried in the request link.

4. The due-diligence desk — local on the operator's device

Due-diligence desk (dds.html): the operator's identity, product line, supplier and buyer contact details, plot geometry, evidence fingerprints, assessment and statement records stay in this browser's storage on your device; we receive none of it. Sealing a record sends only its SHA-256 digest, with a fresh nonce, to the drand beacon operators and our /tsa/* relay, exactly as the stamp tool does. Exports are files you download; nothing is uploaded to us. The operator is the controller; there is no processor because nothing is processed on anyone's behalf. Retention: until you export or clear it — a cleared browser profile or a private window loses it, and the exported bundle is the record you keep for the EUDR five-year period.

5. Statement filing — configured deployments only

Statement filing (dds.html, configured deployments only): the public site holds no Information System credentials, so its /api/dds/* function refuses every call. Where an operator asks for it, Protosonic operates a dedicated deployment that holds that one operator's Information System web-service key as your processor, in the deployment's environment configuration and never in the browser. When you press File, the statement you built (operator, product, quantity, plot geometry, supplier and reference details) is sent through that same-origin function to the EU Information System under your credentials. The Commission's conformance test is run on the acceptance environment before any production filing. The operator is the controller of the transmission, the European Commission is an independent controller of what the Information System receives, and Protosonic is the operator's processor. The function retains nothing; the deployment and its configuration are destroyed when the operator ends it.

6. The account, the payment and the meter

The account. Sign-in is a link sent to your e-mail address, or Continue with Google when that is enabled on the deployment; there is no password. Google sign-in is a top-level redirect to Google and back: this site never loads Google as a page script. The browser is sent to accounts.google.com; token exchange and the address lookup run on our server at oauth2.googleapis.com and openidconnect.googleapis.com. We receive the work e-mail Google asserts for that account, and nothing else from that flow is used to set a plan or a price. A second door, Netlify Identity, is offered on account.html and the homepage: the browser loads a script from identity.netlify.com on those two pages, so that host sees the visitor's IP whether or not they press Login / Sign Up. Pressing the button talks to this site's same-origin /.netlify/identity service and may set Netlify Identity cookies. That session is not the e-mail-link session that holds the plan, the keys and the meter. Protosonic is the controller of the account data — your e-mail address, a signed session cookie, the plan, the period's included and used counts, the top-up balance and the one-sided count — processed to perform the contract with you (GDPR Art. 6(1)(b)). For the contents of a backed-up desk bundle the operator remains controller and Protosonic is processor. Storage is Netlify Blobs (store osfp-accounts); the sign-in e-mail goes through an e-mail provider if one is configured, and we will name it here on the day a deployment configures one. Without its configuration the account function answers 503 and does nothing. Retention: until the account is closed; a backup is deleted when you delete it or close the account.

The payment — Stripe is our processor, and it holds the customer record. Card details and Revolut Pay are entered on Stripe's own hosted checkout and billing portal, not on this site: we never see, receive or store a card number or Revolut credentials, and no payment page is served from here. Revolut Pay is a method on Stripe's pages; we are not a Revolut merchant and we have no separate Revolut account. Stripe Payments Europe, Ltd. (Ireland) acts as our payment processor and, for its own regulatory duties, as an independent controller. The data involved is your e-mail address, billing name and address, VAT identification number if you give one, and the status of your payments and subscription — that is all; we do not receive anything about the card itself beyond its brand and last four digits as Stripe displays them to you, and we do not receive Revolut account details. If you pay with Revolut Pay, Stripe shares what that method needs with Revolut under Stripe's own arrangements. Purpose: to take payment and to meet our tax obligations (GDPR Art. 6(1)(b) and 6(1)(c)); VAT determination is performed by Stripe Tax. Retention: Stripe keeps the customer record under its own policy; we keep what accounting and tax law requires us to keep, which in Estonia is seven years for the underlying documents.

The API key — we store a hash, never the key. A key is generated in your account and shown to you once. What is stored on the account record is a SHA-256 hash of it, with the label you chose, the time it was made and the time it was last used. We cannot show you the key again and we cannot recover it, because we do not have it; that is the point. Revoking a key marks the hash revoked. Retention: until you revoke it or close the account.

The meter — counts, and nothing else. To bill for closed stamps we keep, on your account record, numbers: how many closed stamps the current period included, how many were drawn, how many top-up stamps remain, how many stamps went out one-sided, and when the period rolls. The meter never receives a record, a file, a fingerprint, a plot, a species, a supplier or a customer of yours. The relay it protects is the same pipe described in section 7: a digest with a fresh nonce passes through it and nothing is retained. Counting how many times you stamped tells us nothing about what you stamped, and that separation is deliberate.

