Skip to content

Legal

Privacy policy

Privacy policy

Last updated: July 31, 2026

1. Who we are

Porthatch ("we", "us") operates the products Placet, Veneer, Cordon, Sluice, Duehatch, and Gangway under the same operating entity. Each product is a distinct service, but the data-handling practices below apply to all of them unless stated otherwise.

1a. When we're the controller, and when we're only your processor

Which of the two we are depends on whose data it is, and it decides who a request should go to.

  • Your account and billing data — the email you sign in with, your workspace and plan, Paddle identifiers, and the operational telemetry we generate running the service. Here we are the controller: we decide why and how it is processed, and this policy is your notice for it.
  • Everything you put into the products — Placet boards, decisions and reviewer emails; Veneer and Cordon access rules and audit logs; Sluice lists; Duehatch invoice and customer records; Gangway scan targets and results. Here you are the controller and we are your processor. We hold and process that data only on your instructions, within the retention rules in §5, and we don't decide what it's for.

The processing terms are the ones in this policy and in Terms §4, which is also where the warranties you give us about that data live. We don't yet publish a standalone data processing agreement; if you need one — signed, or incorporated by reference — email privacy@porthatch.app and we'll put it in place before you upload anything.

If you are the end client of one of our customers — a Placet reviewer, a Veneer or Cordon portal user, someone Duehatch emailed about an invoice — then that customer is your controller, not us. You can still write to privacy@porthatch.app: we'll identify who holds your data, pass the request on, and help them answer it. What we won't do is delete or disclose their data on our own authority, because it isn't ours to decide about.

2. What we collect

We collect only what we need to run the service and bill it.

Category Examples Why
Account identifiers Email, name (optional), hashed session cookie Authentication, magic-link sign-in
Workspace data Workspace name, plan, trial state Service provisioning, billing
Product-specific content (Placet) board posts, decisions; (Sluice) uploaded email lists; (Veneer/Cordon) audit metadata about what your clients viewed or edited; (Duehatch) invoice and customer records — amounts, due dates, customer emails — synced from the Stripe account you connect, plus a ledger of the reminders sent; (Gangway) the site URLs you submit and the accessibility scan results Core service functionality
Connected-service credentials (Veneer) Airtable personal access token; (Cordon) Notion integration token; (Duehatch) Stripe restricted key — each stored encrypted (AES-GCM) and used only to call the service you connected Core service functionality
Billing identifiers Paddle customer id, subscription id Subscription and credit-pack management. Paddle is our Merchant of Record and payment processor; card details go directly to Paddle and never reach our servers
Technical telemetry Request id, route, latency, error class, hashed IP (sha256 with a server-side salt — never the raw IP) Operations and security

Veneer + Cordon proxy your own Airtable and Notion data through to your clients — we do not copy that content into our database. We store only the access rules you define and an audit log of which records were accessed or written, by which client email.

3. Why we collect it (legal basis)

For the data where we are the controller (§1a — your account, billing and telemetry) we process on three legal bases. For customer content we act on our customer's instructions, and the legal basis for that processing is theirs to establish, not ours.

  • Performance of a contract — most of it. You signed up; we run the service you paid for.
  • Legitimate interest — operational telemetry (hashed IPs, request metrics) for keeping the service up and abuse-resistant.
  • Consent — held in reserve for anything non-essential we add later. We run no advertising, cross-site tracking or behavioural analytics today; the single cookie that isn't strictly necessary is named and explained in /legal/cookies.

4. Where it lives (subprocessors)

We keep the list of subprocessors and where they're located at /legal/subprocessors. A new subprocessor is published on that page at least 30 days before it takes effect, and we email the notice to the address on your account. Existing customers can object and exit if a new processor is incompatible with their compliance posture.

4a. International transfers

Where the data sits at rest:

  • Neon — the Postgres database holding accounts, workspaces, audit rows and product metadata. EU, Frankfurt.
  • Sentry (error reports) — EU, Germany. Axiom (logs and metrics) — EU, Frankfurt.
  • Cloudflare R2 — uploaded Placet media and Sluice input CSVs. These buckets carry Cloudflare's EU jurisdictional restriction, which means the objects are stored only in the European Union. That is a guarantee, not a placement: it is fixed when a bucket is created and cannot drift.
  • Cloudflare KV and Queues — KV holds caches (no customer content) and is replicated across Cloudflare's network by design; Queues hold billing events, webhook jobs and email retries only while they are being delivered. Neither can be pinned to a jurisdiction on our plan, so we treat both as a possible transfer and rely on Cloudflare's standard contractual clauses. Cloudflare is also a US-parented company, which is true regardless of where an object is stored.
  • GitHub (US) — a nightly encrypted dump of the entire database is kept as a GitHub Actions artifact for 30 days. It is our only backup outside Neon, and it contains everything the database contains.

