Privacy
Privacy policy
What we do with the information involved in running your business through Pordiya — in plain English first, in detail afterwards.
The short version
Pordiya is job management software. You use it to run your trade business: quotes, jobs, clients, invoices. This page explains what we do with the information involved, in plain English first and in detail afterwards.
- Your business records — your clients, your jobs, your invoices — belong to you. We hold them so the app works, and we do not use them for anything else.
- We do not sell personal information, we do not share it with advertisers, and there is no advertising or tracking technology anywhere in the app or on this website.
- Data is stored on servers in Singapore, and we operate the service from the Philippines.
- Three other companies are involved in running the service: our host, our sign-in provider and our payment provider. They are named below.
- You can export everything you have put in, at any time, and delete your account whenever you like.
Who we are
Pordiya is operated by [YOUR NAME OR REGISTERED BUSINESS NAME — set this in Appearance → Customize → Pordiya → Legal], a sole proprietor based in La Trinididad, Philippines, Philippines, at [BUSINESS ADDRESS — set this in Appearance → Customize → Pordiya → Legal].
Because we are established in the Philippines, the Data Privacy Act of 2012 (Republic Act No. 10173) governs how we handle personal information, and the National Privacy Commission is our supervisory authority. Where you are somewhere else, your own country’s privacy law may also give you rights — see Your rights.
Questions about privacy go to hello@pordiya.com. That address reaches a person, not a queue.
Two different kinds of information
This distinction runs through everything below, so it is worth setting out first.
Your information. Your name, your email address, your business details, what you pay and how you use the app. For this we are the personal information controller — we decide what is collected and why, and this policy governs it.
Your customers’ information. The records you put into Pordiya about the people you work for: their names, addresses, phone numbers, job notes, quotes and invoices. For this we are only the personal information processor. It is your data about your customers. We hold and process it on your instructions, we do not decide what goes in it, and we do not use it for our own purposes. Your own privacy policy — the one you give your customers — governs it.
What that means in practice: if one of your customers asks to see or delete what is held about them, that request goes to you, not to us, and we will help you act on it. The terms that govern our handling of that data are in Schedule 1 of our Terms.
What we collect, and why
Account information
Your name, email address, and the business details you enter — trading name, address, tax number, logo, currency and tax settings. We need these to create your account, to sign you in, and to put the right details on the documents you send. Your email address is also how we contact you about the service.
Business records you create
Clients, sites, jobs, quotes, invoices, payments, expenses, hours and photos. We hold these so the app can do its job. We do not read them, analyse them, or use them to build anything — with one exception, set out under Support access below.
Billing information
We never see your card details. Payments are taken by Paddle, who is the seller of record for your purchase (see the Terms). Paddle collects your card and billing details directly; we receive back only your plan, your billing country, the amount and whether it succeeded.
Technical information
When you use the app our servers record the usual things a web server records: the pages requested, the time, the browser and operating system, and the IP address the request came from. This is used to keep the service running, to work out roughly how many people are using what, and to identify abuse. It is not linked to your business records for any other purpose.
Error reports
When something goes wrong, the app records what happened: the error, where in the code it happened, which account was affected, and which build was running. This is how a bug you report can be found and fixed rather than guessed at.
Error reports are scrubbed before they are stored. Email addresses, tokens, passwords, card-shaped numbers and connection details are removed on the way in, not on the way out — so they are not sitting in a database waiting to be exported. Error records are kept for 30 days and then deleted automatically. This system runs on our own servers; no third-party error-tracking service is involved.
What we do not collect
No advertising identifiers. No behavioural tracking. No third-party analytics. No location tracking. No access to your phone’s contacts, microphone or files beyond the photos you deliberately attach to a job. There are no third-party scripts on this website at all.
Why we are allowed to hold it
Under the Data Privacy Act, personal information may be processed where the data subject has consented, or where processing is necessary for a contract, for compliance with a legal obligation, or for legitimate interests that are not overridden by the person’s rights. Ours are:
- Necessary for our contract with you — running your account, storing your records, taking payment. Without this we cannot provide the service you signed up for.
- Legitimate interests — keeping the service secure, preventing abuse, fixing faults, and contacting you about the service itself. We have weighed these against your interests and consider them proportionate, and you can object at any time.
- Legal obligation — keeping records of payments for the period Philippine tax law requires.
- Consent — for anything else. We will ask, and you can withdraw it.
Where we act as processor for your customers’ data, you are responsible for having a lawful basis for holding it.
Where your data is stored
Your business records are stored on servers in Singapore, operated by our hosting provider. Backups are held in the same region.
We operate the service from the Philippines, so our access to your data happens from there. Two of our providers — our sign-in provider and our payment provider — are in the United States.
Pordiya is not offered in the United Kingdom or the European Economic Area. We do not market to those regions, prices are not set in pounds or euros, and we do not knowingly open accounts for businesses established there. If that changes, this policy changes with it, and account holders will be told first.
If you need data held in a specific country for regulatory reasons, tell us before you sign up. We would rather say no than say yes and be wrong about it.
