Skip to content
ProofTell
Sign inSign up
Legal

Privacy policy

Version 1.0 · Effective 1 October 2026

What personal data we collect when you use the ProofTell website, dashboard, API and file verification service, why we collect it, and what we do with it.

ProofTell is a service of Epic Grove Ltd, a company registered in England and Wales (company no. 17285617), registered office 128 City Road, London, EC1V 2NX, United Kingdom. Questions and requests: privacy@prooftell.com.

Two kinds of data

There is your data as our customer: your account, your billing, your messages to us. For that data we are the data controller, and this policy says what we do with it.

And there are the phone numbers, email addresses and IP addresses you submit to be checked. They belong to your own customers and users. For that data you are the controller and we are your processor: we handle it only to return the result to you, under the data processing agreement. The section below summarizes it.

The data you submit for checking

Single lookups. A phone number, an email address or an IP address sent to the API on its own is checked and the result is returned to you. We do not store it.

Assessments. A risk assessment is stored with its inputs, its score and its reasons, so that you can review and explain it later. It is kept for 90 days by default. You can set that period for your organization anywhere from zero, in which case nothing is stored, to 365 days.

Files. An uploaded file, its working data and its result file are deleted 30 days after upload, or as soon as you delete the file.

Logs. The values you submit travel in the body of the request, not in its address, and we keep them out of our logs and error messages.

Where it goes. Everything is processed and stored in the European Union, in Belgium, with one exception that the nature of the check requires: verifying an email address means asking the mail server responsible for it whether the mailbox exists. That request carries the address and nothing else, and passes through verification servers in several countries inside and outside the EU and the UK. IP addresses are looked up on our own servers and are never sent to a third party.

We use submitted data only to return results to you. We do not build lists from it, sell it, use it for marketing, or use it to train machine-learning models.

If a business checked your phone number, email address or IP address with ProofTell, that business decides why and how your data is used, and it is the one to ask. If you write to us instead, we will pass your request on to it where we can identify it.

Your data as our customer

What Why Legal basis Kept
Account: your name, email address, sign-in method (Google, or email and password), the organizations you belong to and your role in each To run your account, sign you in, apply access rights and prevent abuse Contract; our legitimate interest in security While the account exists
Billing: top-ups, balance, the record of charges, billing address, tax ID and payment history To bill you and keep the financial records the law requires Contract; legal obligation While the account exists, then for the period tax and company law require
Usage: the number and cost of calls per organization and per signal; request logs with the calling IP address, the path, the status and the timing To operate, bill, secure and debug the service Contract; our legitimate interest in running a reliable service Usage records while the account exists; request logs for 30 days
Messages: what you write to us about support, sales, security or privacy To answer you Contract; our legitimate interest in answering Up to 24 months after the last message
Evaluation requests: your name, role, company, use case and expected volume To decide on an evaluation credit and to follow up with you about it Steps taken at your request before a contract While the account exists
Service emails: which service emails were sent to you and whether they were delivered To deliver them and to show what was sent Contract; our legitimate interest While the account exists

Your password, if you use one, is handled by our sign-in provider; we never see or store it. Card details are held by our payment provider; we learn that a payment succeeded and for how much, never the card number.

We send service emails: sign-up verification, password reset, invitations, balance and billing notices, and notices about your files. We do not send marketing email without your consent.

Who we share data with

We share data only with the providers below, each bound by data protection terms, and only for the purpose stated. We do not sell personal data.

Provider Purpose Where
Google Cloud Hosting of the service, database, file storage, sign-in, website delivery European Union (Belgium); sign-in and website delivery also use Google’s global network
Stripe Card payments, receipts, the billing portal United States, European Union and United Kingdom
Postmark Delivery of service emails United States

The providers that process the data you submit for checking, as opposed to your account data, are our sub-processors. They are listed on the security page.

Where a provider processes data outside the United Kingdom or the European Economic Area, the transfer relies on an adequacy decision or on standard contractual clauses in that provider’s data protection terms.

We may also disclose data where the law requires it, or to protect the service, our users or the public. If the ProofTell business is sold or merged, customer data passes to the new owner under this policy, and we will tell you beforehand.

Cookies and browser storage

prooftell.com sets no cookies and loads no third-party trackers or advertising scripts.

The dashboard keeps you signed in using your browser’s storage, through our sign-in provider. If you sign in with Google, Google sets its own cookies during that step. When you pay, Stripe’s checkout sets the cookies it needs to take the payment and prevent fraud.

Your rights

You can ask us to give you access to your personal data, correct it, delete it, restrict or object to its processing, or hand it over in a machine-readable form, and you can withdraw a consent at any time. Write to privacy@prooftell.com; we answer within one month.

You can also complain to the UK Information Commissioner’s Office (ico.org.uk) or to the data protection authority of your country.

Security

Traffic is encrypted in transit and data is encrypted at rest. Access to production systems is limited to the people who operate the service. The detail is on the security page. No system is completely secure; if a breach affects your data, we will tell you without undue delay.

Children

The service is for businesses and professionals and is not directed at anyone under 18. We do not knowingly collect data from children; tell us if you believe we have.

Changes

When this policy changes we update the version and the date at the top. For a material change we email the owners of each organization before it takes effect.

Contact

Epic Grove Ltd, 128 City Road, London, EC1V 2NX, United Kingdom. privacy@prooftell.com.

Privacy policy · Version 1.0 · Effective 1 October 2026 · Epic Grove Ltd · Registered in England and Wales, company no. 17285617 · 128 City Road, London EC1V 2NX, United Kingdom

staging