Privacy Policy
1. Who is controller, surface by surface
The same person's data can sit on several surfaces with a different responsible party on each. This table is the map; the sections below give the detail. "Local" means the bytes never leave the device they were made on.
| Surface | Controller | Processor | Where the bytes are | Kept for |
|---|---|---|---|---|
Farmer's record (field.html) | the named buyer who requested it | none — nothing reaches us from the page | the farmer's phone | 90 days on the phone; an unsent record is never pruned |
Hand-off mailbox (/api/handoff) | the buyer | Protosonic; Netlify as sub-processor | Netlify Blobs | 14 days by default (1–30), applied on touch; no sweep job |
Due-diligence desk (dds.html) | the operator | none — local | the operator's device | until exported or cleared |
| Filing deployment (configured deployments) | the operator; the European Commission for what it receives | Protosonic; Netlify as sub-processor | transient in the function | not retained; decommissioned at end of order |
Account (account.html) | Protosonic | Netlify; Netlify Identity (identity.netlify.com) as a page script on this page and the homepage; an e-mail provider if configured; Google as identity provider if you choose Continue with Google | Netlify Blobs | until the account is closed |
| Payments and subscription | Protosonic | Stripe as payment processor; Stripe holds the customer record. Revolut Pay is a method on Stripe's pages, not a second processor | Stripe (EU) — we never receive a card number or Revolut credentials | Stripe's own retention; tax records as law requires |
API key (x-osfp-key) | Protosonic | Netlify | Netlify Blobs — a SHA-256 hash of the key, never the key | until you revoke it or close the account |
| The meter (closed and one-sided counts) | Protosonic | Netlify | Netlify Blobs, on the account record | counts only — no record, no fingerprint, no content, ever |
| Enquiry e-mail | Protosonic | Hetzner Online GmbH (Germany) hosts the CRM we operate; Netlify runs the same-origin door | EspoCRM we operate — not a third-party inbox product | up to 24 months after last contact |
| Stamp, plot, Phone Sync, map tiles | Protosonic for the hashed abuse counters only | — | your device; a digest passes through our relay | not retained; counters expire with the UTC day |
| Checking a stamp or a chain | nobody — no personal data reaches anyone | — | your device only; no server is on this path | nothing is created, so nothing is kept |
2. The farmer's record — what a farmer is owed under Art. 13, in plain words
If you are a farmer, forest owner, cooperative officer or agent using the plot page from a buyer's link, this is what you should know before you press Send.
- Who asked for it. The buyer named on the page. That buyer is the controller of the record you make for it; we are not, and nothing from the page reaches us except a fingerprint at seal time and, when you press Send, the deposit to the buyer's mailbox (section 3).
- What it contains. The map of your plot (a point or a shape), whether the trees were planted or natural, the species, the country, the quantity if you declared a harvest, the time your phone said it was, a photo only if you chose to attach one, and a code that identifies this phone. That phone code is a persistent identifier: records made on the same phone can be linked to each other.
- Why the buyer needs it. EU Regulation 2023/1115 obliges the buyer to hold the location of every plot its wood came from and to keep that for at least five years. That legal duty is the buyer's basis for asking; a photo or a plot name beyond it rests on the buyer's interest in evidence that can be checked and on your choice to add it.
- Where it goes. To the buyer's own files on the buyer's own computer. The buyer files a statement in the EU Information System that carries your plot's location; authorities in the country the furniture is sold in can see that statement.
- How long. Your phone keeps a copy for 90 days and then removes it; a record you never sent is never removed by us. The buyer keeps it for at least five years.
- What it proves and does not. A stamped record fixes what you declared and when. It does not prove your harvest was legal, that the forest was not cleared, or that a photo shows this plot or came from a camera.
- Your rights. To see, correct, withdraw or complain about the record, contact the buyer named on the page; a sealed record cannot be edited, but it can be withdrawn by an amendment record, and the buyer can delete it from every store it controls. You may also complain to your national data-protection authority or to the Estonian Data Protection Inspectorate about our part (the mailbox).
This notice is in English here; the plot page shows its short form in the language you chose.