Who else is involved
Three companies handle data as part of running Pordiya. This list is complete. We will update this page before adding a new one, and paying customers can ask to be notified in advance.
| Company | What they do | What they see | Where |
|---|---|---|---|
| Vultr Holdings Corporation | Server hosting | Everything stored, as the operator of the machine. They do not access it in the ordinary course. | Singapore |
| Supabase, Inc. | Sign-in — sends the link that logs you in | Your email address only. No business records pass through it. | United States |
| Paddle.com Market Ltd | Payments — the seller of record for your purchase | Your name, email, billing address and card details. We never receive the card number. | United Kingdom and United States |
We also use an email delivery service to send the messages the app generates — sign-in links, invoice notifications and reminders. Those messages contain the recipient address and the content of the message being sent.
Webhooks. If you configure a webhook, Pordiya sends business events to a web address you choose. Once that data reaches your endpoint it is outside our control and this policy no longer covers it. You choose the destination; you are responsible for what happens there.
Support access
We can see your account data. Being straightforward about that is more useful than a vague sentence about "authorised personnel".
There is an operations console, on a separate system with its own sign-in, that lets us look at an account to answer a support question or investigate a fault. Three things constrain it:
- It is read-only. The database account it uses cannot alter your invoices, clients or records. That is enforced by the database itself, not by our code being careful.
- We cannot sign in as you. There is no impersonation feature. We see data in a support view; we never operate your account.
- Every look is logged. Each time we open an account, that is written to an append-only audit log which we cannot edit or delete. On a paid plan you can ask us for the entries relating to your account and we will provide them.
We look at accounts to answer your questions, to investigate faults, and where we are legally required to. Not for anything else.
How long we keep things
| What | How long |
|---|---|
| Your business records | While your account is open, then 30 days after you close it, then deleted |
| Backups | Rolling, overwritten within 35 days |
| Records of payments | 10 years, as Philippine tax law requires |
| Error reports | 30 days, deleted automatically |
| Support audit log | 2 years |
| Support emails | 2 years from the last message |
The 30-day window after closure exists so that an account closed by mistake — or by a departing employee — can be recovered. If you need it gone immediately, ask and we will delete it.
Records of what was paid are kept even after deletion, because the Bureau of Internal Revenue requires it. They contain your business name, the amount and the date. Nothing about your customers.
Security
What we actually do, rather than a list of adjectives:
- Separation at the database. Every business’s records are isolated by the database itself, so one account cannot read another’s even if the application asks it to. That is a stronger guarantee than a filter in the software, because it holds when the software has a bug — and software has bugs.
- Encryption in transit. Everything travels over HTTPS. The app refuses to run without it.
- No passwords to steal. Sign-in is by emailed link. We do not store passwords because there are none.
- Restricted application account. The database account the app runs as cannot create or drop tables. A serious bug cannot destroy the schema.
- Finalised documents cannot be quietly edited. Corrections happen through credit notes, which is what an audit expects.
- Scrubbing before storage. Sensitive values are stripped out of error records before they are written.
No system is perfectly secure, and anybody who tells you otherwise is selling something. If there is a breach affecting your data we will notify you and the National Privacy Commission within 72 hours of becoming aware of it, as the Data Privacy Act requires, with what we know, what we are doing, and what you may need to do.
If you have found a vulnerability, email hello@pordiya.com. We will not take legal action against anybody reporting a genuine security problem in good faith.
Your rights
Wherever you are, you can ask us to:
- See what we hold about you — much of it is already in the app, and you can export it yourself at any time
- Correct anything wrong
- Delete your account and its contents
- Export your records in a format another system can read
- Object to a particular use, or ask us to restrict it
- Complain to a regulator if we have got it wrong
Ask at hello@pordiya.com. We will respond within 30 days, and we will not charge you or make it difficult.
Philippines
The Data Privacy Act gives you the rights to be informed, to object, to access, to correct, to erasure or blocking, to damages, and to data portability. If you are not satisfied with how we have handled a request, you may complain to the National Privacy Commission.
Australia and New Zealand
You may complain to the Office of the Australian Information Commissioner, or to the New Zealand Privacy Commissioner.
United States
Several states give residents rights over their personal information, including to know what is collected, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising — there is no advertising technology in this product, so there is nothing to opt out of. You may use an authorised agent, and we will verify the request through the email address on the account.
Canada
You may complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy commissioner.
Children
Pordiya is business software and is not directed at children. We do not knowingly collect information from anybody under 18. If you believe a child has provided us with information, email hello@pordiya.com and we will delete it.
Changes to this policy
When this policy changes, the date at the top changes with it. If a change materially affects your rights we will email account holders at least 30 days before it takes effect, so there is time to object or to leave.
We will not make a change that reduces the protection of data already collected without asking you first.
Contact
Questions, requests and complaints about privacy go to hello@pordiya.com, or by post to:
[YOUR NAME OR REGISTERED BUSINESS NAME — set this in Appearance → Customize → Pordiya → Legal]
[BUSINESS ADDRESS — set this in Appearance → Customize → Pordiya → Legal]
Philippines
We read everything sent to that address and reply within one business day.