PortalWatch

Document 03 of 04

Privacy policy

What PortalWatch reads from your HubSpot account, what we store, and how long we keep it.

Updated 25 September 2026

This Privacy Policy explains how Nidish LLC ("we", "us", "our") collects, uses, discloses, and protects information in connection with the PortalWatch application (the "App") for HubSpot.

It applies to the customer that installs the App in its HubSpot account (the "Customer") and to the HubSpot users of that account whose activity appears in the App ("Users").

For information the Customer processes in HubSpot itself, HubSpot's own privacy notices apply.

Roles

The Customer is the controller of the data in its HubSpot account, including the details of its Users. We act as a processor / service provider on the Customer's instructions when the App reads the Customer's HubSpot configuration and records changes to it. For our own operational records — the authentication and log data described below — we act as a controller.

Information the App processes

2.1 Connection credentials

DataPurposeStorage
HubSpot OAuth access token and refresh token Authenticate read-only API calls to the Customer's HubSpot account Encrypted at rest (AES-256-GCM) on our server
HubSpot Account ID (Hub ID), account domain, and the permissions granted Identify which account a check or request belongs to On our server
The HubSpot user ID and email address of the User who installed the App Know who connected the account On our server

2.2 Configuration data

The App reads the definitions of the Customer's deal and ticket pipelines and stages, deal, ticket, contact and company properties, and workflows. This includes names and labels, stage probabilities, property types and dropdown options, calculation formulas, and workflow settings, actions and enrollment criteria. Workflow actions and criteria can contain whatever the Customer configured in them, such as email addresses or message text.

We store the most recent copy of this configuration so the next check can compare against it, and a history of the changes found between checks.

The App does not read or store the Customer's contact, company, deal or ticket records.

2.3 User activity in the change history

For pipeline changes, HubSpot records which User made the change. The App stores that User's HubSpot user ID, and reads their name and email address from HubSpot so the change history can show who made the change.

When a User saves the App's settings, we record that User's HubSpot user ID and email address alongside the settings.

2.4 Operational logs

Our server writes application logs for reliability and troubleshooting. These logs may include HubSpot Account IDs, User IDs, and error messages. Authentication tokens are redacted from logs. Logs are retained for log retention period — confirm and then deleted.

2.5 Request metadata

When a User opens the App's settings page, HubSpot sends our server signed request metadata: the HubSpot Account ID, the User's ID and email address, and the App ID. We use this only to verify that the request genuinely comes from HubSpot and to show the right account's settings.

How we use information

We use the information above only to:

  • authenticate and make read-only API calls to the Customer's HubSpot account;
  • detect changes to the Customer's configuration and show them, with who made them, on the App's settings page;
  • operate, secure, monitor, and troubleshoot the App.

We do not sell personal information, share it for cross-context behavioural advertising, or use it to train machine-learning models. We do not use the Customer's data for any purpose other than providing the App to the Customer.

Legal bases, where GDPR or UK GDPR applies

Where we act as a processor, the Customer is responsible for establishing a legal basis for the processing it instructs. Where we act as a controller — sections 2.1, 2.4 and 2.5 — we rely on our legitimate interests in operating and securing the App, and on performing our contract with the Customer.

Third parties and sub-processors

RecipientRoleData
Hosting provider — confirm Hosts our server infrastructure All data in section 2
HubSpot, Inc. The platform the App integrates with, and the source of all data the App reads Data the Customer stores in HubSpot

We do not disclose personal information to any other third party except as required by law, to enforce our terms, or to protect the rights, property, or safety of any person.

International transfers

Our infrastructure is located in Infrastructure region — confirm. Where personal data is transferred out of the EEA, the UK, or other regulated regions, the transfer is covered by Transfer mechanism — confirm.

Retention

  • Connection credentials (2.1) are kept for as long as the App is installed. When the Customer uninstalls the App, HubSpot revokes the OAuth tokens and we delete the stored connection record within deletion period after uninstall — confirm.
  • Configuration data and change history (2.2, 2.3) are kept for as long as the App is installed, and deleted with the connection record after uninstall, or sooner on request.
  • Operational logs (2.4) are kept for log retention period — confirm.

Access and deletion requests

Because we act as a processor for the Customer's data, Users should direct access, correction, deletion, portability, and objection requests to the Customer — the HubSpot account owner.

The Customer can ask us to delete its stored configuration data and change history at any time by emailing contact@nidish.com with its HubSpot Account ID. The Customer can also stop all processing by uninstalling the App. See the setup guide.

Security

  • HubSpot access tokens are encrypted at rest (AES-256-GCM), and all data is transmitted over TLS.
  • The App only requests read access. It cannot change anything in the Customer's HubSpot account.
  • All requests from HubSpot are cryptographically signature-verified before they are processed.
  • Access to production infrastructure is limited to authorised personnel.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children

The App is a business tool and is not directed to children. We do not knowingly process the personal information of children.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date and, where required, communicated to the Customer.

Contact

Questions about this Privacy Policy or our data practices:

EntityNidish LLC
Emailcontact@nidish.com
PhoneUS: (+1) 440-318-4500 · India: +91-9315703873
Registered officeAustin, TX, USA
India officeLucknow, UP, India