SealCycle logoSealCycleBack to login

Privacy

Privacy Policy

Last updated August 22, 2026

SealCycle is operated by Davis Digital LLC. This policy explains what information the application collects, who processes it on our behalf, and what we do and do not do with it. It covers two very different kinds of information: data about you, the contractor who holds the account, and data about your customers, which you enter and which they never gave to us directly.

On this page

  1. 1. Who we are and what this covers
  2. 2. Two categories of data, and who is responsible for each
  3. 3. What the application collects
  4. 4. How we use it
  5. 5. What we do not do
  6. 6. Subprocessors — every third party that touches your data
  7. 7. Early access: sample data and sandboxed sending
  8. 8. How your data is protected
  9. 9. How long we keep data
  10. 10. Your choices, and how to request deletion
  11. 11. Changes to this policy
  12. 12. Contact

Who we are and what this covers

SealCycle is field operations software for asphalt maintenance contractors — estimates, scheduling, invoicing, job costing and customer records. It is operated by Davis Digital LLC, a Maryland limited liability company.

This policy applies to the SealCycle application, the public pages on this site, and the customer-facing links the application generates, such as estimate acceptance pages and invoice payment pages.

SealCycle is business software. It is not directed to children and we do not knowingly collect information from anyone under 18.

Two categories of data, and who is responsible for each

This is the most important section in this policy, which is why it comes first.

Category one — your account data. Information about you and your business: your name, email address, password (stored only as a hash), phone number, business name, business address and coordinates, logo and brand assets, service offerings, pricing and material costs, and your settings. You gave this to us directly by signing up and configuring the app. You can see all of it and you can change or remove it.

Category two — your customers' personal data. When you add a customer, request, estimate or invoice, you enter information about a real third party: their name, business name, street address, geographic coordinates, phone number and email address. You may also upload site photos of their property and store a signature they drew to accept an estimate.

Those people did not sign up for SealCycle. They have no account, no login, and in most cases no idea the software exists. We process that information only because you put it there, and only to provide the service to you.

You are responsible for the information you enter about other people. By entering it, you confirm that you have a legitimate business reason to hold it and the right to provide it to a service provider acting on your behalf. You are responsible for answering your own customers if they ask what you hold about them, for correcting it, and for deleting it when you no longer need it. Nothing in this policy makes Davis Digital LLC the party those people deal with — you are. We act on your instructions with respect to that data and we do not use it for our own purposes.

If you are subject to a privacy law that requires a written data processing agreement with your vendors, tell us and we will put one in place. Early access does not include one by default.

What the application collects

Account and authentication. Email address, password hash and sign-in timestamps, handled by our authentication provider. We never see or store your password in readable form.

Business profile. Business name, owner name, phone, address, the coordinates and time zone derived from that address, logo and other brand assets, service settings, and line item and material pricing.

Records you create. Customers, requests, estimates, scheduled jobs, invoices, payments, job costs and any notes, photos or documents attached to them.

Estimate acceptance evidence. When one of your customers accepts an estimate through a link you sent, we record the name they typed, the signature they drew, the time, their IP address and their browser user agent. That exists so the acceptance stands up as a record. It is stored on the estimate and visible to you.

Technical and security data. Server logs, error reports, and IP addresses used to rate limit public forms and payment links against abuse. We deliberately do not write customer email addresses, phone numbers, street addresses, coordinates, access tokens, public links or payment provider payloads into application logs.

Feedback you send us. If you use the in-app feedback form, we receive your message along with your account email, the page you were on and your browser user agent.

SealCycle does not run advertising trackers, third-party analytics pixels or cross-site profiling of any kind. The only cookies the application sets are the ones required to keep you signed in, plus a browser storage entry that remembers whether you collapsed the sidebar.

How we use it

We use the information above to:

  • operate the features you are using;
  • authenticate you and keep one account's data isolated from every other account's;
  • send the transactional email the application generates — estimates, invoices, receipts, alerts and follow-ups (see the early access section below for where that email actually goes right now);
  • calculate distances, routes, weather risk and time zones for the addresses you have entered;
  • process payments when you send an invoice with a payment link;
  • detect and prevent abuse, fraud and automated attacks on public forms;
  • respond to your support requests and act on the feedback you send us;
  • understand which features are being used during early access so we can fix and improve them.

We do not use your customers' personal data to train models, to build a marketing list, or for anything other than delivering the features you asked for.

What we do not do

  • We do not sell your data, or your customers' data, to anyone, for any price, in any form.
  • We do not use it for advertising — not our own, not anyone else's. There are no ad networks, ad pixels or audience-building tags in SealCycle.
  • We do not share it beyond the subprocessors named below, except where we are legally compelled to, or where it is genuinely necessary to protect someone's safety or our legal rights.
  • We do not use your business data to train machine learning models.
  • We do not sign in to your account to browse your records. Where support genuinely requires it, we will ask you first.

If Davis Digital LLC is ever acquired or merged, your data could transfer to the acquiring entity as part of that transaction. We would tell you before that happened, and this policy would continue to apply until you were given notice of a replacement.

Subprocessors — every third party that touches your data

These are the outside services SealCycle relies on to work, each one listed with what it does and what it can see. This list is complete as of the date at the top of this page.

