Last updated: April 14, 2026
Information you provide: Email address (for account creation and free tool access), password (stored as a PBKDF2-HMAC-SHA256 hash, never in plain text), document form data (company name, addresses, amounts, etc.).
Payment information: Processed and stored by Stripe. We never see or store your full credit card number. See Stripe's Privacy Policy.
Usage data: Pages visited, features used, session duration. We use Google Analytics for aggregate site usage analytics.
We use your information to: provide and operate the Service, process payments and subscriptions, generate documents based on your input, send account-related emails (welcome, password reset), send occasional product tips and promotional offers, and improve the Service. We do not sell your personal data to third parties.
Email marketing: If you provide your email address to access our free tools, you may receive occasional emails with tips, product updates, and promotional offers. Every marketing email includes an unsubscribe link. You can opt out at any time by clicking "unsubscribe" in any email or by contacting us at the address below.
We share data with the following third parties only as necessary to operate the Service: Stripe (payment processing), Google Analytics (anonymous site usage analytics), Google Fonts (typography). No other third parties receive your data.
PDFs are generated in-memory and are not stored on our servers. Pro vault stores document metadata (type, number, client, amount, status) while your account is active. Session cookies expire after 35 days. If you cancel your subscription, account data is retained for 90 days then permanently deleted. Email addresses collected via our free tools are retained until you unsubscribe or request deletion. You may request immediate deletion at any time.
We use a single session cookie (HttpOnly, Secure) to keep you logged in. Google Analytics sets cookies to understand site usage. You can opt out of Google Analytics at tools.google.com/dlpage/gaoptout.
All users have the right to: access your personal data, correct inaccurate data, request deletion of your data, and receive a copy of your data in a portable format.
California residents (CCPA): You have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell your personal information. To exercise these rights, email us at the address below.
EU/UK residents (GDPR): Our lawful basis for processing your data is: (a) performance of a contract (providing the Service you subscribed to), and (b) legitimate interest (improving the Service). You may withdraw consent at any time by contacting us.
ProForma does not sell, rent, or trade your personal information to third parties for marketing purposes. This applies to all users, including California residents under the CCPA.
We use HTTPS for all data transmission, PBKDF2-HMAC-SHA256 password hashing, HttpOnly/Secure session cookies, and secure cloud hosting. While we take reasonable measures to protect your data, no method of transmission over the Internet is 100% secure.
ProForma is not intended for users under 18. We do not knowingly collect data from minors. If we become aware of such data, we will delete it immediately.
We may update this Privacy Policy at any time. We will notify registered users of material changes via email. Continued use of the Service after changes constitutes acceptance.
For privacy questions, data access requests, or data deletion requests, contact us at support@proformadoc.com