Skip to main content
Part of Digital Empire

EntryProof Privacy Policy

What we collect

  • Readiness Checker submissions: your store URL and HTS code, plus a hashed (SHA-256, one-way) copy of your IP address for rate-limiting and abuse prevention. We do not store your raw IP address.
  • Email address — if you request the full readiness report.
  • Usage analytics (pages viewed, button clicks, tool funnel events, and masked session replay with all text and inputs masked) via PostHog, plus browser error reports via Sentry. Only after you click Accept on the cookie banner, for every visitor wherever you are; Decline keeps them off and deletes our analytics and attribution cookies (our servers stop recording analytics and attribution visits too). See the cookie policy.
  • Campaign attribution: if you arrive from a tagged link, the page path, UTM tags, referrer and a random first-party session ID (90 days), so a later checkout can be credited to the link. Not recorded after Decline.
  • Billing information, if you subscribe: collected and stored by Stripe; we receive your email, plan and payment status, not your card number.

Where it's sent / who processes it

  • Supabase (US-region hosted database) — stores readiness scans and email captures.
  • Resend — sends the transactional readiness-report email.
  • Stripe (billing, US) — processes and stores payment details for paid plans. stripe.com/privacy
  • PostHog (product analytics, US) — pseudonymous usage events and masked session replay, subject to your cookie choice. posthog.com/privacy
  • Sentry (error tracking, US) — browser and server error reports used to find and fix bugs. sentry.io/privacy
  • We do not sell your data or share it with any other business or broker without your explicit request.

Retention

Readiness scan data (store URL, HTS code, hashed IP) is retained 30 days, then deleted. Email opt-ins are retained indefinitely, or until you unsubscribe / request deletion, whichever is sooner.

Your rights

You can unsubscribe from emails at any time via the link in every email we send. To delete your data yourself (GDPR right to erasure, CCPA right to delete), use our self-serve deletion form — we'll email you a confirmation link, and clicking it permanently deletes your waitlist signup and readiness-checker email captures. For a data export or any other request, email support@enforceintel.com. California residents: EntryProof does not sell personal information, so there is nothing to opt out of under CCPA's "Do Not Sell" provision.

Data breach notification

If we discover a security incident that affects your personal data, we will notify you without undue delay. For users in the EU/UK, where the breach is likely to result in a high risk to the rights and freedoms of natural persons, we will notify affected users without undue delay in accordance with GDPR Art. 34. Separately, we will notify the competent supervisory authority within 72 hours of becoming aware of a personal-data breach in accordance with GDPR Art. 33. For California residents, we will notify you in the most expedient time possible and without unreasonable delay in accordance with Cal. Civ. Code §1798.82. State-law notice requirements for other U.S. residents will be honored as applicable.

How we notify: primary channel is email to the address on file (waitlist or readiness-checker email capture). We may also post a public update on the EntryProof landing page. What we will include: a description of the incident, categories and approximate number of records/users affected, likely consequences, and the mitigation and remediation steps we are taking. Breach concerns: support@enforceintel.com.

v0 — attorney-review-pending. This breach-notification commitment is authored in-house and has not yet been reviewed by outside counsel; it is offered as a good-faith statement of practice and does not waive any statutory rights you may have.

Contact

Questions about this policy or a data request: support@enforceintel.com.

Cookie settings