Privacy Policy
What personal data Lyverto collects, why we collect it, who processes it for us, how long we keep it, and what you can ask us to do with it.
Version 2026-09-29 · Effective 29 September 2026 · Terms of Service
1. Who is responsible
[registered company name — to be confirmed], registered at [registered address — to be confirmed], is the controller of the personal data described here. Contact us about privacy at privacy@lyverto.com.
When a business uses Lyverto to manage its own customers’ or employees’ data — for example shipment consignees or crew records — that business is the controller of that data and we process it on its instructions.
2. What we collect
You give us
- Account details: name, work email, a password (stored only as a one-way hash), and whether you are an individual or a business.
- Business details: organisation name, team members and their roles, and the services, locations and capacity you list.
- Work you do in Lyverto: requests, quotes, shipments, documents, messages and notes.
- Consent records: when you accepted these documents and which version.
Collected when you use Lyverto
- Sign-in records: time, sign-in method, device type, approximate country and region, and a truncated IP address.
- Security records: IP addresses in rate-limiting and abuse-prevention logs, and error reports.
- Email engagement: for onboarding and notification emails, whether a message was opened and which links were clicked. Account emails — sign-in links, password resets, address confirmation — are never tracked.
From others
- If you sign in with Google, Microsoft, LinkedIn, Apple or Facebook, the name, email and picture that provider shares.
- If a colleague invites you to their organisation, your email and the role they assign.
3. Why we use it
- To provide the service you signed up for (performance of a contract): your account, workspace, listings and messages.
- To keep it secure (legitimate interest): rate limiting, fraud and abuse prevention, error monitoring.
- To help you get started (legitimate interest): a short onboarding email sequence, which you can unsubscribe from at any time.
- To meet legal obligations, such as responding to lawful requests.
We do not sell personal data, and we do not use advertising or cross-site tracking cookies.
4. Cookies
We set only the cookies the service needs:
- a session cookie that keeps you signed in (up to 30 days);
- a cookie remembering which sign-in method you used last, so the sign-in page can highlight it.
5. Who processes data for us
These providers process personal data on our behalf, under contract, only for the purposes listed:
| Provider | What for |
|---|---|
| Hetzner | Hosting of the application and its database |
| Cloudflare R2 | Storage of files you upload (documents, images) |
| Resend | Delivery of account and notification emails |
| Trigger.dev | Scheduling background work, such as onboarding emails |
| Pusher | Real-time updates in the app (messages, notifications) |
| Sentry | Error monitoring — technical details of failures, which can include your account id |
| Anthropic and OpenAI | AI features: search, summaries, document extraction |
| Mapbox and OpenWeather | Maps, address lookup and weather for locations you enter |
| Meta (WhatsApp) | Only if your organisation connects WhatsApp messaging |
| Google, Microsoft, LinkedIn, Apple, Facebook | Only if you choose to sign in with that provider: your name, email and profile picture |
| Have I Been Pwned | Checking a new password against known breaches — only the first 5 characters of a one-way hash are sent, never the password |
Content you publish on a public listing is visible to anyone, including search engines and AI agents using our public API.
6. International transfers
Some of these providers process data outside the country you are in. Where the UAE PDPL or the GDPR requires it, transfers rely on adequacy decisions or standard contractual clauses.
7. How long we keep it
- Account and workspace data: while your account is open, then deleted or anonymised after it is closed, unless the law requires us to keep it longer.
- Sessions: up to 30 days. Sign-in links: 15 minutes. Password-reset links: 1 hour.
- Security and error logs: only as long as needed to investigate and resolve issues.
8. Your rights
Under the UAE PDPL, the GDPR and similar laws you can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and withdraw consent. Email privacy@lyverto.com; we answer within 30 days. You can also complain to your data-protection authority.
9. Security
Data is encrypted in transit, passwords are hashed, and access inside organisations is role-based. Report a vulnerability to security@lyverto.com.
10. Changes
If we change this policy materially, we will tell you before the change applies. This policy is read together with our Terms of Service.