Privacy Policy

Last updated: 11 May 2026

This Privacy Policy explains how PROOFsure ("we", "us", "our") collects and processes personal data when you use the PROOFsure web application, mobile-installable app and related services (the "Service"). It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

PROOFsure is operated as a sole trader business by [YOUR FULL NAME], trading as PROOFsure, of [YOUR BUSINESS ADDRESS, UK]. We are the data controller for personal data submitted to the Service by account holders. Account holders are themselves data controllers for the personal data of their customers that they upload — see Section 9.

Contact: hello@proofsure.co.uk. We are in the process of registering with the UK Information Commissioner's Office (ICO). Our registration number will be published here once issued.

2. What personal data we collect

2.1 Account & billing data

  • Name, email address, password (stored as a salted hash by our authentication provider).
  • Business name, trading address, phone number, VAT number (optional).
  • Subscription tier, billing status and Stripe customer ID. We do not see or store full card numbers.

2.2 Job content you create

  • Job titles, descriptions, line items, prices, notes.
  • Customer details you enter (name, address, email, phone) — see Section 9.
  • Photographs you upload, including any EXIF metadata they contain.
  • AI-generated text derived from those photographs and your inputs.

2.3 Technical data

  • IP address, device type, browser, approximate location derived from IP, time zone.
  • Usage events (pages viewed, features used, errors encountered).
  • Cookies and similar storage strictly necessary to keep you signed in and to remember preferences.

3. How we collect it

  • Directly from you when you sign up, complete onboarding, create a job, upload photos or contact us.
  • Automatically through standard server logs and our error-monitoring tools when you use the Service.
  • From our payment processor (Stripe) — limited transaction metadata (last 4 digits, country, success/failure).

4. Why we use it (lawful bases)

We rely on the following lawful bases under Article 6 UK GDPR:

  • Contract performance — to provide the Service you signed up for, including hosting your data, generating reports and processing payments.
  • Legitimate interests — to keep the Service secure, prevent fraud and abuse, debug issues, and improve features. We balance this against your rights and only use the minimum data needed.
  • Legal obligation — to keep accounting records (UK tax law requires retention for 6 years) and to respond to lawful requests.
  • Consent — for any optional marketing emails. You can withdraw consent at any time via the unsubscribe link or by emailing us.

5. Automated processing & AI

When you upload photos to a job, the images and your job context are sent to our AI sub-processor (the Lovable AI Gateway, which routes the request to Google — see Section 7) which returns a draft textual description. This is an assistive tool: the output is presented to you for review and editing before any report is finalised or shared. No decision producing a legal or similarly significant effect on you or your customers is made solely by automated means within the meaning of Article 22 UK GDPR.

We do not use your job content, photos or customer data to train AI models. Our AI sub-processors are contractually prohibited from using your data to train their models on the API tier we use.

6. How long we keep it

  • Account data — for the lifetime of your account, plus up to 30 days after account closure to allow recovery.
  • Job content (jobs, photos, reports) — until you delete the job or your account, whichever is sooner.
  • Billing & tax records — 6 years from the end of the relevant accounting period (HMRC requirement).
  • Server & security logs — up to 90 days, then deleted or aggregated.

7. Who we share it with (sub-processors)

We use the following service providers. Each is bound by a written data-processing agreement and processes data only on our instructions.

  • Supabase (hosted via Lovable Cloud) — database, authentication and file storage. Data is hosted in the European Union (Frankfurt region).
  • Lovable AI Gateway (operated by Lovable, EU) routing to Google LLC (USA) — AI photo analysis and report drafting (Google Gemini API). Photos and prompt context are transmitted via the gateway to Google's Gemini API. Google does not use API data to train its models, and the gateway operator processes the request only to route it. Transfers outside the UK/EEA are protected by the EU/UK Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA) — subscription billing and card processing. PCI-DSS Level 1 certified. Card details are entered directly into Stripe and never reach our servers.

We do not sell your personal data. We do not share it for advertising. We may disclose data where required by law (court order, lawful regulator request) or to defend our legal rights.

8. International transfers

Where data is transferred outside the UK or EEA (notably to Google via the Lovable AI Gateway, and to Stripe in the United States), we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with supplementary technical measures (encryption in transit and at rest). A copy of the relevant transfer mechanism is available on request.

9. Data about your customers (controller-to-controller)

When you upload information about your end customers (name, address, photos of their property, etc.), you are the controller of that data. PROOFsure acts as a processor on your behalf for that content. You are responsible for:

  • Having a lawful basis to collect that data and to upload it to us.
  • Telling your customers, where appropriate, that you use a third-party tool (PROOFsure) to prepare reports and invoices.
  • Honouring your customers' rights requests in respect of that data.

Our use of that data on your behalf is governed by the Data Processing Terms incorporated into our Terms of Service.

10. Your rights

Under UK GDPR you have the right to:

  • Be informed about how we use your data (this notice).
  • Access a copy of your personal data.
  • Have inaccurate data corrected.
  • Have your data erased ("right to be forgotten"), subject to legal retention duties.
  • Restrict or object to processing based on legitimate interests.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where we relied on consent.
  • Lodge a complaint with the ICO (ico.org.uk / 0303 123 1113).

To exercise any of these, email hello@proofsure.co.uk. We will respond within one calendar month.

11. Security

We use HTTPS for all traffic, encryption at rest for stored files, hashed passwords, role-based access, and Row Level Security on our database so that one account cannot access another's data. No system is 100% secure: in the unlikely event of a personal-data breach meeting the UK GDPR threshold, we will notify the ICO within 72 hours and affected users without undue delay.

12. Cookies

We use a small number of strictly necessary cookies and browser storage items required for authentication, session continuity and to remember whether you have dismissed the install banner. We do not use advertising or cross-site tracking cookies and therefore do not require a consent banner under PECR for these.

13. Children

The Service is intended for use by businesses and is not directed at children under 18. We do not knowingly collect data from children.

14. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the latest version. Material changes will be notified by email or in-app notice at least 14 days before they take effect.

This document is provided for transparency and to meet our obligations under UK GDPR and the Data Protection Act 2018. It is not a substitute for independent legal advice for users. Questions? Email hello@proofsure.co.uk.