What the app records, what leaves your device and what does not, who else sees anything, and how long it is kept. As at 30 September 2026.
Who we are. EverStamp is a service of Digital Sandbox B.V., Waalstraat 2, 8052 AE Hattem, the Netherlands. For questions about your data: privacy@everstamp.app.
What we have of you. Your photos stay on your phone. For each file we receive fingerprints, numbers from which no image can be made again, an identifier of your device, and the declaration of Apple or Google about that device. Photos reach us in three cases only, and then encrypted: a share link you make yourself, a delivery at the request of an organisation, and storage at EverStamp if your organisation has switched that on. If your phone belongs to an organisation, or you answer a request of an organisation, our registry also keeps the name of the file, the checklist and the filled-in fields, for that organisation. If you take Plus, we keep track of your credit with a fingerprint of your subscription. If you sign in to the dashboard, we have your email address, your name and your sessions. With every request your IP address and your browser are in our access logs, for at most thirty days.
What for, and on what basis. To provide the service you use: performance of the agreement. For the location on your photos: your consent, which you withdraw in the settings of your phone. For security, the public log, counts that hold no person, and the page an organisation started its trial from: our legitimate interest. For invoices: a legal obligation. What we keep for an organisation, we process as its processor.
Who else sees anything. The suppliers that run our servers and our email, and the services with a role of their own: the time-stamping service, which receives a fingerprint only; Apple and Google, for the check of the device and for the address that goes with a position, for which they receive a coordinate; and for Business the payment provider. The list is below, in the full statement.
Outside the European Union. Most of it stays in the European Union. Some suppliers are American; most of them work under the EU-US Data Privacy Framework, and where that is not so or falls away, the European Commission’s standard contractual clauses apply. You get a copy of those safeguards through privacy@everstamp.app.
How long. Your files are on your phone until you delete them. We keep the public log without a time limit, without names. What we keep for an organisation stays as long as its agreement runs; after that it has thirty days to collect everything, and then it goes, except what the law requires us to keep, such as invoices. The retention per kind of data is in the full statement.
No automated decisions. We take no decisions about you that rest on automated processing alone, and we make no profiles.
Age. The app is for anyone aged 16 or over. Anyone who supplies photos for an organisation as a guest declares to be 18 or older or to act on behalf of the insured person or the tenant.
Your rights. You can ask for access, rectification, erasure, restriction and portability, and you can object. Mail privacy@everstamp.app; you have an answer within a month. If it concerns data we process for an organisation, we forward your request to that organisation. The entries in the public log cannot be erased without breaking the check of files others already hold. You can lodge a complaint with your national supervisory authority; in the Netherlands that is the Autoriteit Persoonsgegevens.
More. The full statement below says per kind of data what we receive, from whom, what for and how long.
EverStamp is built so that the evidence is created on your device and anyone can check it. That is a design decision with a privacy consequence: we do not need your photos, so we do not take them.
What we receive per file is a fingerprint: numbers computed from your photos that cannot be turned back into an image. If your phone is linked to an organisation, or you answer an organisation’s request, the registry also keeps the name of the file, the checklist and the field values, for that organisation. Photos, notes, addresses and positions stay on the phone unless one of three things happens, and the next section names all three. Two of them are your own decision. The third is a setting your employer can switch on, and that is the one worth reading.
A share link is encrypted with a key that lives in the link itself, after the #, which a browser never sends to a server. We hold bytes we cannot read. That is the ordinary case and it covers everything you share yourself.
Two cases work differently, and in both of them we hold the key. One is a delivery answering a company’s request. The other is storage at EverStamp, which an owner or administrator can switch on for a whole organisation. In both, the company has to be able to open the files, so our registry keeps the key for them, encrypted in its vault.
So for those files, EverStamp can open the archive. We say it plainly because it is true and because you would find it out anyway. The registry hands the key to the dashboard only when an owner or administrator of that organisation asks for it, or when an API key of that organisation requests it. Every opening through the dashboard or the API is written to that organisation’s audit log, with who or which API key, and when. Field workers and readers cannot open them. Because we manage the key, someone at EverStamp with access to the servers can technically also open such an archive outside the dashboard, and then without a line in that log. We do so only at the organisation’s written request, or if a competent court or authority obliges us to by an order or demand based on the law. We review such an order or demand, we provide no more than is demanded, and we tell the organisation in advance or as soon as that is allowed, unless the law forbids that notice.
