Prolancer ("we", "us") provides project management software for solopreneurs and small agencies. This policy explains what we collect when you use the platform, why we collect it, and the choices you have.
1. What we collect
We collect only what we need to run the service:
- Account information — your name, email, company name, and the email of teammates you invite.
- Work content — projects, tasks, comments, files, and time entries you create in the platform.
- Billing data — handled by our payment processor (DIME PAY). We store the result of a charge, never your card number.
- Technical logs — IP address, browser/device, and pages visited, used to detect abuse and diagnose errors.
2. How we use it
We use your data to:
- Provide the service you signed up for (the obvious part).
- Bill you for active subscriptions and send receipts.
- Send service emails — notifications, invoices, security alerts. You can mute non-essential ones in Settings → Notifications.
- Keep the platform safe — rate-limit abuse, detect fraud, investigate incidents.
We do not sell your data. We do not run third-party advertising trackers on logged-in pages.
3. Who we share it with
Your data lives in your vendor workspace. Other vendors on the platform cannot see it. We share data with a short list of processors who help us run the service:
- Hosting — our cloud provider stores the database and uploaded files.
- Email delivery — SendGrid sends transactional email (magic links, invoices, notifications).
- Payments — DIME PAY processes subscription charges.
- Error monitoring — Sentry receives crash reports (stack traces, request metadata; no body content).
Each processor is contractually bound to use the data only to provide the service to us.
4. Security
We follow standard security practices: TLS in transit, hashed passwords and tokens at rest, role-based access controls, audit logging on sensitive actions, and rate limits on auth endpoints. No system is perfect — if you discover a vulnerability, please write to us before disclosing it publicly.
5. Cookies
We use a small number of first-party cookies:
- Session cookie — keeps you signed in. Expires after 30 minutes of inactivity.
- CSRF cookie — protects forms from cross-site request forgery.
- Theme preference — remembers light or dark mode.
We do not use third-party analytics or ad cookies on the application.
6. Your rights
You can:
- Access your data — export from Settings → Account, or write to us.
- Correct your data — most fields are editable in the app.
- Delete your account — cancel from Settings → Billing. Cancellation soft-deletes immediately and triggers a permanent purge after 30 days.
- Object to processing or restrict it — write to us; we'll respond within 30 days.
If you're in the EU/UK, these rights flow from GDPR. If you're in California, the equivalent CCPA rights apply.
7. Retention
We keep active account data for as long as your subscription is active. After cancellation, soft-deleted data is purged within 30 days. Backup snapshots roll off within 90 days. Billing records are kept for 7 years to satisfy tax law.
8. Children
Prolancer is a B2B tool and is not directed at anyone under 16. We don't knowingly collect data from children.
9. Changes
We'll update this policy as the product evolves. The effective date at the top of the page reflects the last revision. Material changes will be emailed to active accounts before they take effect.
10. Contact
Questions, requests, or complaints: contact us. We respond to every email from a real person.