Privacy Policy — Rateproof LLC
Effective date: 23 September 2026 | Version: 1.0
This Privacy Policy describes how Rateproof LLC ("Rateproof," "we," "us") collects, uses, and protects information through the Rateproof platform at rateproof.ai.
1. Who We Are
Rateproof LLC is a California limited liability company. For privacy inquiries or to exercise your rights: privacy@rateproof.ai.
2. What We Collect
We collect three categories of information, described below. When you submit rate data, you also provide an email address; the two are stored in separate systems with no key joining them.
2.1 Submission data. Rate and market data you submit through the web form. Your email address is collected at the time of submission but stored separately (see Section 2.2); the submission record itself contains no name, email address, or other identifier, and no key joins a submission to any individual. The form includes free-text fields; Rateproof does not solicit identifying information in the rate and market data fields, but cannot prevent a submitter from volunteering it in free text. In the ordinary course, submission data does not contain personal information because no identifier is stored in the submission record by design. If a submitter voluntarily includes identifying information in a free-text response, that information may constitute personal information under applicable law.
2.2 Email address (rate submission). An email address is required with each rate submission. It is stored in a separate system for the limited purposes described in Section 3. The system is designed so that no key joins your email address to any submission. Some earlier submissions were made when email was optional and may not include an email address.
2.3 Market-waitlist data. If you join the market waitlist, we collect your specialty (skill), home country, and client country, and optionally an email address. Waitlist data is stored separately from submission data; no key joins a waitlist entry to any submission. The waitlist does not collect rate, margin, or challenge information, and no anonymity representation applies to it --- it is a contact-and-interest record, not a rate submission. If you provide an email address with a waitlist entry, it is used solely to notify you when your market's benchmark becomes available; the address is then deleted (see Section 6.3). After your address is deleted, we no longer hold any way to contact you, including about changes to this policy or the Terms of Service.
2.4 Cookies, analytics, and platform-level tracking. Rateproof does not install advertising cookies, behavioral-tracking tools, retargeting tools, analytics, or session-recording technologies of its own. No email sent by Rateproof contains tracking pixels, open-tracking, or click-tracking.
The hosting platform (Base44) operates built-in analytics on hosted sites, recording visit counts, unique visitors, visit duration, page traffic, visitor country, operating system, and referrer. Page URLs are recorded individually; on a private card page, the URL includes the access token that identifies that card. This analytics does not set cookies but writes a session identifier (`base44_analytics_session_id`) to browser Local Storage to associate page views with a browsing session. This is the platform's built-in tool, not Rateproof's; it is platform-operated and cannot be disabled or controlled by Rateproof. Page-view tracking operates separately within the platform and also cannot be disabled by Rateproof.
The platform also includes a session-recording capability. It is not currently enabled on Rateproof.
Rateproof does not install third-party tracking scripts, advertising pixels, or advertising-network cookies on the published site. The platform analytics uses browser Local Storage rather than cookies to maintain session state, as described above. The platform controls what technologies run on hosted sites; Rateproof monitors this but cannot guarantee the platform will not introduce additional technologies in the future.
For Base44's own privacy practices, see base44.com/privacy-policy.
3. How We Use It
3.1 Submission data. To aggregate, analyze, and produce benchmarks. To license aggregated data --- above the minimum cell size of 10 submissions per group --- to institutional buyers. To conduct research on rate trends in the freelance market. Submission data is used only in aggregate, never at the individual level.
3.2 Email address. For two purposes: (i) sending you benchmark results, and (ii) contacting you periodically to ask whether your rates still hold --- plus notices required by these documents or the Terms of Service (such as change-of-control notification or material policy changes). Your email address is never sold, never licensed, never joined to any aggregate or export, and never shared with any third party for their own purposes.
4. What We Do Not Collect or Do
- The submission record contains no name or other identifier. Email addresses are collected separately and stored in a different system with no joining key (see Section 2).
- We do not solicit identifying information in the rate and market data fields.
- We do not sell personal information. (CCPA/CPRA disclosure.)
- We do not share personal information with third parties for their own purposes.
- We do not sell or license individual-level submission data. Only aggregates above the minimum cell size are ever published, licensed, or made available.
- The system is designed so that no key joins an email address to a submission. We do not join email addresses to any aggregate or export.
- We do not join waitlist entries to submissions. The two are stored separately with no linking key.
- We do not retain waitlist email addresses after the market-open notification is sent.
- Rateproof does not install advertising cookies, behavioral-tracking tools, retargeting tools, or analytics of its own. The hosting platform operates built-in analytics as described in Section 2.4.
- We do not publish, display, or license any aggregate for a group with fewer than 10 submissions.
