Privacy Policy
Effective date: August 6, 2026
1. Who We Are
PROOF ("we," "us," or "our") operates the verified effort loyalty platform at verifiedeffort.com and the application at proof.verifiedeffort.com. PROOF is operated by PROOF Verified Effort, Inc., based in California, United States.
This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our website, platform, and related services (collectively, the "Service").
2. Information We Collect
2.1 Account Information
When you create a PROOF account, we collect:
- Email address
- Name (as provided by you or your connected fitness platform)
- Password (stored in hashed form only)
2.2 Fitness Platform Data
When you connect a fitness platform to PROOF (currently Strava; additional integrations planned), we receive activity data from that platform through their authorized API. We limit the activity data we retain to fields used to verify eligible effort and operate the loyalty programs you join. These fields may include:
- Activity type (e.g., cycling, running, swimming, walking)
- Distance, moving time, and total elevation gain
- Date and time of activity
- Activity title
- The fitness-platform athlete and activity identifiers needed to maintain the connection and prevent duplicate credit
- PROOF's verification result and the Points calculated from the activity
We only access data you have explicitly authorized through the OAuth consent flow provided by each fitness platform. You can revoke this access at any time (see Section 7).
PROOF does not retain GPS routes, heart rate, power, kilojoules, Strava intensity scores, activity descriptions, or Strava profile photos for newly processed activities. You can review how eligible effort becomes Points on our PROOF methodology page.
We retain identifiable activity detail for no more than seven days after the activity. After that period, the activity identifier, title, sport, distance, duration, elevation, and other connected-platform detail are deleted from PROOF's active systems. We retain only the provider-free loyalty records needed to preserve Points, rewards, and account history as described in Section 5.
2.3 Brand Program Data
When you join a brand's loyalty program through PROOF, we collect and generate:
- Your connection to specific brand programs
- Brand-scoped Points and reward progress for programs you join
- Reward thresholds reached, credits issued, and redemption/support state
- Limited account and communication details needed to operate the program
2.4 Usage Data
We automatically collect standard usage data when you interact with the Service, including IP address, browser type, device information, pages visited, and referring URL. We use Vercel Analytics for aggregated, privacy-friendly website analytics.
3. How We Use Your Information
We use the information we collect to:
- Verify that athletic activities are real and recorded by the athlete's fitness device or app
- Convert verified activities into athlete-owned PROOF Miles and brand-scoped Points
- Calculate and maintain your athlete identity, program progress, and reward eligibility
- Credit your effort to brand loyalty programs you have joined
- Generate and deliver rewards (e.g., discount codes) on behalf of brands
- Send you transactional notifications about your account and earned rewards
- Detect and prevent fraudulent activity submissions
- Improve and maintain the Service
We do not use your data for advertising. We do not sell your data. We do not use your fitness data to train artificial intelligence or machine learning models.
4. How We Share Your Information
4.1 With Brands You Join
When you join a brand's loyalty program through PROOF, that brand receives limited data necessary to operate their program:
- Brand-scoped Points and next-reward progress for that program
- Reward credits issued, available, expired, redeemed, or otherwise needing support
- High-level program support state, such as joined status or connection health
- Your email address (for program communications you have opted into)
Brands do not receive your raw GPS data, raw activity feed, full activity history, pace, trend, or data from other brand programs you have joined. Each brand only sees loyalty accounting, reward, support, and aggregate program information scoped to its own program.
4.2 With Fitness Platforms
We do not share your data back to Strava or other connected fitness platforms beyond what is required for the API connection to function.
Strava may collect and analyze information about your use of PROOF as permitted by Strava's own terms and privacy policy.
4.3 With Third Parties
We do not sell, rent, lease, or license your personal data to any third party, including advertisers or data brokers. We may share data with service providers who help us operate the Service (e.g., hosting, email delivery), but only under strict contractual obligations to protect your data and use it solely for providing services to PROOF.
4.4 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
5. Data Retention
We retain the minimized activity fields described above for no more than seven days after the activity. During that period, we use the detail to verify eligible effort, prevent duplicate credit, explain your own recent activity, and process activity updates or deletions. We do not store full GPS route coordinates.
After seven days, PROOF deletes the identifiable activity detail and retains provider-free loyalty accounting such as dated Points entries, aggregate lifetime progress, reward and Challenge outcomes, and commerce records. Those retained records preserve value already earned without retaining the connected-platform athlete ID, activity ID, title, sport, route, distance, duration, elevation, or other activity-level performance data.
