Prolify
Back to ProlifyPrivacy Policy
Legal Document

Privacy Policy

Effective Date: January 2026  |  Last Updated: March 2026

Issued by Vectis Group LLC.

Notice at Collection (California Residents)

We collect the following categories of personal information: identifiers (name, email, phone); commercial information (service usage, transaction history); internet/electronic network activity (app and website events, device data); financial information (bank account data, transaction data accessed via Stripe Financial Connections, Plaid, or Wise with your consent); and professional/employment information (business name, entity details, role). We do not sell or share personal information for cross-context behavioral advertising. California residents may exercise rights described in Addendum A. To submit a request, email privacy@prolify.co with subject line "California Privacy Request."

Key Points Summary

  • Data Controller:Vectis Group LLC., a company incorporated in the United States.
  • What We Collect:Account information, business details, financial account data (with your consent via Stripe, Plaid, or Wise), device/usage data, and analytics data.
  • How We Use It:To provide LLC formation, AI bookkeeping, compliance services, and to improve, secure, and communicate about our Services.
  • AI Processing:We use automated systems to categorize transactions, generate financial reports, and provide bookkeeping insights. You can review and correct all AI-generated outputs.
  • Sharing:Only with service providers, financial connectivity partners, and as required by law. We never sell your personal information.
  • International Transfers:Data is processed in the United States. We rely on the EU-US Data Privacy Framework, UK-US Data Bridge, and Standard Contractual Clauses for lawful transfers.
  • Your Rights:Depending on your jurisdiction, you may access, correct, delete, port, or restrict processing of your data. See Sections 10 and Addenda A–C.
  • Contact:privacy@prolify.co

1. Who We Are

This Privacy Policy is issued by Vectis Group, LLC. ("Vectis," "Company," "we," "us," or "our"), the data controller responsible for the personal information described in this policy.

2. Scope of This Policy

This Privacy Policy applies to all personal information we collect, use, store, and share when you:

  • Visit or interact with our website (prolify.co) or any of our subdomains;
  • Create an account and use our Services, including LLC formation, registered agent, compliance, AI bookkeeping, invoicing, and related business services;
  • Link a financial account through Stripe Financial Connections, Plaid, Wise, or any other supported financial connectivity provider;
  • Communicate with us through email, in-app chat, support tickets, or any other channel;
  • Interact with our marketing communications, surveys, or events.

This policy does not apply to third-party websites, applications, or services that we link to or integrate with, even if accessed through our Services.

3. Information We Collect

3.1 Information You Provide Directly

  • Account and Profile Information: Full legal name, email address, phone number, password (stored in hashed form), role or title, and profile preferences.
  • Business and Entity Information: Business name, entity type, formation state, registered agent details, EIN, articles of organization, operating agreements, and other formation or compliance documents.
  • Financial and Bookkeeping Information: Receipts, invoices, bank statements, expense reports, and other financial documents you upload.
  • Payment Information: Billing address, payment card details (processed and stored by Stripe; we do not store full card numbers).
  • Communications: Messages you send to our support team, survey responses, feedback, and testimonials.

3.2 Information Collected Automatically

  • Device and Technical Data: IP address, browser type and version, operating system, device identifiers, screen resolution, and language preferences.
  • Usage Data: Pages viewed, features used, clickstream data, session duration, and actions taken within the Services.
  • Analytics Data: We use PostHog to collect aggregated usage data. For EU/UK users, non-essential analytics cookies require your prior consent.
  • Log Data: Server logs that record requests made to our systems.

3.3 Financial Account Data (Third-Party Financial Connectivity)

If you choose to connect a bank account through one of our supported providers, we access and process financial account data with your explicit consent. Supported providers include Stripe Financial Connections, Plaid, and Wise.

Important: We never receive, store, or have access to your bank login credentials. All authentication occurs directly through the provider's secure connection flow. You may withdraw consent at any time by disconnecting the linked account in your account settings.

4. How We Use Your Information

4.1 Providing and Operating the Services

Creating and managing accounts, processing LLC formations, enabling AI bookkeeping features, processing payments via Stripe, and generating financial views such as cash flow summaries and profit and loss statements.

4.2 Improving and Securing the Services

Analyzing usage patterns via PostHog, troubleshooting technical issues, preventing fraud, detecting unauthorized access, and conducting internal research and development using de-identified and aggregated data only.

4.3 Communicating with You

Sending transactional communications, responding to support requests, and sending marketing communications (only with your consent where required by law).

