1. Who Is Responsible
Otterportal operates the Otterportal service and is responsible for the account, billing-relationship, security, and operational information it handles for its own purposes. Stripe handles payment and billing information under its own terms and privacy notice; Stripe's privacy role may differ depending on the service and processing activity.
When a person submits a privacy request through a customer's portal, that customer generally determines why and how the request information is used. The customer's name, contact address, and privacy-notice link are displayed in its request portal. Questions about the customer's decisions should be directed to that customer.
The self-service MVP is intended for U.S.-based business customers. A requester's stated location is recorded for the customer's routing and review; Otterportal does not use it to select a law, deadline, or legal outcome.
2. Information We Handle
- Workspace information: name, work email, organization, role, authentication and multi-factor-authentication records, session information, organization configuration, and versioned acceptance records for the Terms and this Privacy Notice.
- Billing information: billing contact name and email, legal business name, billing address, tax jurisdiction and tax identifiers, selected plan and billing interval, invoices, and Stripe customer, Checkout, subscription, payment, and transaction identifiers and statuses. Payment-method, address, and tax details are entered on Stripe-hosted pages and handled by Stripe. Otterportal's active application database stores limited Stripe customer, Checkout-session, subscription, and price references and subscription status—not full payment-card or bank-account numbers, billing addresses, tax identification numbers, or invoice copies.
- Request information: requester name and email, request type, stated location, optional account reference, request description, and messages.
- Workflow information: status and activity history, internal notes, organization-configured target dates, verification events, audit events, and delivery records.
- Operational information: session and authentication-challenge records, rate-limit records, error and security logs, encrypted queued-email content, email delivery status, and maintenance and retention records.
3. Where Information Comes From
- Workspace administrators and users provide account, organization, configuration, note, and message content.
- Requesters provide their contact details, request information, stated location, and optional account reference.
- Workspace administrators or other authorized billing users provide billing contact, business, address, and tax information through Stripe-hosted billing pages.
- The application creates authentication, verification, workflow, delivery, security, and activity records as people use the service.
- Stripe creates and maintains customer, Checkout, subscription, invoice, payment, tax, and transaction records and returns limited identifiers and status updates used to administer paid subscriptions.
- Configured hosting, database, email, and monitoring providers may create or return availability, delivery, diagnostic, and security records.
4. Why We Handle Information
Otterportal handles information to:
- create, administer, authenticate, and secure workspace accounts;
- offer and administer subscriptions, collect fees, provide billing-management and invoice access, calculate applicable taxes, address failed payments, and maintain billing records;
- receive, route, track, and document privacy-request workflows;
- provide requester tracking and send service and security messages;
- maintain audit, verification, delivery, and retention records;
- detect and investigate suspected abuse, unauthorized access, service errors, or delivery failures; and
- support, maintain, and improve the reliability of the service and meet the operator's legal obligations.
Otterportal does not determine which privacy law applies, decide whether a request is valid, select a legally required response date, or make legal decisions for the customer.
5. Cookies and Similar Technology
Otterportal uses HTTP-only cookies for administrator and requester sessions and for temporary authentication challenges. The application configures these cookies with SameSite protections and, in production, the Secure attribute. State-changing requests also use same-origin checks.
The current application does not include advertising trackers, cross-site behavioral advertising, or a general-purpose analytics tracker. This notice must be reviewed and updated before a deployment adds analytics, advertising, or other tracking technology.
Stripe-hosted Checkout and billing-management pages may use cookies or similar technology for payment processing, authentication, fraud prevention, security, and service analytics. Stripe describes those practices in its own privacy notice.
6. When Information Is Disclosed
Information may be disclosed to:
- authorized users of the customer identified in the request portal;
- Stripe, the configured payment provider, which processes billing contact details, business names, addresses, tax identifiers, payment-method information, subscription selections, invoices, payments, refunds, disputes, and related transaction information to provide checkout, billing, tax, fraud-prevention, and payment services;
- configured hosting, database, email-delivery, backup, and monitoring providers that process information to provide their services;
- government authorities, courts, advisers, or other parties when reasonably necessary to respond to valid legal process, protect rights or safety, or investigate suspected abuse; and
- participants in a reviewed financing, acquisition, reorganization, or sale of all or part of the business, subject to appropriate confidentiality and legal requirements.
