Legal

Privacy
Policy

Last updated: March 2026 · Statsnapp Technologies

Proof is built on a simple principle — we request only what we need, store as little as possible, and keep you in control at all times. This policy explains exactly what data we collect from each integration, how we use it, and your rights over it.

01

Who We Are

Statsnapp Technologies operates the Proof analytics platform at withproof.io. We are headquartered in Coimbatore, Tamil Nadu, India.

For any privacy-related questions or data requests, contact us directly at Founder@withproof.io. We respond to all enquiries including those from Google's, Meta's, and Shopify's review and compliance teams.

02

What Data We Collect

Data is only collected when you explicitly authorise a connection via that platform's OAuth flow. We collect three categories of data across our integrations.

Account Data (all users)

Data

Why we collect it

Business email address

Used to identify your Proof account and send service notifications

Business name

Used to label your dashboard and confirm the correct profiles are linked

OAuth access tokens

Stored encrypted — used solely to authenticate API requests on your behalf

Google Business Profile

business.manage · read-only

Data

Why we collect it

Aggregate star rating

Displayed as your primary trust metric on the dashboard

Total review count

Used to track review milestones and power the celebration tracker

Latest review text

Displayed on your dashboard — shown in real time, not stored after session ends

Reviewer display name

Shown alongside review text for context — not stored after session ends

New review event (via Cloud Pub/Sub)

Google publishes a notification to our Cloud Pub/Sub topic when a new review is posted — we then fetch only that review. We do not poll the API continuously.

How Cloud Pub/Sub works: When a customer leaves a new Google review, Google publishes a message to our registered Cloud Pub/Sub topic (hosted in Google Cloud). Our server receives this event and makes a single API call to fetch the new review. No data is held in Pub/Sub beyond Google's own transit — we do not store events in the message queue.

Instagram

Basic Display API · read-only

Data

Why we collect it

Follower count

Displayed as a social growth metric on the dashboard

Reach (aggregate)

Used to power reach trend charts over 30 / 90 day windows

Impressions (aggregate)

Shown alongside reach to indicate content visibility

Profile visit count

Displayed as an engagement signal

Shopify

Admin API · read-only

Data

Why we collect it

Daily order count

Used to surface revenue trend signals on the dashboard

Aggregate revenue total

Shown to correlate trust metrics (reviews, followers) with sales trends

Product count

Used to contextualise store activity

Store name & currency

Used to label revenue data correctly on your dashboard

03

How We Use Your Data

  • To display your trust metrics, review activity, social growth, and revenue signals on your Proof dashboard — the sole purpose of every data point we collect.
  • To send you service notifications (e.g. new review alerts, sync errors) via email where you've opted in.
  • To maintain your account and authenticate your platform connections via stored OAuth tokens.
  • We do not use your data for advertising, profiling, or any purpose beyond operating the dashboard you've authorised.
  • We do not sell, license, or share your data with any third party for their own purposes.
04

Data Retention

We apply different retention rules depending on the sensitivity of the data and how it's used.

Review text & reviewer name

Not persisted. Displayed in your dashboard session only. Cleared when session ends or data refreshes.

Star rating & review count

Retained while account is active. Deleted within 24 hours of account closure.

Instagram & Shopify aggregates

Retained to power trend charts. No individual post, order, or customer data stored.

OAuth tokens

Retained while connected. Deleted immediately upon disconnection or account closure.

Cloud Pub/Sub events (GMB)

Not stored by Proof. Events are consumed in transit — we fetch the review from the API and immediately discard the Pub/Sub message.

Account deletion

All data deleted within 24 hours of account cancellation or written request.

05

How We Collect It

All platform data is collected exclusively via official, merchant-authorised OAuth 2.0 flows. Proof employees cannot initiate or alter any merchant's platform authorisation.

  • Google Business Profile — via Google OAuth 2.0 ( business.manage scope, read-only). New review events are received via Google Cloud Pub/Sub (My Business Notifications API) — not by polling.
  • Instagram — via Meta's Instagram Basic Display API OAuth flow. Business account required.
  • Shopify — via Shopify's OAuth app install flow using the Admin API with read-only orders and products scopes.
06

What We Never Do

  • Write to, edit, or modify your Google Business Profile, Instagram account, or Shopify store in any way.
  • Post, respond to, or flag reviews on your behalf.
  • Access individual customer names, addresses, payment details, or any personally identifiable information from Shopify orders.
  • Read private Instagram messages, story content, or follower identities.
  • Store raw review text or reviewer names beyond the active dashboard session.
  • Share any platform data with third parties for advertising, analytics resale, or profiling purposes.
07

Security

  • All traffic between your browser, our servers, and connected platform APIs uses TLS 1.2 or higher.
  • OAuth tokens and credentials are encrypted at rest using industry-standard practices.
  • Cloud Pub/Sub communication with Google is secured via Google's own IAM permission system — only our service account (mybusiness-api-pubsub@system.gserviceaccount.com publisher permission) can publish to our topic.
  • Access to production systems is restricted to authorised Statsnapp Technologies personnel only.
08

Your Rights

  • Revoke access anytime. Disconnect any integration from your Proof dashboard, or directly via each platform's settings (Google Account → Security, Instagram → Apps and Websites, Shopify Admin → Apps).
  • Request data deletion. Email Founder@withproof.io — all linked data is permanently deleted within 24 hours of confirmation.
  • Access your data. Request a summary of what data Proof holds for your account at any time.
  • DPDP Act (India). As an Indian-based company, we operate in compliance with India's Digital Personal Data Protection Act, 2023. You have the right to access, correct, and erase your personal data.
09

Third-Party Services

Proof connects to the following third-party platforms. Their own privacy policies govern how they handle data on their side:

10

Changes to This Policy

We will notify you by email before making material changes to this privacy policy. The "Last updated" date at the top of this page is updated for all changes. Continued use of Proof after notification constitutes acceptance.

Questions or data requests?

Founder@withproof.io

We respond to all privacy enquiries, data deletion requests, and API review team questions.