Privacy
Last updated 9 October 2026
Draft pending legal review. It describes how the product works today; the final version may change before paid launch.
Customers of ProofLoom (businesses)
We store your account (name, email, hashed password), organizations, workspaces, websites, settings, billing records and an audit log of security-relevant actions.
Visitors of websites that use ProofLoom
- The widget stores a random visit ID in the browser. We keep only a site-scoped hash of it, delete it within 30 days, and never fingerprint visitors.
- We read the landing page's UTM source and referrer domain to apply targeting rules; country comes from the hosting network when enabled.
- Businesses can require consent before anything is tracked or shown.
Purchase and sign-up events
Businesses send events to show activity. Raw payloads are encrypted and removed once processed (at most 7 days). Normalized events are kept 30 days. Publicly we show only a first name if the business opts in, city/country and product — never amounts, emails or addresses.
Testimonials
We store the feedback, its versions, the exact permission wording the customer agreed to and when. Contact emails are encrypted and never published. Customers can withdraw permission at any time with their private link.
Social publishing
Social account connections, posts, AI generation and media are handled by our Social publishing service. Social network tokens and AI keys are kept apart from your website data.
Retention
- Public activity entries: at most 7 days. Aggregate analytics: your plan's history (30/90/365 days).
- Audit logs: 180 days. After cancellation: 30 days to export, then deletion. Billing records: as required by law.
Contact
founder@veloxonhub.com
