Sign inStart free

Legal

Proof Impact Privacy & Data Guide

Last updated: July 18, 2026

A factual guide to the data Proof Impact processes, the controls available to workspace customers, and the current retention, export, and deletion behavior.

This page is provided for transparency and is not legal advice. If you have questions about your obligations, please consult your own counsel.

1. What Proof Impact does

In shortProof Impact measures observational relationships between displayed proof and configured conversion events; experiments are separate and automatic promotion is not released.

When a workspace enables Proof Impact, ReTestimonial records eligible widget/proof exposures and configured conversion events, then applies last-touch, first-touch, or fractional observational attribution inside the selected event window. Observational attribution is not proof that a testimonial caused a conversion.

Business workspaces can prepare randomized experiment evidence in beta. Recommendation controls remain presentation-only and do not authorize a live widget-delivery change. Proof Impact does not calculate true ROI because it does not collect cost or margin inputs.

2. Data processed

In shortThe feature uses bounded event, context, money, and first-party identity fields needed for measurement and integrity checks.

  • Exposure evidence: project, widget, testimonial/proof and matched-rule identifiers or immutable snapshots, event time, page path, referrer domain, selected campaign parameters, language, and optional page tags.
  • Conversion evidence: event name and time, project-scoped client/session identifiers, page path, currency and integer minor-unit value when supplied, order/idempotency identities, and attribution status/reason.
  • Customer metadata: at most 20 scalar fields, with bounded key/value length and rejection of credential, payment, direct-identifier, and contact-field names. Metadata is retained as customer data but is not used by reporting or optimization.
  • Integrity and abuse evidence: salted actor hashes, bounded counters, browser heuristics, relationship checks, review reasons, and support reference IDs that do not reveal a visitor’s identity. Raw IP addresses are not stored in Proof Impact security events.
  • Optional first-party identity: salted, project-scoped representations of opaque visitor, customer, or account aliases and explicit domain links. Direct email/phone aliases, browser fingerprinting, and probabilistic identity inference are not supported.
  • Experiment and optimization evidence: assignments, declared outcomes, observations, versioned readouts, shadow decisions/reviews, and append-only rollout-control history.

3. Privacy and collection controls

In shortCollection decisions run before page context or identity is transmitted, and the workspace customer selects the applicable policy.

  • Consent mode can allow implicit measurement or require an explicit granted state.
  • Global Privacy Control and Do Not Track can be honored or ignored according to the workspace's selected policy. IGNORE is a configuration choice, not a compliance claim.
  • When the privacy decision blocks measurement, visitor/session/exposure/identity state is purged, page context is not transmitted, and the blocked conversion is not persisted.
  • Contextual widgets use a minimal privacy preflight before collecting page path, referral, campaign, tag, or language context.
  • Same-session attribution is the privacy-minimal default. Consented identity and cross-domain linking are opt-in, project-scoped, exact-origin, and auditable.
  • Origin allowlists can limit public browser ingestion to configured exact or wildcard origins.

The workspace customer controls its site notice and consent experience and is responsible for choosing settings appropriate to its visitors, purposes, and applicable requirements.

4. Default retention

In shortRaw evidence expires sooner than durable outcomes; active service configuration can set each scheduled class from 1 to 3,650 days.

  • Raw widget/proof exposure events — 90 days.
  • Terminal conversions, attribution rows, experiment assignments/observations, shadow decisions/reviews, and rollout-control events — 730 days.
  • Optimization decisions/state transitions and security/ingestion audit events — 365 days.
  • Optimization signal cache snapshots — 7 days.
  • Expired identity-transfer and exposure tokens — 1 day.
  • Daily aggregate facts and rollup-run evidence — 760 days.

Pending or retryable conversions are not age-deleted before they reach a terminal attribution state. Project configuration, identity graph/audit/suppression state, active server-key metadata, experiment definitions/versions, orders, and other project-owned records remain until the applicable product deletion or project deletion path removes them. The Data Quality view reports the active scheduled retention values.

5. Export, deletion, and support access

In shortAuthorized workspace members can export retained data, and project deletion removes the project-owned Proof Impact graph.

  • Members with data-export permission can page through a retention-bounded Proof Impact JSON export and download observational attribution-summary or raw-ledger CSVs.
  • Exports omit server-key secrets and internal actor hashes; CSV output is protected against spreadsheet formula injection.
  • Deleting a project cascades through its exposures, conversions, attribution, identities, orders, experiments, optimization evidence, daily facts, and configuration.
  • Support-safe diagnostics expose health counters and reasons without metadata, sessions, actor hashes, origins, order IDs, or monetary values.

6. Providers and customer responsibilities

In shortCore infrastructure handles measurement records; optional AI providers are not part of Proof Impact attribution.

Proof Impact measurement is processed by ReTestimonial's hosting, database, edge/storage, rate-limiting, and observability infrastructure as applicable. Authenticated dashboard navigation may use product analytics, but raw Proof Impact ledgers are not its intended input. Proof Impact attribution does not send conversion or exposure ledgers to Anthropic or OpenAI for routine measurement.

See the current Subprocessor Register for provider purpose, data-category, and conditional-use details.

Customers remain responsible for the conversion events, metadata, first-party aliases, notices, lawful basis or consent choices, origin policy, retention requirements, and server credentials they configure. This technical guide does not determine whether a particular configuration complies with law.

Questions? Contact privacy@retestimonial.com. View our Privacy Policy.