Privacy Policy

Effective [August 20, 2026]. Last updated [August 20, 2026].

This policy explains what Pordiya does with personal information — yours, and your customers’. Those are two different things and the law treats them differently, so this policy treats them differently too.

Pordiya is operated by [Pordiya, Inc.] (“Pordiya”, “we”, “us”), a company registered in the Philippines.

The short version

  • We collect the minimum needed to run your account: who you are, what you use, and what you pay.
  • We do not sell personal information, and we never have. There are no advertising trackers in the app or on this website.
  • Your customers’ records — their names, addresses, job details — belong to you. We hold them on your behalf and only do what you tell us to do with them.
  • Everything lives on servers in Singapore.
  • You can export everything you have put into Pordiya, at any time, and take it with you.

The rest of this page is the detail behind those five points.

1. Two different roles

This is the most important thing on the page, and most privacy policies for software like this skate over it.

For your own information, we are the controller. Your name, your email address, your business details, what plan you are on — we decide what happens to that, and this policy governs it.

For your customers’ information, we are the processor and you are the controller. When you add a client, write a quote or record a job address, you are the one deciding to collect that person’s details. We simply store and process it on your instructions. We do not decide what to do with it, we do not use it for our own purposes, and we do not have any relationship with the person it describes.

That matters in practice: if one of your customers asks to see or delete their information, you answer them, and we help you do it. The terms governing that relationship are in our Data Processing Agreement, which forms part of your contract with us.

2. Information we collect about you

When you create an account

  • Your name and email address
  • Your business name, trading name, address, phone number and tax number, if you enter them
  • Your country, currency, timezone and language preference
  • The role each person on your account holds — owner, office or field

We need these to run the service. Your tax number and business address exist because they have to appear on the invoices you send.

When you use the service

  • Which pages you opened and which actions you took, tied to your account
  • The date and time of each sign-in
  • Your IP address, kept briefly, and used to limit abusive request rates
  • Your browser and device type

We use this to keep the service running, to stop abuse, and to work out what to build next. We do not use it to build a profile of you, and it is not shared with advertisers, because there are none.

When you pay us

Card details go directly to Stripe and never touch our servers. We receive and store only: the last four digits, the card type, the expiry date, your billing country, and a record of what you were charged and when.

When something breaks

The app records errors so we can fix them. An error record can contain the address of the page you were on, the account it happened in, and a technical stack trace.

These are scrubbed before they are stored. Email addresses, access tokens, passwords, database credentials and card-shaped number sequences are stripped out on the way in, not on the way out — so they are never written to the database at all. Error records are deleted automatically after 30 days.

If something goes wrong you will see a short reference code on screen. Sending us that code lets us find the exact fault without asking you to describe it.

When you contact us

Whatever you put in the message, plus your name and email address, so we can reply. Enquiries sent through our website are stored so a mail failure does not lose your message.

3. What we do not do

  • We do not sell or rent personal information to anyone, for any price.
  • We do not share it with advertisers or data brokers.
  • We do not run advertising trackers, analytics pixels or session recorders.
  • We do not read your business data to train models.
  • We do not email you marketing you did not ask for.

Our website loads no third-party scripts at all. That is also why it has no cookie banner: there is nothing to consent to.

4. Why we are allowed to hold it

For customers in the UK, the European Economic Area and other places with similar law, our lawful bases are:

WhatBasis
Running your account and providing the servicePerformance of a contract with you
Taking payment and keeping billing recordsContract, and legal obligation
Keeping the service secure, and stopping abuseOur legitimate interests
Fixing faults and improving the productOur legitimate interests
Keeping invoice and tax records after you leaveLegal obligation
Sending you a product email you asked forConsent, withdrawable at any time

Where we rely on legitimate interests, we have considered whether it is fair to you, and we have limited what we collect accordingly.

5. Who else handles it

We use a small number of service providers. Each one is bound by contract to protect the information and to use it only for the service they provide us.

ProviderWhat they doWhere
Vultr Holdings CorporationHosts the servers and the databaseSingapore
SupabaseSign-in links and identity verification onlySingapore
Stripe, Inc.Payment processingUnited States

That is the complete list. When it changes, this table changes with it, and customers on paid plans are told in advance — see the Data Processing Agreement for the notice period.

We will also disclose information where we are legally required to: a valid court order, a lawful request from a regulator, or where it is necessary to protect someone from harm. If we ever receive such a request about your account, we will tell you unless we are legally prohibited from doing so.

6. Where it lives, and moving it across borders

All customer data is stored on servers in Singapore. Backups are held in the same region.

