1. About this policy
This Privacy Policy explains how Two Shores Online ("we", "us", "our") handles personal information in connection with SeaRM, the SeaRM website at searm.com, the sandbox and downloadable demo, and any related support, sales and onboarding (together, the "Services").
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where they apply, we also comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Philippine Data Privacy Act of 2012, and US state privacy laws such as the California Consumer Privacy Act as amended (CCPA).
Two Shores Online is the operator of SeaRM. You can contact us at janmichael@twoshoresonline.com.
2. Our two roles
We handle personal information in two different roles:
- As a controller for information about our own website visitors, trial users, customers and their account users, for example your name and email when you start a trial, and billing details for your subscription.
- As a processor (service provider) for the information our customers put into SeaRM about their own clients, leads and contacts ("Customer Data"). Our customer decides what Customer Data is collected and why, and we process it only on their instructions. Section 8 explains this in more detail.
3. Information we collect
Information you give us
- Contact details: name, work email, phone number, company and role, when you start a trial, book a demo, join a waitlist or contact us.
- Account details: sign-in email, profile photo, signature (if you save one for countersigning), time zone and preferences.
- Billing details: billing contact, company details and payment records. Card details are collected and stored by our payment provider, not by us.
- Support and feedback: what you tell us in emails, calls, meetings and support requests.
Information collected automatically
- Technical data: IP address, browser and device type, operating system, and the pages or screens you use, recorded in server logs for security and reliability.
- Product usage: actions inside SeaRM needed to run the Services, such as sign-ins, sent emails, signature events and audit trails.
- Browser storage: small settings kept in your browser, described in section 10.
Information from others
- Teammates who invite you to a SeaRM workspace.
- Services you connect, such as your email provider, payment providers (Stripe, PayPal), accounting software (Xero) or phone system (Aircall), within the permissions you grant.
- Form tools that send enquiries to SeaRM through a webhook you set up.
4. How we use information
- To provide, maintain and secure the Services, including your trial and workspace.
- To set up accounts, authenticate users and manage access permissions.
- To bill for subscriptions and keep financial records.
- To respond to enquiries, provide support and onboarding, and run demos you request.
- To send service messages, such as sign-in links, security alerts and changes to the Services.
- To send product news and offers where you have agreed or where the law otherwise allows, always with a way to opt out.
- To understand how the Services are used so we can improve them, using aggregated or de-identified information where possible.
- To detect, prevent and investigate fraud, abuse, security incidents and breaches of our Terms.
- To comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not use Customer Data to build advertising profiles or to train general-purpose AI models.
5. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:
- Contract: to provide the Services you or your organisation signed up for.
- Legitimate interests: to secure and improve the Services, prevent fraud, and market to business contacts in ways you would reasonably expect, balanced against your rights.
- Consent: where we ask for it, for example certain marketing messages. You can withdraw consent at any time.
- Legal obligation: to keep tax and accounting records and respond to lawful requests.
6. Who we share information with
We share personal information only as needed to run the Services, with:
- Hosting and infrastructure providers, including cloud servers and our managed database provider.
- Email delivery and mailbox connections you set up, to send and receive the emails you write in SeaRM.
- Payment providers such as Stripe and PayPal, to take payments for subscriptions and, when you use them, for your invoices.
- AI providers, only when you or your workspace turn on AI writing or AI briefings, and only the content needed for that request.
- Professional advisers such as accountants, auditors and lawyers.
- Authorities, where the law requires it or to protect the rights, property or safety of our users, the public or us.
- A buyer or successor, if our business or the Services are sold or restructured, under confidentiality obligations.
Our service providers may only use personal information to provide services to us and must protect it.
7. Overseas disclosure and transfers
Two Shores Online's team is based in the Philippines, and our service providers may store or process information in countries including Australia, the United States, Singapore and members of the European Union. When we disclose personal information overseas, we take reasonable steps under APP 8 to make sure it is handled in line with the APPs.
For transfers of personal information from the EEA or the UK to countries without an adequacy decision, we use safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
8. Customer data in SeaRM
When our customers use SeaRM, they store information about their own clients and contacts, such as names, email addresses, phone numbers, emails, call notes, proposals, agreements, signatures and invoices. For this Customer Data:
- Our customer is responsible for having a lawful basis to collect and use it, and for giving their contacts any notices required by law.