4.4 Legal and Compliance Obligations

Complying with applicable laws, establishing or defending legal claims, fulfilling tax reporting obligations, and responding to lawful requests from regulatory authorities and law enforcement.

5. Automated Processing and AI Features

Our Services use automated systems, including machine learning and AI, to provide core bookkeeping and financial analysis features.

5.1 What Our AI Does

Categorizes transactions, matches receipts and invoices to transactions, detects duplicates and anomalies, generates financial summaries and reports, and suggests chart-of-accounts mappings.

5.2 Human Oversight

All AI-generated outputs are presented to you for review. You can modify, correct, or override any AI-generated categorization at any time.

5.3 Model Training and Your Data

We do not use your individually identifiable connected bank transaction data or uploaded financial documents to train general-purpose or third-party AI models. We may use de-identified and aggregated data to improve our product's AI performance.

5.4 AI Accuracy Disclaimer

Important: AI-generated bookkeeping data, transaction categorizations, financial reports, and insights are provided for informational purposes and may contain errors. Users should independently verify the accuracy of all AI-generated outputs before relying on them for tax filings or financial reporting. Prolify is not a licensed accounting firm and our AI-generated outputs do not constitute professional accounting, tax, or financial advice.

6. How We Share Your Information

We share your personal information only as described below. We never sell your personal information.

6.1 Service Providers (Data Processors)

We engage vetted third-party service providers for cloud hosting, product analytics (PostHog), payment processing (Stripe, Plaid, Wise), email delivery, customer support, and security. All providers are contractually prohibited from using your data for their own purposes.

6.2 Financial Connectivity Partners

When you link a financial account, Stripe, Plaid, and/or Wise process your financial data under their respective privacy policies. We maintain Data Processing Agreements with each partner.

6.3 Legal, Safety, and Compliance Disclosures

We may disclose personal information to comply with applicable laws, enforce our Terms of Service, detect or prevent fraud, or protect the rights and safety of Prolify, our users, or the public.

6.4 Business Transfers

If Prolify is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.

7. International Data Transfers

Prolify is based in the United States. If you access our Services from outside the US—including from the EEA, UK, or Switzerland—your personal information will be transferred to and processed in the United States.

We rely on the following lawful transfer mechanisms: EU-US Data Privacy Framework (DPF), UK-US Data Bridge (UK Extension to the DPF), and Standard Contractual Clauses (SCCs). We conduct Transfer Impact Assessments and implement supplementary measures where necessary.

8. Data Retention

We retain personal information only as long as necessary to fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements.

Data CategoryRetention Period
Account and profile dataDuration of active account + 90 days post-termination
Business formation documentsDuration of account + 7 years from the relevant tax year
Financial/bookkeeping dataDuration of account + 7 years from the relevant tax year
Payment/billing records7 years from date of transaction
Communications3 years from last interaction or account closure
Device and usage data24 months from collection
Analytics data (PostHog)Duration of account or until you opt out
Security and access logs12 months from creation

9. Data Security

We implement administrative, technical, and organizational security measures including:

  • Encryption of data in transit (TLS 1.2+) and encryption at rest;
  • Multi-factor authentication for access to internal systems;
  • Role-based access controls limiting data access to authorized personnel;
  • Regular security assessments, vulnerability scanning, and penetration testing;
  • Employee security training and confidentiality obligations;
  • Incident detection, response, and recovery procedures.

If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at security@prolify.co.

10. Your Rights and Choices

10.1 Universal Rights (All Users)

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate or incomplete personal information.
  • Deletion: Request that we delete your personal information, subject to legal retention requirements.
  • Account Controls: Update your profile, disconnect linked financial accounts, and manage notification and marketing preferences through your account settings.
  • Opt-Out of Marketing: Unsubscribe from marketing emails using the link in any marketing communication.

10.2 How to Exercise Your Rights

Email privacy@prolify.co with subject line "Privacy Rights Request" and include your full name, account email, the specific right(s) you wish to exercise, and your jurisdiction. We will respond to verified requests within 45 days.

10.3 Global Privacy Control

We honor the Global Privacy Control (GPC) signal. If your browser or device transmits a GPC signal, we will treat it as a valid opt-out of sale and sharing of personal information.

11. Cookies, Analytics, and Tracking Technologies

We use cookies and similar technologies to operate and improve the Services.

  • Strictly Necessary Cookies: Required for authentication, security, and core functionality. These cannot be disabled.
  • Analytics Cookies (PostHog): Used to understand how users interact with our Services. PostHog uses first-party cookies with a 365-day expiry and does not track users across different websites.
  • Preference Cookies: Used to remember your settings and preferences.

