This translation is provided for convenience. In case of any discrepancy, the Spanish version prevails. Read the Spanish original

Privacy Policy

Last updated: October 2, 2026

This policy explains what data Portalic processes and what data it does not. It is written from what the system does, column by column, and not from a template: that is why it can state things that most policies avoid.

The most important one, and it comes first: whoever scans the QR code and views your menu is not identified in any way, unless that person decides to leave their details so that the restaurant can contact them or to receive a coupon via WhatsApp.

1. Data controller

The party responsible for the processing (responsable del tratamiento) is the party that operates the Portalic service, from the Argentine Republic.

To exercise your rights or to ask any question about this policy, write to us at hola@portalic.app.

If you need the full details of the party responsible for the processing — the name, the CUIT (Argentine tax identification number) and the legal address (domicilio) — request them at hola@portalic.app and we will provide them to you.

The processing is governed by Law 25,326 on the Protection of Personal Data (Ley 25.326 de Protección de los Datos Personales). The enforcement authority is the Agency for Access to Public Information (Agencia de Acceso a la Información Pública, AAIP), before which you may file a complaint.

2. Data of the restaurant (our customer)

If you contract for Portalic, we process the data we need to provide the service to you and to charge for it:

  • Your email address, which is also your username for signing in to the dashboard.
  • Your password, always stored as a bcrypt hash: we do not store it in plain text and we cannot read it, neither we nor anyone with access to the database.
  • The name of your restaurant and the country you declare when you sign up.
  • The identifiers of your subscription at MercadoPago or Lemon Squeezy and the amount you are charged.
  • The history of changes to the account's email address, which we keep as a record of the sign-in identity.
  • The content of your business: logo, colors, menu, Google review link, Instagram and TikTok links, and the photos and videos you upload.
  • The messages you send us from the dashboard (reports, suggestions, and the reason if you cancel).
  • Your WhatsApp number, only if you enable WhatsApp coupons: we verify it when you write to us from that number and we use it only to notify you of each new contact left through your menu.
  • A shipping address and a contact phone number, only if you sign up in Argentina while the free printed QR codes promotion is active: we use them only to ship you that kit, and they are seen by the Portalic team that prepares it. If you leave a delivery comment, it is stored with the address.

We do not ask for or store your personal name or your CUIT. Your address (domicilio) and your phone number, only in the cases just described and only if you provide them.

And at no point does card data pass through Portalic: payment details are entered directly into MercadoPago or Lemon Squeezy, depending on your country, which are the parties that process the charge. We never see or store them.

3. The dashboard assistant

The restaurant dashboard includes an artificial intelligence assistant that helps you load and edit the menu and answers questions about your own restaurant's data.

What we keep: each message you write to the assistant and each reply it gives you, with its date, the amount of data processed, and whether the message was identified as unrelated to the use of the dashboard or as an attempt to alter its rules. If you attach a photo or a PDF, we keep only the file type and its size: the file itself is not stored.

Why: for security, to prevent abuse of the service, and to be able to provide you with support.

How long: 90 days. A daily process permanently deletes the conversations that exceed that period.

Who reads them: the team that operates Portalic, only for those purposes. They are not published or shared with other restaurants.

Who processes them: to produce each reply, your message — and any photo or PDF you attach — is sent to the provider of the artificial intelligence model — Google (Gemini) or Anthropic (Claude), whichever we have in use — together with the data from your menu and your ratings that the assistant consults in order to reply.

The assistant only accesses your own restaurant's data, and never the name or email address of the customers who left a rating.

If you rate a reply from the assistant, that exchange is additionally stored together with your rating, like the other reports you send us from the dashboard, and it is not deleted after 90 days.

4. Data of whoever scans the QR: none that identifies them, unless they decide to leave it

This is the part worth reading carefully, because it is unusual and it is verifiable.

When someone scans the QR and browses the menu, we record aggregate counters: that there was a visit to the menu, that a product was opened, that the review button was tapped, that a link to Instagram or TikTok was tapped, that the WhatsApp banner was tapped or a coupon was requested. Each of those records contains only the row's own identifier, the restaurant and the location to which it corresponds, the type of event, and the date and time.

We do not store the IP address, any cookie, any device identifier, any session identifier, the browser or operating system, or any device fingerprint. There is no way to reconstruct who did what, or to recognize the same person across two visits: they are counts, not people.

If the customer rates their visit, we store the 1-to-5-star rating and, if they decide to write one, a free-text comment. That comment is written by the person and may contain whatever they choose to put in it, including their own data; only the restaurant sees it, in its dashboard, and it is never published.

There are two moments at which the customer may, if they wish, leave data that does identify them. After a low rating, they may leave their name and their email address so that the restaurant can reply to them: both fields are optional, they are stored together with the comment, only the restaurant sees them, and Portalic does not send any email to that customer; if the restaurant decides to reply, it does so from its own email.

And if the restaurant has enabled WhatsApp coupons, the customer may leave their WhatsApp number and, optionally, their name in order to receive a coupon. We store that number, that name, the code of the coupon issued and whether it was redeemed, associated with that restaurant; the same number receives only one coupon per restaurant. The coupon is sent via WhatsApp through Kapso and Meta's WhatsApp Business platform, so the number and the text of the message pass through those providers. That contact database belongs to the restaurant: it can view it and export it from its dashboard, and if it decides to message them, it does so from its own WhatsApp, under its own responsibility.

The QR menu has no analytics or advertising pixels. Neither does the restaurant dashboard. The measurement described below exists only on the public website portalic.app.

