Revised and posted as of June 26, 2026
Welcome to Portager ("Company", "we", "our", "us"). We are committed to protecting your privacy, confidentiality, and security of your personal information and ensuring it is handled in a safe and responsible manner in accordance with applicable laws and industry standards, including aligning to the Trust Services Criteria established by the American Institute of Certified Public Accountants (SOC 2). Our security and privacy practices are reviewed at least annually and updated accordingly to reflect changes in our operations, legal obligations, and industry best practices.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.portager.ai (the "Site") and use our SaaS platform app.portager.com (the "Platform"). Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Site or use the Platform.
Personal Information
- Contact Information: name, email address, phone number, and company name.
- Account Information: username, password, and other authentication details.
- Business Transaction Data: vendor negotiation records, deal terms, and platform activity data
generated through your use of the Portager platform.
Non-Personal Information
- Usage Data: information on how you interact with our Site and Platform, such as IP addresses, browser types, access times, pages viewed, and referring websites.
- Device Information: information about the device you are using, such as hardware model, operating system, and mobile network information.
- Log and Audit Data: system logs, access records, and audit trails generated as part of platform security monitoring. These records are retained for security and compliance purposes.
We process personal information for the following purposes:
- Providing and maintaining our services.
- Improving functionality and user experience.
- Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the Site and Platform, and for marketing and promotional purposes.
- Send you text messages and push notifications.
- Security monitoring and fraud prevention.
- Legal and regulatory compliance.
- Monitor and enforce compliance with our Terms of Use and applicable law.
We may share your information with:
Service Providers: We may engage third-party service providers (“subprocessors”) to support our services. We require all subprocessors to:
- Enter into data protection agreements.
- Implement appropriate security controls.
- Process personal information only on our instructions.
These third parties are contractually obligated to protect your information and may only use it as directed by Portager. A list of our key sub-processors is available upon written request.
Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
Compliance with Laws: Fulfill our legal and regulatory obligations, including records retention requirements and responding to lawful requests from public authorities.
Protection of Rights: To protect and defend the rights or property of the Company, our users, or others.
We collect only the information necessary to fulfill the purposes described above and do not process personal data for purposes incompatible with those stated.
Portager implements a layered set of administrative, technical, and physical security controls to protect your personal information, including:
- Encryption of data in transit using TLS 1.2 or higher, and encryption of sensitive data at rest (AES-256 or higher).
- Role-based access controls (RBAC) and the principle of least privilege to limit access to personal data to authorized personnel only.
- Multi-factor authentication (MFA) required for all personnel accessing production systems.
- Continuous monitoring of our infrastructure for unauthorized access, anomalies, and potential security incidents.
- Annual third-party security assessments and vulnerability management processes.
However, no security measures are perfect or impenetrable, and we cannot guarantee the absolute security of your data. If you believe your account or data has been compromised, please contact us immediately at security@portager.ai.
Access to personal information is restricted to authorized personnel based on business need. All personnel are subject to confidentiality obligations.
We maintain an incident response program designed to detect, respond to, and recover from security incidents. In the event of a security incident that results in unauthorized access to, or disclosure of, your personal information, Portager will:
- Conduct a prompt investigation to assess the nature, scope, and impact of the incident.
- Notify affected individuals and, where required, relevant regulatory authorities, within the timeframes required by applicable law (including within 72 hours where required under applicable state laws).
- Take reasonable steps to contain and remediate the incident and prevent recurrence.
- Document the incident and our response as part of our ongoing security program.
Breach notifications will be delivered via email to the address associated with your account, or via other reasonable means if email is unavailable.
Depending on your location, you may have the following rights regarding your personal data, subject to any additional agreement we may have with you or your company under any terms or End User License Agreements:
- The right to access - You have the right to request copies of your personal data.
- The right to rectification – You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
- The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.
- The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.
- The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
If you make a request, we will acknowledge receipt within 5 business days and respond substantively within 30 days. If additional time is required, we will notify you of the extension and the reason for the delay.
If you would like to exercise any of these rights, please contact us at privacy@portager.ai
Portager obtains consent to collect, use, and disclose your personal data for the reasonable and necessary purposes set out above. When you provide Portager with your information, such as for signing up to receive emails about business developments, you are consenting to the collection, use, and disclosure of your personal data for these purposes, in accordance with the principles outlined in this notice.
Portager retains personal data only as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law or regulation. Our general retention guidelines are:
- Account and contact data: retained for the duration of the customer relationship plus 3 years, or as required by applicable contract or law.
- Platform transaction and negotiation data: retained for 7 years to satisfy business records and regulatory requirements.
- System logs and audit records: retained for a minimum of 12 months for security monitoring and compliance purposes.
- Marketing communications data: retained until you unsubscribe or 2 years of inactivity, whichever comes first.
Where legal obligations prevent us from fulfilling a deletion request, we will notify you of the relevant obligation and the expected retention period.
Our Site and Platform may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Our Site uses cookies and similar tracking technologies to operate and improve your experience. Cookies may be set by Portager directly or by third-party services we use (such as authentication providers and analytics tools). Categories of cookies we use include:
- Essential / functional cookies: required for authentication and core platform functionality. These cannot be disabled without affecting service availability.
- Analytics cookies: used to understand aggregate usage patterns and improve our service. These may be set by third-party analytics providers.
You can manage cookie preferences through your browser settings. Disabling non-essential cookies will not affect your ability to use the core Portager platform. Please note that some third-party cookies (e.g., authentication session cookies from our identity provider) are required for login and cannot be disabled.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or business operations. When we make material changes, we will notify you by: (a) email to the address associated with your account, and (b) posting the updated policy on this page with a revised "Last Updated" date. Minor changes (such as clarifications) may be posted without individual notice. We encourage you to review this policy periodically. Your continued use of the Site or Platform following the posting of changes constitutes your acceptance of those changes.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides California consumers with various privacy rights. These rights include the right of disclosure and access (the right to request to know more details about the categories Portager collects), the right to deletion of personal data, the right to opt-out of the sale or sharing of personal data for cross-context behavioral advertising, the right to correct inaccurate personal data, and the right to not be discriminated against for exercising these rights.
Categories of personal information we collect (and have collected over the past 12 months) include contact details (name, telephone, and work email) and employee work purchase history, if using the Portager platform (internal purchases, approval records, and payment records). We also collect the platform interaction and log data described above.
Portager does not sell personal information, nor does it share personal information for cross-context behavioral advertising purposes.
California consumers may request additional information or exercise their rights by emailing privacy@portager.ai.
Given that Portager's site and application are not directed to users under 18 years of age, Portager does not sell or share the personal information of any minors under 18. If you are a parent or guardian and believe Portager collected information about your child, please contact Portager and we will take steps to delete the information as soon as possible.
Our Site and Platform are not intended for use by individuals within the European Economic Area (EEA) who are subject to the General Data Protection Regulation (GDPR). If you are located within the EEA, please do not use our Site or Platform. We do not knowingly collect or process personal data of individuals within the EEA.
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
- Privacy inquiries and data subject requests: privacy@portager.ai.
- Security incidents or concerns: security@portager.ai.
- General support: support@portager.ai (for billing, product, and non-privacy inquiries).
- By visiting our website: www.portager.ai.