sendproposalsfast

Legal

Privacy Policy

Effective August 18, 2026

What we collect, why, who else sees it, and how to get it back or have it deleted. Two cookies, both ours, both necessary. No third-party tracking of any kind.

1.Who we are and what this covers

SendProposalsFast is run by Benjamin Krall, an individual doing business as SendProposalsFast, in Florida, United States. This policy covers the website at sendproposalsfast.com, the proposals you write on it, and the emails it sends. Questions about any of it go to support@sendproposalsfast.com.

It is written to be read. Where we could have said “may collect certain information” we have instead listed what we actually store, because a policy you cannot check is not worth much.

2.Your information, and your clients' information

Two different sets of people appear in this service, and we stand in a different relationship to each.

  • You, the sender. We decide what to collect about you and why, so we are the controller of your information and this policy is our promise to you.
  • Your client. When you type a client's name or email into a proposal, that is your information about your contact. We hold it and act on your instructions, which makes you the controller and us your processor. The data processing agreement is a section of the Terms of Use, already agreed, with nothing to sign.
  • The parts we decide ourselves. Three things about your clients are our decision and not yours, so for those we are the controller rather than your processor: the record that an address unsubscribed, which we keep across the whole service; what we do with an abuse report; and the security logs that keep the service standing up. You cannot instruct us to email an address that has opted out, and we would not.

3.What we collect

What you type

  • Your account: your email address and your password, which is stored only as a scrypt hash. Nobody can read it back, us included. Anyone holding a copy of the database would have to guess it, which is what hashing it is for.
  • Your proposals: the title, scope, line items, prices and terms you write, plus your client's name and email address if you enter them.
  • Your saved templates: a copy of a past proposal you chose to keep and reuse, including its title, scope, line items, terms and, if it had them, the client name and email address on it. Deleting the proposal does not delete a template saved from it.
  • Your settings: notification preferences, and on Pro your display name, logo URL, accent color, payment link and deposit percentage.

What your client does

  • The date and time each time a view link is opened.
  • If they accept: the name they typed, the exact items and total they agreed to, and an email address if they asked for a copy of the receipt.
  • If they ask a question: the name they gave and the message they wrote.

What billing needs

If you subscribe to Pro, we store your Stripe customer and subscription ids, the plan, its status and when the current period ends. Your card details are entered on Stripe's own page and never reach us. We send Stripe your email address and your account id so it can find your customer record and email you a receipt.

What the server records

Every request writes one line to our log: the page and the response, the browser's user agent, the domain that linked to us, how long it took, and a daily fingerprint. Where they apply, that line also carries your account id, the id of the proposal you acted on, and what the action was. If the request failed, the error is on the same line.

The fingerprint is a hash of a secret, today's date, your IP address and your user agent, cut down to 16 characters. It lets us count how many people visited a page today. Nobody who obtains the log can turn it back into your IP address, because it is keyed by a secret only we hold, and it changes every day, so one day's value cannot be matched to the next. We do not try to reverse it. We will not claim we are unable to.

We do not write your IP address to those logs. We hold it in memory for up to an hour to enforce rate limits, and then it is gone. One place writes an IP address to the database: if you use the abuse report form, we record the reporter's IP with the report, so reports can be traced if the form itself is abused.

4.Cookies, and what your browser loads

Two cookies. Both are ours, both are necessary for the site to work.

  • __session keeps you logged in. It holds your account id, nothing else, and lasts 30 days.
  • __spf_session is set when you send a proposal without an account. It holds one random id so we can show you your own proposals when you come back, and lasts a year. Registering moves those proposals onto your account.

Both are signed so they cannot be edited, and marked so scripts cannot read them and, outside local development, so they are only sent over HTTPS.

There are no advertising cookies, no analytics cookies, no tag manager, no social buttons, and no fonts or scripts loaded from anyone else's servers. That is why this site has no cookie banner: there is nothing to ask you to consent to.

One exception, and it is the sender's choice rather than ours. On Pro, a sender can point us at a logo hosted somewhere else. When their client opens the proposal, the client's browser fetches that image from wherever it lives, which tells that host the client's IP address and browser. It is not told which proposal, because we do not pass the link on. We do not choose the host and we do not see anything it collects.

5.Why we use it

  • To run the service you asked for: publishing your proposals, showing them to your clients, telling you what happened. This is what performing our contract with you requires.
  • To take payment for Pro and meet the tax and accounting rules that come with it, which is a legal obligation.
  • To keep the service standing up: rate limiting, abuse reports, counting page views. Our legitimate interest in a service that is not being attacked or overloaded, done with as little personal information as we could design it to need.

We do not send marketing email. Every email we send is tied to one of your proposals: it was opened, your client accepted, declined or asked a question, its link is about to close, or, on Pro with reminders left on, a client is being nudged about a proposal nobody has answered. Plus password resets, when you ask for one.

Nothing here is decided by a machine on its own. No algorithm scores you, prices you, or turns you down.

6.Who else sees it

Four companies, each doing one job we could not sensibly run ourselves. All of them are contractually bound to handle the data only on our instructions.

  • Stripe (Subscription payments, United States). Your email address, your account id, your card details (entered on Stripe's own page, never on ours) and your subscription history.
  • Resend (Email delivery, United States). The recipient address and the contents of any email we send you or, on your instruction, your client.
  • DigitalOcean (Hosting, United States). Everything the service stores, because the server and its database run on their infrastructure.
  • GitHub (Code hosting and deployment, United States). Nothing is sent to them by the service. Our deployment runs from their servers and holds a key to ours, so they have technical access to the machine the database is on.