The menu stores a few things in the phone's own local storage — a copy of the menu so that it opens quickly next time, the time of the first scan for the review reminder, and the most recent searches within the menu. That stays on the device, is not transmitted anywhere, and the searches are stored separately for each restaurant, so a phone that scans two different restaurants carries nothing from one to the other.

5. Photos and videos uploaded by the restaurant

The restaurant may upload photos and videos — the "stories" — associated with its products. That material is hosted on Cloudflare R2 and is publicly accessible through its link, because it is part of a menu that is public by definition.

If identifiable people appear in those images, it is the restaurant that must have their consent. This is also established in the Terms and Conditions.

6. Advertising and analytics: only on the public website

On portalic.app, and only when it is served in production, we load Google Analytics 4 and the Meta pixel (Facebook and Instagram) to understand where visits come from and to measure the effectiveness of campaigns. Google Analytics is configured to anonymize the IP address.

When someone signs up, we store alongside that registration the campaign parameters from the URL, the Google Analytics client identifier, and the Meta advertising identifiers derived from the click on an ad.

We are explicit about this: those Meta identifiers are not anonymous. They are pseudonyms that Meta can link to a profile, and they are stored in the same row as the email address of the person who signed up.

In addition, when a payment is confirmed, we send Meta a SHA-256 hash of the purchaser's email address together with the amount charged, in order to attribute the sale to the campaign. A hash is still personal data, and that is why we declare it.

We do not display a consent banner: Argentine regulations do not require one of the kind that the European regulation requires. You can block these technologies from your browser settings or with an extension, and the site continues to work the same way.

7. Cookies

There are two uses, and they should not be confused:

  • Functional: the restaurant dashboard uses a session cookie (httpOnly, Secure, SameSite) to keep you signed in. It does not serve to track you, it cannot be read by JavaScript, and it is not used for advertising purposes.
  • Analytics and advertising: the Google Analytics and Meta cookies described in the previous section, only on the public website and only in production.

The QR menu that your customers see does not set any cookies.

8. IP addresses

Portalic does not store IP addresses in its database. They are used transiently in memory to limit the number of requests for security purposes, and they are discarded when the time window expires or when the service restarts.

A request blocked by that limit generates a log line on the server that includes the IP and the affected endpoint; those logs are retained by our infrastructure provider and are not linked to any account.

9. Third parties involved

These are the services that actually take part in the processing:

  • MercadoPago: processes subscription payments in Argentina and receives the payer's email address.
  • Lemon Squeezy: processes subscription payments for restaurants outside Argentina and acts as the Merchant of Record for that sale. It receives the payer's email address, their country, and the payment details entered in its checkout, which Portalic never sees.
  • Resend: sends transactional emails (welcome, password recovery, account notices).
  • Cloudflare: hosts the website and stores the images and videos.
  • Railway: hosts the API, the database and the scheduled processes, and retains the server logs.
  • Google Analytics and Meta: analytics and advertising for the public website, only in production, as explained above.
  • Kapso and Meta (WhatsApp Business): send the messages of the WhatsApp coupon engine. They receive the number and name of the person who requests a coupon, the restaurant's verified number, and the text of each message.
  • The courier that carries the printed QR code kit, when applicable: it receives the address and the phone number on the shipping label.
  • Google (Gemini) or Anthropic (Claude): provide the artificial intelligence model for the dashboard assistant; we use one of the two. The one in use receives the messages the restaurant writes to the assistant, the photos or PDFs it attaches, and the menu and ratings data that the assistant consults in order to reply.
  • Google (Gemini): when the restaurant asks to improve a product photo, it receives that photo and the product name to produce the improved version. The original photo is kept, and the improved one is published only if the restaurant accepts it.
  • Slack: internal operational notices (a new account, a cancellation, a new registration) that carry the restaurant's name and the subscription amount, never your email address or your customers' data.

And something that ought to be said about what we do NOT do: Portalic does not integrate with the Google Business Profile API, the Instagram API or the TikTok API. We never read a restaurant's reviews, rating or follower count. We only count the clicks that occur within our own pages.

10. Your rights

You can request access to your data, their rectification or their deletion (supresión) by writing to us at hola@portalic.app. We will ask you to write from your account's email address so that we can verify that it is you.

We are candid about the scope: deletion is handled on request and manually. We will not promise you automatic deletion or a set timeframe that the system does not meet today. There is material — in particular images and videos that have already been published — whose complete removal requires intervention on our part. Write to us and we will resolve it; what we will not do is state here something the product does not do.

The data subject (titular de los datos) has the right to request and obtain information about their personal data included in databases, in accordance with Law 25,326 (Ley 25.326). If you believe we did not handle your request properly, you may file a complaint with the Agency for Access to Public Information (AAIP), in its capacity as enforcement authority.

11. Retention and security

We retain account data while the subscription is in effect and for as long afterward as is necessary to comply with legal, accounting and tax obligations. Event counters are retained in aggregate form, and since they do not identify anyone, there is nothing to associate with a person.

Conversations with the dashboard assistant are the exception: they are retained for 90 days, as explained above.

Passwords are always stored hashed, all traffic travels encrypted, and access to each restaurant's data is limited to that account: every query to the database filters by the restaurant making it.

Portalic support may enter your dashboard to help you or to load content you requested, in a session that is limited in time and restricted to your restaurant, and each of those accesses is recorded. The Terms and Conditions describe what support can and cannot do in that session.

12. Minors

Portalic is a tool for businesses and is not directed at minors. We do not knowingly collect data from minors.

13. Changes to this policy

The date of the last update is at the very top. If we change anything material, we update that date and notify active accounts by email before the change takes effect.