- We do not provide any institutional buyer with access to data not simultaneously available to submitters.
5. Service Providers
The platform is built on and hosted by Base44, operated by Wix.com Ltd. Base44 provides application hosting, data storage, and email delivery. Data processed through Base44 is governed by its Data Processing Agreement (available at base44.com/dpa), under which Base44 acts as a processor on our behalf: it does not sell or share personal data and does not use it beyond the purposes specified in our agreement.
5.1 Security certifications. Base44 maintains SOC 2 Type II and ISO 27001 certifications. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Base44 states that access to individual workspaces is enforced through row-level security at the database level.
5.2 Sub-processors. Base44's current sub-processors are those identified in the live Exhibit C of its Data Processing Agreement (base44.com/dpa); that page, not this policy, is the authoritative list. Rateproof's data is processed and stored in the United States. Sub-processor roles, locations, and any changes are governed by the DPA's sub-processor terms.
5.3 Deletion and backup retention. When an email address or other field value is cleared from a record, the prior value is overwritten in place. No version history of prior values is maintained on Rateproof's plan tier, and no application-level copy of the overwritten value is retained.
When a whole record is deleted, Rateproof uses the platform's permanent-deletion tools to remove it from the application immediately, without a recovery period.
Prior values --- whether from field-level clearing or record deletion --- may persist in infrastructure-level backups until rolled off on a rolling purge schedule. Specific backup retention intervals are not published for Rateproof's plan tier; Base44's Data Processing Agreement commits to deletion of backup copies after set intervals. Full account deletion is processed as a GDPR-compliant purge across Base44 and its sub-processors.
5.4 AI and machine learning. Base44's platform includes AI and machine-learning sub-processors (as listed in its DPA Exhibit C) for builder-side features. The platform is designed so that runtime application data is not routed to these sub-processors unless the application builder explicitly configures an opt-in integration. Rateproof has not configured any such integration.
Base44 uses data stored on its platform --- including customer data --- to develop and improve its own internal AI and machine-learning models. These are Base44's internal models; they are not third-party models. Base44 states that its models learn general patterns rather than storing retrievable copies, and that customer data is never exposed to others as structured data. However, Base44 does not guarantee that model outputs are unique; a theoretical possibility exists that elements of stored content could be reflected in AI-generated outputs seen by other users of the platform. Account access is isolated at the workspace level: no other Base44 customer can access Rateproof's application or data.
Opting out of internal-model training is available only on Base44's Enterprise plan. Rateproof does not currently operate on an Enterprise plan.
5.5 Google Workspace. Rateproof uses Google Workspace to host the info@ mailbox through which all outbound email is sent. Sent messages --- including confirmation emails that carry the recipient's email address alongside their card access link --- are retained in the mailbox's sent folder. Google processes data within Google Workspace under its Workspace data processing terms. For Google's privacy practices, see policies.google.com/privacy.
5.6 GoHighLevel. Rateproof uses GoHighLevel (GHL) as a people-ledger: a system of record for contact information. No sending domain is connected to GHL, and it is not used for automated or bulk sending of any kind. Every outbound message is hand-made, sent individually, and logged. GHL processes contact data only within this scope.
6. Retention
6.1 Submission data. Retained indefinitely. The submission record contains no identifier by design, and in the ordinary course submission data does not contain personal information. The dataset forms the benchmark, whose value depends on historical depth. Because submissions are not linked to any individual by design, individual deletion requests cannot be applied to them.
6.2 Email addresses (rate submission). Retained until you request deletion (Section 6.4). Addresses identified as permanently undeliverable may also be removed.
6.3 Market-waitlist data. If you provided an email address with a waitlist entry, that address is deleted promptly after your market-open notification is sent, or upon your deletion request (Section 6.4), whichever comes first. The address is held for that single purpose; once the notification is sent, it is not retained or converted to any other use. After the address is deleted, we no longer hold any way to contact you, including about changes to this policy or the Terms of Service. Non-email waitlist fields (skill, home country, client country) survive the deletion of the email address as anonymous demand-signal counts with no address attached; they do not individually identify you.
6.4 Deletion. When you request deletion of your email address, the address is overwritten in place within your record. No application-level copy of the prior value is retained: Rateproof's plan tier does not maintain version history, and the platform's recovery window holds only whole deleted records, not individually cleared field values. The overwritten value may persist in infrastructure-level backups until rolled off on the schedule described in Section 5.3. To request deletion: privacy@rateproof.ai.
7. Your Rights
7.1 All users, regardless of location. You may:
(i) Request deletion of your email address at any time (Section 6.4). (ii) Request confirmation of whether we hold an email address for you. (iii) Request correction of your email address.
