Last updated: August 2026
This Privacy Policy explains how Business Venture Link Ltd, trading as the BVL Group of Companies ("we", "us", "our"), collects, uses, stores and deletes personal information when you use ProofPack. ProofPack captures job reports, expenses, receipts and financial records for field teams, so this policy covers both photographic evidence and money records.
1. Who We Are And Which Law Applies
ProofPack is operated by Business Venture Link Ltd, trading as the BVL Group of Companies, registered and operating in the Republic of Mauritius. We are the data controller for account data, and a data processor for the content you put into the app (see section 5). Contact: info@thebvl.com
Our home regime is the Mauritius Data Protection Act 2017, which is aligned with the EU General Data Protection Regulation. ProofPack is sold worldwide and we do not restrict who may buy it, so where the law of your own country gives you stronger rights than this policy describes, those rights apply and we will honour them. In particular we recognise the GDPR for users in the European Economic Area and the United Kingdom, and POPIA for users in South Africa. Section 9 sets out how to exercise those rights.
We are not a financial institution. ProofPack records your own expense and job-costing data for your own purposes. We do not report your financial records to any regulator, tax authority, financial intelligence unit or anti-money-laundering body, and we have no statutory obligation to retain them after you leave. That is why section 8 can promise genuine deletion rather than a multi-year hold.
2. What Information We Collect
Account information: your email address and an encrypted password. If you belong to an organisation, your membership and your role within it.
Device information: a randomly generated device identifier, a device name derived from your browser or operating system, and the date the device last connected.
Report content: the job reports, before-and-after photographs, notes, client names and business details you create.
Financial and job-costing records: projects, budgets and budget amendments, cash advances issued to staff, expense slips, returns of unspent float, supplier names, invoice numbers, amounts, currencies and exchange rates, and the approval or void history attached to each of those records.
Receipt and job photographs: images of receipts, slips and site work. These are held in private cloud storage, not embedded in the record itself.
Text read from your receipts: where you use automatic capture, the supplier, date, amount and invoice number read from a photograph, together with a confidence score. You can correct any of it before it is saved.
Audit trail: a record of who changed what and when — edits, approvals, moves between projects, voids and budget amendments, each with the reason given. This is written by the database itself and cannot be altered from the app.
Usage data: basic analytics such as features used and error logs, used to keep the Service working. Not linked to individual reports or expense records.
3. How We Use Your Information
We use your information only to:
- Provide and maintain the Service
- Sync your reports and records across your approved devices
- Calculate float, budgets, project balances and currency conversions
- Flag possible duplicate expense claims for a human to review
- Maintain the audit trail that makes your records defensible
- Send transactional email (account confirmation, password reset)
- Enforce subscription limits
- Comply with legal obligations that apply to us
We do not sell, rent or share your personal information with anyone for marketing or advertising. We do not use your financial records to build any profile of you, and we do not use your data to train machine-learning models.
4. Automated Processing
Two features process your data automatically. Neither makes a decision about you on its own.
Receipt reading extracts fields from a photograph and presents them for you to confirm or correct. Nothing is saved from it without a person accepting it.
Duplicate detection compares a new expense against existing ones and may flag it for review. A flag is a prompt to a manager, not a finding against you — it does not reject a claim, and a person decides the outcome. You are entitled to ask why something was flagged.
5. Organisations: Who Is Responsible For What
When you use ProofPack inside an organisation, the organisation is the data controller for the records its members create — including its staff's expense claims and its own clients' details — and ProofPack is the data processor acting on the organisation's instructions.
This has a practical consequence worth stating plainly. Your organisation's administrators can see the projects, expenses, advances, receipts and audit trail belonging to that organisation, including yours. ProofPack cannot change that without breaking the accountability the product exists to provide.
If you use ProofPack as an individual, you are the controller for any client details you enter, and we are your processor. In either case the controller is responsible for having a lawful basis to hold that information and for answering access or deletion requests from the people it concerns. We will support you in answering them.
Where your organisation is subject to its own record-keeping obligations — audit, donor reporting, tax — meeting them is the organisation's responsibility, not ours. Section 8 explains why that matters when an account is closed.