The switch is off unless your organisation turns it on, it is theirs to set rather than yours, and it applies to every file a member records from that moment. If you are recording for an employer, that is worth knowing before you start: ask them whether it is on.
Short list, and each one gets the least we can give it.
| Who | What they receive | Why |
|---|---|---|
| SK ID Solutions AS (Estonia) | A hash, sent by our server. Nothing from you: not your IP address, not a photo, not a name. | The qualified timestamp over your file and over the report, and over each photo where a timestamp per photo applies. They see a number, never an image. Files stamped before 14 September 2026 carry a timestamp from BOSA, the Belgian federal government’s service; the verification page checks those the same way. |
| The drand relays | A request, and therefore your IP address | The public random value that fixes the lower edge of the window. |
| Apple (on iPhone) | A coordinate for the address suggestion, and the App Attest attestation. Never an image, an address or a name. | Turning a position into a street name, and establishing that the device is genuine. |
| Google (on Android) | A coordinate for the address suggestion; a Play Integrity request when the phone is registered and again for each file; usage statistics from ML Kit (device and app information, performance and which features were used, under a per-installation identifier). Never an image, the recognised text, an address or a name. | Turning a position into a street name, and the on-device text recognition that proposes a number plate or meter reading. Through Play Integrity, Google answers whether the app is the one distributed by Play and whether the phone passes its integrity checks; that request carries a one-time value and nothing else. Our registry keeps Google’s verdict alongside the device: nothing is refused because of it, and it appears neither in your file nor on the verification page. The key attestation itself goes to our registry, not to Google. |
| Google (signing in to the dashboard, if you choose it) | That you sign in to EverStamp with your Google account. In return we receive only your Google account ID, your email address, your name and the address of your profile photo (the scopes openid, email and profile). | Signing in to the dashboard without a password. Google processes your Google account as a controller in its own right, under its own terms. Signing in with a link by email remains possible. |
| Microsoft (signing in to the dashboard, if you choose it) | That you sign in to EverStamp with your Microsoft account, personal or from work or school. In return we receive your Microsoft account ID, your email address and whether it is verified, and your name if Microsoft sends it (the scopes openid and email). We do not call Microsoft Graph and read nothing else from your account. | Signing in to the dashboard without a password. Microsoft processes your Microsoft account under its own terms, as a controller in its own right; for a work or school account, so does the organisation that manages it. Signing in with a link by email remains possible. |
| Resend | Email addresses, and what each email is about: the sign-in emails of the dashboard (a sign-in link valid for 15 minutes, a setting of our Supabase project; a confirmation when you sign up, a recovery email, a confirmation code, and a notice of a new email address, sent to the old one); invitations to members, with the name of the organisation and the link (if the button no longer works, signing in with that address still works, and the invitation stays); requests to guests, with the name of the organisation, the title, the end date, the note if there is one, and the link; to the owners of an organisation, a confirmation of each payment and each credit note with the invoice or credit note attached as a PDF, a notice after a failed direct debit, once a reminder 30 days before a discount or free period ends, a notice when 80 and when 100 percent of the bundle has been used, with the usage and the bundle, the announcement of a material change to the terms, with the date it takes effect and the text as a PDF, and a notice when the trial ends without a bundle and a week before we then delete the data; to the organisation’s mailbox for invoices, if the owner set one, only the invoice or credit note as a PDF, in a plain email without a link to the dashboard; for a support question from the dashboard, the question and each reply to support@everstamp.app, and a confirmation and each answer to the person who asked; to a member whose second step was reset, a notice with a link to sign in again; product news, only to members who switched it on in My account: the email address, the subject, the text in the language of the account and an unsubscribe link with a personal code, also in the headers of the email; and the details you enter when you request a quote or use the contact form on the site | Delivering those emails, and delivering your quote request or message to our inbox, info@everstamp.app. We use a quote request or message only to answer you. |
| Google Workspace (our mailboxes) | Emails to our addresses at everstamp.app, such as info@, privacy@, security@ and support@, including quote requests, messages from the contact form and the support questions and replies that reach support@ | Our email. Google processes it for us under its Cloud Data Processing Addendum. We keep these emails for as long as needed to handle and follow up the question or quote, unless a legal retention obligation requires longer. |