- We process it only to provide the Services and as our customer instructs, under our Terms of Service and, on request, a data processing agreement.
- If you are a client or contact of a SeaRM customer and want to access, correct or delete your information, please contact that business directly. If you contact us, we will pass your request on.
9. Email tracking, calls and video
- Email tracking. SeaRM can tell its users when an email they sent is opened or a link in it is clicked, using a small image and redirected links. Customers are responsible for using tracking in line with the laws that apply to them, such as the Spam Act 2003 (Cth), the GDPR and the UK's PECR.
- Calls. Calls placed through a device's phone, Aircall, WhatsApp, Viber or another app are handled by that provider. SeaRM records the call details and notes a user saves, and call logs sent by a connected phone system.
- Video meetings. SeaRM video meetings use WebRTC, so audio and video travel between participants' browsers, or through a relay server when a direct connection is not possible. SeaRM does not record meeting audio or video. Guests who join from a link provide a display name and, optionally, an email address.
- Electronic signatures. To make signatures reliable, we record the signer's name, email, signature image, consent to sign electronically, time, IP address, device details and a fingerprint of the signed document, and include them in the signing certificate.
10. Cookies and browser storage
This website does not use advertising or third-party tracking cookies. It stores two small settings in your browser: your light or dark theme choice (local storage) and whether you have already seen the opening animation during this visit (session storage). Our fonts are served from our own website. The sandbox and the downloadable demo load their fonts from Google Fonts, which receives your IP address when they load.
The SeaRM app uses browser storage to keep you signed in and remember your preferences, and a service worker so it can be installed and send the push notifications you turn on. You can clear browser storage at any time in your browser settings. If we add analytics in future, we will update this policy and ask for consent where the law requires it.
11. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure, including:
- Encryption in transit (HTTPS) and encryption at rest provided by our infrastructure providers.
- Access controls enforced in the database, so each user sees only what their role allows.
- Signed agreements that are locked and fingerprinted so they cannot be changed after signing.
- Limited staff access on a need-to-know basis, and confidentiality obligations for our team.
No system is completely secure. If a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and other regulators and customers as required by law.
12. How long we keep information
- Account and Customer Data: for as long as the workspace is active. After a trial ends without a plan, or after cancellation, it is deleted within 30 days unless the law requires us to keep it longer.
- Signed agreements and their audit trails: for as long as the customer keeps them in their workspace, because their value depends on being unchanged.
- Billing and tax records: for the period required by tax law, generally five to seven years.
- Enquiries and demo requests: for up to two years after our last contact, unless you become a customer.
- Server logs: for a short period needed for security and troubleshooting.
13. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you, and correct it if it is wrong (APPs 12 and 13).
- Ask us to delete it, or to restrict or object to how we use it.
- Receive it in a portable format, or have it sent to another provider.
- Withdraw consent you have given, without affecting earlier processing.
- If you are a California resident: know what we collect and why, delete or correct it, and opt out of its sale or sharing. We do not sell personal information or share it for cross-context behavioural advertising, and we will not discriminate against you for using these rights.
- Deal with us anonymously or using a pseudonym where that is practical, for example for general questions.
To make a request, email janmichael@twoshoresonline.com. We may need to confirm your identity. We respond within 30 days, or sooner where the law requires. Workspace users can also export their data from SeaRM at any time.
14. Marketing messages
We send product news and offers only in line with the Spam Act 2003 (Cth) and other applicable laws. Every marketing email has an unsubscribe link, and you can also email janmichael@twoshoresonline.com to opt out. We will still send service messages about your account.
15. Children
The Services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children.
16. Complaints
If you have a concern about how we handle personal information, please contact us first at janmichael@twoshoresonline.com. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied, you can contact:
- Australia: the Office of the Australian Information Commissioner, www.oaic.gov.au.
- United Kingdom: the Information Commissioner's Office, ico.org.uk.
- European Economic Area: the data protection authority in your country.
- Philippines: the National Privacy Commission, privacy.gov.ph.
17. Changes to this policy
We may update this policy as the Services or the law change. We will post the new version here with a new effective date and, for significant changes, tell customers by email or in the app before they take effect.
18. Contact us
Two Shores Online
Email: janmichael@twoshoresonline.com
Website: http://twoshoresonline.com/
See also our Terms of Service.