Privacy policy
Last updated 1 August 2026
What this covers
This policy explains what personal data ProposalPro Inc. collects, why we collect it, who we share it with, and what you can ask us to do with it.
It covers the ProposalPro web application and marketing site. It does not cover third-party sites you reach through links we publish.
Data we collect
Account data: your name, email address, password hash, company name, logo, and accent colour.
Content data: everything you enter into a proposal, including client names, client email addresses, scope, pricing, and attachments.
Billing data: your Stripe customer and subscription identifiers, invoice records, and the last four digits and brand of your card. Full card numbers are handled by Stripe and never reach our servers.
Usage data: sign-in events, proposal views (timestamp, IP address, and user agent of the viewer), and feature usage counts.
Why we process it
To provide the service you signed up for — creating, storing, rendering, sharing, and tracking proposals. This is processing necessary to perform our contract with you.
To take payment and meet accounting and tax obligations. This is contractual and legal-obligation processing.
To keep the service secure, prevent abuse, and diagnose faults. This is our legitimate interest in running a safe service.
To send service email you cannot opt out of, such as password resets and payment receipts. Marketing email is separate and requires consent you can withdraw at any time.
AI processing
When you use a drafting feature, the project details you supply are sent to OpenAI to generate the requested text. That may include client names and pricing.
We do not permit those requests to be used for model training. If you would rather no client data leave our infrastructure, do not use the drafting features — every other part of the product works without them.
Who we share it with
Processors that run the service on our behalf: our hosting and database providers, Stripe for payments, Resend for transactional email, and OpenAI for drafting requests. Each is bound by a data processing agreement.
We do not sell personal data, and we do not share it with advertisers.
We disclose data to authorities only where legally compelled, and we tell you unless we are prohibited from doing so.
Proposal viewers
When someone opens a share link we record the time, IP address, and browser user agent so we can show you view activity. That data belongs to the proposal you created.
If you share a link with a client, you are responsible for telling them that opens are logged where your local law requires it.
How long we keep it
Account and content data: for as long as your account is open, then 30 days after closure, then deleted.
Invoice and payment records: seven years, because tax law requires it.
Proposal view logs: 24 months.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to processing, or receive it in a portable format. Export tools for most of this are in settings; email privacy@proposalpro.com for anything else.
We respond within 30 days. If you are in the UK or EEA and unhappy with our response, you can complain to your local supervisory authority.
Security and transfers
Data is encrypted in transit and at rest. Passwords are hashed with bcrypt. Access to production data is limited to staff who need it and is logged.
Some processors operate in the United States. Those transfers rely on Standard Contractual Clauses or an equivalent approved mechanism.
Cookies
We set a session cookie so you stay signed in, and a preference cookie that remembers your light or dark theme. Both are strictly necessary or functional.
We use privacy-preserving analytics that do not set cross-site tracking cookies or build advertising profiles.
Contact
Questions or requests: privacy@proposalpro.com. We answer every one.