| Vercel Web Analytics (this site and the dashboard) | For each page view: the address of the page, without search terms and without the name of the organisation; the page you came from; your country, region and city; operating system, browser and device type; and the time. No cookies: a visitor is recognised by a hash of the request, which is discarded after 24 hours, and nothing is tied to your IP address. | Counting which pages are read, in totals. Not in the app, and not on the verification page. |
| Sentry (Functional Software, Inc.) | When something goes wrong in the dashboard, on our server or in your browser: a technical error report with the kind of error, the message and the stack trace, the route as a pattern (such as /o/[org]/…), the environment and the version. It goes through our server; your browser never talks to Sentry directly. We never send headers, cookies, the IP address of the visitor or who is signed in. We first remove email addresses, account numbers, phone numbers, tokens, identifiers (ours and those of Mollie), invoice numbers and the name of the organisation in an address. An error report can exceptionally contain a piece of text someone entered, such as a name. | Finding and fixing errors in the dashboard. Not in the app, not in the registry and not on this site. |
| Apple App Store, Google Play | Your purchase, if you take Plus | They handle the payment. We never see a card. |
| Mollie B.V. (Amsterdam) | For an organisation on Business: its name and email address (from the company details, otherwise an owner’s), the amount, a description such as “EverStamp Business M, October 2026” and the organisation’s number. The payer enters bank or card details at Mollie; we do not keep them. | Handling the payments of Business: iDEAL, card and SEPA direct debit, as a controller in its own right. |
| VIES (European Commission) | For an organisation in another EU country: its VAT number and country, with our own VAT number as the requester | Checking the VAT number, which the VAT rules require before we charge a business in another EU country without Dutch VAT. We keep the last check with the organisation: valid or not, the country and number, the name and address as VIES gives them, the date and the consultation number. For a sole trader, that name can be personal data. |
The companies that run our own servers are listed by name, with what they do and where they sit, on the security page. That list is part of this statement.
| What for | Basis (Article 6(1) GDPR) |
|---|---|
| Registering your device, recording and sealing your files, the public log, share links and the verification page | Performance of the contract (b): the service you use under our terms |
| Plus, your credit and your purchases of extra files | Performance of the contract (b) |
| Location, for the address on the stamp bar and the position in the file | Your consent (a), which you give with the location permission and withdraw in your phone settings |
| Security and preventing abuse: the access logs, the system journal and the verdict of Play Integrity | Our legitimate interest (f) in a secure service. We do this as a controller in our own right, also where an IP address of a member or a guest of an organisation is in it, and not on its instruction (terms, article 10.1) |
| Backups | Our legitimate interest (f) in a service that can be restored after a failure, for our own data. For the part with data of an organisation we are its processor |
| Error reports of the dashboard | Our legitimate interest (f) in a service that works: finding and fixing errors |
| Your sign-in account for the dashboard: email address, sign-in method, sessions, last sign-in and second step | Performance of the agreement (b): without an account and a session you cannot sign in |
| Keeping the public log indefinitely | Our legitimate interest (f), and that of everyone who relies on a file, in files that stay checkable |
| Payments of Business, invoices and the VIES check | Performance of the contract (b) for the payment; a legal obligation (c) for the invoices, the VIES check and keeping them for seven years |
| Page statistics of this site and the dashboard (Vercel Web Analytics) | Our legitimate interest (f) in knowing which pages are read, without cookies and without recognising you after a day |
| Counting from the access logs how often the verification page and the share link page are opened, and how often someone clicks through to the site | Our legitimate interest (f) in knowing whether the verification page works as a channel; only numbers are kept |
| When an organisation signs up: the page its trial started from | Our legitimate interest (f) in knowing which pages work, without a cookie and without an IP address |
| The management log of the dashboard: what EverStamp’s administrator did, and why a payment attempt failed | Our legitimate interest (f) in a reliable service and in being able to account for what we did |
| Signing in to the dashboard, also with Google or Microsoft | Performance of the contract (b) |
| News in the dashboard, and keeping track of what you have read | Performance of the contract (b) |
| Product news by email | Your consent (a), which you give in My account and withdraw with the unsubscribe link in each email, with one click in your email program, or in My account |
