1.0.3

Terms of Service & Privacy Policy

Aquamark ("Aquamark", "we", "us") provides document watermarking, leak-deterrence, and certification services for brokers and funders in the commercial finance industry.

Important: Aquamark is a deterrence and traceability tool. We cannot guarantee prevention or detection of 100% of leaks, theft, insider misuse, or data access events.

1) What We Do

Aquamark watermarks documents to deter unauthorized sharing and help identify potential leak points. We serve:

Brokers

PlanDescriptionPricing
StandardUnlimited outbound watermarking with broker branding$299 / month
Leak DetectionBroker + funder-specific watermarking to trace leaks$0.05 per file per funder variation

Example: 5 files sent to 5 funders = 25 billable files.

Funders

PlanDescriptionPricing
Funder PlanInbound watermarking to tag broker + funder before internal systems to deter internal misuse$0.05 per file

SecureFunder™ Certification

SecureFunder™ Certification includes a one-time enrollment fee and an annual renewal fee to maintain certification status. Certification is based on demonstrated technical controls and observable system behavior, not self-reported policies, providing clear, objective assurance, with confidentiality maintained throughout the process.

Certification indicates that at the time of review, the funder demonstrated adherence to data-handling controls. Aquamark does not guarantee certified funders are free from breaches, insider threats, or security failures after certification. Certification may be suspended or revoked if standards are not maintained.

2) Document Handling

Broker API

Zero Document Storage: We do not store or retain PDFs. Documents are processed in real-time in memory and removed immediately after processing.

Funder API

30-Minute Retention: Documents are processed in memory on our server and retained for 30 minutes to enable asynchronous processing and retrieval. After 30 minutes, all files and processing records are permanently deleted.

Audit Logs: Server audit logs are available upon request for security review and compliance purposes.

We store uploaded logos to deliver your branding across all services.

3) Data We Collect

4) How We Use Data

5) Sharing

We do not sell personal information. We share data only with service providers (Stripe for payment processing, Render and Supabase for cloud hosting, support tools) or when legally required.

6) Security & Compliance

Infrastructure Security

Compliance Framework

Aquamark operates on enterprise-grade infrastructure certified to industry standards. Our cloud providers (Render, Supabase) maintain SOC 2 Type II compliance, undergo independent security audits, and implement continuous monitoring.

We implement defense-in-depth security controls including encryption at rest and in transit, role-based access controls, and audit logging. Server audit logs are available to clients upon request for compliance and security review.

6.5) Compliance & Audit Features

Contact [email protected] for DPA, security documentation, or compliance inquiries.

7) Billing & Cancellation

8) U.S. & State Privacy Rights

Aquamark primarily serves U.S. businesses and currently falls below thresholds requiring CCPA/CPRA designation as a "business." Regardless, we honor reasonable requests to access or delete account data to the extent feasible.

Submit requests to [email protected].

9) International Users & GDPR Notice

Aquamark is based in the United States and currently serves primarily U.S. business users. As we expand to serve EU/UK clients, we will fully comply with GDPR requirements and provide:

We honor reasonable privacy requests consistent with applicable law.

10) Service Limitations & Liability

Aquamark provides deterrence and traceability tools designed to reduce unauthorized document sharing. While our watermarking technology is effective, no security system can guarantee 100% prevention of determined bad actors, sophisticated insider threats, or all forms of data misuse.

11) Data Breach Notification

In the event of a security incident affecting your account data, we will notify affected customers within 72 hours of discovery via email to the primary account contact. Notifications will include the nature of the incident, affected data types, and remediation steps.

Given our zero-storage architecture for broker documents and 30-minute retention for funder documents, the risk of document exposure is minimal. Account and billing data is protected by our infrastructure providers' SOC 2 certified security controls.

12) Suspension & Termination

Access may be suspended for non-payment, abuse, security risk, or violation of these terms.

13) Dispute Resolution

California law governs. Binding arbitration in San Francisco County. No class actions.

14) Changes

We may update this page as laws or services change. Continued use means acceptance.

15) Contact

Aquamark
490 Post Street, Suite 500, San Francisco, CA 94102
[email protected]