Beyond those, we hand over information if the law genuinely requires it, and we tell you unless we are forbidden to. We may also share what we have to stop someone being harmed, to deal with fraud or abuse, or to defend ourselves in a legal claim, and with our own lawyer, accountant or insurer, who are all bound to keep it quiet.

If the business is ever sold or transferred, your information moves with it, and we will tell you.

We have never sold personal information and we do not. We do not share it for advertising, and we do not use anything you or your clients write to train machine learning models.

7.How long we keep it

  • Your account and your proposals: until you ask us to delete them. A proposal's view link closes after 7 days without an account or 21 days on the free plan, and on Pro after whatever window the sender picked, which can be none at all. That is only the link. The proposal stays in your account either way.
  • A proposal you delete: the link dies at once and it leaves your account at once. Be aware that the underlying record stays in our database, marked deleted. If you need it erased for good, email us and we will do it.
  • Saved templates: they live until you delete the template or the account, and one can hold a client's name and email, because that is what you saved.
  • Password reset links: one hour, then they stop working, and each one works only once.
  • Server logs: they roll off the server as space is needed on it. What survives is a nightly aggregate of counts per page, per browser and per day, which we keep indefinitely. It holds no fingerprint and no IP address. Two things in it are worth naming: the page column records the URL requested, with a proposal's view link reduced to its shape so the token that opens it is not kept, and the browser column records full user agent strings.
  • Unsubscribes: kept indefinitely, on purpose. The record that an address opted out is the only thing stopping us from emailing it again.

Ask us to close your account and we will delete it, your proposals, and everything attached to them within 30 days. Three things outlive that, and you should know which: the unsubscribe record, because deleting it would start the email again; the aggregate counts above, which identify nobody; and whatever tax law requires us to keep about payments, which is the record that you paid and not what you wrote.

8.Your rights

Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to us using it. Email support@sendproposalsfast.com and we will answer within 30 days. If the request is complicated we will tell you inside those 30 days and take up to 45 in total. We may ask you to confirm you control the account's email address before we act, and we will never charge you for it or treat you differently for asking.

If we turn a request down we will say why. You can appeal by replying to that email, and we will answer the appeal within 45 days. If you are still unhappy, you can complain to your state attorney general, to the Information Commissioner's Office in the UK, or to your national data protection authority in the European Economic Area.

If you are in the UK or the European Economic Area, those are your rights under the GDPR, along with the right to restrict processing and the right to receive your data in a portable form.

If you are in California, you have the right to know what we collect and why, to delete it, to correct it, and to opt out of the sale or sharing of personal information. There is nothing to opt out of, because we do neither. If your browser sends a Global Privacy Control signal, nothing changes, because we were not doing the thing it asks us to stop.

California counts an account login together with its password as sensitive personal information. That is the only such information we hold. We use it to log you in and for nothing else, we never disclose it, and it is stored as a hash we cannot read. There is nothing to limit, which is why this site has no “limit the use of my sensitive personal information” link.

There is no button for any of this yet. It runs through the support address and it is answered by a person.

9.If you received a proposal

You do not have an account here and you never need one. Your name and email address are in our system because the person who sent you the proposal put them there, and they are the one who decides what happens to them.

When you open the link, we record the date and time against the proposal so the sender can see it was read. We do not record your IP address or your browser against it. Your request is written to our server log like any other visitor's, which means the user agent and the daily fingerprint described above.

Ask the sender first. If you cannot reach them, email support@sendproposalsfast.com and we will pass the request on and help however we can. Any email we send you carries an unsubscribe link, and using it stops every email from this service to your address, from every sender on it, permanently. If you later want that undone, ask us yourself and we will.

10.How we protect it

  • Everything travels over HTTPS.
  • Passwords are stored as scrypt hashes with a random salt, never as text.
  • Login cookies are signed and cannot be read by scripts in the page, and reset links expire in an hour.
  • View links are long random ids, search engines are told not to index them, and a proposal page never passes its own link to any site the client clicks through to. They are still links, so anyone holding one can read that proposal.
  • Card numbers are never stored by us, because they never reach us.

No service can promise it will never be broken into. If a breach ever affects your personal information, we will tell you and the relevant authority as quickly as we can, and we will tell you what actually happened.

11.Where the data lives

Our server and its database are in the United States, and so are all four of the companies listed above. If you are outside the United States, using the service moves your information here.

Where information about your clients comes from the UK or the European Economic Area, that transfer is covered by the standard contractual clauses in the Terms of Use, under handling your clients' information for you. You agree to them when you agree to the Terms, and there is nothing to sign. The onward transfers to the companies above are covered by the clauses and frameworks in our own agreements with them.

12.Children

This is a tool for running a business. It is not meant for anyone under 18, we do not knowingly collect information from anyone under 18, and we never knowingly collect anything from a child under 13. If you believe a child has given us information, email support@sendproposalsfast.com and we will delete it.

13.Changes to this policy

The effective date at the top says which version is current. If we change something that matters, for instance collecting something new or adding another company to the list above, we will email registered accounts before it takes effect. We will not quietly start doing something this page says we do not do.

14.How to reach us

Email support@sendproposalsfast.com. That address reaches Benjamin Krall directly, and it is where access, correction and deletion requests should go. There is no separate privacy team, which means there is nobody for your message to get lost behind.

If you need a data processing agreement, the section of the Terms of Use on handling your clients' information is it. There is nothing to sign and nothing to request.