Privacy policy
Effective August 5, 2026 · LateShift LLC · support@proofwalk.io
Who we are
Proofwalk is a remote visual support service operated by LateShift LLC, a limited liability company organized in Florida, with its registered address at 7901 4th St N STE 300, St. Petersburg, FL 33702, USA. In this policy "we", "us" and "Proofwalk" mean LateShift LLC. Contact us at support@proofwalk.io.
The two roles we play
Proofwalk is sold to companies, and almost everything inside a session belongs to the company that created it rather than to us. That gives us two different jobs.
- For account data we are the controller. Seat names, email addresses, passwords and billing details are ours to answer for, because we decide what to do with them.
- For session content we are the processor. Photos, recordings, chat, job details and everything a technician sends belong to the customer whose team ran the session. We hold and protect that content, and we act on that customer's instructions. If you are a technician or an end customer asking about a session, the company that ran it is the right place to start, and we will help them respond.
Our processor obligations are set out in the data processing agreement.
What we collect
From people with accounts
- Name and email address, supplied when a seat is created or an invitation is accepted.
- A password, stored only as a scrypt hash. We never hold the password itself.
- Which company the seat belongs to, and whether it is an administrator or a member.
- A signed session cookie so the browser stays logged in.
- IP addresses, used to rate limit sign-in and session-code attempts and then discarded.
From a live session
- Photos and snapshots captured during the session, at full camera resolution.
- Annotations drawn on a captured frame, and reference images pushed to the phone.
- Chat messages in both directions.
- Session recordings, but only when a specialist deliberately starts one.
- Checklist progress, including an append-only record of every step checked and unchecked, the photo attached to each, and the technician's sign-off.
- Job details entered by the specialist: work order number, job name and description.
- Session metadata: the six-character code, timestamps, and the name of the seat that opened it.
- Text read from equipment plates by optical character recognition, when a specialist runs it on a photo.
- Mobile phone numbers, when a specialist sends a join link by text message. See the SMS policy.
Technical diagnostics from the technician's phone
So that a specialist can tell a bad connection from a broken feature, each session records the phone model and browser, what the camera reported it could do, the resolution and frame rate actually sent, a sampled trail of connection quality, whether media travelled directly or through a relay, and any errors the page hit. This is attached to the session report and is visible only to the customer's own specialists.
Live video and audio
Live video and audio travel directly between the technician's browser and the specialist's browser, encrypted end to end. Neither our servers nor our relay can decrypt them, including when a hostile network forces the media through the relay. Live media is not stored at all unless a specialist starts a recording, and a recording is created on the specialist's side and uploaded to us.
How we use it
- To run the session: connecting the two sides, relaying chat, control actions and checklist state.
- To produce and store the job report, which is the record the customer bought the product for.
- To deliver a join link by text message when a specialist asks us to.
- To keep the service secure: rate limiting, abuse prevention, and diagnosing faults.
- To bill and support the account.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use session content to train machine learning models. We run no advertising and no third-party analytics.
Who else sees it
- The customer's own team. Sessions are separated by company. A specialist sees only sessions belonging to their own company, and every seat in that company can see them, because a colleague picking up an unfinished job is the point of the product.
- Anyone holding a share link. A specialist can mint a link that shows the report with no account required, and can revoke it. A shared report deliberately excludes chat, recordings and diagnostics. Treat a share link as public once it is sent.
- Our subprocessors. The full list, and what each one does, is at subprocessors.
- Nobody else, unless the law compels us or you ask us to.
How long we keep it
| What | How long |
|---|---|
| Session recordings | Deleted automatically 14 days after upload. |
| Photos and step evidence | Deleted one year after the session is closed. Deliberately measured from closure, not creation, so a job still running keeps its evidence however long it takes. |
| The session record and report | Kept for the life of the account. Where a photo has aged out, the report says so rather than showing a gap. |
| Chat logs and audit trail | Kept with the session record. |
| Sessions abandoned before anyone joined | Pruned automatically after 24 hours. |
| Account records | Kept while the account is open, then deleted or returned as set out in the data processing agreement. |
| Phone numbers used for a join link | Held with the session log and shown masked. |
Customers on plans with a longer retention obligation can have these periods extended by agreement. Ask us before assuming a longer period applies.
How it is protected
- Everything in transit is encrypted with TLS.
- Live video and audio are encrypted end to end and cannot be read by us.
- Passwords are scrypt hashed. Session cookies are signed.
- Join links and share links are stored only as hashes, so a copy of our session files yields no working links.
- A technician holds no account, and everything the technician side can send is checked on the server before it is accepted.
- Closing a session permanently ends technician access to it.
Being precise about what is not encrypted. Stored photos, recordings, chat and session records are held in plain form on our server's disk. They are protected by access controls and file permissions, not by encryption at rest. Proofwalk as a whole is therefore not an end-to-end encrypted product, even though live video and audio are. If your obligations require encryption at rest, tell us before you buy rather than after.
Cookies
Proofwalk sets one cookie, a signed identifier that keeps a signed-in seat signed in. It is strictly necessary to operate the service, so it does not require consent. We set no advertising cookies, no analytics cookies and no third-party cookies, and there is nothing to opt out of.
If you are a technician
You may be reading this because somebody texted you a link and your camera is now on. You have no account with us and you did not sign up for anything, so this part is written for you.
- The company running the session decides what is collected and how long it is kept. They are responsible for it. We hold it for them.
- Your camera is live only while the session is open, and only after you allow it in your browser. You can deny or revoke that permission at any time, and closing the tab ends the session on your side.
- A recording only happens if the specialist starts one. Needs legal review and a product change: several US states require every party to consent before audio is recorded. The technician's screen should say clearly when recording starts. That notice is not built yet.
- To ask what was collected about you, or to have it deleted, contact the company that sent you the link. If you cannot reach them, write to support@proofwalk.io and we will pass it on and help.
Your rights
Several US states give residents the right to know what personal information a business holds about them, to have it corrected, to have it deleted, and to receive a copy in a portable form. We honour those requests for anyone who asks, whichever state you are in and whether or not the statute technically reaches a business our size. We do not make automated decisions that produce legal effects.
California residents additionally have the right not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, as those terms are defined under California law.
Exercise any of these by writing to support@proofwalk.io. Where the request concerns session content, we will refer it to the customer who controls that session and support them in answering it.
Where the data is held, and who we serve
Proofwalk runs on servers in the United States, in Boston, Massachusetts, and everything described here is stored there. Transactional email is delivered through our mail provider's infrastructure in the European Union, which is the only part of the service that leaves the country. See subprocessors.
Proofwalk is offered to businesses in the United States only. We do not market or sell the service outside it. A join link is not geographically restricted, so if you send one to a technician working abroad, you are responsible for whatever local law applies to that session. Tell us before you do it and we will tell you whether we can support it.
Children
Proofwalk is a workplace tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child's information has reached us, write to support@proofwalk.io and we will delete it.
Changes
When this policy changes we will update the effective date above, and we will tell account holders directly before any change that materially reduces protection for information we already hold.
Contact
LateShift LLC, 7901 4th St N STE 300, St. Petersburg, FL 33702, USA. Email support@proofwalk.io.