Coast DynamixMarine Engineering

Legal

Privacy policy

How Coast Dynamix collects, uses, and protects information submitted through our website, project intake, customer portal, and payment process.

Use your browser print dialog to retain a copy of this Privacy Policy.

Effective: 2026-09-03 · Last updated: September 3, 2026

Version: privacy-2026-09-03-v2 · https://www.coastdynamix.com/privacy

1. Business identity and contact

Coast Dynamix ("we," "us") operates https://www.coastdynamix.com and provides marine reverse engineering, CAD, and manufacturing support from Fort Lauderdale, Florida. Contact: hello@coastdynamix.com. Based in Fort Lauderdale, Florida. We take reverse-engineering jobs from anywhere in the continental U.S. — send photos, measurements, or the part itself. Finished replacements ship back when fabrication is in scope. We travel for larger jobs when it makes sense. International and vessel-down work — including the Bahamas — is evaluated case by case.

2. Categories of personal information collected

Depending on how you interact with us, we may collect: contact information (name, email, phone, company); vessel and project details (boat name, manufacturer, model, location, component descriptions, notes); customer-provided technical data; files you upload (photographs, drawings, CAD models, STEP files, PDFs, and related technical documents); quote and payment records; messages sent through the customer portal; CRM customer records created by our team (including phone-only leads); and technical data such as browser type, device information, IP address, and security/authentication logs.

3. Customer, vessel, project, CAD, photograph, message, quote, and payment information

Project intake and portal use may include vessel identity, project need, dimensions notes, CAD and photograph uploads, quotes, deposit/payment status, and portal messages. Upload only materials needed for engineering review. Do not submit unrelated sensitive personal information. Project information and vessel identities are treated as confidential. NDAs can be accommodated upon request.

4. CRM customer records and stable identifiers

Our team may create standalone customer records in an internal CRM. A customer can exist without a project or portal login. Each customer has a stable internal ID that remains the same if contact details are edited later. Customers may be linked to projects after intake or by an administrator. Creating a CRM customer does not automatically create a portal account or send an invitation.

5. Information collected from portal users

The customer portal uses email magic links for authentication. Portal access may follow a project submission or an administrator invitation. When you sign in, we associate your email with projects you have submitted or been invited to view. Portal messages, quote responses, and Terms-acceptance records (including Terms version and consent text) are stored so we can coordinate work and retain evidence of agreement.

6. Administrator authentication

Administrator access uses individual email/password accounts with optional time-based multi-factor authentication (MFA), plus a rate-limited emergency break-glass password when configured. Admin session cookies are HttpOnly, use SameSite protections, and are marked Secure in production. Authentication and certain security actions are audited without storing password or MFA secrets in those audit records.

7. Server logs, IP addresses, device/browser information, and security logs

Our hosting provider and application may record IP addresses, request metadata, user-agent strings, and authentication-related events to operate, secure, and troubleshoot the service. Quote acceptance may store IP address and user-agent when operationally appropriate for consent evidence.

8. Cookies and analytics

We use cookies or similar technologies for essential sessions (customer portal authentication and admin sessions). If Google Analytics 4 is configured via a measurement ID, we may collect aggregated, non-PII usage events (for example page or conversion events) with IP anonymization enabled in our configuration. We do not intentionally send names, emails, phones, vessel names, descriptions, or filenames to analytics. If analytics is not configured, those scripts are not loaded.

9. Purpose for each category

We use submitted information to review project requests, prepare quotes, perform engineering work, communicate about active projects, deliver files and parts, process payments, maintain project and accounting records, enforce Terms acceptance evidence, improve how we respond to common marine component problems, and secure the service. We do not sell your personal information.

10. Service providers

We use providers to operate the site and deliver services, including: hosting and application platform (Vercel); database (Prisma Postgres / configured PostgreSQL); object storage (Vercel Blob); email delivery (Resend); payment processing (Stripe); optional website analytics (Google Analytics when configured); and optional AI assistance for internal vessel lookup or quote-term drafting (OpenAI when an API key is configured). These providers process data to run the website, store project files, send notifications, measure site performance, process transactions, and support internal engineering tools.

11. Stripe payment processing

Deposits and card payments are processed through Stripe. We receive payment status, amounts, and limited card or billing details provided by Stripe (such as card brand and last four digits) — not your full card number. Stripe handles payment data according to its own privacy policy. Manual/offline payments recorded by our team store method and reference metadata without card PANs.

