Portata
Privacy Policy

Privacy Policy

Last updated: August 6, 2026.

This is the plain-English version. Two kinds of people show up in it. Operators are restaurant owners, managers, and staff who sign up for Portata and use the owner dashboard. Callers are the people who dial a restaurant that uses Portata and talk to our AI host. Both have rights, both deserve straight answers.

1. Who we are

Portata is operated by Portata (referred to in this policy as "Portata," "we," "us," "our"). Privacy questions: hello@portata.dev. Security issues: security@portata.dev. Based in New Smyrna Beach, Florida.

2. What this policy covers

This policy covers the Portata website (portata.dev and its subdomains), the owner dashboard, and the AI host service that answers phone calls placed to a restaurant using Portata. It does not cover what a restaurant does with information after we hand it to them (for example, what they do with a reservation record). The restaurant is the controller of its own customer data once it lands in their hands.

3. The two kinds of data we touch

Operator data (restaurants who buy Portata)

When a restaurant signs up we collect account information (business name, contact name, email, phone, role), payment information handled by our payment processor Stripe (we do not store full card numbers), configuration (menu, hours, FAQs, escalation numbers, reservation preferences, persona tuning notes), and dashboard usage (how you log in, what pages you view, what actions you take).

Caller data (people who dial a restaurant using Portata)

When a caller dials a restaurant we host we collect call metadata (phone number, date and time, duration, which restaurant was called), call audio in real time (used to generate a transcript), the transcript itself, and structured intent (any order the caller placed, any reservation they requested, any message they left). If the caller calls the same restaurant again and the restaurant has memory enabled, we retain small facts the caller volunteered (their name, a delivery address they gave, "make it gluten free"), scoped to that one restaurant only.

4. Why we have it

Operator data is used to run your account, bill you, and deliver the service. Caller data is used to answer the call, take the order, deliver the transcript to you in the dashboard, and help our host remember returning customers when you have that feature turned on. We also use aggregated, de-identified data to improve the service (for example, to spot patterns in why calls get transferred). We do not sell your data. We do not sell caller data. We do not use caller data to train third-party models.

5. Recording and consent

Some US states require every party on a call to consent to recording (California, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, Washington, and others). By default our AI host discloses that it is the AI host in the opening line of every call, and we recommend restaurants in two-party consent states also post a notice at the point of order or ask us to add an explicit recording notice to the greeting. The restaurant is responsible for whatever disclosure its jurisdiction requires; we will help configure the host to match.

6. How long we keep it

Call audio, transcripts, and structured caller data are retained for ninety days by default, then deleted. Restaurants can request earlier deletion of specific calls or a full account export at any time by emailing hello@portata.dev; we act on those requests within thirty days. Owner-facing metadata (call counts, order counts, ratings) may be retained longer in aggregate form for billing, reporting, and legal compliance. Backups roll off within thirty days of the underlying data being deleted.

7. Who we share it with

We share data only with the sub-processors listed below, and only to the extent needed to deliver the service. We do not sell data and we do not share it for third-party advertising. Our current sub-processors are LiveKit (real-time telephony transport), Cartesia (speech-to-text and text-to-speech), OpenAI (language model), Supabase (database and file storage), and Stripe (payment processing). We may also disclose data if required by law, in response to a valid legal process, or to protect the safety of a person or of the service; where legally possible we will notify the affected account before doing so.

8. Your rights as a caller

If you called a restaurant that uses Portata and want to know what we have about you, ask for a copy, or ask us to delete it, email hello@portata.dev with the phone number you called from and the restaurant name. We will respond within thirty days. If you live in California, the EEA, the UK, or Switzerland, you have additional rights under CCPA and GDPR (see below); this route works whether or not those laws apply to you.

9. Your rights as an operator

You can view, export, and delete your account data at any time from the owner dashboard, or by emailing us. You control what your callers hear, how long we keep their data (within the ninety-day default), and whether the memory feature is on. You can turn call recording off if your business model requires it, though the host still relies on real-time audio to answer the call in the first place.

10. California residents (CCPA/CPRA)

You have the right to know what personal information we collect, to request deletion, to correct inaccurate information, to opt out of "sale" or "sharing" (we do neither), and to limit use of sensitive personal information. To exercise any of these rights, email hello@portata.dev. We will verify your identity through the phone number or email associated with the data. We do not discriminate against people who exercise their rights.

11. EEA, UK, and Swiss residents (GDPR)

Our legal bases for processing are performance of a contract (running the service you or the restaurant asked us to run), legitimate interest (improving the service and preventing fraud), consent (where you gave it explicitly), and legal obligation (where the law requires processing). You have the right to access, correct, delete, restrict, and port your data, and to object to processing based on legitimate interest. Email hello@portata.dev to exercise these. If you are not satisfied with our response, you can complain to your local data protection authority. We do not currently have an EU or UK representative appointed; if that changes we will update this section.

12. Cookies and analytics

The portata.dev marketing site uses a single essential cookie to remember whether you have dismissed the demo banner. The owner dashboard uses cookies to keep you signed in. We do not run third-party ad tracking. If we add product analytics later we will list the tool here and make sure it is configured with IP anonymization.

13. Security

All data is encrypted in transit (TLS 1.2 or higher) and at rest. Access to production systems is limited to Portata engineers, gated by single sign-on with two-factor authentication, and logged. If we discover a security incident that affects your data, we will notify you promptly and, at a minimum, within the timeframes required by applicable law.

14. Children

Portata is not directed at children under thirteen and we do not knowingly collect data from them. If you believe a child under thirteen has interacted with our AI host in a way that captured their information, email hello@portata.dev and we will delete it.

15. Changes to this policy

We may update this policy from time to time. Material changes will be posted here with a new "Last updated" date and, if you have an active account, sent to the email on file. Continued use of the service after a change means you accept the new policy.

Contact

Privacy questions: hello@portata.dev. Security issues: security@portata.dev.