Overview
This Privacy Policy explains how Benchmarke collects, uses, shares, and protects information when you use Benchmarke Portal. The portal is an invite-only workspace for Benchmarke website clients to review account details, invoices, documents, work requests, and user access.
By using Benchmarke Portal, you agree to the practices described here. If you use the portal on behalf of a company or organization, this policy applies to the information you provide for that organization and its authorized users.
Information we collect
We collect the information needed to provide secure portal access and client account services.
- Account information, such as name, email address, password credentials for email sign-in, Google profile details when you use Google sign-in, role, workspace membership, and onboarding status.
- Client and workspace information, such as organization name, billing contact details, website domain, workspace profile details, logos, banners, documents, work requests, comments, and request update subscriptions.
- Billing visibility information synced from Stripe, such as invoice number, status, amount, due date, hosted invoice link, and invoice PDF link. Benchmarke Portal does not store card numbers, bank account details, or payment method data.
- Files and images uploaded through the portal, such as workspace documents, client logos, workspace banners, and user profile images.
- Security and usage information, such as session identifiers, authentication events, audit log activity, IP-derived request metadata available to the application, browser type, timestamps, and diagnostic information needed to operate and secure the service.
Google sign-in
Benchmarke Portal uses Google OAuth only to help invited users sign in. When you choose Google sign-in, Google may share basic profile information with us, such as your name, email address, Google account identifier, and profile image.
We use this information to verify that your Google account email matches an invited portal account, create or connect your portal session, display your profile details, and protect account access. We do not sell Google user data, use it for advertising, or use it to train unrelated models.
How we use information
- To create, authenticate, and maintain secure portal accounts and sessions.
- To provide workspace, billing, document, user management, and work request features.
- To send transactional email, including invitations, password reset messages, work request notifications, and request update messages.
- To maintain audit logs, investigate security issues, prevent unauthorized access, and enforce account boundaries.
- To provide client support, troubleshoot errors, improve portal reliability, and satisfy legal or contractual obligations.
Service providers
We use trusted service providers to operate the portal. They may process information only as needed to provide their services to Benchmarke.
- Google, for OAuth sign-in and profile information when you choose Google sign-in.
- Stripe, for invoice source-of-truth data and hosted payment or invoice pages.
- Mailgun, for transactional email delivery.
- DigitalOcean Spaces or another S3-compatible private object storage provider, for private documents and uploaded images.
- Database, hosting, observability, and infrastructure providers used to run the portal securely.
Retention
We keep personal information for as long as needed to provide the portal, support client services, maintain security and audit history, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary by record type, client relationship, and legal requirement.
Uploaded files and account records may remain available while the related workspace or client account is active, unless Benchmarke removes them, the client asks us to remove them, or we are legally required to preserve them.
Security
We use administrative, technical, and organizational safeguards designed to protect portal information. These include invite-only account creation, server-side authorization, private object storage, short-lived signed file access, audit logging, and role-based workspace access.
No internet service is perfectly secure. If you believe your portal account or workspace data may have been compromised, contact us immediately.
Your choices
- You can update some account profile information from portal settings.
- You can choose email/password sign-in or Google sign-in when those options are available for your invited account.
- You can ask Benchmarke to correct, export, or delete personal information, subject to contractual, operational, security, and legal retention requirements.
- You can contact Benchmarke if you need workspace membership changes, profile image removal, document removal, or account deactivation.
Children
Benchmarke Portal is intended for business use by invited client contacts and Benchmarke admins. It is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this Privacy Policy from time to time. When we make changes, we will update the date on this page. Material changes may also be communicated through the portal or by email when appropriate.
Contact
Questions about this Privacy Policy or Benchmarke Portal data practices can be sent to support@benchmarke.io.