Legal

Privacy Policy

Draft — pending legal review.

This document is an internal first draft written by the OriginProof team to describe our actual practices. It has not been reviewed or approved by counsel and should not be relied on as a final, binding legal agreement.

Last updated: 8 August 2026

1. Who we are

OriginProof provides a compliance workspace for consumer brands substantiating U.S.-origin claims. This policy describes what we collect through the application at this domain, the supplier affidavit portal, and our public marketing pages.

2. Account data

Authentication is handled by our managed backend provider. When you create an account we store your email address, a hashed password (we never see the plaintext), your workspace role (member or compliance lead), and sign-in timestamps. We do not use this data for advertising and we do not sell it.

3. Compliance and product data you enter

Products, SKUs, claim types, bill-of-materials components, cost percentages, origin countries, assembly records, supplier records, scores and generated substantiation binders are stored on behalf of your brand. Access is scoped per brand at the database level using row-level security, so users authenticated to one brand cannot read another brand's records. Content you enter is yours; we act as a processor for it.

4. Supplier affidavit submissions

Suppliers submit affidavits through a tokenised link without creating an account. When an affidavit is submitted we record the attesting person's name, title, email, the declarations they certify, any uploaded document, and — because the submission is a signed attestation made under penalty of perjury — the submitting IP address and browser user-agent, together with a timestamp.

That IP and user-agent capture exists solely to evidence the provenance of an attestation in an audit or regulatory response. It is disclosed to the supplier on the submission form before they sign. It is retained with the affidavit record and is visible to the brand that requested the affidavit.

5. Billing data

Paid plans are billed through Stripe. Card details are entered on Stripe's systems and are never transmitted to or stored by us. We store a Stripe customer ID, subscription ID, plan tier, SKU allowance, and subscription status so the application knows what your account is entitled to. Sales enquiries submitted from the pricing page (company name, work email, approximate SKU count, optional message) are stored so we can respond.

6. Operational data

We keep server and application error reports to keep the service working. These may incidentally include a URL, a route name and an account identifier. We do not run third-party advertising or cross-site tracking scripts.

7. Retention and deletion

Compliance records are deliberately durable: substantiation binders and audit history are immutable once generated, because their value depends on being tamper-evident. Records are soft-voided rather than hard-deleted. If you close your account you can request export and deletion of your brand's data, subject to any records we must retain for our own tax or legal obligations.

8. Your access to your own data

We will never withhold read access or binder exports for billing or plan-limit reasons. If an account lapses, write access may be restricted, but you can always read and export your compliance record.

9. Contact

Questions, access requests or deletion requests: hello@getoriginproof.com.