Portfolist
FeaturesHow it worksPricing
Log inCreate your profile
Menu
Portfolist
FeaturesHow it worksPricing
Log inCreate your profile
Portfolist

Your professional profile, always up to date.

Portfolio BuilderCV BuilderStudent Portfolio BuilderDeveloper Portfolio BuilderPricingLog inRegisterChangelogTerms of ServicePrivacy PolicyRefund Policy

Legal

Privacy Policy

How Portfolist handles account data, portfolio content, images, messages, payments, analytics, cookies, and third-party service providers.

Last updated: June 2026

1. Overview

This Privacy Policy explains how Portfolist collects, uses, stores, and protects information when you create an account, build portfolios, upload images, send or receive messages, subscribe to Premium, or visit public portfolio pages.

2. Account Data

  • We collect account details such as name, email address, username, profile image, account type, plan, authentication provider information, and account timestamps.
  • If you create a business account, we may collect company name, website, description, logo, and verification status.
  • If you choose email/password login, Portfolist stores a password hash rather than your raw password.
  • Portfolist may send email verification messages and store verification status, verification timestamps, hashed verification tokens, token expiry timestamps, and resend-rate-limit metadata.
  • We use account data to authenticate you, operate the dashboard, enforce plan limits, personalize the service, and provide support.

3. Portfolio Data

  • We collect portfolio titles, slugs, visibility settings, templates, themes, sections, SEO fields, privacy controls, and version snapshot information.
  • Public portfolios may be visible to anyone with the link and may be indexed by search engines when indexing is enabled.
  • Unlisted and private portfolios are handled according to their visibility settings, but you should avoid storing highly sensitive information in portfolio content.
  • You control whether certain optional information, such as location, public email, and public phone, appears on portfolio pages.

4. Uploaded Images

  • Portfolist may collect and store uploaded images such as profile photos, project images, company logos, testimonial avatars, and portfolio media.
  • Images may be processed, resized, transformed, or hosted through Cloudinary so they can be displayed reliably in your dashboard and public portfolios.
  • You are responsible for ensuring uploaded images do not contain private information or content you do not have permission to use.

5. Messages

  • When visitors or users send messages through Portfolist, we collect message body, sender name, sender email, optional company details, reason, thread status, and timestamps.
  • Messages are used to deliver private outreach to portfolio owners without exposing private contact information publicly.
  • Portfolist may apply spam protection, rate limiting, and moderation to protect users and maintain service quality.

6. Analytics and Views

  • Portfolist may collect simple portfolio analytics such as page views, rough unique visitor identifiers, referrer, country from request headers when available, device type, CTA clicks, and message button clicks.
  • Analytics are used to show portfolio performance in the dashboard and to maintain the reliability and security of the service.
  • Portfolist is designed to keep tracking lightweight and privacy-conscious rather than using complicated behavioral tracking.

7. Cookies and Auth Sessions

  • Portfolist uses cookies or similar session storage to keep users signed in, protect authenticated routes, and operate security features.
  • Authentication providers may set their own cookies or process authentication-related information according to their policies.
  • You can control cookies through your browser settings, but disabling them may prevent account login or dashboard features from working.

8. Payment and Billing Data

  • Portfolist does not store full card or payment account details.
  • Payment information is processed by PayPal.
  • PayPal may collect billing name, email, payment method details, tax or VAT information, billing address, transaction history, and fraud-prevention data.
  • Portfolist may store subscription status, plan, customer ID, transaction references, renewal or cancellation status, and billing metadata needed to manage Premium access.

9. Email Verification and Newsletter

  • Portfolist may send transactional emails such as email verification messages, account notices, support replies, and future password reset emails.
  • If you opt into Portfolist updates, product news, and launch announcements, we store newsletter subscription status, subscription and unsubscribe timestamps, and an unsubscribe token.
  • Newsletter emails include an unsubscribe link, and you can unsubscribe anytime from that link or from account settings.
  • Portfolist may use an email provider such as Resend to process email address, message content, delivery metadata, and unsubscribe-related data needed to send and manage email delivery.

10. Third-Party Services

  • MongoDB or database hosting providers may be used to store account data, portfolio data, messages, analytics events, and application records.
  • Cloudinary may be used to upload, process, transform, host, and deliver images.
  • PayPal may process payments, billing, taxes, invoices, subscription management, payment status, account management, and billing-related webhooks.
  • Resend or another email provider may process email addresses, delivery metadata, unsubscribe links, and transactional or newsletter email content.
  • Authentication providers, such as Google or other configured providers when enabled, may be used to sign users in and verify account identity.
  • Vercel or other hosting providers may process request logs, deployment data, performance data, and infrastructure metadata needed to host Portfolist.
  • An email provider may be used if Portfolist sends account, billing, support, notification, or transactional emails.

11. User Privacy Controls

  • Portfolio owners can set portfolio visibility to public, unlisted, or private.
  • Portfolio owners can control whether messages are allowed, whether location appears, whether email or phone are shown publicly, and whether public pages allow search engine indexing.
  • Email and phone are not public by default and should only appear when both account and portfolio settings allow them.

12. Data Deletion Requests

  • You may request deletion of your account or certain data by contacting Portfolist support.
  • Some records may be retained when required for security, fraud prevention, billing records, legal compliance, dispute handling, or service integrity.
  • Deleted public content may take time to disappear from search engine caches or third-party archives outside Portfolist control.

13. Contact

For privacy requests or questions, contact Portfolist at support@portfolist.com.

Questions about this policy? Contact support@portfolist.com.

Related policies

Terms of ServicePrivacy PolicyRefund Policy