We are a Philippine company, so our staff access data from the Philippines. Payments run through Stripe.

Singapore is not covered by a UK or EU adequacy decision. Where personal information is transferred out of the UK or the European Economic Area, that transfer is covered by:

  • the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, and
  • the European Commission’s Standard Contractual Clauses for transfers from the EEA,

together with the technical measures described in section 8. These are set out in the Data Processing Agreement, which you can enter into with us at no cost — just ask.

For Australian customers: this is a disclosure of personal information to overseas recipients under Australian Privacy Principle 8, and the recipients are those listed in section 5.

7. How long we keep it

WhatHow long
Your account and business detailsWhile your account is open
Your customers’ records, quotes and jobsWhile your account is open, then 30 days
Invoices, credit notes and payment records7 years, because tax authorities require it
Error records30 days
Access logs and audit records12 months
Support enquiries3 years
Marketing preferences and unsubscribesIndefinitely, so we do not email you again by mistake

When you close your account we give you 30 days to export everything, then delete it. Invoices and payment records are the exception: tax law requires them to be kept, and it requires it of you as much as of us.

Backups are overwritten on a rolling cycle, so deleted data can persist in backups for up to 30 days after deletion.

8. How it is protected

  • Every business’s data is separated by the database itself, not by a filter in our code. One account cannot read another’s even if the application asks it to. That is a stronger guarantee than a check in software, because it holds when the software has a bug — and all software has bugs.
  • All traffic is encrypted in transit with TLS.
  • Passwords are not used. Sign-in is by a one-time link sent to your email address, so there is no password of yours for us to lose.
  • The database runs under a restricted account that cannot create or destroy tables.
  • Finalised invoices cannot be silently altered, by us or by anyone.
  • Sensitive values are stripped from error records before storage.

No system is perfectly secure, and anybody who tells you otherwise is selling something. If a breach affects your personal information, we will notify you and the relevant regulator within the time limits the law sets — see the Data Processing Agreement for the specifics.

9. When we look at your account

Sometimes supporting you means looking at your account. So that this is honest rather than assumed:

  • Our support console is read-only for customer records. It can see, and it cannot change your quotes, invoices, clients or prices.
  • We can change account status — suspend, reactivate, extend a payment deadline, change a plan — and nothing else.
  • Every view and every change is written to an append-only audit log, which cannot be edited or deleted, including by us.
  • We cannot sign in as you. There is no impersonation feature, deliberately.

If you want to know whether we have looked at your account, ask, and we will tell you what the log says.

10. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Correct anything inaccurate
  • Delete it, subject to records we must keep by law
  • Export it in a portable format — this one is a button in the app, you do not need to ask
  • Object to or restrict certain processing
  • Withdraw consent where we relied on it
  • Complain to a regulator

To exercise any of these, email hello@pordiya.com. We will respond within 30 days, and we will not charge you or make the service worse because you asked.

If you are in California: you may request the categories and specific pieces of personal information collected, request deletion or correction, and you may not be discriminated against for asking. We do not sell or share personal information as those terms are defined by California law, so there is nothing for you to opt out of.

If you are in the UK or the EEA: you may complain to your supervisory authority — the Information Commissioner’s Office in the UK, or your national authority in the EEA.

If you are in Australia: you may complain to us first, and then to the Office of the Australian Information Commissioner if you are unsatisfied.

If you are in New Zealand: you may complain to the Office of the Privacy Commissioner.

If the request concerns data held in Pordiya by one of our customers — for example you received an invoice from a business using Pordiya — please contact that business directly. They control that information; we only store it for them. If you cannot reach them, tell us and we will pass your request on.

11. Cookies and storage on your device

The app stores things on your device because it has to work without a signal:

WhatWhyHow long
Sign-in sessionTo keep you signed inUntil you sign out
Language preferenceSo the app opens in your languageUntil cleared
Offline queueHolds work created with no signal, until it sendsUntil synced
Offline copy of your dataSo the app opens and works without a connectionUntil cleared

None of these track you and none are shared with anyone. There are no advertising or analytics cookies, on the app or on our website.

Clearing your browser storage while work is still queued will lose that work, so let the app finish syncing before you do.

12. Children

Pordiya is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.

13. Changes

If we change this policy in a way that materially affects you, we will email account owners at least 30 days before it takes effect, and note the change at the top of this page. Continuing to use Pordiya after that date means the new version applies.

Minor corrections — a typo, a clearer sentence, a new sub-processor added to the table — take effect when published.

14. Contact

Questions, requests, or complaints:

Pordiya, Inc. hello@pordiya.com

We answer every message from a person, within one business day wherever we can.

Site by Two Shores Online