Personal data leaves the EEA in these cases:

  • Resend (US) — every transactional email necessarily carries the recipient's address. This applies to every product, because magic-link sign-in is the only way in.
  • Paddle (UK/EU and US) — as Merchant of Record, for payment and tax.
  • GitHub (US) — the nightly backup described above.
  • Stripe (US) — only if you use Duehatch. Unlike Notion and Airtable below, this one is a copy, not a proxy: your invoice and customer records are synced from Stripe into our EU database, which means your customers' names, emails and outstanding amounts exist in both places.
  • Notion and Airtable (US) — only if you use Cordon or Veneer, and only the integration token plus proxy audit; your content stays in your own Notion or Airtable workspace and we never copy it.
  • EmailListVerify — only on Sluice's Deep tier, and only the addresses you submit for verification. See the note on /legal/subprocessors: the vendor serves EEA/UK customers from EU servers, and we are confirming in writing which servers handle our account.

Where a transfer leaves the EEA we rely on the receiving vendor's standard contractual clauses and data processing agreement.

5. How long we keep it

Data Retention
Account + workspace Kept while your account is active; deleted immediately on self-service deletion, or within one month of a verified deletion request by email
Audit log (Veneer, Cordon) 180 days, then deleted; purgeable earlier on request. Neither product is live yet — this is the rule they launch with, not a description of something running today
Workflow + job records (Sluice) Uploaded CSVs and per-row verdicts are purged automatically 90 days after the job runs; only retention-safe counters (no email addresses) remain
Approval boards (Placet) Kept while a board is in progress; purged automatically 90 days after it's marked completed
Synced product content (Duehatch invoices/customers, Gangway scan results) Kept while the workspace is active; purged automatically 90 days after subscription cancellation, or removed immediately as part of a verified account-deletion request
Billing records Kept as long as required for tax and accounting obligations
Technical telemetry 30 days
Database backups A nightly encrypted dump of the whole database, kept 30 days, then deleted automatically

The 90-day purges above are automated — a daily job in each product removes the relevant rows (and, for Sluice, the input CSV from R2) once they pass their retention window. Account and workspace deletion is self-service in every live product (see §6) and takes effect immediately; the email route in §6 remains available and completes within one month.

What backups mean for deletion. Deletion runs immediately against the live systems, and that is what stops your data being used. It cannot reach backups already taken. A record you delete today can therefore survive in an unexpired nightly dump for up to 30 more days, after which the dump is deleted and the record is gone from there too. Those dumps are encrypted at rest, access is limited to the people who operate the service, and they are only ever restored whole, in a disaster — we don't reach into a backup to look up one record. Being honest about the edge case: a full restore brings back the state of the dump, so anything deleted after it was taken would return with it, and re-applying those deletions is part of how we'd finish the recovery. The same applies to the automated 90-day purges above.

6. Your rights

If you live in the EU, UK, or a jurisdiction with comparable rights, you can exercise the rights below. Self-service actions take effect immediately. Where a request comes in by email, we answer within one month of verifying who you are; if a request is complex enough to need longer, we may extend that by up to two further months and will tell you — and why — within the first month.

Requests about data where we are only the processor (§1a) go to our customer as controller; tell us and we'll route it and chase them.

  • Access / portability — self-service in every live product: GET /api/account/export (or the "Export my data" button in /app/settings) returns a JSON archive of the personal data we hold for that product — account, workspace metadata and the content you authored. The export is available once per 24 hours. Notion / Airtable content is excluded because we never store it — fetch it from the source; large uploaded files are referenced by metadata, not embedded. You can also email privacy@porthatch.app and we'll compile the same archive manually.
  • Rectification — edit your account details in /app/settings. Workspace data is editable inside the product UI itself.
  • Erasure — self-service in every live product: the "Delete account" action in /app/settings (confirmed by re-typing your account email) cancels any active subscription immediately, then deletes your workspace content, uploaded files and login from the live systems. Billing records are retained per §5 (tax and accounting obligations), and the backup window in §5 applies — deleted data ages out of the nightly dumps within 30 days rather than vanishing from them at the moment you press the button. Alternatively, email privacy@porthatch.app with the address tied to the account; we confirm via reply (so we don't delete on a spoofed sender) before processing it.
  • Restrict processing / object — email privacy@porthatch.app.
  • Lodge a complaint with your data protection authority.

We don't sell personal data and don't run automated decision-making that produces legal effects.

7. Children

The service is not directed at children under 16. If you believe a child has signed up, email privacy@porthatch.app and we'll delete the account.

8. Changes to this policy

Material changes get a notification to your account email at least 30 days before they take effect — the same notice period as the Terms of service §10 and as a subprocessor change (§4). Continued use after the effective date counts as acceptance.

9. Contact

For privacy questions or DSARs: privacy@porthatch.app.

For everything else: support@porthatch.app.