Legal

Privacy Policy

Last updated: June 10, 2026

ProofCap ("ProofCap", "we", "our", or "us") provides a forensic financial verification platform for SaaS acquisitions (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service, you agree to the practices described below.

1. Information We Collect

1.1 Account information

When you create a ProofCap account, we collect your name, email address, a hashed password, and any company or role information you choose to provide.

1.2 Connected financial and analytics data

ProofCap's core function is to read data from third-party platforms you authorize via OAuth, using read-only scopes:

  • Stripe: subscription, balance, and revenue (MRR/ARR) data needed to verify reported financial performance. We do not access individual customer records, payment methods, or the ability to move funds.
  • Google Analytics (GA4): aggregate traffic, session, and conversion metrics used to cross-reference revenue claims against observed engagement.

We request the minimum scopes necessary to run an audit and never request write access to any connected account.

1.3 Audit reports and verification data

We store the audits you run, including computed scores, generated reports, verification badges, and any share links or access controls (such as passwords or expiry dates) you configure for those reports.

1.4 Billing information

Subscription payments are processed by Stripe. ProofCap does not store full payment card numbers — Stripe provides us with limited billing metadata (such as plan, status, and invoice history) needed to manage your subscription.

1.5 Automatically collected data

We collect standard technical data such as IP address, browser type, device identifiers, and session/authentication cookies needed to keep you signed in and to maintain the security of the Service.

2. How We Use Your Information

  • To operate, maintain, and provide the ProofCap platform;
  • To run forensic audits and generate verification reports and badges;
  • To process subscription payments and manage your account;
  • To send account, security, and service-related communications;
  • To improve our scoring models, detect anomalies, and prevent fraud or abuse; and
  • To comply with legal obligations.

We do not use the financial or analytics data accessed through your connected accounts for advertising, and we do not sell it.

3. How We Share Information

We do not sell your personal data. We share information only with:

  • Infrastructure providers — hosting, database, and email delivery providers that operate the Service on our behalf, under appropriate data processing agreements.
  • Payment processor — Stripe, for billing and subscription management.
  • Anyone you share a report with — if you generate a shareable report link or verification badge, the contents of that report are accessible to anyone who has the link, or who satisfies any password/email verification you configure.
  • Legal and compliance — where required by law, regulation, or valid legal process.

4. Your Connected Accounts

You can disconnect ProofCap's access to your Stripe or Google Analytics account at any time, either from the ProofCap dashboard or directly from that platform's connected-apps settings. Disconnecting immediately stops further data collection from that source, but does not retroactively delete reports already generated.

5. Data Retention

We retain account data, audit history, and reports for as long as your account is active. If you delete your account, we permanently remove your personal data and connected-account tokens within 30 days, except where we are required to retain limited records for legal, tax, or fraud-prevention purposes.

6. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). OAuth tokens are encrypted before storage and are never logged or exposed in API responses. For more detail, see our Security page.

7. Your Rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. See our GDPR page for details on how to exercise these rights.

8. Children's Privacy

The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on the Service. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.

10. Contact Us

Questions about this Privacy Policy or how we handle your data can be sent to [email protected].