| Answering support questions from the dashboard | Performance of the contract (b) |
| Answering a quote request, a message from the contact form or an email | Steps at your request before a contract (b), or our legitimate interest (f) in answering you |
| Deliveries, files kept at EverStamp, and the data of members and guests of an organisation | We process these for the organisation, as its processor; the organisation determines the basis |
Where the data goes. Most of what we hold stays in the European Union: the registry at Hetzner in Germany, the dashboard database at Supabase in the EU, the encrypted archives at Cloudflare R2 under EU jurisdiction, and the signing key at Amazon Web Services in Frankfurt. Vercel (the website, the dashboard and their page statistics) and Resend (email, which it stores in the United States) are American companies and may process data in the United States; they do so under the EU-US Data Privacy Framework and standard contractual clauses. Cloudflare and Amazon Web Services rely on the same two for anything they process outside the EU, and Supabase on standard contractual clauses for any access from outside the EU. Sentry keeps the error reports of the dashboard in its EU region in Frankfurt; its agreement allows processing in the United States and other countries, under the Data Privacy Framework and standard contractual clauses. Google Workspace may store our email outside the EU, under the Data Privacy Framework and standard contractual clauses. You get a copy of the safeguards for these transfers through privacy@everstamp.app. Where a supplier in this paragraph relies on the Data Privacy Framework, the European Commission’s standard contractual clauses apply as a fallback, in case the Data Privacy Framework falls away.
Apple and Google (also for the check that the device is genuine), Microsoft, Mollie, the European Commission (VIES) and the timestamp service SK ID Solutions process what they receive as controllers in their own right, under their own terms; they are not our processors. Apple does so on standard contractual clauses, Google and Microsoft on the Data Privacy Framework and standard contractual clauses, Mollie on standard contractual clauses for anything it processes outside the EEA, SK ID Solutions in Estonia and the European Commission, both within the EU.
The app asks drand.cloudflare.com for the public random value, and a server in Frankfurt (api2.drand.sh) if Cloudflare does not answer. Both are public services that anyone can use; their operator sees your IP address, and we have no agreement with them about it. Cloudflare answers from a nearby data centre and is certified under the EU-US Data Privacy Framework.
Location is used for two things: the address on the stamp bar, and the position recorded inside the file. It is read only while the app is open and you are taking photos. There is no background location. If you deny the location permission, or withdraw it later in your phone settings, the app carries on working and the photos simply carry no position.
| Your files | On your phone, until you delete them. We cannot delete them for you and we cannot recover them for you. |
| The public log | The fingerprints are kept indefinitely, with a device value per file that differs per file; entries from before 29 September 2026 carry the fixed device identifier. They are the basis on which anyone can still check a file years from now, and removing an entry would break that for everyone. |
| Share links | Until the link expires or you withdraw it. By default 7 days on Basis and 30 days on Plus, Business and Enterprise; at most 7 days on Basis, 90 on Plus and 365 on Business and Enterprise. |
| Deliveries and files kept at EverStamp | For as long as the organisation’s subscription runs, or shorter if the organisation sets a shorter term itself. When the subscription ends the organisation has thirty days to collect everything, and after that the file is deleted and the key is destroyed with it. An owner or administrator can withdraw one at any time, and everything goes when the organisation is dissolved. Backups follow the terms under Backups below. |
| Dashboard data | For as long as the organisation exists. If a trial ends without the organisation taking a bundle, the agreement ends and the organisation has thirty days to take a bundle after all or export everything; after that we erase the data in the same way as on dissolution. On dissolution it is erased or stripped of names and contact details: requests, invitations and share links keep only empty rows, without names, and the sign-in accounts of former members who accepted the invitation themselves and belong to no other organisation are removed. Phone links are revoked rather than erased, so that a member sees once that the phone was unlinked by the organisation; the organisation’s name therefore stays in that revoked link for another fourteen days, and only that device sees it. Payments, invoices and support questions are the exceptions; see below. |
| The page a trial started from | When you sign up, we keep with the organisation which page you came from, for example the pricing page, or the verification page with the kind of file. It is a short key, with the bundle of the trial and the time; not an IP address and not a cookie. Only EverStamp’s administrator sees it, to count per page how many sign-ups, trials and paying organisations came; members of the organisation do not see it. It is kept for as long as the organisation exists, and removed on dissolution. Backups follow the terms under Backups below. |
