FirmProof

FirmProof, currently operated by its founder ahead of incorporation as FirmProof, Inc. ("FirmProof," "we," "us," or "our") respects your privacy. This Privacy Policy describes what information we collect when you visit our website at firmproof.io, use our services, or communicate with us, and how we handle that information. This policy applies to firmproof.io, firmproof.tech, any subdomain of either, and our products and services.

Information we collect

Information you give us

  • Contact information you provide when you fill out a form, request a demo, sign up for a newsletter, book a meeting, or otherwise reach out. This typically includes name, email address, company name, job title, and any additional information you choose to share.
  • Communications. The content of emails, meeting notes, and other communications you send us.
  • Documents and files you upload or share with us during an evaluation, design partner engagement, pilot, or paid engagement.

Information collected automatically

  • Site usage data. When you visit firmproof.io, we collect standard log data: IP address, browser type, referring page, pages visited, time spent on pages, and device information. We use this to understand how visitors find and use our site.
  • Cookies and similar technologies. See "Cookies" below.

Information from third parties

We do not currently buy or receive personal information about you from third-party data brokers. If that changes, we will update this policy and notify you.

How we use your information

  • To respond to your inquiries and provide services you request
  • To operate, maintain, and improve our website and product
  • To communicate with you about FirmProof, including product updates and (with your consent) marketing communications
  • To detect, prevent, and respond to fraud, security, and abuse concerns
  • To comply with legal obligations

We do not sell your personal information. We do not use your personal information for automated decision-making that produces legal or similarly significant effects about you.

How we share your information

We share your information only with:

  • Service providers (sub-processors) we use to operate our business. Our current list is published and kept current at firmproof.io/trust.
  • Legal authorities, when required by valid legal process, and only to the extent required.
  • A successor entity in the event of a merger, acquisition, or sale of assets, subject to reasonable protections including notice.

We do not share your information with third parties for their own marketing purposes.

Cookies

We use the following categories of cookies on firmproof.io:

  • Strictly necessary cookies for site function (session, security, load balancing). Cannot be disabled without breaking the site.
  • Analytics. We use PostHog for aggregate site analytics, configured cookieless: no persistent identifier is stored on your device, and no cross-site tracking is performed.

We do not use advertising cookies. We do not participate in cross-site tracking. If we add any additional cookie categories, we will update this policy and provide a cookie consent mechanism at that time.

Your rights

Regardless of where you are located, you have the following rights with respect to information we hold about you:

  • Access. Ask us what personal information we hold about you.
  • Correction. Ask us to correct inaccurate information.
  • Deletion. Ask us to delete your personal information, subject to legal retention obligations.
  • Portability. Ask for a copy of your information in a machine-readable format.
  • Objection. Object to specific uses of your personal information.
  • Withdrawal of consent. Where we rely on your consent, withdraw it at any time.

To exercise any of these rights, email us at privacy@firmproof.io. We will respond within 30 days.

Additional rights for EU/UK residents (GDPR)

If you are in the EU or UK, our legal bases for processing your personal information are:

  • Consent (for marketing communications and non-essential cookies)
  • Legitimate interests (for site analytics, security, and responding to your inquiries), balanced against your rights and interests
  • Contract performance (once we have a signed agreement with you or your organization)
  • Legal obligation (where we must retain or disclose information by law)

You have the right to lodge a complaint with your local supervisory authority.

Additional rights for California residents (CCPA/CPRA)

If you are a California resident, you have specific rights under the CCPA/CPRA, including the right to know what personal information we collect and how it is used, the right to deletion, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under California law. To exercise any right, email privacy@firmproof.io.

Data security

We use reasonable technical, administrative, and physical safeguards to protect information from loss, misuse, unauthorized access, disclosure, and alteration. Details of our security practices are published at firmproof.io/trust. No system is perfectly secure; if we experience a data breach affecting your personal information, we will notify you as required by applicable law and typically within 72 hours of confirmation.

Data retention

We retain personal information for the periods described at firmproof.io/trust. In summary:

  • Prospect contact information: up to 24 months from last interaction
  • Design partner and pilot artifacts: duration of engagement plus 30 days
  • Session recordings: 90 days by default
  • Financial and transaction records: 7 years (tax and accounting requirement)
  • Communications: as long as reasonably necessary for the purpose

International data transfers

FirmProof is based in the United States. Data you provide to us is processed in the United States and may be transferred to other countries where our sub-processors operate (see firmproof.io/trust). Where we transfer personal data of EU/UK residents to countries not deemed to provide adequate protection, we use the European Commission's Standard Contractual Clauses or another approved transfer mechanism.

Children's privacy

FirmProof is a business-to-business service and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected information about a child, email privacy@firmproof.io and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if we have your email) or by prominent notice on firmproof.io, and update the "Last updated" date at the top.

Contact us

Privacy questions or requests: privacy@firmproof.io Data protection contact: Robert Hudson, Founder, FirmProof, Austin, Texas, USA