Privacy Policy
Last updated: September 11, 2026
This policy explains what data MCR System collects, how it is used, and who it is shared with.
1. Data we collect
When you use the Service, we collect:
- Signup data: name, email, password (hashed, never stored in plain text), and company name;
- Data you enter: clients, estimates, invoices, catalog items, scheduled jobs, job expenses, and notes related to your business;
- Receipt files (Business plan): photos or PDFs you upload as proof of a job expense, stored in a private file bucket. They are never publicly listable — access is only through a link generated for you at the moment you view the expense, which expires shortly after;
- Usage data: when a document is opened, viewed, or approved by your client through the public portal (to power notifications and automatic reminders);
- Support requests: the "Chat with Sophia" widget is a guided, button-based menu (not an AI chatbot — no conversation text is sent to any AI provider). If you use its "talk to a real person" option, we store the name, email, phone (if provided), and message you submit so our team can follow up;
- Payment data: processed directly by Stripe — we do not store card numbers or sensitive payment data on our servers.
2. How we use the data
We use the data we collect to:
- Operate the Service's features (create/send documents, schedule jobs, process payments);
- Generate an AI-assisted first draft of an estimate when you choose to describe a job in your own words (the description you type, along with your catalog's item names, is sent to our AI provider to produce that draft — see section 3);
- Send transactional emails (account confirmation, password reset, follow-up reminders when enabled by you);
- Prevent fraud and abuse (e.g. login attempt limits, bot verification on public forms);
- Monitor and fix errors, to keep the Service reliable;
- Improve the Service based on how it's used.
We do not sell personal data to third parties.
3. Who we share data with
We use the following service providers, which process data on our behalf:
- Supabase — database, authentication, and file storage (including uploaded receipt photos/PDFs on the Business plan);
- Vercel — application hosting;
- Stripe — subscription processing and payments received from your clients;
- Resend — sending transactional emails;
- Google (Gemini API) — only when you use the AI-assisted estimate feature: processes the job description you type and your catalog's item names to generate a structured draft;
- Cloudflare (Turnstile) — verifies that login, signup, and public portal actions come from a human, not a bot;
- Sentry — error monitoring, so we can detect and fix problems in the Service; session recording is turned off.
Each of these providers has its own privacy policy and is contractually obligated to protect the data it processes.
4. Data about your own clients (third parties)
When you add one of your clients to the Service (name, email, phone, address), that data is stored to enable sending estimates/invoices and to run the public portal. You are the "controller" of that data with respect to your own clients; we act as the technical processor of the infrastructure.
5. Cookies
We use only essential session cookies (authentication), needed to keep you logged in. We do not use tracking or third-party advertising cookies.
6. Data retention
We keep your data for as long as your account is active. Deleted records (clients, items, jobs, estimates, invoices, job expenses) are marked as removed and disappear from listings, but the underlying record — and, for a deleted job expense, its receipt file — is kept, for example so we can help you recover something deleted by mistake. If you need a specific record permanently erased, contact us at the email below and we'll process that request. Closing your account entirely removes your data outright, with no recovery window.
7. Your rights
You can request access to, correction of, or deletion of your data at any time by contacting the email below. Billing records may need to be kept for legal/tax obligations even after an account is closed.
8. Security
We use per-organization access control (each company only sees its own data), hashed passwords, login attempt limits, and encrypted connections (HTTPS) throughout the application.
9. Changes
We may update this policy from time to time. Significant changes will be communicated by email or a notice within the Service.
10. Contact
Privacy questions: mcrsystem.suport@gmail.com.
Questions about this document? Email mcrsystem.suport@gmail.com.