Privacy Policy
Privacy Policy
Last updated: August 22, 2026
PortalShip (“PortalShip,” “we,” “us”) provides a customer portal that connects to a business’s HubSpot account. This policy explains what information we collect and how we use it. It applies to (1) businesses and their staff who sign up for PortalShip (“Admins”) and (2) the Admins’ own customers who are invited to use a portal (“Portal Customers”).
Information we collect
Admin account information. When you create a PortalShip account, we collect your name, email address, and password (stored as a salted hash, never in plain text). If you subscribe to a paid plan, billing is handled by Stripe — we store your Stripe customer and subscription IDs, but never your full card number.
Your HubSpot connection. When you connect HubSpot, we store your OAuth access and refresh tokens, encrypted at rest. We use these tokens to read and write data in your HubSpot account on your behalf — contacts, deals, tickets, quotes, and pipeline data — strictly to display and operate your customer portal. We do not copy this data into a second, permanent database; it’s read live from HubSpot each time and only cached briefly to keep the portal responsive.
Portal Customer information. When an Admin invites one of their customers, we store that customer’s email address, their HubSpot contact ID, and records of when they logged in or were invited. Signing in uses a one-time “magic link” emailed to them — we don’t require or store a password for Portal Customers.
Documents and files. Files a Portal Customer uploads (for example, in response to a file request) are stored directly in the Admin’s HubSpot account, attached to their contact or deal record — not on PortalShip’s own servers. Files an Admin shares with a customer are stored using our cloud storage provider (Vercel Blob) and served by reference.
Emails. We use Resend to send transactional emails (magic links, notifications). If an Admin configures their own outgoing mail server instead, we store those SMTP credentials encrypted at rest and send through that server rather than ours.
Marketing site. If you start a free trial or subscribe for product updates on our marketing site, we collect your email address and, for trial signups, may record it as a lead in our own internal HubSpot account so our team can follow up.
How we use information
We use the information above to:
- Operate and display the customer portal on an Admin’s behalf
- Authenticate Admins and Portal Customers
- Send transactional emails (magic links, notifications, receipts)
- Process subscription billing
- Provide customer support and respond to inquiries
- Maintain the security and integrity of the service
We do not sell personal information, and we do not use third-party advertising or analytics trackers on PortalShip. The only cookies we set are the session cookies needed to keep you signed in.
Who we share information with
We share information only with the service providers needed to run PortalShip:
- HubSpot — the Admin’s own CRM, which the Admin already controls
- Stripe — payment processing for paid subscriptions
- Resend — transactional email delivery
- Vercel — application hosting, database, and file storage
Each of these providers only receives the information necessary to perform its function and is bound by its own privacy and security commitments. We may also disclose information if required by law, or to protect the rights, property, or safety of PortalShip, our users, or others.
Data retention
We retain Admin and Portal Customer account records for as long as the Admin’s subscription is active, plus a reasonable period afterward for legal and accounting purposes. An Admin can disconnect HubSpot or delete their account at any time; doing so revokes our access to their HubSpot data immediately. HubSpot data itself is never duplicated into permanent storage on our side, so disconnecting HubSpot leaves your CRM data exactly as it was.
Security
OAuth tokens, SMTP credentials, and passwords are encrypted at rest. All traffic to PortalShip is encrypted in transit (HTTPS). No method of storage or transmission is completely secure, so while we work to protect your information, we can’t guarantee absolute security.
Your choices and rights
You can access, correct, or delete your Admin account information at any time from your account settings, or by contacting us. Because Portal Customer data lives in the Admin’s own HubSpot account, requests from a Portal Customer to access or delete their data should generally go to the Admin (the business they’re a customer of) first — we’ll assist an Admin with any such request. You can also contact us directly at info@portalship.io.
Children’s privacy
PortalShip is a business-to-business service and is not directed at, or knowingly used by, children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. If we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify Admins directly.
Contact us
Questions about this policy or your data? Email us at info@portalship.io.
