Privacy Policy
Last updated 30 August 2026
Written against the code rather than from a template. Where we hold something you might not expect, it is named. Where a control you might assume exists does not exist, that is stated too — sections 08 and 10 are the ones worth reading if you read only two.
01Who we are
Bunker Fuel Prices operates bunkerfuelprices.com and is the controller of the personal data described here. Reach us at privacy@bunkerfuelprices.com.
The service runs on a single server in Nuremberg, Germany, rented from Hetzner Online GmbH. Your data is stored there, inside the European Union. Some of the third parties in section 05 process data outside the EU, and each is named.
02What we collect about you
An account holds: your email address, an optional name, the organisation you belong to, your role in it, your plan and seat count, the date your address was verified, and timestamps recording alert opt-in and unsubscribe. The account itself is keyed by an identifier we generate, not by your email.
Your organisation record holds its name, country and website, its Stripe customer and subscription identifiers, plan state — and a sanctions and know-your-customer screening status with free-text notes. We are telling you about the screening field because you would not otherwise expect it.
Two things are derived rather than given. First, submitting any address to the sign-in form creates an account record for it immediately, before the address has been verified — so a record can exist because somebody else typed your address. Second, when your email domain is not a well-known consumer mail provider, we infer a company name from that domain and store it. You can correct or clear both.
Operational data is whatever you put into the product: vessels you monitor, including their IMO numbers, positions and consumption figures; requests for quote you raise; the replies suppliers send; and closed stems.
Email captured outside registration — from a price submission form, from a page that asks for an address, or as the sender of a price-list email — is stored separately, with the page it came from and the date consent was given.
03What we do not collect
This section is unusually specific because most privacy policies describe tracking the site does not do. Ours does none of it:
- No IP addresses are stored. No column holds one and no code reads a forwarding header for identity.
- No user agents, and no device fingerprinting.
- No analytics of any kind. There is no Google Analytics, no tag manager, no advertising pixel, no session replay, no A/B testing tool, and no third-party error monitoring.
- No passwords. Sign-in is a link emailed to your address, so we never hold a password to lose.
- No third-party requests from your browser. Typefaces are served from this domain rather than from a font host, so loading a page contacts nobody but us. The only exception is Stripe’s own checkout, which you reach only by choosing to pay.
04Cookies
bfp_session holds a signed token identifying your account. It is HttpOnly, SameSite and served over HTTPS only, it exists so that you stay signed in, and signing out clears it.
bfp_ref is set only if you arrive through a partner’s introduction link. It holds nothing but that partner’s code, so that we can credit the introduction if you later become a customer, and it expires after 60 days. It identifies the partner, not you, and it is not used to build any profile of you or shared with anyone.
bfp_lang remembers a language you choose from the menu, so the site opens in it next time.
Those are all of them. There are no analytics cookies, no advertising cookies and no third-party cookies of any kind — which is why you are not being asked to accept any. All three are strictly necessary to do the thing you asked for: stay signed in, honour the link you followed, and keep the language you picked.
05Who we send data to
Each of these receives something specific, and only that:
| Processor | What reaches them | Where |
|---|---|---|
| Hetzner | Hosts the server and therefore everything on it. | Germany |
| Stripe | Your email, organisation name and subscription. Card details go to Stripe directly and never touch our server. We store the payment events Stripe sends us in full. | US / EU |
| Mailgun | Sends our email and receives supplier replies addressed to us, so it handles the content of both. | US / EU |
| Resend | Transactional email, where configured. | US |
| OpenRouter | The AI gateway. Section 06 sets out exactly what is sent. | US |
| Anthropic | Used when a supplier reply is too hard for the first model to read reliably. | US |
| AISStream | Vessel positions come in. Nothing about you goes out. | EU |
| OilPriceAPI | Market prices come in. Nothing about you goes out. | US |
We do not sell personal data, and we do not share it for advertising. There is no advertising on this site.
06What our AI actually does with an email
This is the part most worth your attention, so it is written plainly rather than in the abstract.
When a supplier replies to a request raised through us, and the reply matches an open request, and it passes an automated screen, then the sender’s address, the subject line, the message body and any attachments are sent unaltered to a third-party AI provider so that the price can be read out of it. We do not redact or mask anything first. The request’s own context — its reference, port, grade, quantity and the vessel name — is sent alongside.
