Privacy Policy
Most privacy policies are long because the company holds a lot. Ours is short because the software runs on your computer and your business data never reaches us.
Last updated 21 September 2026
The short version
- Your business data never reaches us. Customers, jobs, invoices, documents, email, accounting — all of it stays in a database on your own computer.
- We hold what it takes to sell you a licence and give it back to you when you lose it: your name, your email address, what you bought, and the key itself.
- We never see your card. Stripe takes the payment.
- We do not sell or share anything with advertisers, data brokers or anybody else, and we never will.
- QuickBooks tokens pass through and are not stored — no database row, no log line, nothing at rest.
PortalPoint Technology Solutions LLC of South Plymouth, New York is the controller of the personal data described below. Questions, or any request under this policy, go to Trent@portalpointsolutions.com.
What the desktop software does with your data
PortalPoint is installed software, not a hosted service. Its database and its files live in a folder on the computer you installed it on, and it serves the application to you over your own network. We have no access to it, no copy of it, and no way to reach it.
That means the things a hosted product would do for you are yours to do: taking backups, deciding who on your network may reach the server, and keeping the machine patched. The software has a backup tool and a diagnostics page to make those easy, and the handbook inside the application explains them.
It also means that if you receive a data request about one of your own customers — an access request, a deletion request — you can answer it yourself, from your own database, without asking us. There is nothing for us to hand over.
What this website collects
Four things, each for one reason:
When you buy a licence
Your name, your email address, what you chose (modules, seats, number of businesses), the amount charged, and the licence key we issue. We keep the key itself so we can send it again if you lose it, rather than issuing you a second one.
Payment is handled by Stripe. Your card number never touches this site and we never hold it. Stripe tells us the payment succeeded and nothing more. Stripe processes it as a controller in its own right, under its own privacy policy.
When you start a free trial
Your name, your email address and the trial key. The address is the identity for a trial, which is how one trial per business is enforced. If you later buy, we record that the purchase came from a trial.
When you recover a lost licence key
You give an email address; we email a single-use link to it if there is a licence registered at that address. The link is stored only as a hash with a short expiry, and it stops working the moment it is used — so a forwarded email is harmless. We deliberately give the same answer whether or not an address has a licence, because otherwise this page would tell a stranger who our customers are.
When the software checks in
An installation with a network connection tells us it is alive. It sends the licence key, a fingerprint of the machine, the application version, the operating system, and a short hint of the computer’s name, and we record when it was first and last seen and how many times it has checked in.
The fingerprint is a hash of stable machine facts. It is not reversible into a person or a machine, and its only job is to count installations against the seats a licence covers. No business data is ever sent.
When you contact us
A message through the contact form reaches us by email with whatever you put in it. We keep it as long as the conversation is useful.
QuickBooks and other connections
Intuit does not permit a desktop application to receive an OAuth redirect directly, and offers no way to connect without a client secret. Shipping that secret inside a downloadable application would hand it to anyone who downloads the application, so the handshake is brokered by this website instead.
Nothing from it is stored here. The authorisation code is passed back to your own installation, the token exchange and every later refresh are performed and answered in the response, and the tokens are kept on your computer. There is no database row, no cache entry and no log line holding them, and this website never reads your QuickBooks company data. What authorises the exchange is the signed licence key your installation already holds.
Microsoft 365, Google and other connections are made by your own installation directly, and their tokens never leave your computer at all. If you supply an API key for an AI provider, your installation talks to that provider directly and we are not in the path.
Who else touches it
- Cloudflare — hosts this website and its database, and sees the ordinary request information any web host sees.
- Stripe — takes payments and holds the card details we never see.
- Microsoft — delivers our outbound email, including your licence key.
- Intuit — is the other end of the QuickBooks handshake described above.
That is the complete list. We do not use advertising networks, third-party analytics or tracking pixels, and this site sets no advertising or tracking cookies.
How long we keep it
- Licence records — for as long as the licence exists, and afterwards for as long as tax and accounting law requires us to keep a record of the sale.
- Trial records — two years, then deleted.
- Check-in records — for the life of the licence. They are deleted with it.
- Recovery links — minutes. They expire quickly by design.
Your rights
You may ask us what we hold about you, ask for it to be corrected, ask for a copy, or ask us to delete it. Write to Trent@portalpointsolutions.com and we will answer within 30 days. There is no charge.
Deletion has one limit worth stating plainly: if you still hold a valid licence, deleting the record of it means we can no longer prove it is yours, re-send it, or support it. Your installation will keep working — it verifies the key by signature, not by asking us — but the key would be gone from our side for good. We will say so before we do it.
If you are in the UK or the European Economic Area, our lawful bases are the contract between us (issuing and supporting your licence) and our legitimate interest in enforcing the terms of a licence we sold (the check-in). You have the right to complain to your data protection authority.
If you are in California: we do not sell or share personal information as those terms are defined by the CCPA, and we have not in the preceding twelve months.
Children
This is business software. It is not directed at children, and we do not knowingly collect personal information from anyone under 16.
Security, and what to do if something goes wrong
Traffic to this website is encrypted in transit. Secrets are held in the hosting platform’s secret store and not in our source code. The licence signing key exists in one place and cannot be read back out of it. On your own machine, the software encrypts stored credentials and locks its data folder to administrators.
If we ever suffer a breach affecting your personal data, we will tell you and the relevant authority without undue delay, and we will tell you what was affected rather than the minimum we can get away with.
If you find a security problem in our software or this website, please tell us at Trent@portalpointsolutions.com. We would much rather hear from you than not.
Changes
We may update this policy. The date at the top is when it last changed. If a change materially affects what we collect or why, we will say so here rather than quietly revising it.
The licence terms that go with this policy are the end user licence agreement.