Privacy Policy
Effective:
This Privacy Policy explains how ProofRows, the United States-based operator of ProofRows, (“ProofRows,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal data. It applies to our public websites, applications, APIs, integrations, beta program, and support interactions (collectively, the “Service”). It also explains the choices and privacy rights available to you.
1. Scope and our role
ProofRows is the controller or business responsible for personal data used to manage accounts, subscriptions, the public website, security, support, and our business relationship with you.
The Service is operated from the United States and may be used by eligible customers in other countries. This policy applies wherever you use the Service, subject to any additional rights and requirements under the law that applies to you.
When a customer uploads bank statements, receipts, client records, or related information to a workspace (“Customer Data”), the customer decides why and how that data is processed. For that Customer Data, the customer is the controller or business and ProofRows acts as its processor or service provider. We process Customer Data only to provide the Service and follow the customer’s instructions, as described in our Data Processing Addendum.
This policy does not govern third-party websites, accounting platforms, banks, or other products that you choose to connect to or visit.
2. Personal data we collect
- Account and identity data — email address, account identifier, authentication status, and, if you use a sign-in provider, the provider identifier and basic profile details it makes available. Password credentials are handled by our authentication provider; ProofRows cannot read your password.
- Customer and workspace data — client names, industry, contact details, notes, retention settings, API keys in hashed form, integration settings, and other information you add to the workspace.
- Financial documents and extracted data — statement and receipt files; bank and account details; account-holder and counterparty names; transaction dates, descriptions, amounts, balances, categories, confidence indicators, source locations, and your edits or review decisions.
- Usage and audit data — pages processed, plan usage, job status, export format, filename, row count, options, integrity hash, and timestamps. We do not retain the generated export file itself.
- Billing data — if paid billing is available and you subscribe, we receive payment-customer and subscription identifiers, plan, price, billing period, and payment status from our payment processor. We do not store full payment-card numbers or card security codes.
- Communications and beta applications — the name, email, company, role, expected document volume, message, attachments, and other information you provide when you request access or contact support.
- Device, security, and consent data — IP-derived or hashed network identifiers, coarse region, browser and operating-system family, request and event timestamps, authentication and security events, consent choices, policy version, and Global Privacy Control status. Our hosting and security providers may also process standard connection logs needed to deliver and protect the Service.
- Public-site analytics — if you opt in, our analytics provider receives public page URLs, page titles, device and browser information, and cookie identifiers used to count visits. Analytics is not loaded inside the signed-in workspace and does not receive Customer Data.
3. Where personal data comes from
We receive personal data from:
- You, when you create an account, apply for beta access, configure a workspace, upload documents, choose cookie settings, purchase a plan, or contact us.
- Customers that upload records concerning their clients, account holders, employees, vendors, or other counterparties.
- Sign-in, payment, integration, and other providers you direct us to use.
- Your browser, device, and network when you use the Service.
- The Service itself, when it creates extraction results, validation signals, usage records, and audit events.
4. How and why we use personal data
We use personal data to:
- Provide the Service — authenticate users, receive documents, run extraction and validation, save edits, generate exports, support integrations, and administer accounts.
- Follow customer instructions — process Customer Data under the Terms and Data Processing Addendum.
- Manage plans and payments — measure usage, administer trials, process subscriptions, maintain billing records, and prevent duplicate or fraudulent charges.
- Secure and maintain the Service — detect abuse, enforce access controls and rate limits, diagnose failures, preserve audit trails, and protect users and systems.
- Communicate with you — respond to support and privacy requests and send essential account, security, policy, or service notices.
- Understand our public website — measure visits and improve public pages only when you have consented to analytics.
- Comply with law — respond to lawful requests, enforce agreements, resolve disputes, and meet tax, accounting, fraud-prevention, and regulatory obligations.
Where the GDPR, UK GDPR, or similar law applies, our legal bases are performance of a contract, compliance with legal obligations, your consent, and our legitimate interests in operating, securing, supporting, and improving the Service. When we rely on consent, you may withdraw it at any time without affecting earlier lawful processing. When we rely on legitimate interests, we consider the sensitivity of the data and your rights.
5. Document extraction and automated processing
ProofRows uses OCR, extraction systems, validation rules, and machine-learning tools to turn uploaded documents into structured records and review signals. An extraction provider may receive document pages and return structured data solely to perform this task. We do not use Customer Data to train our models, and we do not authorize our providers to train models on it.
Extraction results can be wrong and are designed for human review. ProofRows does not use Customer Data to make decisions that produce legal or similarly significant effects about an individual. Customers decide how to review, correct, export, and use the results.
6. How we disclose personal data
We disclose personal data only as needed for the following purposes:
- Cloud infrastructure and authentication — database, private object storage, account authentication, and encrypted data hosting.
- Document extraction — OCR and structured extraction of documents at the customer’s direction.
- Application hosting — serving the Service, routing requests, and processing operational connection data.
- Payments — checkout, subscription administration, invoicing, fraud prevention, and payment support.
- Transactional email — account confirmation, password reset, and essential service notices. We do not include document contents in transactional email.
- Error monitoring — operational diagnostics after financial values, request contents, credentials, and sensitive URLs are removed.
- Public-site analytics — measurement of public page visits after you opt in. Analytics does not run in the signed-in workspace.
- Integrations you choose — accounting or other platforms when you direct ProofRows to export or transmit data to them.
- Legal and safety recipients — courts, regulators, law enforcement, professional advisers, insurers, or other parties when reasonably necessary to comply with law, protect rights and safety, or establish and defend legal claims.
- Business transfers — a prospective or completed merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and data-protection safeguards.