12. Email provider

Transactional project, quote, and portal emails are sent through Resend when configured. Email content may include project references and authorized links; large files are not sent as attachments.

13. Hosting, database, and object storage

Application hosting runs on Vercel. Structured records are stored in PostgreSQL via Prisma. Project files and deliverables are stored with Vercel Blob (private storage) and associated with your project record.

14. AI vessel lookup and related processing

When enabled for internal admin use, vessel or project text may be sent to OpenAI to assist with public-registry style vessel context or draft quote language. AI vessel data is unverified. Confirm the information and its sources before using it in quotes, drawings, engineering decisions, or customer communications. AI results must never update billing automatically. Results may be stored on the project record for operator review.

15. File access controls

Access to admin tools and sensitive file links is restricted to authorized personnel. Signed or authenticated links may be used for sensitive file access. Customer portal users see only customer-visible files for their projects.

16. Internal versus customer-visible files

Some files and notes are internal-only (for example vendor contacts, internal notes, and certain admin uploads) and are not shown in the customer portal. Customer-visible deliverables are intentionally marked for portal access.

17. Public-project approval

Projects are not listed publicly by default. Public case studies or project listings require explicit admin approval after a project is shipped or closed, using curated public title/summary fields. Approval is never preselected.

18. No automatic public publication

Submitting a project, accepting a quote, or paying a deposit does not authorize public advertising of your project. Separate explicit publicity approval is required. Internal notes, quotes, pricing, vendor information, messages, payment data, and unapproved vessel identities are not published.

19. Data retention by category

We retain project, contact, quote, payment, message, and file metadata for as long as needed to complete active work, maintain business records, support warranty or engineering history, resolve disputes, and comply with legal obligations. We do not claim automatic deletion on a fixed calendar schedule for all categories.

20. Accounting, warranty, engineering-history, dispute, and legal retention

Certain records (including payment metadata, accepted quotes, Terms consent evidence, and engineering deliverables) may be retained longer when needed for accounting, warranty, engineering history, chargeback/dispute handling, or legal compliance.

21. Deletion, correction, and access requests

You may request access, correction, or deletion of information that is no longer required for an active project by contacting hello@coastdynamix.com. We will respond within a reasonable time. Deletion is subject to our need to retain records for accounting, warranty, engineering history, disputes, or legal purposes.

22. Identity verification for requests

Before fulfilling access or deletion requests, we may verify your identity using the email or other contact details associated with the project or portal account.

23. Circumstances where deletion cannot be completed

We may decline or limit deletion when records are required for an active project, unpaid balances, disputes, chargebacks, warranty, tax/accounting, or other legal obligations.

24. Security safeguards

We use reasonable technical and organizational measures to protect information, including encrypted connections (HTTPS), access controls on admin systems, MFA options for admin users, and signed or authenticated links for sensitive file access. We do not claim absolute security, military-grade protection, or formal information-security certification. No method of transmission or storage is completely secure.

25. Data-breach response

If we become aware of a security incident involving personal information, we will assess the situation and take appropriate containment and notification steps as required by applicable law, including review with counsel regarding Florida breach-notification obligations where applicable. Our internal incident playbook is not a public document.

26. International data processing

Providers may process data in the United States or other locations where they operate. International projects are evaluated individually; cross-border transfers may occur through our hosting, email, payment, storage, or AI providers.

27. Children’s privacy

Our services are directed to marine businesses and adult vessel owners/operators. We do not knowingly collect personal information from children under 13. If you believe a child has submitted information, contact hello@coastdynamix.com.

28. No sale of personal information

We do not sell personal information. We do not share personal information for cross-context behavioral advertising as that term is commonly used; if our analytics or advertising practices change, we will update this policy.

29. Targeted advertising or sharing disclosures

If Google Analytics is configured, aggregated site-usage measurement may occur as described above. We do not operate a separate targeted-advertising network on customer project data.

30. Policy changes

We may update this policy from time to time. The effective/updated date and version identifier on this page will change when we do. Material changes will be reflected on this page; continued use of the site after changes means you should review the updated policy.

31. Effective date

This policy version privacy-2026-09-03-v2 is effective 2026-09-03 (last updated September 3, 2026).

32. Contact procedure

Questions about this policy or your information: hello@coastdynamix.com. For project-related transactional email preferences, contact us — we may still need to send messages about active quotes or work in progress.