MarginClean← Back

Legal

Privacy Policy

Last updated: July 28, 2026

This notice describes MarginClean's current data practices. It is not legal advice and does not replace the cleaning business's own privacy notice or compliance obligations.

1. Scope and who we are

MarginClean (“MarginClean,” “we,” “us,” or “our”) provides managed online estimate, service-request, payment-authorization, and owner dashboard software for residential cleaning businesses.

This policy covers information from cleaning-business leads and subscribers, as well as end customers who submit a request through a MarginClean-powered request site. The cleaning business controls the cleaning relationship and may have its own privacy policy. For questions about a specific cleaning, contact that business directly.

2. Information we process

The information depends on how you use the service:

  • Cleaning-business onboarding: business and contact names, phone numbers, email addresses, service area, ZIP codes, pricing, add-ons, branding, optional license or credential text, notification email, selected plan, and intake responses.
  • Platform subscription: billing email, Stripe customer and subscription identifiers, payment status, plan, and transaction records. Stripe receives the underlying payment-card details.
  • End-customer contact and address: name, email, phone, street address, city, state, ZIP code, and notes supplied with a request.
  • Request details: requested service, frequency, add-ons, bedrooms, bathrooms, approximate square footage, estimate, preferred date, arrival window, confirmation number, request status, and timestamps.
  • Optional request-recovery data: when an end customer separately chooses an email reminder, we may preserve the request fields entered so far, the current step, a server-calculated estimate, consent and unsubscribe status, secure-link metadata, and recovery-message history. We do not store card numbers, CVCs, or Stripe card-entry fields in a recovery draft.
  • Card-authorization identifiers: Stripe Customer, SetupIntent, and PaymentMethod identifiers, card-on-file status, authorization metadata, and resulting PaymentIntent identifiers or status. MarginClean does not receive or store the complete card number or CVC in its booking database.
  • Account and support data: owner login email, authentication user identifier, tenant assignment, configurable notification settings, support messages, and other information sent to us.
  • Technical and security data: hosting and infrastructure providers may process IP address, device/browser information, request metadata, cookies, and logs needed to deliver, secure, and troubleshoot the service.
  • First-party product events: an anonymous browser-session identifier, an allowlisted event name, page path, limited non-contact properties, and timestamp used to understand the estimate and request funnel. These events are designed not to include names, email addresses, phone numbers, street addresses, notes, card data, or recovery tokens.

Free-text notes may contain information the sender chooses to provide. Do not include unnecessary sensitive information in a booking note.

3. How we use information

  • Validate intake, calculate estimates, and configure sites.
  • Create and preserve service requests for the cleaning business.
  • Authorize a card for possible off-session charging after a completed cleaning and process an owner-initiated charge.
  • Operate tenant-scoped dashboards and owner authentication.
  • Send request receipts, owner alerts, confirmation or cancellation updates, review requests, receipts, onboarding, support, and other operational messages.
  • If separately requested, preserve an unfinished request and send a limited operational email with a secure link to resume it.
  • Measure aggregate product usage and funnel performance without placing contact, address, note, payment, or recovery-token data in product-event properties.
  • Deliver data to a webhook or downstream system selected by the cleaning business.
  • Process MarginClean subscriptions and manage the service.
  • Prevent abuse, investigate failures, enforce agreements, and comply with applicable obligations.

4. Payment handling

Stripe hosts the card-entry fields and processes payment credentials. A cleaning request uses a SetupIntent to authorize a reusable payment method; submitting the request does not itself create a cleaning charge. If the business confirms and completes the service, an authenticated owner can initiate an off-session charge through Stripe.

Stripe's handling of payment data is governed by its own terms and privacy policy.

5. Providers and recipients

We use providers to operate the service, including:

  • Stripe for platform subscriptions, card authorization, and cleaning-service payments.
  • Supabase for booking data, tenant mappings, settings, and owner authentication.
  • Resend for transactional email delivery.
  • Vercel for hosting, request processing, and infrastructure logs.
  • Business-selected webhooks and integrations, which may include Zapier, Make, n8n, a CRM, or a spreadsheet. The cleaning business chooses and is responsible for those destinations.

