Privacy Policy
Last updated September 5, 2026
This policy explains what personal data Proposly collects, why, and what rights you have. It applies to our website and app.
1. Data we collect
- Account data — your name, email, password (stored hashed by our authentication provider), and business name.
- Content you enter — proposals, pricing, and the client names, emails, and details you add to them.
- Recipient data — when a proposal is opened or accepted we record the recipient’s name, email, signature, IP address, and timestamps, so you have a record of acceptance.
- Payment data — handled by Stripe. We store Stripe identifiers and status, not full card numbers.
- Technical data — logs, and if analytics is enabled, aggregate usage data. We do not sell your data or use third-party advertising trackers.
2. Why we use it
To provide and secure the Service, process payments, send transactional email (proposal sent, proposal accepted, password reset), provide support, comply with law, and improve the product. Our legal bases, where GDPR applies, are performance of a contract, legitimate interests, and consent where required.
3. Sub-processors
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Stripe — subscription billing and client deposit payments.
- Resend / Amazon SES — transactional email delivery.
These providers process data on our behalf under their own security and privacy commitments. Data may be processed in the United States.
4. Retention
We keep your account data for as long as your account is active. After you delete your account we remove or anonymise personal data within 30 days, except where we must keep records for legal, tax, or dispute purposes.
5. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, object to certain processing, or withdraw consent. You can export or delete your data from account settings, or email us and we will action the request. You may also complain to your local data protection authority.
6. Recipients’ data
When you enter a client’s details you are the controller of that data and Proposly is your processor. You are responsible for having a lawful basis to contact your clients. If a recipient asks us to remove their data we will refer them to you and assist as required.
7. Cookies
We use a small number of strictly necessary cookies for login sessions and security. If we add analytics or any non-essential cookie we will ask for consent where the law requires it.
8. Security
Data is encrypted in transit. Access to production systems is restricted. Every account’s data is isolated by row-level security, and public proposal links use unguessable tokens. No system is perfectly secure; if a breach affects your data we will notify you as required by law.
9. Children
The Service is not directed to anyone under 18 and we do not knowingly collect their data.
10. Changes
We may update this policy. Material changes will be notified by email or in the app before they take effect.
Questions? hello@proposly.net