Skip to content
Security & trust

Your customers' data, handled properly

When you connect your store, you trust us with customer names, emails and phone numbers. Here's how we protect them today, and how we keep reviews honest.

Encrypted

HTTPS everywhere; files and keys encrypted

Deleted on time

Invitation contact details after ३ years by default

No card numbers

We never ask for or store them

Your team, controlled

Roles, 2FA and an activity log

How we protect data

Security in practice

Data

Pages and the API are served over HTTPS. Uploaded documents, proof files and imports are encrypted file by file (AES-256-GCM), and the keys you give us for integrations are stored encrypted. Customer contact details from invitations are deleted after ३ years by default, or sooner if you choose.

Access

Passwords need at least 12 characters and are checked against known data breaches (only a short, anonymous part of a hash leaves our server). Two-step verification with an authenticator app, which a business can require for its whole team, plus roles per profile and an activity log.

Payments

Proofwell never asks for or stores card numbers. When a plan is paid by card, the card is entered only on the payment provider's own secure pages.

Records and backups

An append-only audit log that can't be edited or deleted, a tamper-evident log of review decisions, and nightly database backups. An off-site copy of the backups is being set up.

Privacy and the law

Privacy tools for the laws where you operate

These tools help you meet your obligations. They aren't legal advice or a certification.

UK and EU

GDPR

Customer data requests (a copy or deletion), records of consent, and contact details deleted on schedule.

Malaysia and Singapore

PDPA

Customer data requests (a copy or deletion), records of consent, and contact details deleted on schedule.

India

DPDP Act

Customer data requests (a copy or deletion), records of consent, and contact details deleted on schedule.

Documents

Our privacy policy, business terms and how anyone can ask for their data.

Privacy policyBusiness termsData requests

Certifications

We don't hold security certifications such as SOC 2 or ISO 27001 yet. We'll only list certifications here once we actually hold them.

Review integrity

Keeping reviews trustworthy

Your reviews are only valuable if shoppers believe them.

Proof on every review

Badges show how each review was checked, from order matching to identity checks.

Reports checked by people

Reported reviews go to our moderation team, and reviewers can be asked for proof of their experience.

No paid rankings

No plan changes scores, rankings or moderation. No plan can remove reviews.

Report a security problem

Found a vulnerability? Tell us through the contact form and we'll reply by email.

Contact us →

Questions from your IT team

Send us your security questions and we'll answer what we can.

Get in touch →
Questions

Security FAQ

Where is data stored?

On Proofwell's own database and file servers. We'll name the hosting region on this page before launch, and tell business customers before it changes.

Who can see customer emails and phone numbers?

Only your team members with access to that profile, and Proofwell staff when needed to support you. Customer contact details are never shown publicly.

Can I get or delete my data?

Yes. Download your reviews, invitations and more from your account, and anyone can ask for a copy or deletion of their personal data.

Do you have certifications like SOC 2 or ISO 27001?

Not yet. We don't claim certifications we don't hold.

Start collecting reviews customers trust

Free to start. The Free plan needs no card.

Start freeBook a demo

Cookie settings

EssentialLog in, security and fraud checks
PreferencesRemember your country
AnalyticsNot used. We'll ask before we ever add any.