3. The hand-off mailbox
Supplier hand-off (dds.html → field.html): a request link carries a random token; the supplier's phone posts the sealed plot record and its stamp to our same-origin /api/handoff/<token> mailbox (Netlify Blobs, strong consistency), where it waits for the buyer's desk to collect it. A request expires 14 days after it was made (the buyer can choose 1–30): after that, the next touch of that token — a post, a pull or a close — deletes the request and everything posted to it. There is no separate clean-up job: an expired entry that nobody touches again stays in the store, unread by us, until it is touched. The buyer's desk can close a request early, which deletes it at once. The mailbox holds the declared record and its seal; it cannot alter either and we do not read them. Only the buyer holding the token can collect. Posts are counted against a hashed per-IP daily limit.
Roles. The buyer whose desk created the link is the controller; Protosonic is the buyer's processor for the mailbox, under a data-processing agreement attached to the buyer's order, and Netlify, Inc. (United States) is our sub-processor for storage. Retention is the 14-day (1–30) expiry above, applied when the token is next touched. Limits: 256 KB per deposit, 20 deposits per request, 30 requests created, 40 posts and 120 reads per network per UTC day, declared-plot deposits only. Deposits are stored as posted, in the clear: "we do not read them" is a promise, not a lock, until deposits are encrypted to a key carried in the request link.
4. The due-diligence desk — local on the operator's device
Due-diligence desk (dds.html): the operator's identity, product line, supplier and buyer contact details, plot geometry, evidence fingerprints, assessment and statement records stay in this browser's storage on your device; we receive none of it. Sealing a record sends only its SHA-256 digest, with a fresh nonce, to the drand beacon operators and our /tsa/* relay, exactly as the stamp tool does. Exports are files you download; nothing is uploaded to us. The operator is the controller; there is no processor because nothing is processed on anyone's behalf. Retention: until you export or clear it — a cleared browser profile or a private window loses it, and the exported bundle is the record you keep for the EUDR five-year period.
5. Statement filing — configured deployments only
Statement filing (dds.html, configured deployments only): the public site holds no Information System credentials, so its /api/dds/* function refuses every call. Where an operator asks for it, Protosonic operates a dedicated deployment that holds that one operator's Information System web-service key as your processor, in the deployment's environment configuration and never in the browser. When you press File, the statement you built (operator, product, quantity, plot geometry, supplier and reference details) is sent through that same-origin function to the EU Information System under your credentials. The Commission's conformance test is run on the acceptance environment before any production filing. The operator is the controller of the transmission, the European Commission is an independent controller of what the Information System receives, and Protosonic is the operator's processor. The function retains nothing; the deployment and its configuration are destroyed when the operator ends it.
6. The account, the payment and the meter
The account. Sign-in is a link sent to your e-mail address, or Continue with Google when that is enabled on the deployment; there is no password. Google sign-in is a top-level redirect to Google and back: this site never loads Google as a page script. The browser is sent to accounts.google.com; token exchange and the address lookup run on our server at oauth2.googleapis.com and openidconnect.googleapis.com. We receive the work e-mail Google asserts for that account, and nothing else from that flow is used to set a plan or a price. A second door, Netlify Identity, is offered on account.html and the homepage: the browser loads a script from identity.netlify.com on those two pages, so that host sees the visitor's IP whether or not they press Login / Sign Up. Pressing the button talks to this site's same-origin /.netlify/identity service and may set Netlify Identity cookies. That session is not the e-mail-link session that holds the plan, the keys and the meter. Protosonic is the controller of the account data — your e-mail address, a signed session cookie, the plan, the period's included and used counts, the top-up balance and the one-sided count — processed to perform the contract with you (GDPR Art. 6(1)(b)). For the contents of a backed-up desk bundle the operator remains controller and Protosonic is processor. Storage is Netlify Blobs (store osfp-accounts); the sign-in e-mail goes through an e-mail provider if one is configured, and we will name it here on the day a deployment configures one. Without its configuration the account function answers 503 and does nothing. Retention: until the account is closed; a backup is deleted when you delete it or close the account.
The payment — Stripe is our processor, and it holds the customer record. Card details and Revolut Pay are entered on Stripe's own hosted checkout and billing portal, not on this site: we never see, receive or store a card number or Revolut credentials, and no payment page is served from here. Revolut Pay is a method on Stripe's pages; we are not a Revolut merchant and we have no separate Revolut account. Stripe Payments Europe, Ltd. (Ireland) acts as our payment processor and, for its own regulatory duties, as an independent controller. The data involved is your e-mail address, billing name and address, VAT identification number if you give one, and the status of your payments and subscription — that is all; we do not receive anything about the card itself beyond its brand and last four digits as Stripe displays them to you, and we do not receive Revolut account details. If you pay with Revolut Pay, Stripe shares what that method needs with Revolut under Stripe's own arrangements. Purpose: to take payment and to meet our tax obligations (GDPR Art. 6(1)(b) and 6(1)(c)); VAT determination is performed by Stripe Tax. Retention: Stripe keeps the customer record under its own policy; we keep what accounting and tax law requires us to keep, which in Estonia is seven years for the underlying documents.
