Last updated: February 2026
Propopad is operated from Sweden by Propopad.
Privacy contact: privacy@propopad.com
This policy explains how we handle data for users worldwide, with specific sections for EU/EEA users (GDPR) and California users (CCPA).
Account information: Email, name, and password (hashed) when you sign up.
Business information: Agency name, website, logo, brand colors, contact details, and business settings you provide.
Proposal content: Everything in your proposals, service descriptions, pricing, client information, testimonials, terms, timelines.
Client information: Names, emails, companies, and notes about your clients that you enter.
Website scan data: When you choose to scan your website, we extract publicly available business information, services, testimonials, and branding from the URL you provide. Raw scan data is deleted after 90 days; extracted results remain in your account.
Analytics data: When your clients view proposals, we record page views, sections viewed, time spent, device type, and IP address. IP addresses are anonymized after 30 days.
Usage data: How you use Propopad, pages visited, features used, timestamps. Collected to improve the Service.
Payment data: Processed entirely by Stripe. We never see or store card numbers.
Cookies: Session cookies for authentication (essential), preference cookies for settings (optional), analytics cookies for service improvement (optional). No advertising or tracking cookies.
We use your data to provide and maintain the Service, generate AI content for your proposals, show you proposal engagement analytics, process your payments, send transactional emails (proposal viewed, accepted, etc.), and improve the Service.
We do NOT sell your data. We do NOT use your content to train AI models. We do NOT share your data with advertisers.
You may enter personal data of others (clients, testimonial subjects). You are responsible for having appropriate permission to store and use this data. For testimonials detected during website scanning, you explicitly approve each one before it is used in proposals.
We share data with these providers to operate the Service: Supabase (database and authentication, EU), Anthropic (AI content generation, US), Stripe (payment processing, US), and our website scanning provider (US). For transfers to the US, appropriate safeguards are in place.
Account data, proposals, and client information are kept until you delete them or your account, then deleted within 30 days. Proposal analytics are kept 12 months after proposal expiry. Raw website scan data is kept 90 days. Payment records are kept 7 years (Swedish accounting law). Server logs are kept 90 days. Backups containing deleted data are purged within 90 days.
All users can access and export all their data from Settings, correct inaccurate data in-app, delete specific data or their entire account, and contact us at privacy@propopad.com.
EU/EEA users additionally have GDPR rights to restrict processing, data portability, object to processing based on legitimate interest, withdraw consent for website scanning, and lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
California users have CCPA rights to know what personal information is collected, delete personal information, opt out of sale of personal information (we don't sell data), and non-discrimination for exercising privacy rights.
We respond to all requests within 30 days.
We protect your data with encryption in transit and at rest, row-level security isolating each account's data, regular security monitoring, and access controls limiting employee access to customer data.
We use essential cookies for authentication (cannot be disabled) and optional analytics cookies to improve the Service (can be disabled). We do NOT use advertising or tracking cookies.
Propopad is for users 18 and older. We do not knowingly collect data from minors.
Material changes are communicated via email 30 days in advance.
Privacy questions: privacy@propopad.com