Privacy Policy
Last updated: 2026-08-13
This policy explains what personal data SpaceOS collects, why, who we share it with, and the choices you have. SpaceOS is operated by Portonics Limited, Dhaka, Bangladesh. A key distinction runs through it: for your own account and billing data we are the controller, while for the business and end-customer data you keep inside your Space we act only as a processor, on your instructions.
1. Scope
This policy covers the SpaceOS marketing website, the SpaceOS application, the storefronts and public pages our customers run on the platform, and the emails and notifications we send. It does not cover third-party sites you reach from ours, or a customer's own privacy practices inside their Space — for those, contact that business directly.
2. Controller and processor: which is which
When you sign up for SpaceOS, we decide how your account, billing, and usage data are handled — there we are the controller. When you run your business on SpaceOS, the customer records, orders, bookings, staff records, and files inside your Space are yours; we hold and process them on your behalf and on your instructions, as a processor. If you are an end customer of a business that uses SpaceOS, that business is the controller of your data, and requests about it should go to them first — we will help them action it.
3. What we collect
| Category | Examples | Our role |
|---|---|---|
| Account data | Name, work email, phone, password hash, role, language, sign-in and session records, Google profile basics if you use Google Sign-In | Controller |
| Space and business data | Company name, addresses, branding, module configuration, products, bookings, orders, invoices, inventory, payroll, files and reports you create | Processor |
| End-customer data | Your customers' and visitors' names, contact details, delivery addresses, order and booking history, loyalty balances — entered by you or by them on your storefront | Processor |
| Billing data | Subscription plan, invoices, payment status, card brand and last four digits (full card numbers stay with our payment processors) | Controller |
| Technical data | IP address, device and browser type, timestamps, pages viewed, referrer, error diagnostics, audit-log entries | Controller |
| Enquiry data | Anything you send us through the demo form, support portal, or email, plus first-touch campaign attribution | Controller |
We do not intentionally collect special-category data (health, biometrics, religious or political views). Do not put it into free-text fields. We do not sell personal data, and we do not use your business or end-customer data to train machine-learning models for other customers.
4. How we use it
- to create and administer accounts, Spaces, and user access;
- to provide the modules you have enabled and operate the platform day to day;
- to process subscription payments, issue invoices, and collect amounts due;
- to send service communications — invitations, password resets, receipts, booking and order notifications, security alerts, and material changes to these policies;
- to provide support, investigate incidents, and reproduce reported problems (support access to a Space is logged);
- to keep the platform secure and reliable: authentication, rate limiting, abuse and fraud detection, audit logging, error monitoring, and backups;
- to understand usage in aggregate and improve the product, and — with consent — to measure marketing campaigns;
- to meet our legal, tax, and accounting obligations, and to enforce our terms.
Depending on where you are, our legal grounds are: performance of our contract with you, our legitimate interests in running and securing the service, your consent (for analytics cookies and marketing email), and compliance with legal obligations. You can withdraw consent at any time without affecting processing that already happened.
5. Cookies and analytics
We use a small number of first-party cookies and similar storage:
- Strictly necessary — session and authentication cookies, workspace selection, and security tokens. The platform cannot work without them, so they are not subject to consent.
- Preference — theme, language, and layout choices you have made.
- Analytics — Google Analytics 4, used to count visits and understand which pages and features get used. On our marketing site these tags load only after you accept them in the cookie banner; decline and they are never loaded. You can change your mind by clearing site data for this domain and choosing again.
- Attribution — a first-party cookie that remembers which campaign or referrer brought you to the site, so a demo request can be credited correctly. It holds no name or email.
Storefronts run by our customers have their own consent banner, controlled by that business, which gates any analytics or advertising tags they have configured. We configure GA4 with advertising signals and ad personalisation switched off, and we do not use it for cross-site advertising. We do not currently respond to Global Privacy Control or Do Not Track browser signals in a standardised way; the consent banner is the control that governs.
