Privacy Policy
What personal information ProofMate holds, why we hold it, where it lives, and how to get at it or have it removed.
Effective 2 August 2026 · Applies to ProofMate at proofmate.nz
1. Who this policy covers
ProofMate is provided by Ben Adam, a sole trader based in New Zealand, trading as ProofMate. We are an "agency" under the Privacy Act 2020 and this policy explains how we meet the information privacy principles in that Act.
This policy covers the proofmate.nz website, the ProofMate application, and the private proof links we generate for your clients.
2. Two different kinds of information
This distinction matters, so it comes first.
Information about you, our customer
When you sign up and run a workspace, we collect information about you and your team. We are responsible for that information and this policy governs it.
Information about your clients, which you put into your workspace
Your clients' names, contact details, job notes and the artwork you make for them are your records, not ours. Under section 11 of the Privacy Act 2020, we hold that information as your agent — in law it is held by you, and you are the agency answerable for it.
What that means in practice:
- You decide what goes in, how long it stays and who on your team can see it.
- We use it only to run ProofMate for you, or when you ask us for support.
- If one of your clients asks to see or correct what is held about them, that is your request to answer, not ours. If they contact us directly, we will point them to you and let you know.
- You need your own basis for collecting it: collect it fairly, be open with your clients about what you use it for, and keep it accurate.
3. What we collect
When you create an account
- Your first and last name, and your email address.
- A cryptographic hash of your password. We never store your actual password and cannot see it.
- If you turn on two-factor authentication, the secret needed to verify your codes, and your recovery codes in hashed form.
- Whether your email address has been confirmed, and one-time tokens used for confirming an address or resetting a password.
When you set up a workspace
- Your business name and the settings you choose, including branding used on proofs.
- Which plan the workspace is on, its usage against the plan limits, and any invoice reference you enter. No card or bank details are stored in ProofMate.
- Who is a member of the workspace, their role, and invitations sent or accepted.
What you put in
- Your clients' details: name or company name, email address, mobile and phone numbers, preferred contact method, where they came from, and any notes you write about them.
- Jobs, proofs and their versions, production notes, and the files you upload — artwork, photos, mockups and generated previews.
When a proof is reviewed
This is the part your clients should know about, and it is deliberate. When someone opens a proof link and responds, we record their answer, any comment they leave, the date and time, and the IP address and browser user-agent of the device that responded.
We keep that because an approval with no evidence behind it is not much use to you. It is what lets you show, later, that a specific version was approved at a specific moment. We do not use it to track anyone across websites, we do not build profiles from it, and we do not share it.
Security and audit records
- An audit log of significant actions in a workspace — who did what, when, with the IP address and browser used. This is how account misuse gets investigated and how approval history stays trustworthy.
- Ordinary web server logs, which include IP addresses, requested pages, timestamps and error details.
When you contact us
Your emails to us and our replies, including anything you choose to send us to help diagnose a problem. If you send us a file to look at, we treat it exactly like the rest of your content.
4. Why we collect it
We only collect what we need, and we use it for these purposes:
- To give you your account and workspace, and to keep them working.
- To show proofs to the clients you send links to, and to record their responses.
- To send the emails the service depends on: confirmations, password resets, invitations, proof notifications and notices about your workspace or these policies.
- To measure your usage against your plan limits and to invoice you.
- To keep accounts secure, investigate misuse, and enforce the Acceptable Use Policy.
- To provide support when you ask for it.
- To fix faults and improve ProofMate.
- To meet our legal obligations, including keeping tax records.
We do not use your information for advertising or marketing profiling, we do not sell it, and we do not use your content to train machine learning or artificial intelligence models.
Giving us your name, email and password is required — without them there is no account. Everything else is your choice, though leaving out a client's email means you cannot email them a proof.
5. Who else sees it
We keep this list short on purpose.
- The people you choose. Members of your workspace, and any client you send a proof link to.
- Email delivery. Emails ProofMate sends leave through our own mail server at mail.proofmate.nz. Once an email leaves us, it is handled by the recipient's mail provider, which may be anywhere in the world. That is true of all email, and it is why we keep the contents of our emails to the minimum needed.
- Web fonts. Our pages load typefaces from Google's font service. Your browser requests them directly, which discloses your IP address to Google. No account information is sent, and nothing about your workspace or your clients is involved.
- Where the law requires it. If we are legally obliged to disclose information — a court order, or a serious threat to someone's safety — we will comply, and we will tell you unless we are prohibited from doing so.
- If ProofMate changes hands. If the service is sold or restructured, information may transfer to the new provider, who would have to keep to a policy at least as protective as this one. We would tell you first.
We do not use third-party analytics, advertising trackers or social media pixels.