We may also disclose information when reasonably necessary to comply with law, protect the service or people, investigate fraud, or complete a business transaction subject to appropriate safeguards. MarginClean does not currently sell personal information for money or operate an advertising-data business.

6. Email, SMS, and marketing choices

MarginClean sends operational emails related to requests, account access, status changes, payment, onboarding, and support. An unfinished-request reminder is sent only after the end customer separately opts in to that reminder. The consent is optional and is not required to submit a request. A cleaning business may separately use exported data or optional templates for follow-up marketing. That business is responsible for obtaining any required consent, identifying itself, and honoring unsubscribe, STOP, and other opt-out requests across its providers and downstream systems.

MarginClean does not currently provide a built-in SMS sender or a universal marketing-suppression list. Recovery emails include an unsubscribe path, and a recovery unsubscribe suppresses later recovery reminders for that cleaning-business request flow. For other communications from a cleaning business, use the unsubscribe method in the message or contact the business directly.

7. Retention and deletion

We retain information for as long as reasonably needed to operate the service, maintain transaction and security records, resolve disputes, and meet applicable obligations. Stripe, Supabase, Resend, Vercel, and business-selected integrations apply their own retention practices.

The current product does not automatically delete booking rows on a fixed schedule. Cleaning businesses should define and operate a retention process appropriate to their customers and locations. A deletion request may be limited by backups, fraud prevention, payment records, disputes, or legal retention requirements.

An unfinished recovery draft and its resume and unsubscribe capabilities expire on the cleaning business's configured schedule, from 1 to 30 days (7 days by default). Expiry prevents later recovery access and delivery. A daily scheduled process deletes expired recovery contact, progress, consent, and delivery rows in bounded batches. If a run reaches its batch cap or fails, remaining expired rows are removed by a later successful run. Unsubscribing stops later recovery reminders; it does not shorten the configured retention window.

Before deleting an expired recovery draft, we add only its non-identifying outcome to tenant-level totals: abandoned and recovered request counts, abandoned estimated value, and recovered estimated value. Those aggregate totals do not retain the customer's name, contact details, address, request fields, consent evidence, message history, booking identifier, or recovery capabilities.

First-party product events are assigned an expiration 13 months after creation. A scheduled retention process removes events after that expiration. Separate security, hosting, transaction, consent, and operational records may follow different retention periods described in this policy or required by the relevant provider or obligation.

8. Security

We use access controls, tenant-scoped database policies, server-only credentials, request validation, and payment providers designed to reduce risk. No system or transmission is completely secure. Cleaning businesses are responsible for protecting their accounts, limiting webhook access, and promptly reporting suspected misuse.

Recovery links are tenant-bound and expire. Server records keep only a verifier for the resume capability rather than a reusable plain-text token. A resumed estimate is recalculated from the current pricing configuration, and the business still confirms service timing.

9. Requests and privacy choices

Depending on where you live, you may be able to request access, correction, deletion, or other treatment of personal information. We may need to verify your identity and determine whether MarginClean or the cleaning business is responsible for the relevant data.

For a booking or cleaning-service record, contact the cleaning business first. You can also email hello@marginclean.com. We will route or respond to the request as appropriate.

10. Cookies and third-party elements

The owner dashboard uses cookies or similar storage for authentication and session continuity. Stripe and hosting providers may use necessary technologies in their embedded components or infrastructure. MarginClean does not currently run third-party behavioral advertising on the booking flow.

The booking flow may use short-lived browser storage for a same-device draft and request-safety identifiers. Before recovery consent, the local fallback omits the entered name, email, phone, street address, city, preferred date, and notes. First-party product measurement uses a random browser-session identifier and does not use third-party advertising cookies.

11. Children

MarginClean is intended for cleaning businesses and adults requesting household services, not for children to use independently. Contact us if you believe a child submitted personal information without appropriate involvement.

12. Changes and contact

We may update this policy as the product or our practices change. The date above shows the latest revision. We will provide additional notice when required or appropriate for a material change.

Privacy questions can be sent to hello@marginclean.com.