For users in the EEA and UK, we display a cookie consent banner before setting non-essential cookies.

12. Data Breach Notification

In the event of a personal data breach affecting your personal information, we will notify you and the relevant supervisory authorities in accordance with applicable data protection laws, including GDPR Articles 33 and 34, GLBA Safeguards Rule breach notification requirements, and the breach notification laws of all applicable US states.

13. Children's Privacy

Our Services are intended for use by adults and business entities. We do not direct our Services to individuals under 18 years of age, and we do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a minor, please contact us at privacy@prolify.co.

14. Consumer Reporting Disclaimer

Prolify is not a consumer reporting agency as defined by the Fair Credit Reporting Act. Our Services do not constitute consumer reports and the financial data generated by our AI bookkeeping features should not be used to determine any individual's eligibility for credit, insurance, or employment.

15. Third-Party Links and Integrations

The Services may contain links to third-party websites, applications, or services. This Privacy Policy does not apply to any third-party sites or services. We encourage you to read the privacy policy of any website you visit.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide prominent notice through the Services, by email, or by other means prior to the changes taking effect. Material changes include: changes to categories of personal information collected, new purposes of processing, changes to data sharing practices, or modifications to your rights.

17. Dispute Resolution

17.1 Governing Law

This Privacy Policy and any disputes arising out of or relating to it shall be governed by the laws of the United States, without regard to conflict of laws principles.

17.2 Arbitration (US Users)

For users located in the United States: Any dispute that cannot be resolved through informal negotiation within 30 days shall be resolved exclusively through binding individual arbitration administered by the American Arbitration Association. There shall be no right or authority for claims to be arbitrated on a class, collective, or representative basis. You may opt out of this arbitration provision by sending written notice to privacy@prolify.co within 30 days of first accepting this Privacy Policy.

17.3 EEA and UK Users

The arbitration provision in Section 17.2 does not apply to users located in the EEA, UK, or Switzerland. Nothing in this Privacy Policy limits your right to bring proceedings before the courts of the EU Member State or UK jurisdiction in which you reside, or your right to lodge a complaint with a supervisory authority.

18. Contact Information

Addendum A: California Residents (CCPA)

This addendum supplements the main Privacy Policy for California residents pursuant to the CCPA/CPRA.

We have collected in the preceding 12 months: Identifiers (name, email, phone, IP address), Financial information (bank account data, transaction data), Commercial information (services purchased, usage history), Internet/electronic activity (browsing, app usage), Professional/employment information (business name, role), Geolocation (inferred from IP), and Inferences (AI-generated transaction categories). None of this information has been sold or shared for cross-context behavioral advertising.

Your California Privacy Rights:

  • Right to Know/Access the categories and specific pieces of personal information we collected.
  • Right to Delete personal information we collected, subject to statutory exceptions.
  • Right to Correct inaccurate personal information.
  • Right to Opt Out of Sale/Sharing — We do not sell or share personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive PI — You may request we limit our use of sensitive personal information.
  • Right to Non-Discrimination — We will not discriminate against you for exercising any of your CCPA rights.

To submit a request, email privacy@prolify.co with subject "California Privacy Request."

Addendum B: European Economic Area Residents (GDPR)

We process your personal data on the following lawful bases: contract performance (account creation, LLC formation, AI bookkeeping, payment processing), legal obligation (tax compliance, AML/KYC obligations), legitimate interest (product analytics, fraud prevention, security monitoring), and consent (marketing emails, non-essential cookies, financial account linking).

Your GDPR Rights:

  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object to processing (Art. 21)
  • Rights related to automated decision-making (Art. 22)
  • Right to withdraw consent at any time (Art. 7)
  • Right to lodge a complaint with a supervisory authority (Art. 77)

You may request a copy of our Legitimate Interest Assessments or Standard Contractual Clauses by contacting privacy@prolify.co.

Addendum C: United Kingdom Residents (UK GDPR)

Our UK Representative is: Mark Damsell, damsell@prolify.co. We rely on the UK-US Data Bridge (the UK Extension to the EU-US Data Privacy Framework) and the UK International Data Transfer Agreement for transfers from the United Kingdom to the United States.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk, Telephone: +44 (0)303 123 1113.

The mandatory arbitration provision in Section 17.2 does not apply to UK residents. Nothing in this policy restricts your rights under UK GDPR or the Data Protection Act 2018.

© 2026 Vectis Group, LLC. All rights reserved.

This document is for informational purposes and does not constitute legal advice. Prolify recommends consultation with qualified legal counsel for compliance verification.