The deployment operator is responsible for documenting the actual providers, subprocessors, agreements, and disclosure practices used in production.
Stripe may process information on the operator's instructions and for its own purposes, such as meeting legal obligations and preventing fraud, as described in Stripe's Privacy Policy and applicable service terms.
7. Sale, Advertising, and AI Use
The current MVP does not include functionality to sell workspace or request content, use that content for cross-context behavioral advertising, or process customer content with artificial-intelligence models. Disclosing information to providers that operate the service is not an advertising use.
Before introducing a materially different use, the operator must review and update this notice and provide any notice or choice required by applicable law.
8. Retention and Deletion
Workspace administrators can configure retention periods for eligible request, audit, verification, and email-delivery records. Scheduled maintenance applies those settings only when automated retention is enabled. Request records become eligible for scheduled deletion only after they reach a closed, declined, or withdrawn status and pass the configured retention period. Expired sessions, authentication challenges, verification links, rate-limit records, and completed delivery records are cleaned up on separate schedules.
Self-service account deletion can remove an individual user or, when the user is the last member, the workspace and its active-database records. In a workspace with other users, a limited account-deletion audit record is preserved. Deletion from the active database does not establish immediate deletion from backups, infrastructure logs, caches, email providers, or downstream systems; those systems have separate lifecycles and may also be subject to legal-preservation requirements.
Otterportal keeps its Stripe customer and subscription references, current billing status, and limited webhook-processing records while needed to operate the workspace, reconcile billing, prevent duplicate processing, or meet legal obligations. Stripe separately retains payment, invoice, tax, dispute, and transaction records under its own terms, account settings, and legal obligations. Canceling a subscription or deleting a workspace therefore does not necessarily cause immediate deletion of records held by Stripe. Production placeholder: the deployment operator must document and apply its actual financial-record retention schedule and Stripe deletion-request workflow before accepting live payments.
9. Security
Otterportal includes role-based access controls, scoped permissions and sessions, signed and expiring links, rate limiting, protected audit records, browser security headers, and application-layer encryption for selected secrets and queued email content when properly configured.
Production startup requires the operator to confirm protected database transport or private networking and data-at-rest encryption. Hosting, network, database, backup, monitoring, access review, and incident-response controls still depend on the production operator and its providers. No online service can guarantee that information will never be accessed, lost, or misused.
10. Children
Otterportal workspace accounts are a business service and are not directed to children under 13. A customer receiving a request remains responsible for determining whether and how it may handle information concerning a child or an authorized representative. If the operator learns that a child directly created a workspace account, it should investigate and take appropriate action.
11. Your Choices and Rights
For a privacy request submitted to a customer, contact that customer using the address in its portal. Depending on location and context, a person may have rights or choices concerning personal information; the customer controlling the request decides how to evaluate and respond to it.
Workspace users can use the available account-deletion control. Requests to access or correct workspace-account information, or questions about this notice, may be directed to the service operator using the contact information below. Requests may be subject to identity checks, legal exceptions, and record-preservation obligations.
An authorized workspace user can review or update available billing information through the Stripe billing-management portal. Requests concerning billing information held for Otterportal may be sent to the service operator using the contact information below. Stripe may direct requests about data it processes for Otterportal back to the operator and may handle other requests under its own privacy notice.
12. Third-Party Services
A production deployment may rely on configured hosting, database, email-delivery, monitoring, backup, and payment services. When paid billing is enabled, Otterportal uses Stripe-hosted checkout and billing-management pages. Those providers process information under their own service terms and privacy commitments. The actual provider and subprocessor list must be completed and kept current before production use. Production placeholder: the exact Stripe contracting entity and any additional billing or tax providers depend on the production account and customer location and must be documented by the deployment operator. If Stripe is replaced or supplemented, this notice must be updated before the new provider processes personal information. The current MVP does not provide a functional customer-integration or object-storage workflow; this notice must be updated if those features are added.
13. Changes to This Notice
This notice may change as the product and its operating practices change. Material changes should be presented through reasonable notice before they apply prospectively. If a proposed change would materially expand how previously collected information is used, the operator must first assess any notice, choice, consent, or other legal requirement. The updated date and document version are retained with new account acceptance records.
14. Contact
For questions about an Otterportal workspace account or this Privacy Notice, the deployment operator must publish a legal contact before production use.
The deployment operator must also publish a mailing address before production use.