The API key — we store a hash, never the key. A key is generated in your account and shown to you once. What is stored on the account record is a SHA-256 hash of it, with the label you chose, the time it was made and the time it was last used. We cannot show you the key again and we cannot recover it, because we do not have it; that is the point. Revoking a key marks the hash revoked. Retention: until you revoke it or close the account.
The meter — counts, and nothing else. To bill for closed stamps we keep, on your account record, numbers: how many closed stamps the current period included, how many were drawn, how many top-up stamps remain, how many stamps went out one-sided, and when the period rolls. The meter never receives a record, a file, a fingerprint, a plot, a species, a supplier or a customer of yours. The relay it protects is the same pipe described in section 7: a digest with a fresh nonce passes through it and nothing is retained. Counting how many times you stamped tells us nothing about what you stamped, and that separation is deliberate.
7. The tools that keep your files on your device
- Browser stamp tool: file hashing and sealing run locally; we never receive your file. At stamp time the browser fetches the current public randomness round from the drand beacon operators (api.drand.sh, drand.cloudflare.com — no file data is sent) and, to close the time bracket, sends the file's SHA-256 digest (not the file) with a fresh nonce through our same-origin
/tsa/*relay to two RFC 3161 timestamp authorities: freetsa.org and DigiCert (timestamp.digicert.com). The relay is a pipe — we do not retain the digest — and the TSA receives a digest it cannot reverse into your file. Verification sends nothing anywhere: it runs offline on your device. - Plot or source declaration (try.html): if you allow it, the browser reads device GNSS in order to declare a point or polygon. An applicable micro or small primary operator may instead type a postal address or reference from an applicable official system for the simplified route. These details stay on your device unless you download an export or stamp the declaration (in which case only the SHA-256 of that JSON is relayed to timestamp authorities, same as any other file). Phone GNSS and eligibility for the simplified route are operator-declared fields; the stamp does not prove either claim. We do not receive a live location stream.
- Map tiles (opt-in): the chain map on try.html draws declared plots over a public-domain Natural Earth outline served from this site, so viewing it contacts nobody else. If you switch on Show OpenStreetMap tiles in the map legend, or press the map's own “show the map” button, your browser fetches map images directly from the OpenStreetMap Foundation (tile.openstreetmap.org), which then sees your IP address and which map areas you view; none of your files or records is sent. The switch is off on every load and remembered only for the browser session.
- Place search (you type it): the plot map's search box sends the words you type to our same-origin
/api/geocode. That function asks the OpenStreetMap Nominatim service (nominatim.openstreetmap.org) with a contactable User-Agent. Nominatim sees the query text and this server's address, not your plot, your corners or your files. Nothing is searched until you press Go. A result is a suggested map centre, not a location proof. - Phone Sync (acoustic path): the rendezvous mailbox at
/api/copresencebriefly holds, per pairing session, four sample-clock integers and two confidence numbers from each device, keyed by a one-way hash of a secret that never reaches the server. It cannot derive a location or a distance from them; entries expire within 10 minutes. The screen-to-camera path uses no server at all.
8. Enquiries and e-mail
Evidence tools and team enquiries: the free pack builder and recipient review tool process selected files in this browser. The review tool keeps its draft in the current tab until you download it; importing a pack or receipt does not upload it. A Workspace interest or assisted-setup request includes the contact, company, enquiry type, workflow, optional reviewer requirements, estimated volumes and preferred date you review on teams.html. It uses the same enquiry route described below only after you press Send, or your own mail client if you choose e-mail. It does not include source documents. For assisted setup, the written scope must agree the document transfer method, access and retention arrangements before you share those documents with us.