The submission system is designed so that submissions are not linked to any individual. In the ordinary course, submission data cannot be individually accessed, corrected, or deleted because it contains no identifier connecting it to you. Waitlist entries that include an email address can be identified and deleted on request; non-email waitlist fields do not individually identify you.
7.2 California residents (CCPA/CPRA). In addition to the rights above, California residents may:
(i) Request to know the categories of personal information collected and the purposes of collection. (ii) Request to know the categories of third parties with whom personal information is shared. (iii) Opt out of the sale or sharing of personal information (note: Rateproof does not sell personal information and does not install advertising-network tracking on the published site --- see Section 4). (iv) Request to limit the use of sensitive personal information (note: we do not collect sensitive personal information as defined by the CPRA). (v) Not be discriminated against for exercising any of these rights.
We will respond to verified requests within 45 days, with one 45-day extension if reasonably necessary and communicated to you. To exercise any right: privacy@rateproof.ai.
7.3 Note on submission and waitlist data. The submission record is designed to store data without identifiers. In the ordinary course, submission data does not constitute personal information under the CCPA, the CPRA, or comparable privacy laws because no identifier is stored in or linked to the submission record. If a submitter has voluntarily included identifying information in a free-text field, that submitter may contact us to discuss options for addressing it. The rights of access, correction, and deletion described in this section apply to your email address.
8. International Users
Rateproof serves freelancers internationally. If you are located outside the United States:
8.1 Transfer. Your email address --- required for rate submissions, optional for waitlist entries --- is transferred to and processed in the United States. By providing your email address, you consent to this transfer. The submission record contains no identifier; in the ordinary course, submission data is not personal data under applicable law. Waitlist entries that do not include an email address contain only market-interest data (skill, home country, client country) that does not individually identify you.
8.2 Universal rights. The rights described in Section 7.1 apply to you regardless of your location. You may request deletion of your email address, confirmation of what we hold, and correction --- on the same terms and timelines as any other user.
8.3 Local law. Rateproof does not currently maintain representatives or registrations in jurisdictions outside the United States. If your local law provides rights regarding your email address beyond those described in Section 7.1, contact us at privacy@rateproof.ai and we will work to honor your request consistent with our practices and the commitments described in these documents.
9. Cookies and Tracking Technologies
Rateproof does not install advertising cookies, behavioral-tracking tools, retargeting tools, analytics, or session-recording technologies of its own. No email sent by Rateproof contains tracking pixels, open-tracking, or click-tracking.
The hosting platform (Base44) operates built-in analytics on hosted sites. This analytics is platform-operated and cannot be disabled or controlled by Rateproof; the data it records is described in Section 2.4. Rateproof does not install third-party tracking scripts, advertising pixels, or advertising-network cookies on the published site. The platform analytics uses browser Local Storage rather than cookies to maintain session state (Section 2.4). The platform controls what technologies run on hosted sites; Rateproof monitors this but cannot guarantee the platform will not introduce additional technologies in the future. For Base44's own privacy practices, see base44.com/privacy-policy.
If Rateproof adds analytics or tracking capabilities in the future, this section will be updated before they are deployed, and the material-change notice described in Section 12 will apply.
10. Security
We maintain reasonable administrative, technical, and physical safeguards to protect the information we hold. Email addresses are stored in a system separate from the submission dataset, with no joining key between them by design. Waitlist data is also stored separately from submissions with no linking key. Access to stored email addresses is restricted to authorized personnel for the purposes described in this policy.
The platform infrastructure maintains SOC 2 Type II and ISO 27001 certifications, encrypts data at rest and in transit, and enforces row-level security at the database level (see Section 5).
No system is perfectly secure. We cannot guarantee the absolute security of your information, but we are committed to promptly addressing any incident that affects the information we hold.
11. Children
Rateproof is not directed to individuals under 18 years of age. We do not knowingly collect information from anyone under 18. If we learn that we have collected an email address from someone under 18, we will delete it promptly.
12. Changes to This Policy
This policy is versioned. The current version number and effective date are stated at the top of this page. Changes are published with a new version number and effective date and apply prospectively only.
If we make material changes, we will notify users with an email address on file --- whether provided with a rate submission or a waitlist entry --- by email. "Users with an email address on file" is evaluated at the time notice is due; Rateproof does not reconstruct previously cleared addresses to create a notification population. Promises in force at the time you provided your email address are not weakened retroactively.
13. Contact
For privacy inquiries, to exercise your rights, or to report a concern:
privacy@rateproof.ai
Rateproof LLC
2209 Irving Street, Unit 205
San Francisco, CA 94122
The promises this policy supports are stated in The Rateproof Covenant.