Legal
Privacy Policy
Last updated: September 10, 2026
This Privacy Policy explains how the operator of portfolioriskhub.com (“PRH,” “we,” “us”), doing business as Portfolio Risk Hub and forming Portfolio Risk Hub, LLC under Mississippi law, handles information on portfolioriskhub.com and in the Portfolio Risk Hub application (the “Service”).
Entity status. Portfolio Risk Hub, LLC is in formation and has not yet received an effective Certificate of Formation from the Mississippi Secretary of State. Until formation is effective, these terms bind the operator of the Service. When formation is effective, Portfolio Risk Hub, LLC becomes the contracting party under this Privacy Policy without a new click-accept, unless we post a material update.
If you have a workspace, your organization is generally the customer. You retain all rights you have in those source files; PRH does not claim ownership of them (third-party materials remain subject to their owners’ rights — see Terms §3). We use identifiable workspace data to run the Service for you. Separately, we may create and commercialize only sufficiently aggregated and de-identified analytics and benchmarks, as described below and in Terms §3. We do not sell your identifiable book, and we do not create a commercial dataset of tenant or resident personal information.
1. Who this covers
- Site visitors (marketing pages, demo / sample hub).
- Account users (people who log in to a firm or authority workspace).
- Concierge contacts (people who email us files or instructions for onboarding).
The public sample hub (including any Crescent Bend demonstration) is illustrative. Do not put live personal data into public demo fields.
2. Information we collect
A. You give us
- Name, work email, organization name, password (hashed), and billing contacts.
- Customer files and data loaded into a workspace: schedules of values, policy documents, coverage summaries, Coverage Scenario Explorer inputs, board-report inputs, and similar insurance-program records.
- Emails you send to hello@ or legal@ at portfolioriskhub.com.
- Payment details if live billing is on (processed by Stripe; we do not store full card numbers).
B. We collect automatically
- Log data, device/browser type, approximate location from IP, pages viewed, and cookies or similar needed to run the site and keep you logged in.
- Security and error diagnostics from our hosts.
C. We do not intentionally collect
- Social Security numbers, driver’s-license images, or payment-card PAN/CVC. Please do not upload them.
- Information from children under 18. The Service is for organizations, not consumers or kids.
3. How we use information
- Provide, secure, and improve the Service and concierge onboarding.
- Create and administer workspaces; display the book you asked us to load.
- Communicate about the Service, billing, and policy/legal notices.
- Prevent abuse, debug, and comply with law.
- If you ask for a paid plan, process payment via Stripe.
- Create sufficiently aggregated and de-identified analytics and benchmarks, which we may retain and commercialize. That is not a sale of your identifiable book.
We do not sell personal information. We do not sell your identifiable workspace files. We do not compile or sell a commercial dataset of tenant or resident personal information.
How the book gets filled (v1). Hand entry, structured CSV / structured-file import, and concierge onboarding load the book. Storing a policy PDF is not the same as extracting it into coverage lines. v1 does not include automated AI document extraction. If optional AI document extraction is offered later, this Privacy Policy will be updated, the AI subprocessor will be named, and the customer can decline. We do not use Customer Content to train general-purpose AI models.
4. How we share information
We share information only:
- With service providers that host or operate the Service under a contract, currently including:
- Vercel (application hosting);
- Neon (Postgres database, our system of record for workspace data);
- Vercel Blob (private file storage for uploaded documents);
- Cloudflare (DNS and email routing for portfolioriskhub.com);
- Stripe (payments, if and when live charges are enabled).
- With your own users inside your workspace, according to permissions you set.
- If the law requires (subpoena, court order), or to protect rights, safety, or security.
- In a company transaction (formation already in progress; later merger or asset sale), subject to this policy or notice.
We will not give identifiable Customer Content to an insurance carrier, TPA, or broker unless you direct us to or you use a feature that does so. Sharing property-level detail with carriers (an Underwriting Network) is not part of the base Service and is not enabled. If offered later, it would require a separate opt-in.
Mail to hello@portfolioriskhub.com and legal@portfolioriskhub.com is received in company-controlled mailboxes for the Service. Do not send confidential material to those addresses unless you are authorized to do so.
5. Customer files and confidentiality
Workspace insurance files are your (or your client’s) confidential source records. We treat identifiable Customer Content as customer-confidential, store files in a private blob store, and use Neon as the database of record. Production customer data is not supposed to live in the public demo. Sufficiently aggregated and de-identified Derived Data may be retained and commercialized as described in this policy and Terms §3.
You decide what to upload. If you are a public housing authority, public-records law may require you to disclose some records. We are not your records officer.
On written request when an account closes, we will export then delete or de-identify source Customer Content from production systems as described in the Terms of Service, except backups that expire on their cycle and legal retains. We may retain sufficiently aggregated and de-identified Derived Data after source deletion.
6. Cookies
We use cookies or local storage that are necessary to run the site (session, authentication, load balancing). We do not run a third-party advertising pixel on the app as of this policy. If that changes, we will update this policy.
7. Retention
Account data: for the life of the account plus a reasonable close-out period.
Source Customer Content: until you delete it or the workspace is closed, then we delete or de-identify it from production systems as in Section 5.
Aggregated and de-identified Derived Data: may be retained after source deletion and used as described in Section 3 and Terms §3.
Billing records: as tax and accounting rules require.
Server logs: a short operational period unless needed for security.
8. Security
We use HTTPS, private file storage, access-controlled databases, and least-privilege practices we consider commercially reasonable. No system is perfectly secure. Keep original policies in your own records. Notify us promptly at legal@portfolioriskhub.com if you believe an account was compromised.
9. Your choices and rights
You may request access, correction, or deletion of personal information we hold as controller (account profile, site logs) by emailing legal@portfolioriskhub.com. For files inside a customer workspace, ask your organization’s administrator first; we process that data for them.
If U.S. state privacy laws (for example a consumer right to know, delete, or opt out of sale/share) apply to you, we will honor a verifiable request as required. We do not sell or share personal information for cross-context behavioral advertising.
We will not discriminate against you for exercising a privacy right.
10. International visitors
The Service is operated from the United States. If you access it from elsewhere, you understand information is processed in the U.S.
11. Changes
We will post updates here and change the date above. Material changes will also be emailed or shown in-product when we have a contact.
12. Contact
Portfolio Risk Hub (Portfolio Risk Hub, LLC in formation)
legal@portfolioriskhub.com · hello@portfolioriskhub.com
https://portfolioriskhub.com