Privacy Policy

Last updated: April 2026

1. Who we are

PortfoliPros Ltd (“we”, “us”, “our”) operates the Portfolys website and platform. We are the data controller for the personal data we collect and process in connection with the Platform. For questions about this Privacy Policy or your personal data, you can contact us via the “Report an issue” or “Make a request” links in the footer, or at the contact address provided on the Platform.

2. Data we collect

We collect and process the following categories of personal data:

  • Account data: name, username, email address, and password (stored in hashed form). We also store email verification status and, where applicable, verification timestamps.
  • Profile data: profile description, display currency preference, and (for creators) information related to your creator channel and Stripe account (e.g. Stripe customer ID, Stripe account ID, onboarding status). We do not store full payment card numbers; payment card details are processed by our payment provider (Stripe).
  • Usage and technical data: information about how you use the Platform (e.g. pages visited, actions taken), device and browser information, and IP address. We may use cookies and similar technologies as described below.
  • Content and communications: posts, replies, messages (including direct messages and support messages), and any content you submit when reporting an issue or making a request.
  • Payment and subscription data: subscription status, payment history, and transaction identifiers. Actual payment card details are held by our payment processor, not by us.

We process your data on the following legal bases (where applicable under UK and EU data protection law):

  • Contract: to create and manage your account, provide the Platform (including communities, subscriptions, tips, feed, and creator tools), process payments, and communicate with you about your account and the service.
  • Legitimate interests: to improve and secure the Platform, prevent fraud and abuse, enforce our terms, and handle support and moderation (e.g. reports, issues, requests).
  • Consent: where we rely on consent (e.g. for certain marketing or non-essential cookies), you may withdraw it at any time.
  • Legal obligation: where we must process data to comply with law (e.g. tax, anti-fraud, or regulatory requirements).

4. Payment processing

Payments (subscriptions and tips) are processed by Stripe. When you add a payment method or make a payment, Stripe collects and processes your payment details in accordance with their privacy policy and terms. We receive transaction identifiers, status, and related information necessary to operate subscriptions and payouts; we do not store full card numbers or CVV. Stripe acts as a data processor for payment processing on our behalf and may also act as a controller for their own purposes (e.g. fraud prevention). Their privacy policy is available at stripe.com/privacy.

5. Sharing and recipients

We may share your data with:

  • Payment providers (e.g. Stripe) to process payments and payouts.
  • Hosting and infrastructure providers that host our systems and process data on our instructions.
  • Other users as necessary to operate the Platform (e.g. your username and profile to other members and creators; your content to communities and subscribers as you choose).
  • Authorities where required by law or to protect our or others’ rights and safety.

We do not sell your personal data. We require processors to protect your data by contract and only use it as we instruct.

6. Data retention

We retain your data for as long as your account is active and as needed to provide the Platform, comply with legal obligations, resolve disputes, and enforce our agreements. After account closure we may retain certain data (e.g. transaction records for legal and accounting purposes) for periods required by law. Unverified accounts may be removed in accordance with our account policies.

7. Your rights

Depending on where you live, you may have the right to:

  • Access your personal data and receive a copy.
  • Rectification of inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) in certain circumstances.
  • Portability of your data in a structured, machine-readable format where technically feasible.
  • Object to processing based on legitimate interests, or to restrict processing in certain cases.
  • Withdraw consent where we rely on consent (without affecting the lawfulness of processing before withdrawal).
  • Lodge a complaint with a supervisory authority (e.g. in the UK, the ICO; in the EU, your local data protection authority).

To exercise these rights, contact us via the links in the footer or the contact address on the Platform. We will respond within the timeframes required by applicable law.

8. Cookies and similar technologies

We use cookies and similar technologies to operate the Platform (e.g. authentication, session management, security, and preferences). Some of these are essential for the service to function. We may also use analytics and similar tools to understand how the Platform is used and to improve it. Where we use non-essential cookies that require consent, we obtain your consent via our cookie banner. You can adjust your browser settings to refuse or delete cookies; some features may not work correctly if you disable essential cookies. For full details on the cookies we use and how to manage them, see our Cookies Policy.

9. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes encryption (e.g. in transit and where appropriate at rest), access controls, and secure development practices. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

10. International transfers

Your data may be processed in the United Kingdom, the European Economic Area, or in countries where our service providers operate. Where we transfer data outside the UK or EEA, we ensure appropriate safeguards are in place (e.g. adequacy decisions, standard contractual clauses, or other approved mechanisms) in accordance with applicable data protection law.

11. Children

The Platform is not intended for users under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will take steps to delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy on the Platform and indicate the date of the last update. Material changes may be communicated by email or a notice on the Platform. We encourage you to review this policy periodically.

13. Contact

For questions about this Privacy Policy or your personal data, please use the “Report an issue” or “Make a request” links in the footer, or contact us at the address provided on the Platform.