Privacy
Privacy policy
Last updated 2026-06-01.
1. The short version
- We collect what we need to run the service: your email, the data you create inside the apps, payment metadata for Pro subscriptions.
- We don’tsell your data. We don’t train AI models on it. We don’t share it with advertisers.
- When you use the AI assistant, the conversation goes from our server to Google so it can answer. They see it; we don’t share with anyone else.
- You can export or delete your data any time from /account.
2. What we collect
- Account info. Email + name from your sign-in (Google or email/password). Optional profile fields you fill in.
- Your business data. Whatever you put into the apps: customers, work orders, vehicles, products, menus, contracts, photos, etc. Lives in our database in the United States.
- Payment metadata. If you subscribe to GoGoPortal Pro, Stripe (our payment processor) holds your card. We store the subscription status, period dates, and a Stripe customer id. We never see your card number. When an app lets you take payments from your own customers (via Stripe or Square), that processor — not us — holds the card details.
- Usage data. Standard server logs (IP, user-agent, requested URLs, timestamps). Used for security + debugging; rotated within 30 days.
- Reports you file.If you use a “Report this …” link to flag a public page, we store what you reported, the reason and any details you add, and — so we can follow up and curb abuse of the form — your email (if you give one) and IP address.
- AI conversation data. See §4.
3. How we use it
- To provide the service to you (the obvious one).
- To fix bugs, prevent abuse, and keep the service running.
- To send you transactional emails: invoice receipts, password resets, login codes, contract notifications you triggered, etc. You can unsubscribe from non-essential mail; account & security mail is required while you have an account.
- To improve the product. We read aggregated, anonymized metrics about which features get used. We do not read individual user data unless we’re responding to a support request you filed, or investigating an abuse report.
Specific things we don’tdo: we don’t sell your data to anyone; we don’t use it for advertising; we don’t train AI/ML models on it; we don’t share it with a parent company because we don’t have one.
4. The AI assistant
The AI assistant is opt-in. It’s hosted on our own Google Gemini key (free up to a daily message cap) — there’s nothing to set up and no key to bring. Here’s exactly what happens with the data:
- The hosted assistant.We run it on our own Google Gemini key — you don’t supply anything. We keep a simple per-day count of how many assistant messages you’ve sent so we can enforce the free cap; the model cost is ours.
- Chat messages. Each turn of conversation is sent to Google, which answers the hosted assistant, so it can respond. Google’s privacy policy applies to whatever it sees — please read theirs. We don’t share with any other AI provider.
- Tool results. When the AI needs to look something up to answer (e.g. “how many open work orders do I have?”), we run a database query scoped to your shop and pass the result back to the AI as part of its context. So the AI provider sees the data the AI needed in order to answer.
- Audit log.We keep a record of each chat session on our server: your messages, the AI’s replies, every tool call, every confirmed mutation. You can read your own audit log at /account/ai. Site admins (Scott + anyone he’s designated) can read all audit logs to debug problems and to read user feedback (see below).
- Feedback you give the AI.When you tell the AI things like “I wish there were a button for X” or “this is confusing,” the AI files that as feedback. The verbatim quote is stored alongside your email + name so the team can follow up if helpful. Don’t put anything into chat you wouldn’t want a human at GoGoPortal to read.
5. Cookies + similar tech
We use one cookie: the authentication session cookie that keeps you signed in. No analytics cookies, no advertising cookies, no third-party trackers. The session cookie is httpOnly, Secure, and SameSite=Lax — standard hardening.
6. Where data lives
Servers + database in the United States. Payment data is held by Stripe (also US, with their own infrastructure). AI traffic goes to Google, which powers the assistant (typically US/EU). If you’re in the EU/UK, you’re consenting to data leaving your region by using the service.
7. Your rights
- Access.Everything you put in is visible to you in the relevant app — there’s no hidden shadow profile. Email
support@gogoportal.iofor an exhaustive export if you want one. - Correction. Edit your own records inside the apps.
- Deletion. Delete your account from /account. We’ll erase your personal data within 30 days unless legally required to retain (e.g. payment records for tax purposes). Anonymized aggregates may persist.
- Portability. CSV exports exist for the major data types (customers, work orders, etc); ask support if you need anything not exposed in-app.
- Complaint.If you’re in a jurisdiction with a data-protection authority (GDPR / UK ICO / CCPA / etc.), you can complain to them about how we handle your data. We’d prefer you complain to us first so we can fix it.
8. Children
GoGoPortal isn’t directed to anyone under 16. We don’t knowingly collect data from children. If you think a child has signed up, email us and we’ll delete the account.
9. Changes to this policy
Material changes get an email to your account address with at least 14 days’ notice before they take effect. Cosmetic changes (typos, clarifications) just get a new “Last updated” date.
10. Contact
Email support@gogoportal.io for any privacy question. We read every message.