What this notice covers
It covers the public Proofline website at proofline.sh and the hosted Proofline service. Proofline Dev, Inc. operates both.
The contact form
When you send a message, the form stores the name, email address, company and message you enter, together with an opaque identifier for the message and the time it arrived. Those records are stored in a Cloudflare D1 database.
A notification of the message is emailed to Proofline so that a person can read it and reply. We use what you send only to answer you.
Your IP address is used to rate limit submissions at the edge, so that the form cannot be flooded. Proofline does not store it with the message.
Booking a call
When you book a call, Proofline stores your name, work email, chosen time and time zone, and any company, deployment platforms and notes you provide. Cloudflare D1 stores the request, its booking status, identifiers and submission time. Proofline receives an email notification to arrange the call and respond to your questions.
Proofline sends your booking details to Cal.com to check availability and create the booking. Cal.com adds the meeting and those details to Google Calendar and uses Google Meet for the call. The invitation can include your company, deployment platforms and notes. If automatic booking fails, Proofline keeps your request and follows up by email.
Your IP address is used to rate limit booking submissions. Proofline does not store it with the request.
Investor deck access
To open the investor deck, you can verify your email address with Google or a one-time code sent by Proofline. Google processes your sign-in under its own terms. Proofline stores the verified email address, the sign-in method, and the time you first access the deck in each session. We use this information to control access and to know who has viewed the materials.
One-time codes expire after ten minutes. A deck session lasts for one day and can be ended by signing out. Cloudflare delivers the code and stores the access records in D1. Proofline removes expired code requests and sessions daily.
While you view the deck, Proofline records which slides you open, the time each slide is visible in your foreground tab, fullscreen use, navigation by swipe, button, dot, or keyboard, and clicks on source links. It also records the page visit time, last activity time, viewport size, and browser user agent. This helps Proofline understand interest in the materials and follow up with viewers. The owner can review this activity in a private dashboard. It does not record keystrokes, pointer positions, or activity on other websites.
Cookies and analytics
The public website sets no advertising or analytics cookies. The investor deck activity described above is tied to its required access session cookie.
With your consent, the signed-in app uses Cloudflare Zaraz and Mixpanel's EU service to measure feature visits and actions, including whether an action is accepted, refused, or fails, and basic browser and device details. Mixpanel uses a random browser identifier. Proofline excludes account and organization identities, repository names, customer content, full page addresses, IP addresses, and location from these events.
The app remembers your choice in a consent cookie. You can change it through "Analytics preferences" in the account menu. The app honors your browser's Do Not Track and Global Privacy Control settings.
After you sign in to Proofline, the hosted service sets a cookie named
__Host-proofline-returning on this browser for 180 days. It records only that somebody
signed in here, so that the website can show you a partner login link. It holds no account, no
organization and no identifier, and it grants no access to anything.
Signing out leaves it in place. The account menu in Proofline has a "Forget this browser" action that removes it, and clearing your browser data removes it too.
The investor deck uses a separate, secure session cookie to remember your verified access for one day. It is removed when you sign out or clear your browser data.
The hosted service
The hosted service processes the account, configuration, code, infrastructure and review data you provide through the integrations you authorize. It processes that data to provide the service: to run reviews, to record the evidence behind them, to keep the service working and secure, and to support your use of it.
You decide which supported systems to connect. Proofline accesses those systems through the permissions granted to the integrations you configure.
Infrastructure providers
Proofline runs on infrastructure operated by others, and those providers process data on our behalf in order to run it. Cloudflare serves this website, rate limits contact and booking submissions, and stores those submissions in D1. Cal.com processes booking details to schedule calls. Google provides the calendar and video meeting services for those calls.
How long we keep it
Proofline keeps information only as long as it is reasonably needed for the purposes described here, or to keep the service secure, to resolve disputes, and to meet legal obligations.
Access, correction and deletion
Write to hello@proofline.sh to ask what information Proofline holds about you, to have it corrected, or to ask us to delete it. Tell us enough to find the record, such as the email address you used.
Changes to this notice
When this notice changes, the effective date at the top of the page changes with it. The current version is the one published here.
Contact
Questions about this notice go to hello@proofline.sh.