Legal
Privacy
Policy.
How we collect, use, and protect your personal data — and the rights you have over it.
Introduction & scope
PortalKit (“we”, “our”, or “us”) provides a client portal platform for freelancers and agencies (“Service”). This Privacy Policy explains how we collect, use, share, and protect personal information when you use our Service, and describes the rights you have over your data.
This policy applies to all users of the Service — including freelancers and agencies who create accounts (“Freelancers”), and their clients who access portals (“Clients”). Where we refer to “you” in this document we mean any person whose personal data we process in connection with the Service.
By creating an account or accessing a client portal, you acknowledge that you have read and understood this policy. If you do not agree, you should not use the Service.
Who we are
PortalKit is operated by a company registered in the Democratic Socialist Republic of Sri Lanka. We are the data controller for personal data relating to our account holders (Freelancers) and the visitors to our marketing website.
For personal data that Freelancers store within their client portals — including their clients’ names, email addresses, files, messages, invoices, and contracts — the Freelancer is the independent data controller. PortalKit processes that data only as a data processor, acting on the Freelancer’s instructions. See Section 6 for more on this two-sided relationship.
We comply with the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA), the EU and UK General Data Protection Regulations (GDPR / UK GDPR) for users in those regions, the Australian Privacy Act 1988 (as amended) for Australian users, the California Consumer Privacy Act / CPRA for California residents, and the India Digital Personal Data Protection Act 2023 (DPDP Act) for Indian users.
Our contact details are in Section 15.
Legal basis for processing
We collect and process personal data only when we have a lawful basis to do so. The bases we rely on, consistent with the Sri Lanka PDPA 2022 and GDPR, are:
- Contract performance — processing necessary to provide the Service you have signed up for (e.g. account creation, billing, sending portal access links).
- Legitimate interests — processing necessary for our legitimate business interests where those interests are not overridden by your rights (e.g. security monitoring, fraud prevention, service improvement, internal analytics).
- Legal obligation — processing required by applicable law (e.g. retaining financial records for tax purposes).
- Consent — where we ask for your permission before processing (e.g. optional marketing emails). You may withdraw consent at any time without affecting the lawfulness of prior processing.
For users subject to the India DPDP Act 2023, the primary basis for processing is your consent, which we obtain at account creation. You may withdraw consent at any time; doing so may prevent us from providing the Service.
Data we collect
Account data (Freelancers)
When you create a PortalKit account we collect your name, email address, and business name. Your password is managed by Supabase Auth; we never see or store plain-text passwords. We also store your Paddle customer ID and subscription status for billing purposes.
Client portal data
Freelancers store their clients’ personal data — names, email addresses, portal slugs, PIN backup codes (hashed), files, project details, messages, invoices, and e-signed contracts — within the Service. This data is processed by us solely on behalf of the Freelancer as described in Section 6.
Authentication tokens
When a Client accesses a portal via a magic link, we generate a cryptographically signed token. Only a SHA-256 hash of that token is stored in our database; the plain token is delivered once via email and is never persisted on our servers. Tokens expire after 24 hours and are single-use.
Billing data
All subscription and add-on payments are processed by Paddle, who acts as Merchant of Record. We store only Paddle transaction IDs and the last-four digits of your payment method (as provided by Paddle). We do not store full card numbers, CVV codes, or bank account details.
Technical and usage data
We collect server log data including IP addresses, browser type, operating system, referring URLs, and request timestamps. This data is used for security monitoring, abuse prevention, and diagnosing technical issues. We also use Plausible Analytics — a privacy-first analytics tool that collects no personal data, sets no cookies, and does not track individuals across sites. See Section 13.
Support and communications
If you contact us by email or through our contact form, we retain your message content and contact details in order to respond and improve our support processes.
How we use your data
We use the data we collect to:
- Create and maintain your account and provide the Service
- Process billing through Paddle and manage your subscription
- Deliver portal magic-link access emails to your clients via Resend
- Send transactional notifications — portal activity, invoice receipts, security alerts
- Send onboarding and product update emails (you may unsubscribe at any time)
- Respond to support and legal enquiries
- Monitor, analyse, and improve the Service (using aggregated, non-personal Plausible data)
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with applicable law and enforce our Terms of Service
We will not send you unsolicited marketing emails. Where we send product updates, you may unsubscribe via the link in any email or by contacting us at privacy@portalkit.app.
Two-sided platform
PortalKit is a two-sided platform. When a Freelancer creates a client portal and stores their client’s personal data within it, the Freelancer is the independent data controller for that data. PortalKit is the data processor, acting solely on the Freelancer’s instructions.
This means:
- Freelancers are responsible for ensuring they have a valid legal basis to collect and process their clients’ personal data and for providing their clients with any required privacy notices.
- Freelancers are responsible for complying with all applicable privacy laws in the jurisdictions of their clients — including but not limited to GDPR, UK GDPR, Australia Privacy Act, CCPA, and India DPDP Act.
- If a Freelancer’s client exercises a data subject right (e.g. erasure or access), it is the Freelancer’s responsibility to respond. PortalKit will reasonably assist Freelancers in meeting such obligations upon request.
- A Data Processing Agreement (DPA) between PortalKit and Freelancers is available on request at legal@portalkit.app for Freelancers who require one for GDPR or other regulatory compliance.