| Guests | Contact details that the organisation entered: erased 30 days after the request is completed, expires or is withdrawn. The name of a guest, as the organisation entered it or as the guest typed it, stays with the request and the file until the organisation is dissolved. Webhook messages carry that name but no contact details; webhook deliveries are removed after 30 days. |
| Members of an organisation | Name and email address, in the dashboard for as long as the member exists. After a member is removed, the organisation’s audit log keeps a line with the name and email address, and the registry keeps the name with the invitation and the device link, both until the organisation is dissolved. Owners and administrators see when each member last signed in. An owner can sign a member out everywhere; because sessions belong to the account, that also applies at other organisations, and it is recorded in the organisation’s audit log. Every member sees their own sign-in sessions: the device as the browser reports it, the IP address and when the session was last active, and can end them; nobody sees another person’s sessions. Supabase keeps this for each session until it ends: when you sign out, end it yourself, or an owner or EverStamp signs you out or resets your second step, and at the latest after 8 hours without activity or after 7 days. Those terms are settings of our Supabase project, and after a session ends the access token works for at most a quarter of an hour. An owner can reset the second step of a member (remove their authenticator apps and sign them out everywhere), but only if that account is not an active member of another organisation where the owner is not also an owner; that is recorded in the organisation’s audit log and the member gets an email. Someone who has lost everything can ask EverStamp for a reset, after an identity check: an email from the account’s address and a call back on a number we already knew, in person or by video call with identification, or confirmation by another owner of the same organisation. The management log then keeps the account, the reason and the check, the audit log of each of that account’s organisations records the reset by EverStamp, and the member gets an email. If you sign in with Google, Supabase also keeps your Google account ID and what Google sends (email address, name and the address of your profile photo), for as long as your account exists. If you sign in with Microsoft, Supabase keeps your Microsoft account ID and what Microsoft sends (email address, whether it is verified, and your name if it is sent), also for as long as your account exists; an invitation is only linked to an address Microsoft has verified. We use these details only to sign you in and your name as a suggestion for your name when you create an organisation; we do not use the photo, and not the details for anything else. |
| Payments and invoices of an organisation | Every payment gets an invoice, already marked as paid. We keep payments and invoices until seven years after the end of the year in which the invoice was made (the statutory retention period for tax records), also after the organisation is dissolved; after dissolution only EverStamp can read them. A credit note keeps the invoice it refers to until its own term has passed. An invoice holds the name of the organisation (or a different name with a separate billing address), its billing address (a separate one if the owner set it, otherwise the company address), its country and VAT number, its own reference such as a PO number if the owner set one, the lines, the amounts and Mollie’s payment reference, and the VIES check if VAT is reverse charged. An issued invoice never changes: the name, address, reference and VAT number of the moment it was issued stay on it, also on a later credit note. Only the owner sets the billing address, the reference and a mailbox for invoices; a change is recorded in the organisation’s audit log, with the old and the new value. In the dashboard, only owners and administrators see them. If EverStamp gives an organisation a discount, it appears as its own line on the invoice, such as ‘Discount 50%’. The percentage, the end date if there is one, when the discount was set and which EverStamp administrator set it are kept with the organisation in the dashboard database until EverStamp removes the discount or the organisation is dissolved; in the dashboard, only owners and administrators see the percentage and the end date. The reason is in the management log. On dissolution we withdraw the direct debit mandate at Mollie and remove, on our side, the references to the customer and the mandate at Mollie and the last VIES check; Mollie keeps its own records under its own terms. |
| Support questions | The name and email address from the account, the organisation, the subject, the messages, the language and the times, in the dashboard database. Two years after a question was closed, the daily job deletes it with its messages. When the organisation is dissolved, a question stays without the link to the organisation. The emails about it also sit in our mailbox at Google: for as long as needed to handle and follow up the question, unless a legal retention obligation requires longer. |