Providers receive only the data needed for their function and are contractually limited in how they may use it. Customers covered by our Data Processing Addendum may request the current named Customer Data sub-processor list at privacy@proofrows.com and receive advance notice of changes as described in that addendum.
We do not sell personal data, rent it to data brokers, share it for cross-context behavioral advertising, or use it for targeted advertising.
7. Cookies and public-site analytics
We use essential technologies to keep accounts secure and complete requested payment flows. Non-essential analytics is disabled unless you opt in. You can reject it or withdraw consent at any time through Cookie preferences, and we honor supported Global Privacy Control signals. Our Cookie Policy identifies the technologies, providers, purposes, and retention periods in detail.
8. Security and access controls
We use technical and organizational safeguards designed for the sensitivity of the data. Customer records are protected by database row-level access controls. Uploaded documents are stored in private object storage, encrypted at rest, and transmitted over TLS. Source previews use a document-specific link that expires after 60 seconds. API key secrets are hashed and shown only at creation. Generated export files are streamed to your browser instead of being retained on our servers.
Access to Customer Data is limited to providing and securing the Service, investigating suspected abuse, responding to a support request you initiate, or complying with law. No online service can guarantee absolute security. Visit our Security page for current controls and reporting instructions.
9. Retention and deletion
- Source statements and receipt files are automatically deleted after the retention period configured for the client; the default is 30 days.
- Extracted records and review history remain available until you delete the related record or account so completed work is not lost when a source file expires.
- Generated exports are built in memory and streamed to your device. We retain an audit record containing format, filename, options, row count, integrity hash, and timestamp, but not the export file.
- Account and workspace data remain while the account is active. Account deletion removes active workspace rows and uploaded statement and receipt objects. Limited records may remain where a provider must retain them for fraud prevention, legal compliance, dispute resolution, or backup rotation.
- Cookie-consent records are retained for the period reasonably needed to document your choices, the applicable policy version, and compliance with privacy law.
- Billing, support, security, and legal records are retained only as long as reasonably needed for their purpose and any applicable legal, accounting, or dispute-resolution requirement.
10. International data transfers
ProofRows is based in the United States. We and our providers may process and store personal data in the United States and other countries where our providers operate. Those countries may have privacy laws different from the laws where you live. When applicable law requires a transfer safeguard, we use a recognized mechanism such as an adequacy decision, contractual protections, or another lawful transfer mechanism. Additional transfer terms for Customer Data appear in our Data Processing Addendum.
11. Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to access, correct, delete, or receive a portable copy of personal data; restrict or object to processing; withdraw consent; opt out of certain disclosures or targeted advertising; and appeal a decision about your request. You also may have the right to complain to your local privacy or data-protection authority. We do not discriminate against anyone for exercising a privacy right.
- Access and export — review workspace records and export statement data from the Service.
- Correction — edit workspace and extracted data in the Service or ask us to correct account information.
- Deletion — delete individual records or use Settings → Danger zone to delete the account.
- Cookie choices — use Cookie preferences to reject or withdraw non-essential analytics consent.
- Privacy request — email privacy@proofrows.com.
We may need to verify your identity and authority before completing a request. If an authorized agent submits a request, we may ask for proof of authorization and direct verification with you. We will respond within the period required by applicable law and explain any lawful reason we cannot fulfill all or part of a request.
You may use the same request process regardless of where you live. We will provide the rights required by applicable law; some rights and response periods vary by location.
If your request concerns Customer Data that a ProofRows customer uploaded about you, contact that customer first. The customer controls that data, and we will assist it in responding as required by law and our Data Processing Addendum.
12. United States state privacy notices
If a state privacy law applies to our processing, the categories described in section 2 may include identifiers; customer records and financial information; commercial and subscription information; internet or other electronic activity; professional or employment information you provide; and inferences limited to extraction and validation results. Customer-uploaded financial documents may contain sensitive personal information. We process that information only to provide and secure the Service at the customer’s direction, not to infer characteristics about individuals.
In the preceding 12 months, we have not sold personal information or shared it for cross-context behavioral advertising. We do not offer a financial incentive for personal information. Where required, we honor Global Privacy Control as a request to opt out of sale, sharing, or targeted advertising—even though ProofRows does not currently engage in those practices.
13. EEA, United Kingdom, and Switzerland
Individuals in these regions may have rights to be informed; access and receive a copy of personal data; correct inaccurate data; request deletion or restriction; receive portable data; object to processing based on legitimate interests; withdraw consent; and avoid decisions based solely on automated processing that produce legal or similarly significant effects. ProofRows does not make such solely automated decisions about individuals.
You may lodge a complaint with the data-protection authority where you live, work, or believe a violation occurred. We encourage you to contact us first so we can address the concern directly.
Where applicable law requires ProofRows to appoint a representative in the European Economic Area, the United Kingdom, or another region, we will appoint one and publish the representative’s contact details here. Until a regional contact is listed, send privacy questions and requests to privacy@proofrows.com.
14. Children
The Service is designed for business professionals and is not directed to anyone under 18. Customers may not intentionally upload personal data about anyone under 18. If you believe a child’s personal data has been submitted, email privacy@proofrows.com so we can investigate and take appropriate action.
15. Changes to this policy
We may update this policy as the Service, our providers, or applicable law changes. We will post the revised policy and update the effective date. If a change materially affects how we use Customer Data or reduces your rights, we will provide reasonable advance notice by email or in the Service unless a legal or security need requires faster action. When required, we will request consent before applying a new use.
16. Contact us
Send privacy questions, rights requests, and complaints to privacy@proofrows.com. For product help, visit our Support page. Please do not email statement files or other sensitive financial information.