Third-party data processors
We use the following sub-processors to operate the Service. Each processes data only as directed by us under appropriate data processing agreements:
- Supabase Inc. — PostgreSQL database, user authentication, and file storage. Servers may be located in the United States or European Union. Privacy Policy
- Paddle.com Market Ltd (Paddle) — subscription billing and one-time add-on purchases. Paddle acts as Merchant of Record and is subject to their own privacy obligations. Privacy Policy
- Resend Inc.— transactional and lifecycle email delivery. Email content (including magic-link tokens) is processed through Resend’s infrastructure. Privacy Policy
- Plausible Analytics — privacy-first web analytics. Plausible uses no cookies, collects no personal data, and does not track individuals across sites. Analytics data is aggregated only. Privacy Policy
- Netlify Inc. — hosting for our marketing and admin applications via global CDN. Privacy Policy
- Spaceship (VPS hosting) — server infrastructure for the PortalKit dashboard application.
We do not use Stripe or any other payment processor for subscriptions or add-on purchases. We do not sell your personal data to any third party.
International data transfers
PortalKit is operated from Sri Lanka. Our sub-processors (Supabase, Paddle, Resend, Netlify) may process your data in servers located in the United States or the European Union.
EU & UK users (GDPR / UK GDPR)
For transfers of EU or UK personal data to countries outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism. We conduct transfer impact assessments where required and implement supplementary safeguards consistent with the Schrems II ruling.
Indian users (DPDP Act 2023)
The India DPDP Act 2023 requires explicit consent for cross-border transfers of Indian personal data. By accepting these terms and creating an account, you provide such consent for your data to be processed by our sub-processors as listed above. You may withdraw this consent by deleting your account.
Australian users (Privacy Act 1988)
For transfers of Australian personal data overseas, we take reasonable steps to ensure our overseas sub-processors handle data in a manner consistent with the Australian Privacy Principles. By using the Service, you consent to such transfers where technically required.
For questions about our cross-border transfer safeguards, contact privacy@portalkit.app.
Data retention
We retain personal data only for as long as necessary:
- Account data — retained while your account is active and for 30 days after account closure to allow for recovery. After 30 days, account data is permanently deleted.
- Client portal content (files, messages, projects, invoices) — deleted when the Freelancer deletes the portal or closes their account.
- Financial records — Paddle transaction IDs and billing history may be retained for up to 7 years where required by applicable tax or accounting law.
- Magic-link tokens — SHA-256 hash purged automatically after 24 hours or on first use, whichever comes first.
- Server logs — retained for up to 90 days for security monitoring, then automatically deleted.
- Analytics data — Plausible analytics are aggregated and contain no personal data; they are not subject to a personal retention period.
You may request deletion of your personal data at any time by contacting privacy@portalkit.app. We will confirm deletion within 30 days unless retention is required by law.
Your rights
Depending on your location, you have the following rights over your personal data. To exercise any right, contact us at privacy@portalkit.app. We will respond to verified requests within 30 days (45 days for California residents where permitted).
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data (“right to be forgotten”), subject to legal retention requirements.
- Portability — receive your data in a structured, machine-readable format (CSV/JSON).
- Restriction — request that we temporarily suspend processing in certain circumstances.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Opt out of profiling / automated decisions — we do not make automated decisions with legal or similarly significant effects; this right is noted for completeness under CCPA/CPRA and India DPDP Act.
Sri Lanka (PDPA 2022)
Requests under the Sri Lanka PDPA may be lodged with the Data Protection Authority of Sri Lanka once the Authority is fully operational.
EU & UK (GDPR / UK GDPR)
You have the right to lodge a complaint with your local supervisory authority — the Information Commissioner’s Office (ICO) in the UK, or your national data protection authority in the EU.
Australia (Privacy Act 1988)
You have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
California (CCPA / CPRA)
California residents have the right to know what personal information is collected, to request deletion, to correct inaccurate data, and to opt out of the sale or sharing of personal information. We do not sell or share personal information. Contact us at privacy@portalkit.app or the California Attorney General if you believe your rights have been violated.
India (DPDP Act 2023)
Indian users have the right to access, correction, erasure, and to withdraw consent at any time. Complaints may be lodged with the Data Protection Board of India once it is fully operational.
Data breach notification
In the event of a personal data breach, we will take the following steps:
- Sri Lanka PDPA — notify the Data Protection Authority within 30 days of becoming aware of a breach that is likely to harm data subjects.
- EU / UK GDPR — notify the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to the rights and freedoms of natural persons.
- Australia Privacy Act (2024 reforms) — notify the OAIC and affected individuals without undue delay where a breach is likely to result in serious harm.
- India DPDP Act — notify affected data principals and the Data Protection Board of India without unreasonable delay.
- Affected users — we will notify affected users directly by email as soon as is reasonably practicable, describing the nature of the breach, data affected, likely consequences, and steps we have taken.
To report a suspected security incident, email security@portalkit.app.
Children's privacy
The Service is intended for individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you are under 18, please do not use the Service or provide us with any personal data.
If you become aware that a child under 18 has provided us with personal data, please contact us at privacy@portalkit.app immediately. We will take prompt steps to delete the data.
For users subject to the India DPDP Act 2023, parental or guardian consent is required for processing personal data of individuals under 18. We do not knowingly process such data without the required consent.
Policy updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by email or by a prominent notice within the Service at least 14 days before the change takes effect.
We are actively monitoring the development of Sri Lanka’s PDPA secondary regulations (expected late 2025 / early 2026) and any Digital Economy Act that may be enacted. We will update this policy promptly when those instruments come into force to ensure continued compliance.
The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
Contact
For questions, concerns, or requests relating to this Privacy Policy or your personal data, contact us at:
PortalKit — Privacy Team
We aim to acknowledge all privacy-related enquiries within 2 business days and to provide a full response within 30 days of receiving a verified request.