sealous
privacy

Privacy Policy

This policy explains what personal data Sealous collects, why we collect it, who we share it with, and the rights you have under the GDPR.

Last updated 31 August 2026

Who we are

Sealous is a marketplace that connects B2B companies with freelance sales development representatives (SDRs) who book qualified sales meetings on a pay-per-meeting basis. Sealous is operated from Lithuania. We do not yet operate through a registered company entity, so this policy refers to the operator simply as "Sealous".

This policy applies to everyone who uses Sealous, whether you sign up as a business or as an SDR.

What data we collect

We collect the information you give us when you create an account and use the service:

  • Business accounts: company name, website, industry, company size, HQ country, company registration number, contact email, and the campaign details you enter (such as your target market, brief, and the bounty you offer per meeting).
  • Business enquiries: when you ask to book a call, we collect your first and last name, work email, company website, job title, how you heard about us, a description of your business and ideal customer profile, and your answers about deal size, cost per opportunity, sales team size, and meetings wanted per month.
  • SDR (caller) applicants and accounts: first and last name, email, phone number, years of B2B sales experience, the industries you have sold into, LinkedIn URL, how you heard about us, whether you have registered individual activity (individuali veikla), and the CV you upload with your application.
  • Meeting and prospect data: when an SDR books a meeting, they enter details about that meeting and the prospect (such as company and contact name) so the business can review it.
  • Account and technical data: your hashed password once you set one (we never see or store your password in plain text) and the basic session information needed to keep you signed in. SDR applicants do not set a password until their account is approved.

How we use your data

We use your data to:

  • create and operate your account, and confirm your email address;
  • run the marketplace: match businesses with SDRs, run campaigns, and let businesses review applicants and meetings;
  • send transactional email such as confirmations, approvals, meeting updates, and payout notifications;
  • review and approve accounts, including reviewing SDR applications and the CVs submitted with them, and prevent fraud and abuse;
  • operate, secure, and improve the service.

We do not sell your personal data, and we do not use it for third-party advertising.

Legal basis (GDPR)

For users in the EU, we process personal data on the following bases:

  • performance of a contract, to run your account and the marketplace;
  • taking steps prior to entering into a contract at your request, for example when we review the application and CV you submit to become a caller, or when you send a business enquiry and book an intro call;
  • our legitimate interests, such as vetting accounts, preventing fraud, and improving the service;
  • our legitimate interest in keeping the service working and understanding how it is used, which is why we run error tracking and cookieless web analytics;
  • legal obligations, where they apply.

Where we rely on consent, you can withdraw it at any time by contacting us.

Who we share it with

We share data with a small set of providers who process it on our behalf to run the service:

  • Supabase - database, authentication, and file storage, including CV files. Hosted in the EU.
  • Resend - sending transactional email.
  • Vercel - application hosting and cookieless web analytics. The analytics receive page views and basic device and browser information.
  • Sentry - error tracking, so we can find and fix faults in the service. Sentry receives technical error data; events are ingested in the EU (Germany), though Sentry is a US-based company.
  • Cal.com - scheduling for our intro calls. When you book a call, Cal.com receives your name, your email, and the time you pick. Cal.com, Inc. is a US-based company and its service is hosted in the United States.

These providers process your data only to provide their service to us. We may also disclose data where we are required to by law. We do not currently collect payment card data; if we add payment processing in the future, it will be handled by a third-party payment processor and described here.

Data retention

We keep your account data for as long as your account is active. CV files are used only for reviewing your application and are kept while your SDR account is active; CV files from applications that are not approved are deleted twelve months after the application, unless the applicant asks us to delete them sooner. Audition voice recordings are no longer collected; a small number collected under an earlier version of signup remain in private storage and will be deleted before public launch. If you ask us to delete your account, we remove your personal data, unless we are required to keep some of it to meet a legal obligation or to resolve a dispute.

Security

Passwords are stored hashed by our authentication provider (Supabase); we never store them in plain text. Core data is hosted in the EU. CV files are kept in a private storage bucket that is not publicly accessible; they can be opened only by Sealous through short-lived signed links, for the purpose of reviewing your application. Access to personal data is limited to what is needed to run the service. Business accounts require email confirmation to activate; SDR applicants do not set a password or confirm an email until their application is approved.

Your rights

Under the GDPR you can request access to your data, correction of inaccurate data, deletion of your data, and a copy of the data you gave us. You can also object to or ask us to restrict certain processing.

To exercise any of these rights, email contact@sealous.com and we will respond. You also have the right to lodge a complaint with your local data protection authority.

Cookies

We use only essential cookies needed to sign you in and keep your session active. We do not use third-party advertising cookies or cross-site tracking.

International transfers

Our core data (database, authentication, and storage) is hosted in the EU, and our error-tracking events are ingested in the EU (Germany). Some of our providers, such as our email, hosting, error-tracking, and scheduling providers, are US-based companies and may process limited data outside the EU. Where that happens, we rely on appropriate safeguards, such as the European Commission's standard contractual clauses.

Changes to this policy

We may update this policy from time to time. When we make a material change, we will update the date at the top of this page. Continuing to use Sealous after a change takes effect means you accept the updated policy.

Contact

For any question about this policy or your data, email contact@sealous.com.