Privacy Policy
Version 2026-08-27 · Last updated: August 27, 2026
1. Who we are and what this policy covers
PorterBase is a software-as-a-service product created and operated by VSDEV INC, a California corporation. PorterBase and vsdev.ai are brands operated by VSDEV INC.
In this policy, “PorterBase,” “we,” “us,” and “our” refer to VSDEV INC. Where privacy law distinguishes between a controller and a processor, VSDEV INC is the controller of account and service-operation information, and acts as a service provider or processor for the business records a customer organization enters into the Service.
This policy covers the PorterBase website, the PorterBase web application, and the PorterBase browser extension (together, the “Service”).
This policy is a notice of how we handle information. It is not a request for blanket consent: most of what is described here is necessary to provide the Service you or your organization asked for, to keep it secure, or to meet a legal obligation.
2. Information we collect
Account and authentication information
- Your name and email address
- Your password, stored only as a cryptographic hash — never in readable form
- Email-verification and password-reset records
- Session information used to keep you signed in
- The version of the Terms of Service you accepted and the version of this Privacy Policy you acknowledged, the date and time, how you accepted (registration, invitation, or a later re-acceptance), and the IP address and browser user-agent string of that request
Business account and team information
- Business name, type, phone, email, website, address, timezone, currency, and logo
- Your role and permissions within a business, and whether you are a field technician
- Team member and technician records, including status and default warehouse
- Invitations sent to an email address, including who sent them and when they were accepted
Operational and inventory records
- Warehouses and storage locations
- Part catalog entries, categories, part items, and inventory levels
- Inventory transactions — stock added, assigned, used, returned, transferred, damaged, or lost
- Vendor records, including vendor contact information a customer enters
- Jobs and job identifiers
- Purchase orders, order lines, shipments, and tracking information
- Product URLs on vendor websites
- Activity and audit records of changes made in the Service, including which user made a change and the values before and after
Browser-extension information
- An authentication token issued to the extension after you sign in
- Vendor cart content the extension reads from a vendor page you are on: the vendor identifier, part number, part name, quantity, unit price, product URL, an optional job identifier, and cart or order notes and numbers
Technical and security information
Our hosting provider and our application produce server logs in the ordinary course of running the Service. These can include IP address, request time, the page or endpoint requested, and error information. We use the IP address and email address of a sign-in attempt to rate-limit repeated failures.
Communications
If you email us — for support, a privacy request, or a legal notice — we keep that correspondence and whatever you include in it.
Preferences stored on your device
Your theme choice and view preferences are stored in your browser’s local storage. They stay on your device and are not sent to us.
What we do not collect
PorterBase does not include an analytics SDK, an advertising SDK, a third-party error-monitoring service, a session-replay tool, or any cross-site tracking technology. We do not build advertising or behavioral profiles, and we do not collect browsing history from the extension.
3. Where the information comes from
- Directly from you, when you register, complete onboarding, or use the Service
- From the owner or an administrator of the business you belong to, who may create or edit records about you as a team member or technician
- From a team invitation sent to your email address
- From the browser extension, when you use it on a vendor page
- From vendor cart pages that you choose to sync
- From automated security and server logs
- From our service providers, in the course of delivering email and hosting the Service
4. How we use information
- To authenticate you and keep your session secure
- To provide, operate, and maintain the Service
- To create and manage business organizations, roles, and team membership
- To run inventory, assignment, job, and purchase-order workflows
- To synchronize vendor carts through the browser extension when you ask it to
- To send transactional email — email verification, password resets, and team invitations
- To keep a record of which version of our legal documents you agreed to
- To protect the Service: security monitoring, rate limiting, fraud and abuse prevention, and debugging
- To respond to your support, privacy, and legal requests
- To comply with applicable law
We do not use your business data to train machine-learning models, and we do not use it for advertising.
5. The browser extension
What it reads, and when
The PorterBase browser extension reads cart and product information from supported vendor websites. It does this on the vendor pages it supports, when you are signed in to PorterBase in the extension and you use it to view or sync a cart. It reads the vendor identifier, part numbers, part names, quantities, unit prices, product URLs, and any job identifier or note attached to the cart.
