Panorivo

Privacy policy

Last updated 7 August 2026

Panorivo holds two different kinds of information: yours, as someone who signs up, and your clients', which you put in to run your work. This explains both, because they are not the same thing and the law treats them differently.

Who is responsible

Panorivo (“we”, “us”) is an independently run online service, with no offices and no paper. For questions about anything on this page, to exercise any of the rights set out below, or to complain about how we have handled your information, email info@panorivo.com — that is the only contact address and it reaches the person responsible.

There are two relationships to keep apart. For your account information we are the data controller. For information about your clients — their names, their addresses, their files, what you have quoted them — you are the controller and we are a processor acting on your instructions. We do not decide what to do with your clients’ data, and we do not use it for our own purposes.

What we collect about you

InformationWhy
Name, email address, passwordTo create and secure your account. Passwords are stored only as a bcrypt hash — we cannot read yours.
Business details: trading name, postal address, phone, website, VAT number, bank details, payment terms, logo, accent colourTo put them on your invoices, quotes, contracts and client portal. Bank details are shown to the clients you invoice, because that is how they pay you.
Your discipline and currencyTo set the wording and money formatting the app uses for you.
Content you create: projects, tasks, time entries, expenses, notes, uploadsTo provide the service. This is your working record.
Technical records: sign-in events, IP address and browser at sign-offSecurity, and evidence. When a client approves a handover we record the typed name, the time, the IP address and the browser, because the point of an approval is that it can be relied on later.

What you put in about your clients

When you add a client we store what you type: name, email address, phone number, company, billing address, and anything you write in a brief, a message or a custom form field. When you upload files for them, we store the files. When a client uses their portal we store what they send you — messages, approvals, and any proposal they submit.

You are responsible for having a lawful basis for putting that information here, and for telling your clients that you use a tool like this. We only process it to run the service for you: we do not sell it, mine it, or use it to train anything.

Files and how they are stored

Uploads are not public. They are written outside the web root and can only be fetched through an endpoint that first checks you own the file, or that it has been shared with the client asking for it. A share link that you password-protect stays protected. Deleting a file in the app deletes the bytes from disk, not just the row in the database.

Cookies and analytics

Essential

A session cookie keeps you signed in. It is required for the app to work at all and cannot be switched off. Your light/dark preference is kept in your browser’s local storage, never sent to us.

Analytics

We use Google Analytics 4 to count visits to the public pages and see which ones people arrive on. It sets cookies (_ga, _ga_*) and shares your IP address and page URL with Google, including transfers to the United States under Google’s standard contractual clauses. It is not used to identify individuals and we do not join it to your account.

Who else sees anything

WhoWhat, and when
Our hosting providerEverything, as the operator of the server the app and database run on. Bound by their contract with us.
Our email providerThe recipient address and the content of transactional emails — invites, invoices, reminders, notifications.
StripeOnly if you connect it, and only the invoice amount, reference and your client’s email address so they can pay by card. Card details are handled by Stripe and never reach us.
Google AnalyticsPublic-page visits, as described above.

We may also disclose information if the law requires it. We do not sell personal data to anyone, and there is no advertising on Panorivo.

How long it is kept

Your content is kept while your account exists. Delete a project, client or file and it goes immediately — deletions in Panorivo are real, not flags. If you want your whole account removed, email us and we will delete it, including uploads, within 30 days. Some records may persist briefly in encrypted backups after that. Anything we are legally required to keep, such as records relating to payments we have processed, is kept for as long as the law requires and no longer.

Your rights

Under UK GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict how we use it, object to processing, or ask for it in a portable format. Reports already export to CSV whenever you like, so you never need to ask us for that. Email info@panorivo.com and we will respond within one month.

If your data is here because you are somebody’s client, ask that freelancer first — they control it. If you cannot reach them, contact us and we will help.

If you are unhappy with how we have handled something you can complain to the Information Commissioner’s Office at ico.org.uk.

Security

Passwords are hashed with bcrypt. The site is served over HTTPS. Every database query for your data is scoped to your account in one place in the code rather than page by page, and uploads are access-checked on every request. No system is perfect: if we ever become aware of a breach affecting your data we will tell you and, where required, the ICO within 72 hours.

Children

Panorivo is for people running a business, and not intended for anyone under 18.

Changes

If this policy changes materially we will say so on this page and update the date at the top. Continuing to use Panorivo after a change means the new version applies.

See also our terms of use.