A great deal never reaches a model at all. Mail that cannot be matched to an open request is stored and handled by a person. A free, deterministic screen runs first and discards bounces, read receipts, out-of-office replies, empty messages, and anything containing no price-shaped figure and no attachment. Where the mail arrives through Mailgun we use its stripped version, with the quoted reply chain and signature block already removed, in preference to the raw body. The HTML part of a message is stored but is never sent to a model.
Attachments. PDFs and images are sent to the model. Where a separate transcription model is configured, an image is normally read by that one model and only its text goes onward. If the transcription is unreadable, the original image is forwarded instead, and in that fallback case one image is processed by two providers.
The assistant. What you type into the dashboard assistant is sent to the same gateway, together with the recent conversation, a fixed system prompt and the list of actions available to it. If you ask it about your fleet, your vessel data goes with the question.
Nothing is ordered on your behalf without you. The assistant can draft and prepare, but an action with commercial effect requires a human approval step.
We do not use your data to train models, and we do not permit our providers to do so under their business terms. Do not put anything into a supplier email or the assistant that you would not want processed by a US-based AI provider.
07Alerts and marketing
Be clear about how consent is currently taken: there is no separate tick-box. Confirming the sign-in link we email you is what records your consent to opportunity alerts, and the sign-in page says so. If that is not what you want, unsubscribe — one click, no sign-in required, and the link is in every alert.
Unsubscribing is durable. Signing in again afterwards does not turn alerts back on; restarting them is a deliberate act in your settings. An unsubscribe covers both your account and any separately captured copy of the same address.
08How long we keep things, and what that really means
We do not delete rows. The application has no row deletion in it at all. Expiry is a change of status, not a removal: a request that lapses is marked expired and stays. Stopping monitoring on a vessel sets a flag and keeps its history. Inbound supplier messages are kept indefinitely by design, because the parser is versioned and history has to be re-readable when it changes.
Treat that as the retention position: records persist until you ask us to erase them, and section 10 tells you how.
Backups. A nightly job copies the database to another directory on the same server and removes copies older than fourteen days. Two honest caveats: the copies sit on the same machine and the same disk as the live database, so they protect against mistakes rather than against losing the server; and the job reports nothing when it fails. We are not going to describe that as a disaster-recovery arrangement, because it is not one yet.
09Security, stated accurately
Traffic is encrypted in transit with certificates renewed automatically. Session tokens are signed. The API keys we hold for third parties live only on the server and in no source file. The site sends a content security policy and the usual protective headers.
What we are not claiming: the database is a file on the server, and individual fields are not separately encrypted. Anyone with access to that machine has access to the data on it, which is why access to it is narrow.
Sessions live in the signed cookie itself rather than in a table we keep. That means we cannot show you a list of your active sessions or end one remotely. Signing out ends the session in the browser you are using.
If you find a security problem, write to security@bunkerfuelprices.com. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.
10Your rights, and how to actually use them
If you are in the UK or the European Economic Area you have rights of access, rectification, erasure, restriction, portability and objection. These are not hypothetical here:
- Access and portability. Signed in, request /api/v1/account/export and you get a JSON file containing every record we hold against your account and organisation — immediately, without asking us.
- Erasure. A POST to /api/v1/account/erase with a typed confirmation overwrites your email and name, removes your device tokens, opts the address out everywhere it appears, and ends your session.
- What erasure keeps, and why. Requests for quote you sent, the supplier replies to them and any closed stems are retained as business records for the statutory period. They no longer identify you. We would rather tell you this than promise total deletion and quietly keep invoicing records.
- Rectification and objection. Write to us and we will do it. There is no form.
Our lawful bases are: performing our contract with you, for the product itself; our legitimate interest in operating and securing the service; your consent, for alerts; and legal obligation, for accounting and sanctions screening.
You can complain to your data protection authority. If you are in the EEA, ours would be the authority for Bavaria, where the server sits.
11Children
This is a commercial marine fuel service. It is not directed at children and we do not knowingly hold data about anyone under 16. If you believe we do, write to us and we will remove it.
12Changes
When this policy changes materially we will update the date at the top and, where the change affects how we handle data you have already given us, tell account holders by email. We will not change it silently.
Questions about anything on this page: legal@bunkerfuelprices.com.