Enquiry / e-mail: whatever you choose to write to us — typically your name, your work e-mail address and the question you are asking. The Ask panel and the enterprise quiz last step are the same door: a same-origin POST to /api/crm, which creates a Lead in EspoCRM we operate, hosted by Hetzner Online GmbH (Germany). Plots, stamps, desk bundles and Information System credentials are never sent that way. An e-mail link uses your own mail client. Purpose: answering you (legitimate interests, and steps prior to a contract where you are asking about buying: GDPR Art. 6(1)(f) and 6(1)(b)). Protosonic is the controller. The first-party Ask panel answers locally on your device and sets no cookie. Nothing on this site asks you for a turnover figure as an input to a price. Retention: up to 24 months after last contact, unless a contract or tax law requires longer.
9. Hosting logs and abuse limits
Our static host may process IP address and user-agent transiently to deliver pages. To enforce the per-network anti-abuse limits we store a hashed daily counter (not the IP itself) for timestamp-relay, sign-in, hand-off, Phone Sync and Ask-panel messages. These per-network counters are not the meter: the meter (section 6) counts stamps against an account, this counts requests against a hashed network, and neither holds anything you stamped. Purpose: prevent infrastructure abuse (GDPR Art. 6(1)(f)). Counters expire with the UTC day. Protosonic is the controller.
10. Blockchain hygiene
Procurement and privacy officers ask "is this a blockchain, and what goes on it". The answer, once: no blockchain is needed to check a stamp — a stamp is checked offline from its own bytes, a public randomness round and timestamp-authority tokens. Where a public append-only log is used, now or later, what is registered is a 32-byte identifier, never a record, as one more independent clock beside the others. There is no token, no per-stamp transaction, no data on any chain, and no chain per company. A chain, if one is ever used, is one witness among several and is never load-bearing on its own. Today no stamp minted on this site is registered in any log at all, and every surface says so.
11. Cookies and analytics
This site is designed without advertising trackers, analytics scripts or cookie banners. If a future analytics tool is added, we will update this policy and, where required, obtain consent. The account session cookie is strictly necessary, carries no tracking, and is set only after you sign in. The Ask panel sets no cookie. On account.html and the homepage the Netlify Identity widget may set its own cookies on this origin after you press Login / Sign Up. Stripe sets its own cookies on Stripe’s hosted checkout and billing portal, on Stripe’s pages and under Stripe’s policy; none of them is set on this site. If you choose Revolut Pay, Stripe may send you on to Revolut’s pages, where Revolut sets its own cookies under Revolut’s policy; none of them is set on this site either.
12. Recipients and transfers
Enquiry submissions become a Lead in the CRM we operate (EspoCRM, hosted by Hetzner Online GmbH in Germany); the same-origin door that creates that Lead runs on Netlify. An e-mail link uses your own mail client. Hosting and e-mail providers act as processors or sub-processors. Stripe Payments Europe, Ltd. (Ireland) is our payment processor and holds the customer record; Stripe, Inc. (United States) is its sub-processor and Stripe's own transfer safeguards apply. The timestamp authorities — two free ones, and a qualified third where this deployment has contracted one — receive digests only; the drand operators receive nothing. We do not sell personal data. Transfers outside the EEA — Netlify, Inc. and DigiCert are in the United States — use appropriate safeguards (EU Standard Contractual Clauses); the digest sent to DigiCert is not personal data. Hetzner hosts the CRM in Germany. Nobody receives anything when a stamp is checked, because nothing leaves the device that checks it.
13. Retention, in one place
- Farmer's phone: 90 days for sealed entries; an unsent entry is never pruned.
- Hand-off mailbox: 14 days by default (1–30 at the buyer's choice), applied on the next touch; no sweep job; closed at once by the buyer.
- Desk: until exported or cleared by the operator.
- Filing deployment: nothing retained by the function; decommissioned when the operator ends it.
- Account: until closed.
- API keys: the hash, until you revoke it or close the account.
- Meter counts: on the account record while it is open; the previous period's counts are overwritten when the period rolls.
- Payments: Stripe's own retention for the customer record; ours is what accounting and tax law requires (seven years in Estonia for the underlying documents).
- Enquiries: up to 24 months after last contact.
- Abuse counters: the UTC day.
14. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and objection. For surfaces where we are controller, contact pilot@openstamps.com. For a farmer's record or a mailbox deposit, the buyer is the controller and we will refer your request to it and assist it. You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to your own national authority.
15. Children
The Service is for business users. It is not directed at children.
16. Changes
We may update this policy; the date above will change.