Where the data goes
Cart data is transmitted to PorterBase only to provide the cart-sync functionality you requested. In PorterBase it is stored as a purchase order or cart belonging to your business, with its lines, part numbers, quantities, prices, and product URLs.
What it is never used for
Website content and browsing data collected by the extension are not used for advertising, are not sold or transferred to data brokers, are not used for creditworthiness or lending decisions, and are not used for any purpose unrelated to the cart-sync feature. The extension does not read pages other than the vendor pages it supports, and it does not collect your browsing history.
Permissions and tokens
The extension requests only the permissions the cart-sync feature requires. It authenticates with a token issued when you sign in, which expires after seven days and must be kept confidential — anyone holding it can act as you in the extension API. Where a browser store requires a prominent disclosure and your affirmative consent before this kind of data collection begins, that disclosure is presented inside the extension itself, and not only through this policy.
6. Cookies and local storage
PorterBase uses only strictly necessary cookies and local storage. We do not use advertising cookies, analytics cookies, or third-party tracking cookies, so there is no consent banner to click through.
- Authentication cookie — keeps you signed in. Without it the Service cannot work.
- Active business cookie — remembers which business account you are currently working in.
- Local storage — your theme and view preferences, held on your device only.
If we ever add analytics, advertising, or other non-essential cookies, we will assess the applicable consent requirements and implement a real consent mechanism before those cookies are set.
7. How information is shared
Within your organization
PorterBase is a team product. Owners and administrators of a business can see the records belonging to that business, including team member and technician records, assignments, inventory actions, and the activity log of who changed what.
Service providers
These providers currently process information on our behalf:
- Vercel — application hosting and the server logs that hosting produces
- Resend — delivery of transactional email (verification, password reset, and invitations)
- Our managed PostgreSQL database provider — storage of the application database and its backups
We do not currently use a payment processor, because the Service is free. If we introduce paid plans we will name the payment processor in this policy before any payment information is collected.
Legal requirements
We may disclose information where we are required to by law or in response to valid legal process, and where necessary to establish, exercise, or defend legal claims or to protect the rights and safety of users, third parties, or the Service.
Business transfers
If VSDEV INC is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.
8. Sale of personal information and advertising
We want to be unambiguous about this:
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising.
- We do not use targeted advertising, and PorterBase carries no advertising.
- We do not allow third parties to collect cross-site activity through PorterBase.
9. How long we keep information
We keep information for as long as it is needed for the purpose it was collected for, and then delete it or retain it only where the law requires or permits. Deletion in production is not instantaneous in backups: deleted records persist in encrypted backups until those backups age out of our provider’s rolling retention cycle.
- Account information — kept while your account is open.
- Business, inventory, job, vendor, and purchase-order records — kept while the business account is open. These belong to the customer organization, not to an individual team member.
- Activity and audit records — kept while the business account is open, so an organization can reconstruct what happened to its inventory.
- Vendor-cart data from the extension— kept as part of the business’s purchase-order records, on the same basis.
- Extension authentication tokens — expire seven days after they are issued. The token is held by your browser; we do not keep a copy.
- Email-verification tokens — expire after 24 hours. Password-reset tokens — expire after one hour.
- Invitations— expire seven days after they are sent; the record that an invitation was sent and accepted is kept with the business’s team history.
- Legal acceptance records — including the IP address and user-agent string captured with them, kept while your account is open and for up to six years after it closes, as evidence of the agreement between us.
- Server and security logs— kept for the period set by our hosting provider’s log retention, and longer where needed to investigate a specific security incident.
- Support and legal correspondence — kept for as long as needed to handle the matter and to show how a request was handled.
- Closed accounts — see the next section.
We do not promise a fixed universal deletion deadline, because our backups and our providers’ deletion cycles cannot guarantee one. We will act on a deletion request within the period required by applicable law.