6. Where Your Data Is Stored
Account data, reports and financial records are stored in Supabase, a cloud database provider, on servers in the European Union (AWS eu-west-1). Receipt and job photographs are held in a private storage bucket that is not publicly readable; images are served through short-lived signed links.
Your data is isolated from other organisations by row-level security enforced in the database itself, not merely in the app. Neither ProofPack staff nor Supabase staff read your report or expense contents in the ordinary course of running the Service.
Because the Service is sold worldwide, using it may involve transferring your information across borders — typically from your country to the European Union. Where that transfer is from the EEA or the UK, it is made under the European Commission's Standard Contractual Clauses.
7. Sub-Processors
We use the following providers to run the Service. Each processes data on our behalf under a data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and private file storage for photographs | European Union (AWS eu-west-1) |
| Cloudflare | Application hosting and content delivery | Global edge network |
| Google Play Billing | Subscription payments for the Android app. Card details are handled by Google and never reach us. | Global |
| Exchange rate provider | Daily currency reference rates. Receives currency codes and dates only — never your amounts, suppliers or records. | Global |
We will give notice before adding a sub-processor that handles your records.
8. Retention And Deletion
While your account is open, money records are never deleted. Projects, advances, expenses and returns that have money attached cannot be removed by you, by your organisation's administrators, or by us. This is enforced in the database, not by a setting. A mistake is corrected by voiding the original and recapturing it, or by an opposing entry, so the history stays intact. That is what makes your records worth relying on.
We hold your records to run your account, not for our own purposes. We have no reporting obligation to any financial regulator, so once you stop using the Service there is no reason for us to keep anything.
When you delete your account, you export first and we then delete permanently. Because your records may matter to you afterwards — for your own audit, tax or donor reporting — account deletion requires you to download a complete export of your data first. That export is yours to keep. After the deletion completes we hold nothing, and we cannot restore it, for you or for anyone else. There is no recovery window and no hidden copy. Keeping your export safe becomes your responsibility at that point, and we cannot take it back on.
Deletion removes your account, your reports, your financial records and your stored photographs. Residual copies in encrypted backups are overwritten within 90 days and are never returned to service in the meantime.
One limit you should know about. If you belong to an organisation, records you created belong to that organisation, which is their controller. Deleting your personal account removes you and your personal data, but does not delete the organisation's financial history, because that would destroy other people's records. If you want the organisation itself deleted, an owner must request it and the same export-first rule applies.
9. Your Rights
Wherever you are, you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate
- Receive a copy of your data in a portable format
- Request deletion of your personal information
- Object to, or ask us to restrict, a particular processing activity
- Withdraw consent where processing relies on it
- Complain to your national data protection authority
Contact info@thebvl.com to exercise any of these. We respond within 30 days and never charge for a first request.
One honest caveat on erasure. Inside a live account we cannot delete an individual money record, because the integrity of a financial history is the point of the product and selective deletion would defeat it. What we can always do is delete the whole account, which removes everything. If you are a member of an organisation, direct the request to that organisation as controller and we will assist them in meeting it.
10. Security
Access is authenticated per user and enforced per row in the database. Photographs are stored privately and reached only through short-lived signed links. Confirmation and sign-off links are single-use, time-limited, and stored only as a hash — we cannot reconstruct a link from what we hold. Traffic is encrypted in transit.
No system is perfect. If a breach affects your personal information we will notify you and the relevant authority without undue delay, and tell you what happened rather than only that something did.
11. Cookies & Local Storage
ProofPack stores your records and settings in your device's local storage so the app works offline, and caches photographs there so they display without being downloaded repeatedly. This stays on your device except when syncing to your own account. We use no advertising cookies and no third-party tracking scripts.
12. Children
ProofPack is a workplace tool and is not directed at children under 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, contact us and we will remove it.
13. Changes to This Policy
We may update this policy. We will notify you by email or in-app notice at least 14 days before any material change takes effect.
14. Contact
Privacy enquiries: info@thebvl.com
You may also complain to the data protection authority where you live. For Mauritius this is the Data Protection Office; in the EEA and UK, your national supervisory authority; in South Africa, the Information Regulator.