Skip to content
Proofel

Privacy Policy

Last updated: July 5, 2026

This Privacy Policy explains how Proofel (“Proofel”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards personal information when you use our website at proofel.com and our email review, annotation, versioning, and approval service (together, the “Service”). It also describes your privacy rights and how the law protects you. By using the Service, you acknowledge that you have read and understood this policy.

Who we are & how to contact us

Proofel (ABN 41 243 417 418) is the entity responsible for your personal information. For all privacy matters — including access, correction, and deletion requests — contact us at:

For the personal information contained in the email designs and other content our customers upload or forward to the Service, Proofel generally acts as a data processor (or “service provider”) that handles that content on the customer’s behalf and on their instructions; the customer is the controller. For account, billing, usage, and marketing data, Proofel is the controller. See Your email content below.

Scope & definitions

  • Customer — the individual or organisation that holds a Proofel account.
  • Authorised User — a team member the Customer invites into their workspace.
  • Guest Reviewer — a person who opens a share or review link to comment on or approve content without a Proofel account.
  • Content — the email designs, HTML, images, subject lines, sender names, versions, comments, annotations, tags, labels, and approval decisions placed in the Service.
  • Personal information (or “personal data”) — information that identifies, relates to, or could reasonably be linked to an identifiable individual, as defined by the Australian Privacy Act 1988, the EU/UK GDPR, and the CCPA/CPRA, as applicable.

Information we collect

Account information. When you create an account we collect your email address, name, and password (stored only as a salted hash — we never see it), together with profile details you choose to add such as a display name, avatar, timezone, and notification preferences.

Content you upload or forward. The core of Proofel is Content you choose to put into it: email designs (HTML, images, and metadata such as subject lines, preheaders, and sender names), versions, comments, annotations, approval decisions, tags, and labels. Emails you forward or send to your unique canvas address are parsed and stored the same way; images inside them are cached to our storage so your previews keep working. This Content may itself contain personal information about you or third parties.

Guest Reviewer information. Reviewers who open a share or review link without an account provide a display name so feedback is attributable. We associate that name (and, for approval links, the email address the link was issued to) with the comments and decisions they make.

Billing information. If you subscribe to a paid plan, our payment processor (Stripe) collects and stores your card and billing details. Proofel never receives or stores your full card number; we store only your subscription status, plan, billing interval, seat count, billing email, and your card’s brand and last four digits for display.

Usage & log information. We keep standard operational logs (IP address, browser and device type, and timestamps) and product-event data (for example, share-link view counts and feature usage) needed to run, secure, debug, and improve the Service. We also collect analytics and advertising data through cookies and similar technologies, described in our Cookie Policy.

How we use information & our legal bases

We use personal information for the following purposes, relying on the legal bases noted:

  • To provide the Service — rendering your emails, syncing comments in real time, routing approvals, and sending the notifications you configure. Basis: performance of a contract.
  • To operate our business — billing, support, security, fraud and abuse prevention, and service emails about your account. Basis: performance of a contract, legitimate interests, and legal obligation (for tax and accounting records).
  • To improve the Service — analysing aggregated and de-identified usage patterns to understand and enhance how Proofel works. Basis: legitimate interests.
  • To market the Service — sending product, onboarding, and lifecycle emails, and measuring and promoting Proofel through analytics and advertising. Basis: legitimate interests and, where required, consent.

We do not sell your personal information, and we do not share your Content except with the subprocessors listed below, as needed to run the Service, or as described in this policy.

Your email content (controller and processor)

When you upload, forward, or otherwise submit Content to Proofel, you determine what that Content contains and who it is shared with. For that Content, Proofel acts as your processor and handles it only to provide the Service and on your instructions. You are responsible for ensuring you have the right and a lawful basis to submit that Content, including any personal information about third parties within your email designs. Business Customers who require a formal Data Processing Agreement (DPA) incorporating the EU Standard Contractual Clauses can request one at support@proofel.com.

Marketing communications

We send account-related transactional messages (such as approval requests, comment notifications, and billing receipts) that are necessary to operate the Service; these are not marketing and are always sent. We also send onboarding and lifecycle emails to help you get value from Proofel. You can opt out of non-essential marketing emails at any time using the one-click unsubscribe link in those messages or by contacting us; doing so records your preference and stops marketing emails while transactional messages continue. Our email practices are designed to comply with applicable anti-spam laws, including the Australian Spam Act 2003 and the U.S. CAN-SPAM Act.

