Last updated: June 10, 2026
ProofCap ("ProofCap", "we", "our", or "us") provides a forensic financial verification platform for SaaS acquisitions (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described below.
When you create a ProofCap account, we collect your name, email address, a hashed password, and any company or role information you choose to provide.
ProofCap's core function is to read data from third-party platforms you authorize via OAuth, using read-only scopes:
We request the minimum scopes necessary to run an audit and never request write access to any connected account.
We store the audits you run, including computed scores, generated reports, verification badges, and any share links or access controls (such as passwords or expiry dates) you configure for those reports.
Subscription payments are processed by Stripe. ProofCap does not store full payment card numbers — Stripe provides us with limited billing metadata (such as plan, status, and invoice history) needed to manage your subscription.
We collect standard technical data such as IP address, browser type, device identifiers, and session/authentication cookies needed to keep you signed in and to maintain the security of the Service.
We do not use the financial or analytics data accessed through your connected accounts for advertising, and we do not sell it.
We do not sell your personal data. We share information only with:
You can disconnect ProofCap's access to your Stripe or Google Analytics account at any time, either from the ProofCap dashboard or directly from that platform's connected-apps settings. Disconnecting immediately stops further data collection from that source, but does not retroactively delete reports already generated.
We retain account data, audit history, and reports for as long as your account is active. If you delete your account, we permanently remove your personal data and connected-account tokens within 30 days, except where we are required to retain limited records for legal, tax, or fraud-prevention purposes.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). OAuth tokens are encrypted before storage and are never logged or exposed in API responses. For more detail, see our Security page.
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. See our GDPR page for details on how to exercise these rights.
The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on the Service. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.
Questions about this Privacy Policy or how we handle your data can be sent to [email protected].