Nautiplex
Legal

Privacy Policy

Last updated: 2026

This page is a starting template describing what the DockIQ platform actually collects and does today — it has not been reviewed by a lawyer. Confirm the content with legal counsel before relying on it for a real launch.

What we collect

If you submit a booking request on a listing page, we collect the name, contact details, and message you provide, so the operator can follow up with you directly. We never process payments and never store payment card details — this is a lead-capture form, not a checkout.

If you sign in to the admin dashboard, authentication is handled by Supabase Auth (email/password or Google sign-in) — we don't see or store your password ourselves.

When a physical QR code is scanned, we record basic technical details of that scan: device type, browser, language, approximate country (from the hosting provider's network, not GPS), and a randomly generated session identifier. We don't use any third-party advertising or analytics trackers.

How long we keep it

QR scan records are automatically deleted after 400 days by an automated cleanup job — nothing is retained indefinitely by default. Booking requests are kept until the operator or an administrator removes them.

Who we share it with

Data is stored with Supabase (our database and authentication provider) and served via Vercel (our hosting provider). We don't sell data or share it with advertisers. A booking request is shared with the specific operator you contacted, since that's the point of submitting it.

Your rights

If you're in the EU/EEA, GDPR gives you the right to access, correct, or request deletion of your personal data. To exercise these rights, contact us at [contact email to be added].