Subprocessors

We engage a small set of trusted third-party providers to run Proofel. Each processes personal information only to provide services to us and is bound by contractual data- protection obligations. We may update this list from time to time and will take reasonable steps to give notice of material changes.

ProviderPurposePrimary location
SupabaseApplication hosting, database, authentication, and storage.United States
NetlifyWebsite hosting and content delivery.United States / global CDN
StripePayment processing and subscription billing.United States
ResendOutbound email delivery.United States
MailgunInbound email processing.United States
BrowserlessOn-demand webpage rendering.United States
Postmark (SpamCheck)Spam scoring — only when you explicitly run a spam check on an email.United States
Google (Analytics & Ads)Analytics and advertising.United States / global
Meta PlatformsAdvertising and conversion measurement.United States / global
Microsoft ClarityProduct analytics and session insights.United States
jsDelivr (CDN)Content delivery network.Global CDN

Cookies & tracking

Proofel uses first-party cookies and browser storage for essential purposes — keeping you signed in, remembering preferences such as your theme, and caching data so pages load fast — and uses Google Analytics, Google Ads, Meta, and Microsoft Clarity for analytics and advertising. For a full description of the cookies we use, why we use them, and how to control or opt out of them, see our Cookie Policy.

International data transfers

Proofel is based in Australia, and our subprocessors operate primarily in the United States and other locations, as shown above. This means your personal information may be transferred to, stored in, and processed in countries outside your own, whose data- protection laws may differ. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or the EU–U.S. Data Privacy Framework where a provider is certified. Where we disclose personal information to overseas recipients under Australian Privacy Principle 8, we take reasonable steps to ensure those recipients handle it consistently with the Australian Privacy Principles and remain accountable for it. By using the Service you understand your information will be handled as described here.

Data retention & deletion

We keep personal information only as long as necessary for the purposes described in this policy. Your Content stays in your account until you delete it or delete the account. Deleting a canvas removes its versions, comments, annotations, and share links; deleting your account removes your Content from our production systems, with residual copies in encrypted backups expiring on our backup-rotation schedule. We retain billing and transaction records for as long as required by tax and accounting law (generally up to seven years), and we keep operational logs for a limited period for security and troubleshooting. To request deletion or a copy of your personal information, contact support@proofel.com.

Security

We take reasonable technical and organisational measures to protect personal information. All traffic is encrypted in transit (TLS) and data is encrypted at rest by our infrastructure providers. Access to Content is enforced with row-level security in the database, and share-link passwords are stored only as bcrypt hashes. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

Your privacy rights

Depending on where you live, you may have some or all of the following rights over your personal information:

  • EU/UK (GDPR): to access, rectify, erase, restrict, or port your data, to object to processing, and to withdraw consent at any time.
  • California (CCPA/CPRA): to know, access, correct, and delete your personal information, and to opt out of any “sale” or “sharing” of it. We do not sell personal information, and we honour opt-out preference signals such as the Global Privacy Control (GPC). We will not discriminate against you for exercising these rights.
  • Australia (Privacy Act / APPs): to access and seek correction of the personal information we hold about you.

These rights apply to both account holders and Guest Reviewers. To exercise any of them, write to us at support@proofel.com. We may need to verify your identity, and we will respond within the timeframe required by applicable law. If your personal information sits inside a Customer’s workspace as Content, we may refer your request to that Customer as the controller.

Children

Proofel is a business tool intended for use by adults. The Service is not directed to children, and we do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us and we will delete it.

Data-breach notification

If we become aware of a data breach that is likely to result in a risk to your rights or serious harm, we will notify affected individuals and the relevant regulators as required by law — including the Australian Notifiable Data Breaches scheme and, where applicable, the GDPR’s 72-hour regulator-notification requirement.

Changes to this policy

We may update this Privacy Policy as our Service and legal obligations evolve. We will post the updated version on this page with a new “Last updated” date, and for material changes we will provide additional notice (by email or in-app) where appropriate.

Complaints & contact

If you have a privacy question, request, or complaint, please contact us first at support@proofel.com so we can resolve it. If you are not satisfied with our response, you may lodge a complaint with a supervisory authority — in Australia, the Office of the Australian Information Commissioner (OAIC); in the EU, your local Data Protection Authority; or in the UK, the Information Commissioner’s Office (ICO).