If a connected platform reports an activity update or deletion during the seven-day period, PROOF removes the activity detail. Points or rewards already issued from that activity may remain so participating brands can honor earned value. To prevent duplicate credit, PROOF may retain only the activity identifier until the original seven-day period expires; that identifier is not shown to brands or used for marketing.
A confirmed disconnect deletes the connected platform's authorization credentials, provider identifiers, and detailed activity records from PROOF's active systems. Limited operational and security logs may remain for their normal short retention period, and deleted records may remain temporarily in encrypted backups until those backups expire.
Disconnecting does not delete earned loyalty value or completed commerce history. PROOF retains provider-free aggregate lifetime progress, brand-scoped Points, Challenge outcomes, earned rewards, and purchase or refund records so that brands can honor value already earned and maintain necessary financial and support records. These preserved records do not include the deleted fitness-platform athlete ID, activity ID, title, date, sport, route, distance, duration, elevation, or performance data.
If you delete your PROOF account, we will delete personal data within 30 days, except where we must retain limited information for legal, fraud-prevention, financial, or security obligations. De-identified aggregate data that cannot reasonably identify you may be retained for analytics.
6. Data Security
We implement industry-standard security measures to protect your personal information, including encryption in transit (TLS/SSL), encrypted storage of sensitive credentials, and access controls limiting who can access personal data within our organization. OAuth tokens used to connect fitness platforms are stored securely and refreshed according to each platform's requirements.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
7. Your Rights and Choices
7.1 Access and Portability
You may request a copy of the personal data we hold about you by contacting us at team@verifiedeffort.com.
7.2 Correction
You may update your account information at any time through the Service. If you believe any data we hold is inaccurate, contact us and we will correct it.
7.3 Deletion
You may delete your PROOF account at any time. Upon deletion, we will remove your personal data within 30 days. You may also request deletion of specific data by contacting us at team@verifiedeffort.com.
7.4 Disconnect Fitness Platforms
You may disconnect any connected fitness platform at any time through the Connections page in your PROOF account settings. Using PROOF's disconnect control lets us confirm revocation with the platform and delete the authorization, provider identifiers, and detailed activity records described in Section 5.
You may also revoke PROOF's access directly through the platform's own settings:
- Strava: Settings → My Apps → PROOF → Revoke Access
Revoking access directly through Strava stops PROOF's authorization, but the external notification may not immediately complete PROOF's detailed-data cleanup. If you revoke through Strava instead of PROOF, contact team@verifiedeffort.com and we will complete the deletion. In either case, your aggregate lifetime progress, brand Points, completed Challenges, earned rewards, and completed purchases remain. If you reconnect later, PROOF starts processing eligible activity from the new authorization forward; it does not import activity from before that new authorization, and deleted activity detail is not restored.
7.5 Communication Preferences
You may opt out of promotional emails at any time by clicking the unsubscribe link in any email or updating your preferences in your account settings. Transactional emails related to your account and earned rewards may still be sent as necessary for the operation of the Service.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose about you
- Request deletion of your personal information
- Opt out of the sale or sharing of your personal information (we do not sell your data)
- Non-discrimination for exercising your privacy rights
- Correct inaccurate personal information
- Limit use and disclosure of sensitive personal information
To exercise any of these rights, contact us at team@verifiedeffort.com. We will respond to verifiable requests within 45 days as required by California law.
9. International Data Transfers
PROOF is based in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We take appropriate measures to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
For users in the European Economic Area (EEA) or United Kingdom, we process data in compliance with GDPR requirements, including maintaining appropriate legal bases for processing and providing data subject rights as required by Articles 15–22 of the GDPR.
10. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal information, please contact us at team@verifiedeffort.com.
11. Third-Party Fitness Platform Terms
Your use of connected fitness platforms is governed by their respective terms and privacy policies. We encourage you to review these:
- Strava: Privacy Policy · API Agreement
PROOF's access to your fitness data is subject to the terms of each platform's API agreement. We do not access data beyond the scope of the permissions you grant during the OAuth authorization process.
12. Cookies and Tracking
The PROOF website uses minimal cookies necessary for the Service to function (such as session cookies for authentication). We use Vercel Analytics for aggregated website analytics, which does not use cookies or track individual users. We do not use third-party advertising cookies or trackers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service prior to the change becoming effective. The "Effective date" at the top of this page indicates when the policy was last revised. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
PROOF Verified Effort, Inc.
Email: team@verifiedeffort.com