Margin One
Privacy Policy
How Margin One and M1COS collect, use, and protect your information
Privacy Policy
LEGAL NOTICE: This Privacy Policy is provided for informational purposes and should be reviewed by qualified legal counsel before reliance in production or contractual settings.
Effective Date: June 9, 2026
Last Updated: June 9, 2026
────────────────────────────────────────────────────────
1. WHO WE ARE AND SCOPE
────────────────────────────────────────────────────────
Margin One Consulting ("Margin One," "we," "us," or "our") provides operational intelligence consulting and the Margin One Client Operating System ("M1COS," pronounced "Me-Kos") to home service contractors in the HVAC, plumbing, and electrical trades.
This Privacy Policy describes how we collect, use, disclose, and protect information when you:
• Visit our public website at https://www.margin.one (the "Site");
• Submit inquiries through contact, demo, or consultation forms;
• Create or use an account on the M1COS platform, client portal, or related admin tools (collectively, the "Platform");
• Participate in a consulting engagement with Margin One; or
• Otherwise interact with us in a business capacity.
This policy applies to business-to-business ("B2B") relationships. It covers visitors, prospective clients, authorized users of customer organizations ("Tenants"), and individuals who contact us on behalf of a company. It does not apply to third-party websites, services, or integrations that we do not control, even when linked from the Site or Platform.
If you access M1COS on behalf of a Tenant, your organization may have its own policies and agreements that also apply. Where a written Master Services Agreement, subscription order, or data processing addendum ("DPA") between Margin One and your organization conflicts with this Privacy Policy, that agreement controls for the parties to it.
This Privacy Policy is incorporated by reference into our Terms of Service (https://www.margin.one/terms). It does not, by itself, create contractual rights beyond those set forth in our Terms or a separate written agreement with Margin One.
────────────────────────────────────────────────────────
2. INFORMATION WE COLLECT
────────────────────────────────────────────────────────
We collect information in the following categories, depending on how you interact with us.
A. Account and Identity Information
When you register for or access the Platform, we collect information such as your name, business email address, password (stored in hashed form through our authentication provider), profile details (including optional avatar image), role assignments (for example, platform administrator, tenant administrator, or client user), and tenant or organization affiliation.
B. Business and Client Data ("Tenant Data")
Tenants and authorized users may upload, connect, or generate business information within M1COS, including but not limited to:
• Company and organizational profile information;
• KPIs, goals, scorecards, action plans, and meeting notes;
• Financial, marketing, sales, and operational metrics;
• Documents, dashboards, embedded reports, and portal content;
• Integration configuration and sync metadata;
• Onboarding checklists, tasks, and notifications.
Tenant Data may include personal information about your employees, customers, or vendors that you choose to store in the Platform. Margin One processes Tenant Data on behalf of and under the direction of the applicable Tenant.
C. Website and Communication Information
When you use our Site or contact us, we may collect:
• Contact form submissions (name, email, company, message, and form intent such as demo or consultation requests);
• Email and other correspondence with our team;
• Information you provide when scheduling a strategy session or requesting a platform demo.
D. Usage, Device, and Log Information
We automatically collect certain technical information when you use the Site or Platform, such as:
• IP address, browser type, device identifiers, and operating system;
• Pages viewed, features used, timestamps, and referring URLs;
• Authentication events, API requests, and error logs;
• Audit and activity records related to administrative actions within the Platform.
E. Cookies and Similar Technologies
We use cookies and similar technologies for essential Platform functions, including session management and tenant context (for example, remembering your active tenant selection). Our public Site may also use analytics technologies when configured by Margin One administrators, such as Google Tag Manager or Google Analytics measurement IDs stored in system settings. You can control cookies through your browser settings; disabling certain cookies may limit Platform functionality.
F. Integration and Third-Party Source Data
When a Tenant connects third-party services to M1COS, we may receive data from or about those services, including OAuth tokens, account identifiers, sync logs, and business metrics pulled from connected systems. Integrations available in the Platform include, without limitation:
• QuickBooks Online (Intuit)
• Housecall Pro
• Google Ads, Google Analytics, Google Search Console, and Google Local Services Ads
• Meta (Facebook) Ads
• Yelp
• Looker Studio and other embedded analytics/reporting tools
• n8n workflow automation for lead capture, email/SMS routing, report refresh, and KPI sync
The categories of data received through integrations depend on the permissions granted by the Tenant and the third party's own policies.