6. Who we share it with
We share personal data with service providers who process it on our behalf, under contract, and only for the purposes below. These are our current sub-processors:
| Provider | What they do | Where |
|---|---|---|
| Vercel | Application hosting, CDN, and edge routing | United States / global edge |
| Supabase | Managed PostgreSQL database, backups, and file storage | Regional cloud (Singapore / United States) |
| Stripe | Subscription billing and card payment processing | United States / global |
| PortPos | Payment gateway for local (Bangladesh) card and wallet payments | Bangladesh |
| Resend | Transactional email delivery (invitations, receipts, alerts) | United States / EU |
| Upstash | Redis for rate limiting, queues, and short-lived caches | Regional cloud |
| Sentry | Application error and performance monitoring | United States / EU |
| Google (Analytics 4) | Website and product usage analytics, after consent | United States / global |
We also share data: with integrations you switch on (for example a messaging or delivery provider you connect); with professional advisers under confidentiality; where required by law, regulation, or valid legal process; where necessary to protect our rights, our customers, or public safety; and with an acquirer in the event of a merger, acquisition, or sale of assets, under equivalent protections. We will give notice, where lawful, before disclosing customer data in response to a legal request.
7. International transfers
Portonics Limited is based in Bangladesh, and our infrastructure providers operate globally. Personal data processed through SpaceOS is therefore likely to be transferred to, stored in, and accessed from countries other than your own — including the United States, Singapore, and the European Union — whose data-protection laws may differ from those where you live. Where such transfers involve data protected by the UK GDPR, EU GDPR, or a comparable regime, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses in our agreements with sub-processors, and we apply encryption in transit and access controls throughout.
8. How long we keep it
- Space and end-customer data — for as long as your Space is active, and for 30 days after termination so you can export it or reactivate, after which it may be permanently deleted.
- Account data — for the life of the account, plus a short period afterwards for security and dispute-handling.
- Billing and invoice records — for as long as tax and accounting law requires, typically several years, even after the account closes.
- Security, audit, and error logs — for a limited retention window sized to incident investigation, then deleted or aggregated.
- Backups — deletions propagate to backups on our standard rotation, so a deleted record can persist in an encrypted backup for a short period before ageing out.
9. Your rights and choices
Subject to the law that applies to you, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to processing, receive it in a portable format, and complain to a supervisory authority. To exercise any of these, write to spaceos@portonics.com. We will verify your identity and respond within 30 days; where we act as a processor for a business customer, we will pass the request to them and support them in answering it.
You can also manage a lot yourself: update your profile and notification preferences in your account settings, unsubscribe from marketing email using the link in the footer of any such email (service emails cannot be switched off while your account is active), and accept or decline analytics cookies from the banner.
10. Data deletion requests
SpaceOS has a deletion-request flow built into the product. A staff member with access to a customer record can file a data-deletion request on that customer's behalf from the customer's page in the dashboard. Filing a request does not itself erase anything: it records the request, notifies the Space's owners and SpaceOS support, and places it in a review queue where a person completes or rejects it, with the outcome communicated to the address on the request. We target closing these out within 30 days of filing.
Erasure is a reviewed, manual act on purpose. Records tied to completed financial transactions — invoices, payments, tax records — usually cannot be deleted outright; in those cases we anonymise the personal details and retain the financial record for as long as the law requires.
To delete an entire account or Space, or if you are an end customer and the business you dealt with is unreachable, write to spaceos@portonics.com and we will handle it directly.
11. Security
We protect personal data with encryption in transit (TLS), hashed credentials, role-based access control, per-Space data isolation enforced in the application layer, rate limiting, a strict content-security policy, audit logging of sensitive actions, least-privilege access for our own staff, and regular backups. We monitor for errors and anomalies and run periodic vulnerability scans. If a breach affects your personal data and poses a risk to you, we will notify you and any relevant regulator without undue delay.
12. Children
SpaceOS is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has been provided to us, contact us and we will delete it.
13. Changes to this policy
We will update this policy when our practices or the law change. The "last updated" date above always reflects the current version, and material changes are notified by email or in-product notice before they take effect.
14. Contact us
Portonics Limited, Dhaka, Bangladesh — privacy enquiries, access and deletion requests, and sub-processor questions: spaceos@portonics.com. Your use of SpaceOS is also governed by our Terms of Service and Refund & Cancellation Policy.
Questions? spaceos@portonics.com
Portonics Limited · Dhaka, Bangladesh