6. Where your information is stored
Your account details, your workspace data and your uploaded files are stored on server infrastructure we operate in New Zealand. Your content is not transferred offshore, and it is not held with an overseas cloud provider.
The two exceptions are the ordinary ones described in clause 5: email, once it has left our mail server on its way to the recipient, and the web font request your browser makes.
7. How we protect it
- All traffic to proofmate.nz is encrypted in transit with HTTPS.
- Passwords are stored only as salted hashes, using the standard ASP.NET Core Identity hashing. Nobody at ProofMate can read your password.
- Two-factor authentication is available on every account and we recommend turning it on.
- Every workspace is separated at the data layer, so one workspace cannot query another's records. Proof links use long random tokens that cannot be guessed or enumerated.
- Access to the underlying server and database is limited to the people who have to have it — in practice, one person — and the application's own database login cannot alter the database structure.
- We take backups so your work survives a hardware failure.
No system is perfectly secure. If a privacy breach happens that is likely to cause you serious harm, we will notify you and the Office of the Privacy Commissioner as the Privacy Act 2020 requires, and we will tell you plainly what happened.
8. How long we keep it
- While you are using ProofMate: as long as your workspace exists, because a proofing history that quietly loses old versions would not be worth much.
- Deleted files: when you delete a file it stops counting against your storage immediately and can still be restored for 30 days. After that the bytes are erased for good. A record of what the file was stays behind so proof history still makes sense.
- Closed workspaces: if you ask us to close a workspace, we keep it recoverable for 30 days in case of a mistake, then erase it.
- Approval and audit records: kept for the life of the workspace. These are the records that prove what was approved, so we do not thin them out.
- Server logs: kept only as long as they are useful for diagnosing faults and investigating abuse, then discarded.
- Invoices and tax records: kept for seven years, as New Zealand tax law requires. This is the one category we cannot delete on request.
- Backups: deleted information persists in backups until those backups age out in the normal cycle.
9. Your right to see and correct your information
Under the Privacy Act 2020 you can ask us to:
- Show you what personal information we hold about you;
- Correct it if it is wrong. If we disagree that it is wrong, you can require us to attach a statement of the correction you asked for;
- Export it so you can take it elsewhere.
Email support@proofmate.nz. We will confirm we have received it and answer within 20 working days, which is the limit the Act sets. There is no charge. We may need to check you are who you say you are before we hand anything over.
Occasionally the Act lets us refuse part of a request — for example where releasing something would disclose someone else's personal information. If that happens we will tell you which part we are refusing and why, and you can take that to the Privacy Commissioner.
Much of this you can do yourself without asking: your own details are on your profile page, your clients' details are editable in your workspace, and your files can be downloaded at any time.
10. Deleting your information
You can delete individual files, archive or delete clients, and delete jobs yourself.
To have a whole workspace or your whole account erased, email support@proofmate.nz from the address on the account and say clearly what you want removed. We will confirm what will be erased before we do anything irreversible, because it cannot be undone afterwards.
Two things survive a deletion request:
- Invoices and tax records, which we are legally required to keep for seven years.
- Records we need to keep to deal with a live legal claim or a serious abuse investigation.
If you are a team member rather than the owner, we can delete your own account, but the workspace and its content belong to the business — and the record of the approvals you handled has to stay for the history to hold together. Ask the workspace owner about the workspace itself.
11. Cookies
ProofMate uses only the cookies it needs to work. There are no advertising or tracking cookies.
- A session and authentication cookie, so that you stay logged in as you move between pages. If you block it you cannot log in.
- An anti-forgery token, which stops another site submitting a form to ProofMate on your behalf. This is a security measure.
Your client does not need to log in or accept anything to view a proof — the private link is the only key.
12. Children
ProofMate is a tool for businesses and is not aimed at children. We do not knowingly collect information from anyone under 16, and accounts require you to be at least 16. If you believe a child has given us information, tell us and we will remove it.
13. If you are unhappy with how we handled your information
Tell us first. Email support@proofmate.nz with "Privacy complaint" in the subject line and set out what happened. We will acknowledge it promptly, look into it properly, and tell you what we found and what we intend to do.
If we cannot resolve it, or you would rather not come to us, you can complain to the Office of the Privacy Commissioner, which is free and independent:
- Website: privacy.org.nz
- Phone: 0800 803 909
- Email: enquiries@privacy.org.nz
You do not need our permission to do that, and we will not treat you any differently for doing it.
14. Changes to this policy
If we change this policy, the effective date at the top of the page changes with it. If a change materially affects how we handle your information, we will email account holders at least 30 days before it takes effect.
15. Contact
Privacy questions, access requests, corrections and complaints all go to support@proofmate.nz. Ben Adam handles them personally.