Privacy Policy
LogisWave, Esdoornstraat 20, 3434 CD, The Netherlands, is the controller for personal data described in this policy. Contact privacy@logiswave.com about privacy or your rights.
1. Data we process
We process account details such as name, email, authentication records and legal acceptance; receipts, images, PDFs, extracted text and categories; workspace membership and business details; preferences, notifications and push tokens; security, audit and service-delivery records; and support communications. We also keep limited app-review request records: the request source, qualifying receipt or invoice action, device platform, app version, campaign assignment, request time and whether Harbor started or completed the native request, found it unavailable or encountered an error. Apple and Google do not tell Harbor whether their review dialog appeared, was dismissed, or resulted in a rating or review, so Harbor does not collect that response. With permission, the app may use approximate device location to suggest a currency. Harbor does not require location permission for signup.
2. Why and on what basis
- To create your account and provide requested Harbor features: performance of our contract.
- To secure accounts, prevent abuse, maintain reliable operations and keep limited audit records: our legitimate interests and those of users.
- To time app-review requests after successful use, avoid excessive repeat requests and understand whether the native request mechanism is working: our legitimate interest in improving Harbor. Eligibility may use account age, device platform, preferred language, business participation and counts of completed receipt or invoice actions. A targeted request is attempted only after your next successful qualifying action; it does not itself send a push notification or email.
- To meet tax, accounting, consumer, privacy or other legal duties: compliance with law.
- For optional processing that is not needed for the service: consent, where specifically requested. Consent may be withdrawn without affecting earlier lawful processing.
3. How data is obtained
Most data comes directly from you or other members of a workspace. Authentication providers may send verified identity information when you choose social sign-in. Optional extraction services may derive structured fields from files you submit.
4. Google services
If you choose Google Sign-In, Harbor receives a stable Google account identifier, verified email address and, when available, profile name solely to authenticate you, create or link your Harbor account and protect access. The Google identity token is verified and is not retained.
If you enable Google Drive backup, the Harbor app requests access only to Google Drive’s hidden application-data folder. It uses that permission to create, read and update an encrypted receipt backup so you can restore your records on another device. Harbor cannot access your other Google Drive files. Drive authorisation and file transfer are handled by the app on your device; the Harbor backend does not receive your Google Drive access token or Drive backup file.
Harbor does not sell Google user data, use it for advertising or share it except as necessary to provide these user-facing features, maintain security, comply with law or act with your explicit consent. Harbor’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
5. Service providers and sharing
We share data only as needed with providers supporting hosting, authentication, email, push notifications, file processing or receipt extraction; with members of workspaces you join; when required by law; or during a properly safeguarded business transfer. Providers act under contractual and confidentiality obligations appropriate to their role.
6. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers must use a lawful mechanism and appropriate safeguards. Contact us for information relevant to the providers used for your account.
7. Retention
Account and workspace data is kept while needed to provide Harbor. App-review request records linked to an account are kept for no more than 397 days and are removed when that account is deleted or anonymised. A deletion request is normally completed after a configurable cooling period, currently 30 days, unless cancelled. Personal data is then deleted or anonymised; a minimal anonymised request record may remain to demonstrate completion. Security and notification-delivery records are retained only for limited operational periods. Shared business records may remain with the business workspace where another member needs them or law requires retention.
8. Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, objection and portability. You may withdraw consent where consent is the basis. Harbor provides account export and deletion controls in the app. You may also email privacy@logiswave.com. We may need to verify your identity and normally respond within one month.
9. Complaints
You may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority where you live or work. We encourage you to contact us first so we can address the concern.
10. Security
We use technical and organisational measures intended to protect data, including access controls, encrypted transport and credential protection. No service can guarantee absolute security; please protect your account and report suspected compromise.
11. Children
Harbor is not directed to children who cannot lawfully enter the agreement in their country. Contact us if you believe a child provided data without required authorisation.
12. Changes
We publish the current policy and version here. We will provide appropriate notice of material changes and request renewed acknowledgement or consent where required.
13. Contact
LogisWave
Esdoornstraat 20, 3434 CD, The Netherlands
privacy@logiswave.com