| Management log | Each action of EverStamp’s administrator in the dashboard, and each failed payment attempt: the time, the account that acted, the action, what it concerns (an organisation, an account, a support question, an invoice or a quarter) and details, such as the error message of a failed payment, the number of a credit note with the reason typed for it, the reason and the identity check of a reset of the second step, or the reason for a discount, with the percentage and end date before and after. Free text in a reason or an error message can exceptionally contain a name. Only EverStamp’s administrator can see it. The daily job deletes entries older than 12 months. |
| News and product news | What you have read under News: your account, the message and the time you read it. Your choice for product news by email: your account, on or off, the unsubscribe code and when you last changed it; no email address. Product news is off unless you switch it on, and an unsubscribe stays until you switch it on again yourself. For each message we only record when it was mailed and to how many people. All of this for as long as your account exists; when the account is deleted, your choice and what you have read go with it. |
| File details for an organisation | The name of the file, the checklist and the field values: for as long as the organisation exists. On dissolution they are erased; the line with the fingerprints and the sequence number stays, without a name. |
| Your Plus subscription | The fingerprint, your monthly usage and your extra files. We keep purchased credit for as long as you have any, also after your subscription ends; without credit we remove the link 60 days after the subscription ends. |
| Backups | Of the registry, every copy, on the server itself and encrypted (age) at Cloudflare R2 and the Hetzner Storage Box, disappears no later than 17 days after it was made; the backup script checks that limit itself, counting the copies of the whole server at Hetzner. Supabase makes the backups of the dashboard database, under the setting of our plan there (now 7 days). |
| Access logs and system journal of the servers | 30 days. For each request the access logs hold, among other things, the IP address, the browser and the time. From the access logs we count per day how often the verification page and the share link page were opened, by which route (QR, PDF or link) and by how many different visitors, and how often someone clicked through to the site. We tell different visitors apart by IP address and browser, only while counting. We keep only the numbers, without IP address, browser, file or share link. We keep those numbers without a time limit, because they say nothing about a person. |
| Page statistics | Vercel keeps them under the setting of our plan there (now 12 months), and may keep them longer. The hash that recognises a visitor is discarded after 24 hours. |
| Cookies and browser storage in the dashboard | Only on dashboard.everstamp.app, only functional, set by the dashboard itself, never for tracking: lang (the language you chose, one year), tz (the time zone of your browser, so that times show correctly, one year), nav (whether the menu is open or collapsed, one year) and the sign-in cookies of Supabase (sb-…-auth-token, your session, which ends when you sign out, after 8 hours without activity and after 7 days at most, under the settings of our Supabase project; the cookie itself stays at most 400 days; while you sign in also a …-code-verifier for the sign-in link). In your browser, not as a cookie, the sign-in page also keeps the email address you last used (localStorage), only to fill it in again when a link has expired; it goes nowhere and stays on that device until you clear it. Vercel Web Analytics sets no cookie. This website, everstamp.app, sets no cookies at all. |
| Error reports of the dashboard | At Sentry, under the setting of our plan there (now 30 days). |
Under the GDPR you can ask for access to your data, correction, erasure, restriction and portability, and you can object to processing. Write to privacy@everstamp.app. About your own account and the app without an organisation you will have an answer from us within a month. If it concerns data we process for an organisation, such as a delivery at its request or a file it keeps with us, we forward your request to that organisation, which answers it, and we let you know that we did.
Two honest limits. We hold almost nothing about you, so an access request will usually return a device identifier and a list of hashes. And the entries in the public log cannot be erased without breaking the checkability of files that other people already hold; if that affects you, write to us and we will explain what can and cannot be done in your case.
We take no decisions about you that rest on automated processing alone, and we make no profiles.
The app is for anyone aged 16 or over. We ask for location on the basis of your consent; anyone younger than 16 cannot give that consent themselves.
You can also complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
| Controller | Digital Sandbox B.V. Waalstraat 2 8052 AE Hattem The Netherlands |
| Privacy and data requests | privacy@everstamp.app |
| Anything else | info@everstamp.app |
| Reporting security issues and misuse | security@everstamp.app |
If this statement changes, we update the date at the top. This page is the single source for both app stores; there is no second version.