Website privacy
Privacy Policy
Last updated: August 13, 2026
This Privacy Policy explains how Marginr collects, uses, stores, and protects information when you use marginr.com, the free margin check, and Marginr early-access communications.
Data we hold
Marginr holds only the information needed to provide the check, deliver requested resources, operate paid services, and keep the service secure:
- Your name and work email address, if you request results, a resource, an audit, or founding access;
- The business-only statement lines you review or enter in the free margin check, including vendor or lender names, amounts, cadence, merchant totals, owner recognition and duplicate decisions, its indicative result, and your practice-size range;
- Limited first-party service events: the form step reached or completed, anonymous page engagement and active-time totals, result and offer views, resource requests and confirmed resource-access clicks, checkout status, and purchases;
- Any information you voluntarily provide in a form, email, or direct communication;
- Your practice or business information, where you choose to provide it;
- Business financial files you submit for a paid audit, such as a P&L, fee schedule, A/R aging report or loan statement.
A random session identifier connects form-step events during one unfinished check. That identifier is not stored on the submitted assessment or lead and cannot be used by the owner dashboard to reconcile step activity with your name, email, answers, or financial figures. Anonymous page-engagement events carry only a controlled page label and rounded active time; they do not carry a form session, result token, account identifier, URL parameters, IP address, or user-agent string. Marginr does not set an analytics cookie.
For abuse prevention, the application converts the network address supplied by Cloudflare into a salted, route-specific one-way hash used in short rate-limit buckets. It does not store the raw address in the funnel database, and those buckets are automatically trimmed after about 24 hours.
A draft of your reviewed or manually entered answers stays in session storage in your browser until you submit the completed check. Selected file bytes stay only in the active browser page while the upload is prepared; they are not placed in session storage. The submitted answers are stored separately in the secure assessment record and are not sent to the email or analytics provider. The database trims anonymous page-engagement and landing-click events after 13 months, and unlinked form sessions after 30 days, as new funnel events are accepted.
Free-check result links expire after 30 days. Exact assessment answers remain linked to the lead for up to 12 months so Marginr can provide and support the service, improve the evidence rules, and resolve questions. After 12 months, an automated retention job replaces the assessment with a research snapshot that removes direct identifiers, strips free-text equipment names, and converts exact figures into broad ranges. The de-identified snapshot is deleted three years later.
Lead, order, consent, and service records are kept only as long as reasonably necessary to provide the service, meet legal or accounting duties, resolve disputes, or maintain security. You can request access, correction, or deletion by contacting paulmatthieu@marginr.com.
How we use assessment answers
Marginr keeps the exact business figures you submit so it can calculate your private result, preserve the result link, deliver a requested service, and improve the calculation and evidence rules. We do not sell or rent those answers, use them for unrelated advertising, or provide an identifiable assessment to data brokers.
Raw assessment answers stay in Marginr's assessment database and are not included in Resend Contact properties, marketing events, Stripe metadata, or public analytics. The Cloudflare Access-protected owner dashboard can show reviewed assessment values in an expanded assessment detail view so Marginr can support the result; vendor descriptors and model confidence metadata are not displayed in aggregate funnel reporting. Service providers may process limited data only to host the service, extract statement lines, deliver requested email, protect access, or process payment.
If assessment information is used for research, Marginr removes direct identifiers such as names and email addresses, removes free-text labels, limits or rounds combinations that could identify a practice, and reviews any published output for re-identification risk. Marginr will not publish an identifiable client case or attribute a result to a named practice without that client's explicit permission.
Data you must not submit
Marginr is not designed to collect patient information, health information, medical records, dental treatment details, or protected health information. Please do not submit such information through any form, email, or early-access request.
We do not sell or rent your personal information or assessment answers. At the time this policy is published, Marginr does not use advertising tracking cookies or ad-tracking pixels. Automated statement extraction is described separately below because the processor's current retention and data-use controls also apply.
If you provide your work email, we use it to deliver what you requested and to communicate about a purchase or service. These operational messages are necessary to fulfil your request.
Providing your email does not automatically subscribe you to marketing. Optional research and offer emails are sent only when you tick the consent box. Every marketing email carries an unsubscribe link, and you can withdraw consent at any time.
The separate “save and email me one resume link” option sends one requested recovery message immediately. It is unchecked by default and does not subscribe you to marketing. Merely typing a name or email does not trigger recovery or marketing email.
Measurement and decisions
Marginr uses the practice-size range and derived result labels to choose the resource, offer, and email journey shown to you. The decision rule and its version are stored with the assessment so the route can be explained and audited. The current rule offers the smaller Desk Read to a single-location practice and the Full Margin Audit to multi-location and group practices.
First-party step and anonymous active-time totals are used to understand where the check is difficult, which pages are useful, and whether requested resources and offers are reached. Marginr does not treat a link preview by an email security scanner as a resource access: that event is recorded only after a person confirms on an intermediate page. It records access to the resource, not proof that a file finished downloading or was read.
An owner dashboard shows aggregate funnel counts and limited lead-routing details. Its expanded assessment view can display the reviewed business values needed to support a result. The dashboard and its APIs are protected by Cloudflare Access.
Service providers and security
Marginr uses service providers to host the website and database, extract statement lines, deliver email, and process payments. At launch these are expected to include Cloudflare, Mistral AI, Resend, Stripe, and GitHub. They process limited information on Marginr’s behalf under their own contractual and privacy terms. Resend receives contact details, consent state, controlled routing labels, and the expiring private result link needed in requested or consented email, but not raw assessment answers or collections figures.
When you choose upload, Marginr transmits the selected PDF contents or decoded CSV text to Mistral AI, a company based in France, for OCR and structured extraction. Marginr processes the response in request memory and does not save the original file to disk or D1. Mistral's current Privacy Policy, Data Processing Addendum, Commercial Terms, and privacy controls documentation govern that processing. The published privacy policy states that standard API inputs and outputs may be retained for a rolling 30 days for abuse monitoring unless zero data retention is enabled. Before opening the beta, Marginr must verify the production account's training controls and zero-data-retention status. If you do not want a file sent to the extraction processor, use manual entry.
We use access controls, encrypted connections, secret-key separation, signed payment notifications, input validation, rate limits, and expiring result links. No internet service can promise absolute security. If we become aware of a material incident, we will assess and handle it as required by applicable law.
Payments
Payments are processed by Stripe. Marginr does not receive or store your full card number. Stripe processes payment and transaction information under its own privacy terms, while Marginr receives the customer, order, amount, and payment-status information needed to fulfil the service, issue receipts, and handle refunds.
Do not place patient information in checkout fields or paid-service files. Business files submitted for an audit are used only to deliver that service and handle related support, legal and accounting obligations.
Contact
For privacy questions or requests, including access, correction, or deletion of your information, contact:
If you are in the European Union and believe your rights have not been respected, you may also contact your local data protection authority. In France, this is the CNIL. This policy should be reviewed before launch if Marginr’s company identity, processors, international transfers, or retention practices change.