Two versions, one meaning. Most companies bury what they actually do in legal language so nobody reads it. We wrote this to be read. The plain version is the real one. Flip to Legal for the precise wording a lawyer will want. They say the same thing.
Two things you hand us, plus a little we log:
The findings themselves are public information about other websites. That is data about them, not private data about you.
We collect: (a) information you submit, namely the brand domain and the email address entered into the scan request form (“Submitted Information”); and (b) technical data collected in the ordinary operation of the Service, namely your IP address and request timestamps (“Technical Data”), processed for service delivery, security, and abuse prevention. Findings concerning third-party domains are derived from publicly available records and do not constitute personal data relating to you.
We use your email and domain to run your scan, send you the results, and reply if you write to us. We use the logs to keep the service working and fair. That is the whole list. We do not sell your data, we do not run ads, and we do not hand you to data brokers.
We process Submitted Information and Technical Data solely to: (a) perform and deliver the Service, including transmission of Findings to the address you provide; (b) respond to your communications; and (c) preserve the security, integrity, and equitable availability of the Service. We do not sell personal data and do not disclose it for advertising or cross-context behavioral advertising.
Two companies help us run Provenstone, and that is the entire list:
They handle your data only to do those jobs. Nobody else gets it, and we never sell or rent it. If a law ever compelled us to disclose something, we would tell you first, unless we were legally barred from saying so.
We disclose personal data only to the sub-processors that operate the Service, presently Cloudflare, Inc. (request storage, delivery, and security) and Google LLC (electronic mail transmission), each acting on our documented instructions. We do not otherwise disclose personal data except where required by law, and where lawfully able we will notify you before doing so.
Your request sits in our queue for at most 7 days, then it deletes itself automatically. The record that we ran a scan for you, and the email that ties it to you, we keep until you ask us to remove it, because that is what lets us follow up and watch for new fakes. You can delete all of it yourself, any time, right below.
Submitted Information held in the intake queue is automatically deleted within seven (7) days. Scan records and the email associating them with you are retained until you request erasure or until they are no longer needed to provide or follow up on the Service, whichever is earlier. You may exercise erasure at any time via the controls in the following section.
Your data is yours, so getting a copy or wiping it is a button here, not a favor you have to ask us for and wait on.
Either one starts the same way: we email that address a one-click confirm link. That is not us stalling. It is the opposite. It means nobody can pull or erase your data just by typing your email into this box. You confirm, and it is usually done within minutes.
You may obtain a copy of, or request deletion of, the personal data we hold associated with your email address using the controls below. To prevent unauthorized disclosure or erasure, each request is verified by a single-use confirmation link sent to that address and valid for twenty-four hours; we act only upon confirmation. Fulfilment is ordinarily completed within minutes of confirmation.
Enter the email you gave us. We send a confirm link to it first, then act.
Security is the whole product, so we treat your data like it:
We maintain technical and organizational measures appropriate to the risk, including: segregation of the public intake from the scanning environment, which is not addressable from the public internet; authentication of outbound email from provenstone.com via SPF, DKIM, and DMARC; and the absence of third-party tracking or advertising technologies. A single local preference (plain or legal text) is stored in your browser and is never transmitted to us. No method of transmission or storage is perfectly secure, and absolute security cannot be guaranteed.
If we make a meaningful change, we will not do it quietly. We will email everyone who has given us an address before the change takes effect, and we will keep the earlier versions so you can see exactly what changed. A small fix, like correcting a typo, just updates the date at the top. Changing a policy without telling the people it affects is exactly the kind of thing we built Provenstone to be the opposite of.
We may revise this Policy. For any material change, we will provide notice by email to addresses on record before the revised Policy takes effect, and we will retain prior versions for reference. Non-material corrections are reflected by updating the effective date above. Your continued use of the Service after a material change becomes effective constitutes acceptance of the revised Policy.
Provenstone is an independent brand-protection service, and we are formalizing the company now. It is built for businesses protecting their own brands, not for children, and we do not knowingly collect data from anyone under 16. Your data is handled on Cloudflare and Google infrastructure, which operate data centers globally. Questions, or want a request handled by hand instead? Email hello@provenstone.com.
The Service is intended for businesses and is not directed to children; we do not knowingly collect personal data from individuals under 16, and will delete any such data on becoming aware of it. Personal data is processed on infrastructure operated globally by the sub-processors identified above. To exercise any right, or for any inquiry, contact hello@provenstone.com.