7. The tools that keep your files on your device

8. Enquiries and e-mail

Evidence tools and team enquiries: the free pack builder and recipient review tool process selected files in this browser. The review tool keeps its draft in the current tab until you download it; importing a pack or receipt does not upload it. A Workspace interest or assisted-setup request includes the contact, company, enquiry type, workflow, optional reviewer requirements, estimated volumes and preferred date you review on teams.html. It uses the same enquiry route described below only after you press Send, or your own mail client if you choose e-mail. It does not include source documents. For assisted setup, the written scope must agree the document transfer method, access and retention arrangements before you share those documents with us.

Enquiry / e-mail: whatever you choose to write to us — typically your name, your work e-mail address and the question you are asking. The Ask panel and the enterprise quiz last step are the same door: a same-origin POST to /api/crm, which creates a Lead in EspoCRM we operate, hosted by Hetzner Online GmbH (Germany). Plots, stamps, desk bundles and Information System credentials are never sent that way. An e-mail link uses your own mail client. Purpose: answering you (legitimate interests, and steps prior to a contract where you are asking about buying: GDPR Art. 6(1)(f) and 6(1)(b)). Protosonic is the controller. The first-party Ask panel answers locally on your device and sets no cookie. Nothing on this site asks you for a turnover figure as an input to a price. Retention: up to 24 months after last contact, unless a contract or tax law requires longer.

9. Hosting logs and abuse limits

Our static host may process IP address and user-agent transiently to deliver pages. To enforce the per-network anti-abuse limits we store a hashed daily counter (not the IP itself) for timestamp-relay, sign-in, hand-off, Phone Sync and Ask-panel messages. These per-network counters are not the meter: the meter (section 6) counts stamps against an account, this counts requests against a hashed network, and neither holds anything you stamped. Purpose: prevent infrastructure abuse (GDPR Art. 6(1)(f)). Counters expire with the UTC day. Protosonic is the controller.

10. Blockchain hygiene

Procurement and privacy officers ask "is this a blockchain, and what goes on it". The answer, once: no blockchain is needed to check a stamp — a stamp is checked offline from its own bytes, a public randomness round and timestamp-authority tokens. Where a public append-only log is used, now or later, what is registered is a 32-byte identifier, never a record, as one more independent clock beside the others. There is no token, no per-stamp transaction, no data on any chain, and no chain per company. A chain, if one is ever used, is one witness among several and is never load-bearing on its own. Today no stamp minted on this site is registered in any log at all, and every surface says so.

11. Cookies and analytics

This site is designed without advertising trackers, analytics scripts or cookie banners. If a future analytics tool is added, we will update this policy and, where required, obtain consent. The account session cookie is strictly necessary, carries no tracking, and is set only after you sign in. The Ask panel sets no cookie. On account.html and the homepage the Netlify Identity widget may set its own cookies on this origin after you press Login / Sign Up. Stripe sets its own cookies on Stripe’s hosted checkout and billing portal, on Stripe’s pages and under Stripe’s policy; none of them is set on this site. If you choose Revolut Pay, Stripe may send you on to Revolut’s pages, where Revolut sets its own cookies under Revolut’s policy; none of them is set on this site either.

12. Recipients and transfers

Enquiry submissions become a Lead in the CRM we operate (EspoCRM, hosted by Hetzner Online GmbH in Germany); the same-origin door that creates that Lead runs on Netlify. An e-mail link uses your own mail client. Hosting and e-mail providers act as processors or sub-processors. Stripe Payments Europe, Ltd. (Ireland) is our payment processor and holds the customer record; Stripe, Inc. (United States) is its sub-processor and Stripe's own transfer safeguards apply. The timestamp authorities — two free ones, and a qualified third where this deployment has contracted one — receive digests only; the drand operators receive nothing. We do not sell personal data. Transfers outside the EEA — Netlify, Inc. and DigiCert are in the United States — use appropriate safeguards (EU Standard Contractual Clauses); the digest sent to DigiCert is not personal data. Hetzner hosts the CRM in Germany. Nobody receives anything when a stamp is checked, because nothing leaves the device that checks it.

13. Retention, in one place

14. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and objection. For surfaces where we are controller, contact pilot@openstamps.com. For a farmer's record or a mailbox deposit, the buyer is the controller and we will refer your request to it and assist it. You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to your own national authority.

15. Children

The Service is for business users. It is not directed at children.

16. Changes

We may update this policy; the date above will change.