Pricing and margin data is sensitive. This policy explains, in plain language, what MarginShock collects, why, and what we will and won’t do with it.
What we collect
- Account information: your name, email address, whether you’ve confirmed it, and a hashed (never plain-text) password.
- Business profile: an optional business name, your industry, and your benchmark-participation setting.
- Calculator inputs and results: costs, usage, job counts, prices, and margins you enter, whether or not you are logged in.
- Pricing adjustments and outcomes: surcharges, customer notices you generate, and customer-response and revenue/margin results you choose to record.
- Launch waitlist: if you ask to be notified when a paid plan launches, your email address, which plan, and your optional answer about the feature you want most. We use it only to send a confirmation and one launch email, and to decide what to build first.
- Usage analytics: which pages are viewed and which steps are completed (for example “calculator completed”), tied to a random ID stored in a first-party cookie (
ms_aid). We don’t store IP addresses in analytics and don’t link analytics to your account. If your browser sends Do Not Track or Global Privacy Control, we don’t collect analytics at all. - Abuse-prevention data: to rate-limit requests we keep short-lived counters keyed by a one-way hash of your IP address or email (not the raw values), deleted within about two days. Hosting providers also keep standard server logs for security.
How we use it
- To run the product: calculate results, save your history, and generate customer notices.
- To build aggregated, anonymized industry benchmarks — for example, typical surcharge levels and customer acceptance rates by industry and region.
- To understand which parts of the product are useful, and to improve them.
- To keep the service secure and stop bots and abuse.
Benchmarks and anonymized data
Calculations made without an account are stored without any link to a person or business. When benchmarks are published, they will show aggregates only, and only for groups large enough that no individual business can be identified. We never publish or show your individual pricing, margins, or customer results to anyone else.
You can turn benchmark participation off at any time in Dashboard → Settings. When it’s off, none of your business’s data — past or future — is included in benchmarks.
What we don’t do
- We don’t sell your personal information or individual business data.
- We don’t show your numbers to other users.
- We don’t collect your customers’ names or contact details.
- We don’t use third-party advertising or tracking cookies.
Service providers
We use a small number of providers to run MarginShock:
- DigitalOcean — application hosting and database.
- Anthropic — writes customer notice drafts. When you generate a notice, the relevant details (industry, cost type, percentage change, surcharge amount, and business name if provided) are sent to Anthropic’s API.
- Cloudflare Turnstile — checks that forms are submitted by a person, not a bot. Cloudflare processes technical signals from your browser for this check.
- Resend — delivers account emails (email confirmation and password reset) and waitlist emails.
Security
Passwords are hashed with bcrypt, email and reset links are single-use and expire, all traffic is encrypted in transit over HTTPS, database connections are encrypted and certificate-verified, and access to the database is restricted. No system is perfectly secure, but we take reasonable measures to protect your data.
Your choices
- Benchmark participation: on/off in Settings.
- Waitlist emails: every waitlist email has a one-click unsubscribe link. Deleting your account also removes you from the waitlist.
- Delete your account: self-serve in Settings. Your login, business profile, saved policies, and notice drafts are deleted immediately. If benchmark participation is on, your calculations and outcomes are kept only as anonymous numbers with no link to you; if it’s off, they’re deleted too.
- For access, correction, or export requests, contact [email protected].
Changes
If we make material changes to this policy, we’ll update the date above and, for significant changes, notify account holders by email.
Contact
Questions about privacy? Reach us at [email protected].