ProviderPurposeWhat it can see
SupabaseDatabase, authentication and file storageEverything stored in the app: your account, your customers, estimates, invoices, uploaded photos, logos and signatures.
VercelApplication hosting and serverless executionTraffic to the app, request metadata and server logs, plus data in transit as pages and API routes run.
StripeCard payment processing for invoicesInvoice amounts and the paying customer's billing details. Card numbers go directly to Stripe and never reach SealCycle's servers.
ResendTransactional email deliveryRecipient email addresses and the full contents of estimates, invoices, receipts, alerts and follow-ups we send on your behalf.
Google (Maps, Places, Geocoding, Routes, Time Zone)Map display and address autocomplete, converting addresses to coordinates, drive-time and route optimization, and resolving your business time zoneStreet addresses and coordinates for your business, your customers and your job sites. Not names, emails or phone numbers.
TwilioSMS delivery — configured but NOT activeNothing today. Text messaging is switched off across the product and no message has been sent. If it is turned on later, Twilio would receive recipient phone numbers and message contents, and this policy will be updated before that happens.
UpstashRate limiting for public forms and payment linksIP addresses and request counters, held briefly. No record contents.
CloudflareBot protection (Turnstile) on public formsIP address, browser signals and a challenge token for visitors submitting a public form. No record contents.
Open-MeteoWeather forecasts for scheduled workLatitude and longitude of job sites and the dates being checked. No names, addresses or contact details.

Each of these providers has its own privacy terms and its own security posture, and we are relying on them. We will update this list before adding a new provider that can see your data.

These providers are primarily based in the United States, and your data is stored and processed there.

Early access: sample data and sandboxed sending

Your account was seeded with fictional data. Early access accounts are created pre-populated with sample customers, estimates, scheduled jobs and invoices so there is something to look at on the first login. Every one of those records is invented. The customer names are fictional, their email addresses all end in @example.com — a domain permanently reserved by standards policy so it can never reach a real inbox — and the property addresses are real commercial locations used purely so maps, distances and weather show something plausible. No real person's information is in your seeded data, and none of it came from another contractor's account.

You can delete the sample records at any time, and you should once you have your own work in the app.

Email is sandboxed. While early access is on, email that would normally go to one of your customers is redirected to your own address instead. Your customers do not receive estimates, invoices or follow-ups during this period.

Payments are in test mode. Payment links run against the payment provider's test environment. No card is charged and no money moves.

Text messaging is off. No SMS is sent to anyone.

How your data is protected

Every record in SealCycle is tagged with the account that owns it, enforced at the database level, so one account cannot read another's data even if the application has a bug.

Uploaded files fall into two groups. Site photos, customer-submitted request photos and acceptance signatures are held in private storage and served only through short-lived signed links. Your business logo and brand assets are held in a public bucket, because they are embedded in the estimates and invoices you send and have to load for the recipient without a signed link that would expire. Anyone with the URL can view your logo. That is your own branding, not personal data, but it is worth knowing — do not upload anything to Brand Assets that you would not put on a business card.

Customer-facing links, such as estimate acceptance and invoice payment pages, are reachable without a login by design. They are protected by long random tokens stored only as hashes, so the link itself is the credential and we cannot reconstruct it from the database.

Public forms are rate limited and protected against automated abuse. Application logs are written deliberately to exclude personal data, tokens and secrets.

None of this is a guarantee. No internet service can promise it will never be breached, and SealCycle is early software. If we discover a breach affecting your data, we will tell you promptly and tell you what we know.

How long we keep data

While your account is open, we keep the records you create for as long as you keep them. SealCycle does not automatically purge your customers, estimates, invoices or job history — that is your business record, and deciding when it is no longer needed is your call. Delete a record in the app and it is removed from the live database.

When you close your account, we acknowledge your request within 5 business days and delete your account data and the records in it within 60 days. Account deletion is currently carried out by hand rather than by an automated process, which is why the window is 60 days and not shorter.

Some things outlive that. Payment records held by our payment processor, and email delivery logs held by our email provider, are retained under those providers' own policies and legal obligations, and we cannot delete them on request. Encrypted infrastructure backups roll off on their own schedule, generally within 30 days, and deleted data can persist in a backup until that window passes. Aggregate, non-identifying usage counts may be retained.

Early access data. Early access is a testing period. If the program ends and your account is not carried forward, we will give you notice and a window to export your data before it is deleted.

Your choices, and how to request deletion

Access and correction. Everything we hold about your business is visible inside the application and editable there. Settings holds your business profile, and every customer, estimate and invoice record can be opened and changed.

Deleting individual records. Delete a customer, estimate, invoice or uploaded file in the app and it is removed. This is the right route for a single customer who asks you to remove them.

Deleting your whole account. Email privacy@sealcycle.com from the address on the account and ask for deletion. We will acknowledge within 5 business days, give you a chance to export anything you want to keep, and delete the account and its records within 60 days. There is no self-service delete button in the app yet, and deletion is performed manually.

Requests from your customers. If one of your customers contacts us directly asking about their data, we will point them to you, because you are the party that decided to collect it. If you need help acting on such a request, ask us and we will help.

Marketing email. Product and early access update emails include an unsubscribe link. Transactional email about your own account and records cannot be unsubscribed from while the account is open.

Depending on where you or your customers live, additional rights may apply — for example under the California Consumer Privacy Act or the EU and UK General Data Protection Regulation. SealCycle is built for US contractors and we have not certified compliance with any of those regimes. Email us and we will do what the law requires of us.

Changes to this policy

SealCycle is under active development and this policy will change as it does — particularly when a new subprocessor is added or SMS is switched on. The revision date at the top of this page always reflects the current version.

For a change that materially affects how your data or your customers' data is handled, we will email account holders rather than relying on you noticing the date change.

Contact

Privacy questions, deletion requests, data processing agreements and anything else covered here:

privacy@sealcycle.com

Davis Digital LLC, Maryland, United States.

© 2026 SealCycle · Davis Digital LLC

Privacy PolicyTermsAccessibilityContact