Privacy Policy
Effective 27 September 2026. This policy describes what BankChangeProof, operated by InfiniHash LLC, collects and how it is used.
What we collect
- Account data: your email address, a hash of your password, your name if you enter it, and the account name.
- Content you create: vendor records (names, contacts, verified phone numbers, email domains, bank name, account type and the last four digits of an account; never a full account number), change requests with the message text you paste (long digit runs are redacted before storage), callback and approval notes, uploaded files and the documents generated from them.
- Activity records: a timestamped history of actions in your account (the event chain), including the IP address of the person who opened, called, approved, denied or released a change request. This history is the product: it is what makes the record evidence.
- Technical logs: request paths, timings, request ids and error details, kept for 30 days for operations and security. Logs never contain passwords, session tokens or file contents.
- Usage counts: page views per day and per page, without IP addresses or cookies.
Cookies
We use a session cookie to keep you signed in, a short-lived cookie for confirmation messages, and a cookie that binds forms to your browser to prevent cross-site request forgery. None are used for advertising or cross-site tracking.
How we use data
To operate the Service, to send emails you request (verification, password reset, invitations), to respond to support requests, to detect abuse and to maintain security. We do not sell personal data and do not use your content to train models or for advertising.
Sharing
- Your team: users in your account see its vendors, change requests and evidence; approval notices, hold reminders and the monthly digest are emailed to them. Vendors never receive anything from the app.
- Processors: hosting and network providers (including Cloudflare), Stripe for payments through the InfiniHash App Store, and an email delivery provider for transactional email. Each processes data only to provide its service.
- Legal: we disclose data when required by law or to protect the rights and safety of users and the public.
Retention
Account data and content are kept while your account exists. Backups are kept for 14 days. Technical logs and error records are kept for 30 days. When an account is deleted, its vendors, change requests, files and events are removed within 30 days, after which backups containing them expire. Archived vendors stay readable until then.
Your rights
You can view and export your data from the application at any time. You can correct your account details on the account page. To delete your account, or to exercise access, correction or deletion rights under applicable law, email [email protected] from the account owner's address.
Security
See the Security page for the measures we take.
Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect their data.
Changes
We will announce material changes to this policy by email or in the application before they take effect.
Contact
InfiniHash LLC · [email protected]