Legal

Privacy policy

Last updated: October 5, 2026

This policy explains what personal data Proveely processes, why, who we share it with and how you can exercise your rights. It applies to proveely.com, to the management panel (app.proveely.com) and to the online stores our customers publish with Proveely.

1. Who we are

Proveely is a catalog, pricing and sales management platform for distributors and retailers, built and operated from Uruguay. For any privacy question, write to info@proveely.com.

We process personal data in accordance with Uruguay's Personal Data Protection Law No. 18,331 and its regulations.

2. What data we process

Depending on how you relate to Proveely:

  • Visitors to proveely.com: aggregated browsing data (pages viewed, device, approximate country) through Google Analytics and Microsoft Clarity, and whatever you send us through the contact form (name, email, company and message).
  • Customers and panel users: each user's name, email and company, their permissions, the log of actions they take (audit trail) and the business data they upload or sync (suppliers, products, prices, orders).
  • Shoppers at our customers' stores: name, email, phone, addresses, orders and payments. Here Proveely acts as a data processor: the data belongs to the business that sells, and we process it only to provide our service to that business.
  • Marketing integrations a customer chooses to connect (Google, Meta, Microsoft Clarity): detailed in the next section.

3. Integrations with Google, Meta and Microsoft

From the Metrics section of the panel, each customer can connect their own accounts on these platforms to see their statistics inside Proveely. Connecting is optional, is authorized by the customer with their own account, and can be undone at any time.

  • Google (analytics.readonly and webmasters.readonly permissions): we read the metrics of the Google Analytics 4 property and the Google Search Console site the customer picks — traffic, channels, pages, recorded sales, Google clicks and impressions — and the email of the connected account, to show it in the panel.
  • Meta (Facebook and Instagram): we read the list of pages, the linked Instagram Business account and its statistics (followers, reach, interactions and recent posts), the Pixel's events and the metrics of the chosen ad account (spend, clicks and results).
  • Microsoft Clarity: with the export token the customer generates, we read aggregated metrics of their project (sessions, active time, scroll depth and frustration signals).

All of this access is read-only: Proveely does not post, does not edit campaigns and does not change anything in the connected accounts. Access tokens are stored encrypted and are never shown or sent to the browser. Metrics are stored temporarily as a cache, to stay within each platform's limits, and are replaced on every refresh.

We use this information only to show customers their own metrics inside Proveely. If a branch connects the account, the users of its parent company can also view those metrics, read-only. We do not sell it, use it for advertising, share it with third parties or use it to train artificial intelligence models. The details for Google data are in the next section.

Meta Conversions API: if a business turns it on, when a sale happens in its store Proveely sends that purchase event to the business's own Meta Pixel. The shopper's email, phone, name and location are sent encrypted with an irreversible hash (SHA-256), together with the IP address, the browser and Meta's cookies at the time of purchase. We do this on behalf of and under the instructions of the business, which is responsible for informing its shoppers.

4. Google user data

This section describes specifically how Proveely accesses, uses, stores, shares and deletes Google user data when a customer connects their Google account from the Metrics section of the panel.

Data we access:

  • With the analytics.readonly scope: the user's list of Google Analytics 4 accounts and properties, so they can pick one, and the reports of the chosen property (users, sessions, page views, traffic channels and sources, recorded purchases and revenue, and real-time active users).
  • With the webmasters.readonly scope: the user's list of Google Search Console sites, so they can pick one, and the search statistics of the chosen site (clicks, impressions, CTR, average position, top queries and pages).
  • With the openid and email scopes: the email address of the connected Google account, only to show in the panel which account is connected.

How we use it: only to show that company its own metrics inside the Proveely panel. If a branch connects the account, the users of its parent company can also view those metrics, read-only. We do not use Google data for advertising, do not sell it, do not use it to build user profiles, and do not use it to train or improve artificial intelligence or machine learning models. Proveely never changes anything in Google Analytics or Search Console.

How we store it: Google access and refresh tokens are stored encrypted (AES-256) in our database and are never sent to the browser. Reports are cached for up to one hour to avoid repeating requests, and are replaced on every refresh.

Who we share it with: no one. Google data only goes through the infrastructure providers that host Proveely (Supabase and Railway), under confidentiality obligations. No one on the Proveely team reads this data, except with the customer's consent to provide support, for security, or to comply with the law.

Retention and deletion: we keep the tokens and the cache only while the account is connected. Clicking Disconnect in the Metrics section deletes them immediately and revokes access at Google. Users can also revoke it at any time at myaccount.google.com/permissions, or ask us to delete it at info@proveely.com.

Proveely's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. What we use data for

  • Providing the service: authenticating users, syncing catalogs, processing orders, sending each purchase's emails and showing metrics.
  • Answering support requests and contact form messages.
  • Keeping the platform secure, detecting errors and preventing fraud.
  • Improving the site and the product with aggregated usage statistics.
  • Complying with legal obligations.

6. Who we share data with

We do not sell personal data. We share it only with the providers we need to run the service, each limited to its role:

  • Infrastructure and hosting: Supabase (database and authentication), Railway (servers) and Vercel (website, panel and stores).
  • Email: Resend, for transactional emails and invitations.
  • Payments: Mercado Pago, when the shopper chooses to pay with it.
  • Contact form: Formspree.
  • Website analytics: Google Analytics and Microsoft Clarity.
  • Artificial intelligence: Anthropic, only when a customer uses automatic categorization or descriptions; it receives product data, not shoppers' personal data.
  • Google, Meta and Microsoft, only within the integrations each customer connects (section 3).

Some of these providers process data outside Uruguay, with the safeguards required by law. We may also disclose data when a competent authority requires it under the law.

7. How long we keep data

We keep data while the customer's account is active and for as long as needed to meet legal obligations. An integration's tokens and cache are deleted as soon as the customer disconnects it. The platform's technical and monitoring metrics are deleted automatically between 30 and 90 days after they are generated.

8. Security

We use encrypted connections (HTTPS), encryption of credentials and tokens in the database, access control by company and by permission, and an audit log of panel actions. No system is infallible, but we work to protect data with reasonable measures, and we will notify affected people and the authority if an incident requires it.

9. Your rights

You can request access to, rectification, update, inclusion or deletion of your personal data by writing to info@proveely.com. If you are a shopper at a store, you can also contact the business directly, as it is responsible for that data; we help it answer you.

If you believe we did not handle your request properly, you can file a complaint with Uruguay's Personal Data Regulatory and Control Unit (URCDP).

10. How to delete your data

To delete the data of an integration (Google, Meta or Microsoft Clarity):

  • Go to the Proveely panel, Metrics section, and click Disconnect on the integration. We immediately delete that account's access tokens and stored metrics.
  • You can also revoke access from the platform itself: on Google, at myaccount.google.com/permissions; on Facebook, in your account settings, Business integrations section. Once revoked, Proveely can no longer read the data and the tokens become useless.
  • If you no longer have access to the panel, or you want us to delete all of your account's data, write to info@proveely.com from the registered email. We reply and complete the deletion within 30 days.

11. Cookies

proveely.com uses Google Analytics and Microsoft Clarity cookies to measure how the site is used, in aggregate. The panel uses the browser's local storage to keep your session and preferences. Our customers' stores may use their own measurement tools (for example, Google Analytics or the Meta Pixel), configured by each business.

12. Changes to this policy

If we change this policy, we will publish the new version on this page with its update date and, if the change is significant, we will tell our customers by email or in the panel.

13. Contact

For any question about this policy or your data: info@proveely.com.