1. Who We Are
GetProposalFlow (“we”, “us”, “our”) operates the GetProposalFlow software platform at getproposalflow.com. This Privacy Policy explains how we collect, use, share, and protect personal data when you use the Service.
2. Data We Process
Depending on the features you use, we may process:
- Account data: name, email address, agency name, profile avatar, plan, and account preferences
- Authentication data: password hashes and authentication tokens managed by Supabase Auth; we do not receive your plaintext password
- Workspace data: proposals, content, pricing, invoices, clients, contacts, team invitations, brand settings, payment-method settings, and API-key metadata
- Client interaction data: proposal views, approvals, e-signatures, timestamps, IP addresses used for signature records, and invoice activity
- Subscription data: your plan, subscription status, Paddle customer and transaction references; Paddle handles payment-card information
- Support and communication data: messages sent to support and email delivery records
- Technical and usage data: browser, device, approximate network information, pages viewed, product events, error logs, and security records
3. How We Use Data
- Provide, secure, maintain, and improve the Service
- Create accounts, authenticate users, and manage workspace access
- Generate proposal drafts through the AI provider you select
- Display proposals, signatures, invoices, branding, and payment options to your clients
- Process GetProposalFlow subscriptions through Paddle
- Send account, proposal, invoice, reminder, and onboarding emails
- Measure product funnels and diagnose reliability or security issues
- Respond to support requests and comply with legal obligations
We do not sell personal data or use proposal and client content for third-party advertising.
4. Your Responsibilities for Client Data
Users choose which client information to enter and which documents to share. If you use the Service for client data, you are responsible for having an appropriate legal basis, giving any required notices, and honoring your obligations to those clients. Do not upload sensitive information that is unnecessary for the proposal or invoice workflow.
5. Service Providers
We use providers that process data on our behalf or provide part of the Service:
- Supabase: database, authentication, file storage, and server functions
- Paddle: GetProposalFlow subscription checkout, billing, tax handling, and refunds as Merchant of Record; see Paddle's Privacy Policy
- Google Gemini, OpenAI, or Anthropic: proposal text generation when that provider is selected; project instructions are sent to the selected provider
- Resend: transactional and onboarding email delivery
- Vercel: website hosting, serverless endpoints, and content delivery
- PostHog: cookieless, non-autocaptured product analytics used to understand page and funnel performance
- Tawk.to: customer-support chat when the chat widget is used
These providers have their own terms and privacy practices. Data may be processed in countries other than your own, subject to the safeguards available through the relevant provider and applicable law.
6. AI Providers and User-Supplied Keys
Google Gemini is available as the default provider. You may select OpenAI or Anthropic and, where supported, provide your own API key. Proposal instructions and related text are sent to the selected provider to generate a draft. Do not include confidential or sensitive data unless you are authorized to send it to that provider.
7. Storage and Retention
We retain account and workspace data while your account is active and as needed to provide the Service. After a verified deletion request, personal data is deleted or anonymized within 30 days unless it must be retained for security, dispute resolution, legal compliance, or financial recordkeeping. Backup copies may remain for a limited period before rotation.
8. Cookies and Browser Storage
We use essential browser storage for authentication and security. Product analytics are configured without persistent analytics cookies or automatic page-element capture. The support-chat provider may use browser storage when you interact with the widget. We do not use advertising cookies.
9. Security
We use measures including encrypted transmission, managed authentication, access controls, and database Row Level Security. No online service can guarantee absolute security. Keep your password and API keys confidential and contact us if you believe your account has been compromised.
10. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of personal data. You may also have the right to withdraw consent and complain to a data-protection authority.
Send a request to [email protected]. We may need to verify your identity. We will respond within the period required by applicable law.
11. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal information to the Service.
12. Changes and Contact
We may update this Policy as the Service changes. The date on this page shows the latest revision. We will provide additional notice for material changes when required.
Privacy questions and requests can be sent to [email protected]. General support is available at [email protected].
Need help?
We aim to keep these policies readable. Contact support if you have a question about your account, data, subscription, or refund.
Contact support