This Privacy Policy explains how Portalyx ("Portalyx", "we", "us", or "our") collects, uses, shares, and protects information when you use the Portalyx admin dashboard, the Portalyx Driver mobile application, our website, and related services (together, the "Service").
Portalyx is a Software-as-a-Service (SaaS) Fleet & Shipping ERP intended for use by businesses. By creating an account or using the Service, you agree to the practices described below.
1. Who is the controller
The data controller for the Service is the legal entity operating Portalyx (the "Company"). For privacy questions you may contact us at privacy@portalyx.app.
2. Information we collect
2.1 Account & profile data
- Name, email, phone number, company name, role, and country.
- Authentication credentials (handled via Firebase Authentication).
- Subscription tier and billing contact details.
2.2 Driver data (entered by your organization)
- Driver name, phone, national ID, driving license number and expiry, salary type, and emergency contacts.
- Driver custody balances and trip-related allowances.
- Photos of fuel receipts, tolls, proof-of-delivery documents, and odometer readings uploaded through the driver app.
2.3 Operational data
- Trip records: origin, destination, route, container number, dates, status.
- Truck and generator profiles, license / insurance dates, maintenance logs.
- Client and supplier records, including custody, guarantees, and account statements.
2.4 Financial data
- Invoices, payments, payment methods (cash / bank / check), VAT and withholding tax records.
- Account statements and reconciliation entries.
2.5 Device & technical data
- Firebase Cloud Messaging (FCM) push tokens, device identifiers, app version, operating system.
- IP address, approximate geolocation derived from IP, and request logs for security and abuse prevention.
- Crash reports and diagnostic logs needed to fix bugs.
2.6 Cookies & similar technologies
The Portalyx web dashboard uses essential cookies for authentication and security. We do not use third-party advertising cookies.
3. How we use information
- Operate the Service — authenticate users, run trips, generate invoices, deliver alerts.
- Customer support — diagnose issues, restore data, and answer your questions.
- Billing — manage subscriptions and process payments.
- Improve the Service — measure feature usage in aggregate, fix bugs, and prioritize improvements.
- Security — detect abuse, fraud, or unauthorized access.
- Legal compliance — respond to lawful requests and meet tax and accounting record-keeping requirements.
4. Legal bases (where applicable)
- Performance of the contract you (or your employer) signed with us.
- Our legitimate interests in operating, securing, and improving the Service.
- Compliance with legal obligations (tax, accounting, anti-fraud).
- Your consent, where specifically requested (e.g., marketing emails).
5. Third-party services we use
- Firebase Authentication — sign-in and identity.
- Firebase Cloud Messaging (FCM) — push notifications.
- Firebase App Check — verifies that requests come from genuine Portalyx apps.
- Hosting & database providers — to host the application and store your data.
Each provider processes data on our behalf under their own security and privacy commitments.
6. How we share information
We do not sell your personal data. We share information only:
- With our service providers (above) acting as data processors.
- With your organization's authorized administrators (e.g., a driver's data is visible to their employer).
- When required by law, court order, or to protect rights, safety, or property.
- In a corporate transaction (merger, acquisition, asset sale), with notice to you.
7. Data retention
We keep your data for as long as your account is active and as required to provide the Service. Financial and tax records are retained for the period required by Egyptian law (typically five years from the end of the relevant fiscal year). When you close your account, we delete or anonymize personal data on a defined schedule, except where law requires longer retention.
8. Security
- API requests are AES-encrypted in transit between the apps and our backend.
- Sessions are protected by JWT authentication and Firebase App Check.
- Passwords are stored as cryptographic hashes; we never see plain-text passwords.
- Database access is restricted by role and audited.
- Daily backups are encrypted and access-controlled.
No system is 100% secure. We commit to best-effort safeguards and timely breach notification.
9. International transfers
Some of our service providers operate from outside Egypt. When data leaves the country, we rely on the providers' security and contractual safeguards to protect it.
10. Your rights
Subject to local law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion (subject to legal retention requirements).
- Receive an export of your data in a portable format.
- Withdraw consent for processing based on consent.
- Object to certain processing or request restriction.
To exercise these rights, email privacy@portalyx.app from the address associated with your account. We may need to verify your identity before responding.
11. Children's privacy
The Service is intended for businesses and is not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify account administrators by email or in-product notice.
13. Contact us
Questions, concerns, or requests:
- Email: privacy@portalyx.app
- General contact: portalyx.app/en/contact
This Privacy Policy is provided for transparency and clarity. If any conflict exists between this English version and a translated version, the English version controls.