10. What happens to data after suspension, closure, or termination
This section describes what happens to information. The circumstances in which access may be restricted or ended are set out in the Terms of Service, not here.
- While access is restricted or suspended, your data continues to exist but you may be unable to sign in or use some features. Extension tokens and sessions may be revoked.
- Closing an individual team member’s account does not delete the business’s inventory, purchase-order, job, transaction, or audit records. Those records belong to the customer organization and remain with it, and they may continue to show that an action was taken by that person.
- When a business owner closes an entire business account, the business’s records are deleted or anonymized on the schedule described above, subject to the exceptions below.
- We may retain information where we are required or permitted to: to comply with a legal obligation, to preserve records under a legal hold, to establish or defend legal claims, to keep security and abuse records, and to keep evidence of legal acceptance.
- Personal information we retain after closure is limited to what those purposes require, and is not used to provide the Service to anyone.
11. Security
We use reasonable technical and organizational measures to protect information: encrypted transport (HTTPS), passwords stored only as hashes, signed session and extension tokens with fixed lifetimes, role-based access control within each business, isolation of each business’s data from every other business’s, rate limiting on sign-in, and a browser-extension API that is separate from the web application’s session.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account or your extension token has been compromised, email porterbaseinfo@gmail.com immediately.
12. Your privacy rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, to have it corrected, to receive a copy in a portable format, to have it deleted, and — where applicable — to restrict or object to certain processing. You have the right not to be discriminated against for exercising these rights.
PorterBase does not currently offer self-service account deletion or self-service data export in the application. To make any of these requests, email porterbaseinfo@gmail.com from the address on your account and tell us what you are asking for.
We will verify your identity before acting on a request, usually by confirming control of the account email address, and we may ask for additional information where a request concerns sensitive records. We handle requests within the period required by applicable law rather than a single universal deadline, and we will tell you if we need more time or if an exception applies.
If you are a member of a business account, much of the data about you in PorterBase belongs to and is controlled by that organization. Where it is legally appropriate, we will refer your request to the business owner or administrator and let you know we have done so.
13. Tracking signals
PorterBase does not track you across other websites or over time, and no third party collects cross-site activity through the Service. Because there is nothing to opt out of, we do not respond to Do Not Track browser signals.
We honor Global Privacy Control signals where applicable law requires it. Since we do not sell or share personal information for cross-context behavioral advertising, such a signal does not change how we handle your information.
14. International users
PorterBase is operated from the United States, and information is stored and processed there. If you use the Service from outside the United States, you are transferring information to the United States, which may have different data protection rules than your own country.
VSDEV INC is the controller of the information described in this policy. Where the law of your country gives you rights over that information, including a right to complain to your local supervisory authority, you can exercise them by contacting porterbaseinfo@gmail.com. Where we rely on a legal basis for processing, it is the performance of our contract with you or your organization, our legitimate interest in operating and securing the Service, compliance with a legal obligation, or your consent where consent is what the law requires.
We have not appointed an EU or UK representative or a data protection officer, and we do not claim to have completed a full GDPR compliance program.
15. Children
PorterBase is a business product and is not intended for children. The Terms of Service require every user to be at least 18 years old. We do not knowingly collect personal information from a child. If we learn that we have, we will delete the account and the associated personal information promptly, and we will notify the business owner if the account was created through a team invitation. If you believe a child has given us information, email porterbaseinfo@gmail.com.
16. Third-party websites
The Service links to vendor websites and other third-party sites, and the extension operates on vendor pages. Those sites have their own privacy policies and practices, which we do not control and are not responsible for.
17. Changes to this policy
We may update this policy. Each version carries a version identifier and a “last updated” date at the top of this page. If a change is material, we will give notice by email or a prominent in-app notice.
We will not ask you to consent to processing that does not legally rely on your consent. Where a change does depend on consent, we will ask for it separately and clearly.
18. Contact us
Privacy requests, deletion and export requests, security reports, and general questions all go to the same monitored mailbox. We do not operate separate privacy, legal, or support teams.