Legal

Privacy Policy

Last updated · August 2026

1. Who is responsible

WarmProof is run by Oinam Johnson Singh, an individual trading from New Delhi, India. For anything in this policy — including a request to see, export, correct or delete your data — write to hello@warmproof.com and a person will answer.

Under UK and EU data protection law, that is the data controller for account information. For the testimonials you collect, the relationship is different — see 'Your customers' data' below.

2. What we collect, and why

When you create an account: your name, email address, and a password we never see in readable form. If you sign in with Google we receive your name, email address and profile picture from Google, and nothing else.

When you use WarmProof: the testimonials, forms, walls and popups you create, and any brand settings such as a logo or colours.

When someone answers one of your collection forms: whatever they typed, their name and email address if they gave one, and any video or voice recording they made.

We do not use tracking cookies and we run no third-party analytics on this website. The only cookie set is the one that keeps you signed in.

3. Where it is stored

WarmProof uses Supabase, which hosts our database and file storage on Amazon Web Services in the United States (region us-east-1). Your account details, your testimonials and your customers' recordings are stored there.

If you are in the UK, EU or India, this means your personal data is transferred to and processed in the United States. Supabase acts as our processor under a data processing agreement and relies on the European Commission's Standard Contractual Clauses for that transfer.

The marketing site and the application are served by Hostinger. Email we send you goes through our own mail server at Hostinger.

4. Video and voice recordings

Recordings are kept in a storage bucket that is public in the technical sense: anyone holding the exact link can play the file. The links contain a random identifier that cannot be guessed, and they are never listed anywhere, but they are not password-protected.

This is a deliberate trade. A hosted wall is read by strangers who have no account, and a private file cannot be shown to someone who has not signed in without putting a server in front of every playback. You should treat a recording as unlisted rather than secret, and not collect anything through WarmProof that would be harmful if it were seen.

Deleting a testimonial deletes its recording.

5. Your customers' data

When someone leaves you a testimonial, you decide what to ask, what to publish and how long to keep it. In data protection terms you are the controller of that information and WarmProof is your processor: we hold and display it on your instruction and for no purpose of our own.

That also means the responsibility for asking lawfully sits with you. WarmProof records consent at the moment of collection and shows you what was agreed to, which is the evidence you would need if anyone asked.

We never sell any of it, never use it to train anything, and never show one account's testimonials to another.

6. How long we keep it

Your content stays until you delete it or close your account. Cancelling a paid plan does not delete anything.

Deleting your account removes your testimonials, private feedback, forms, walls and recordings. This is immediate and cannot be undone, so export anything you want to keep first. Backups taken before a deletion age out within 30 days.

7. Your rights

You can ask to see what we hold, have it corrected, have it deleted, or have a copy in a portable format. Write to hello@warmproof.com; we answer within 30 days and there is no charge.

If you are in the UK or EU you also have the right to object to processing and to complain to your data protection authority. We would rather you told us first, but that route is yours regardless.

8. Security, honestly

Every connection is encrypted. Passwords are hashed by Supabase and never stored in a form anyone can read. Database access is governed by row-level rules that make one account's data unreachable from another's session, and we test that rather than assume it.

No system is unbreakable and anyone claiming otherwise is selling something. If we ever discover a breach affecting your data, we will tell you and the relevant authority within 72 hours of becoming aware of it, and we will tell you what actually happened.

9. Changes

If we change this policy in a way that materially affects you, we will email every account holder at least 14 days before it takes effect, and update the date at the top of this page.

Questions about any of this? Write to hello@warmproof.com — a human reads every message.