Customer portal
The portal is where your customers sign in to see their own documents, tickets and orders.
Portal access is its own kind of identity
A contact is granted portal access. They do not become a member of your organization, they do not get a role, and they cannot be given one by mistake.
This separation is structural, not a setting
If a customer were a user with a narrow role, they would be one misconfiguration away from your data. As a different kind of identity, the misconfiguration is not available to make.
What a customer sees
Their own documents, their own tickets, their own orders. Not another customer's, not your internal notes, not your costs.
Registration
How somebody gets access is configurable per organization: by invitation only, on request with approval, or open registration. Invitation-only is the right default for most businesses.
Registration asks for little on purpose: a shape (company or private person), the name, a company's identifiers, an e-mail and a password. The address is not asked here — the account page and the checkout take it. From the moment the access exists the contact is linked to the account, so the shop recognizes the customer: their address is shown at the checkout instead of asked, the order lands on their own record, and no duplicate contact appears at the first purchase.
Sign-in never dead-ends
Three journeys keep an account reachable without your staff's help:
- Forgotten password — the sign-in page mails a reset link (valid two hours) from your firm's own mail identity; following it sets a new password and signs the customer in.
- Lost verification — a registration that was never confirmed can have its verification re-sent, from the expired-link page or simply by registering the same address again: the portal recognizes the half-made account and re-sends instead of refusing.
- A second supplier — a person who is already a customer of one firm on the platform registers on your site with the same e-mail and their existing password; that creates your customer contact and access for them (honoring your registration mode) without a second account. Your data and the other firm's never touch.
WHY the request doors always answer the same sentence: a page that answered "no such account" differently from "mail sent" would let anyone test which e-mail addresses are your customers. The answer is identical either way — only the mailbox owner learns more.
The reset mail is brandable in Configuration → Mail templates (Portal: password reset), like the verification and invitation mails.
Enquiries
A portal enquiry can become a lead or a ticket, so a customer's question arrives where it will be worked rather than in an inbox.
The account page
Customers manage their own details and their contact preferences. Consent withdrawn there is consent withdrawn everywhere, immediately.
The area is one frame with tabs — a column beside the content on a
desk, a strip that scrolls on a phone: Overview (a glimpse of every
agenda with the way into its tab), Orders & invoices, Shipments
(only where the firm runs the transport agenda), Downloads & licences
(only where a release or a licence exists for the customer),
Enquiries, Support, Files, My details and Account
settings. Every tab is its own address under /account/, so a link from a
mail lands on the right one; the pages are never indexed.
My details is where a customer keeps their name, phone and billing address — and, for a company, IČO, DIČ and IČ DPH. The values live on the contact record itself, the same fields the checkout prefills and the invoice renders; an emptied field clears. A customer edits only the contact their account acts for, and a record another account already acts for keeps its owner.
An address typed at the checkout by a signed-in customer is remembered on their contact too — the next checkout shows it with a pencil, the invoice carries it. Only what was typed and differs is written; the e-mail and the name stay the customer's own. An anonymous checkout keeps making its own contact, as before.
Where the firm sells through a merchant of record (Paddle), Orders & invoices also opens the processor's customer portal for the signed-in customer — invoices, payment details and cancellations live there; see Paddle.