Sign in

Privacy Notice

This notice explains what personal data PORTLS collects, how it's used, and the choices you have. Operational and security details also live on the Trust & Security page.

Last updated: July 15, 2026. Maintained by PORTLS as editable project content, not legal advice.

Who is the controller

PORTLS is operated by Kevin Florentin (individual seller, operating PORTLS) — the "we" / "us" in this notice — who acts as the data controller for account and billing data. Contact: hello@portls.to. For visitor data collected inside your PORTLS workspace (clicks, events, conversions attributed to your links), you — the workspace owner — are the controller and PORTLS processes that data on your behalf.

What we collect

Account holders.

  • Email address, workspace handle and name.
  • Authentication metadata (sign-in timestamps, provider).
  • Billing metadata from Paddle: customer id, subscription state, country, last-4 of card — Paddle stores the card and tax data itself.
  • Content you put into PORTLS: link destinations, product catalogs synced from connected stores, source labels, member invites.
  • Support messages you send us.
  • Basic server logs (IP, user agent, timestamps) for security.

Link visitors. When someone clicks a PORTLS short link we record:

  • Truncated IP (used for coarse geolocation, then discarded).
  • Country / region derived from IP.
  • User agent, referrer, and UTM parameters on the link.
  • A rolling hashed visitor id for de-duplication.

We do not attempt to identify individual visitors. Real IPs are not stored beyond the request.

How we use it

  • Provide the service (accounts, links, dashboards, emails).
  • Attribute clicks and conversions to workspace links.
  • Filter bots and abusive traffic.
  • Bill you and comply with tax / accounting obligations.
  • Send transactional and (opt-out) performance-report emails.
  • Secure the service and investigate incidents.
  • Improve PORTLS in aggregate — never by profiling individual visitors.

Legal basis (EEA/UK)

  • Contract: providing the workspace you signed up for.
  • Legitimate interests: security, fraud prevention, service improvement, and coarse-grained click analytics.
  • Legal obligation: tax and accounting records via Paddle.
  • Consent: where required by your local law for the tracking snippet you install on your own site.

Who we share it with

  • Paddle — Merchant of Record for all payments, subscription management, tax, invoicing, and refunds.
  • Lovable Cloud (hosting, database, authentication) — infrastructure processor.
  • Email delivery infrastructure used by Lovable — for transactional and report emails.
  • Stores you connect (Fourthwall, Lemon Squeezy, Ko-fi, Shopify) — only when you enable that integration.
  • YouTube Data API — only when you connect a channel; queries use your provided API key against Google's APIs under their terms.
  • Lovable AI Gateway — when you use the AI description helpers, prompts are sent to the configured model provider. We don't use those inputs to train models.
  • Authorities — where required by valid legal process.

International transfers

Data may be processed outside the EEA/UK by our subprocessors (notably Lovable Cloud and Paddle). Where required, transfers rely on Standard Contractual Clauses or an adequacy decision maintained by that subprocessor.

Retention

  • Account, workspace, and content data is kept while your subscription is active. After cancellation or non-payment, data is scheduled for deletion after a 30-day grace period.
  • Click and event telemetry is retained per your plan's retention window (see the Trust page).
  • Owner-initiated workspace deletion (Settings → Danger zone) applies a 30-day grace period, then permanently erases the workspace.
  • Paddle retains invoicing / tax records as required by law even after your workspace is deleted.

Your rights

Depending on your jurisdiction you may have the right to access, correct, export, delete, or restrict processing of your personal data, and to object to certain processing. Account holders can:

  • Export their workspace data as JSON from Settings.
  • Request workspace deletion from Settings.
  • Contact support for anything else.

EEA/UK residents have the right to lodge a complaint with a supervisory authority.

Security

We use TLS in transit, encrypted managed database storage, role-based access to production systems, row-level security in the database, and time-limited service credentials. See the Trust & Security page for more.

Cookies

The PORTLS app uses first-party cookies / storage only for authentication and preferences. Redirects set a short-lived cookie for de-duplication. We do not run cross-site ad or analytics trackers on our marketing pages.

Changes to this notice

We'll update the date at the top of this page when this notice changes. Material changes will also be surfaced in-app for active workspaces.

Contact

For privacy questions, data requests, or complaints, email hello@portls.to or reach us through support from your workspace.