Privacy Policy
How Proofmark handles account, handover, approval, payment-status, and delivery records.
Introduction
Proofmark helps freelancers and agencies record client approval, payment status, and final-file delivery. This policy explains the information required to operate that workflow and the evidence visible to account owners and their clients.
What we collect
We store account identity, branding, client contacts, agreements, project metadata, deliverables, and settings needed to provide the service.
We record subscription billing events, approval timestamps, payment status, file hashes, unlocks, and completed download events. Proofmark does not store payment-card numbers.
Approval and network evidence
When a client responds through a valid approval link, Proofmark records the request IP supplied by the hosting network, the request user agent, and locally detected browser/device details. We do not send the visitor to a separate IP geolocation service and do not infer or store a country from that IP.
How we use data
We use this information to operate client handovers, protect private files, investigate abuse, support users, maintain approval and delivery records, and improve the service. We do not sell personal information.
Service providers
Supabase provides authentication, database, and private file storage; Dodo Payments processes Proofmark subscription billing; Resend delivers configured transactional email; and hosting or analytics providers process limited operational data when those services are enabled.
Export, deletion, and retention
Account owners can download a structured export from Settings. Account deletion requires a recent sign-in and is scheduled after a seven-day cooling-off period, during which it can be cancelled before processing starts. Live application records and account-owned storage are removed in retryable stages. Existing managed backups cannot be selectively edited; protected copies expire under the configured provider backup schedule. Independent processors may retain records under their own legal and operational obligations.
Operational records
Proofmark keeps bounded delivery and worker-health metadata to operate and secure the service. Current code purges global webhook diagnostics after 30 days and background notification and worker evidence after 90 days. Active handover evidence remains available while the account is active unless the account owner deletes the account.
Policy updates
We may update this policy when the product or its providers change. Material changes will be reflected by the updated date below. Contact support@proofmark.space with privacy questions.