Privacy policy

Last updated 2 September 2026

Closewatch measures how people read the proposals you send. That means we record things about your clients, so this page says plainly what is collected, why, who it reaches, and how long it is kept.

Two different people are described here

An account holder is someone who signs up and uploads proposals. A reader is someone who opens a proposal link an account holder sent them. Almost all the confusion about tracking tools comes from mixing those two up, so they are kept separate below.

What we collect from account holders

  • Your email address, and the name and company name you choose to enter. Your company name is what readers see as the sender.
  • If you sign in with Google, the email address and name on that Google account. We ask Google for nothing else, and we cannot see your Google password.
  • The proposal PDFs you upload, which are held in private storage that is not publicly listable.
  • A session cookie so you stay signed in.
  • On a paid plan, an identifier for your Stripe customer record and what Stripe reports about the subscription: its state and when the period ends. Your card number is typed on Stripe’s own pages and never reaches us.

What we record when someone opens your proposal

This is the part that makes the product work, so it is worth reading closely. When a reader opens one of your links we store:

  • When the link was opened, when the reader was last active, and how many separate times they have come back.
  • How many seconds of visible attention each page received, and whether the last page was reached.
  • Whether the PDF was downloaded or printed.
  • The browser, operating system and device type, taken from the request.
  • The referring web address, if the browser sent one.
  • A one-way salted hash of the IP address, truncated. The address itself is never written down, and the hash cannot be turned back into one.
  • Whether the request looked automated, and which rule flagged it, so bots and link previews can be excluded from your numbers.

We do not learn a reader’s name or email address from their visit. The only name attached to a link is the label the account holder typed when creating it. Additional readers appear as “Reader 2”, “Reader 3” and so on.

Cookies

Closewatch sets two cookies and no others. A session cookie keeps account holders signed in. A cookie named cw_vid is set on a reader’s browser holding a random identifier, so that the same person returning tomorrow is recognised as a second visit rather than a second person. It is first-party and server-only, cannot be read by JavaScript, and lasts a year.

There are no advertising cookies and nothing that follows anyone around the rest of the web. Our own pages — the home page, sign-in and the dashboard — count visits with Cloudflare Web Analytics, which sets no cookies and does not fingerprint anyone. It never loads on a share link: the page a reader is sent runs no analytics script at all.

Who else sees it

We do not sell data and we do not share it for advertising. It reaches these companies only because they run parts of the service:

  • Supabase: the database, sign-in, and file storage.
  • Cloudflare: hosting the application, and counting visits to our own pages.
  • Resend: sending notification email, when that is switched on.
  • Stripe: taking payment, for account holders on a paid plan.
  • Google: only if you choose to sign in with Google.

If you are an account holder in the UK or EU, the data you collect about your own clients is yours and we process it on your instructions. Our data processing agreement sets out those terms, and lists the same companies above as sub-processors.

How long it is kept

  • Delete a proposal and its file, its links and every visit, page view and event recorded against it are deleted with it.
  • Share links stop working 60 days after they are created, and can be revoked sooner at any time.
  • Close your account and we delete your proposals and the tracking data attached to them.
  • Twelve months after a visit, we strip the parts of it that could point at a person: the hashed IP address, the city, and the referring link. What is left is the reading itself — when, how long, which pages — and the country. This runs nightly, whether or not anyone asks.

Nothing here is kept because it might be useful one day. A visit is kept because the account holder is still working the deal it belongs to, and stops being kept in full the moment that stops being true.

Your choices

Account holders can export or delete their data from inside the product, or by writing to us. Readers who would rather not be measured can ask the person who sent the proposal to revoke the link, or write to us directly and we will remove the visits associated with it.

Your responsibilities as an account holder

You decide who receives a link, so you are the one who knows whether the laws that apply to you and your client require you to say that the document is tracked. Some jurisdictions and some industries do. Closewatch gives you the tooling; the disclosure obligation is yours.

Changes

If this policy changes in a way that affects what is collected, the date at the top changes and account holders are told before it takes effect.

Questions about anything here? Email hello@getclosewatch.com.