G. Payment and Billing Information
If and when billing features are enabled, payment information may be processed by our payment processor(s). Margin One does not intend to store full payment card numbers on its own systems.
────────────────────────────────────────────────────────
3. HOW WE USE INFORMATION
────────────────────────────────────────────────────────
We use the information described above for the following purposes:
• Providing, operating, maintaining, and improving the Site, Platform, and consulting services;
• Authenticating users, enforcing role-based access, and maintaining multi-tenant isolation;
• Configuring, executing, and monitoring third-party integrations at a Tenant's direction;
• Displaying dashboards, reports, KPIs, goals, documents, and other Tenant-configured content;
• Responding to inquiries, demo requests, and consultation scheduling;
• Sending service-related communications, security notices, and operational updates;
• Analyzing aggregated or de-identified usage to improve performance, reliability, and product design;
• Detecting, preventing, and addressing fraud, abuse, security incidents, and technical issues;
• Complying with legal obligations and enforcing our Terms of Service and agreements;
• Creating and maintaining audit logs and integration sync logs for security and troubleshooting.
We do not sell personal information. We do not use Tenant Data to build advertising profiles for unrelated third parties.
────────────────────────────────────────────────────────
4. LEGAL BASES AND PURPOSES (WHERE APPLICABLE)
────────────────────────────────────────────────────────
For users in jurisdictions that require a legal basis for processing (including certain U.S. state laws and, where applicable, international frameworks), we rely on one or more of the following, depending on context:
• Performance of a contract — to provide the Platform and consulting services you or your organization request;
• Legitimate interests — to secure our systems, improve our services, communicate with business contacts, and operate a B2B SaaS platform, balanced against your rights;
• Consent — where required for optional analytics, marketing communications, or certain integration connections;
• Legal obligation — to comply with applicable law, regulation, legal process, or enforceable governmental request.
Tenants are responsible for establishing an appropriate legal basis for personal information they upload or sync into M1COS about their own employees, customers, or other individuals.
────────────────────────────────────────────────────────
5. HOW WE SHARE INFORMATION
────────────────────────────────────────────────────────
We share information only as described below.
A. Service Providers and Subprocessors
We use trusted vendors to host, secure, and operate our services. These providers process information on our behalf under contractual obligations appropriate to their role. Current categories of subprocessors include:
• Supabase — authentication, PostgreSQL database, file storage, and row-level security infrastructure;
• Vercel — application hosting, deployment, and edge delivery;
• n8n — workflow automation and webhook orchestration for lead capture, notifications, scheduled reporting, and integration callbacks;
• Intuit (QuickBooks Online) — accounting data when connected by a Tenant;
• Housecall Pro — field service and CRM data when connected by a Tenant;
• Google (Ads, Analytics, Search Console, Local Services Ads, Looker Studio) — advertising, analytics, search, and reporting data when connected by a Tenant;
• Meta Platforms — advertising data when connected by a Tenant;
• Yelp — business and advertising data when connected by a Tenant;
• Email and SMS delivery providers — when configured through n8n or related automation for lead routing.
This list may evolve as we add or replace vendors. Enterprise customers may request subprocessor information applicable to their engagement.
B. At Tenant Direction
We disclose Tenant Data to third-party integrations when authorized by the Tenant's administrators. Data shared with those third parties is also subject to their privacy policies and terms.
C. Within Margin One
Authorized Margin One personnel and platform administrators may access information as needed to provide support, maintain the Platform, investigate security issues, fulfill consulting deliverables, and manage CMS content. Access is limited by role and business need.
D. Business Transfers
If Margin One is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.
E. Legal and Safety
We may disclose information if we believe in good faith that disclosure is necessary to comply with law, respond to lawful requests, protect the rights and safety of Margin One, our users, or others, or investigate fraud or security issues.
We do not rent or sell personal information to data brokers for their independent marketing purposes.
────────────────────────────────────────────────────────
6. MULTI-TENANT DATA HANDLING
────────────────────────────────────────────────────────
M1COS is a multi-tenant platform designed for strict organizational separation.
• Each Tenant's data is logically segregated in our database layer using tenant identifiers and Row Level Security ("RLS") policies enforced by Supabase/PostgreSQL;
• Tenant administrators control which users within their organization can access Tenant Data;
• Platform administrators may access Tenant Data when necessary to operate, secure, and support the Platform, troubleshoot integrations, or fulfill contractual obligations — not for unrelated commercial exploitation;
• Tenants are responsible for the accuracy, legality, and permissions associated with data they upload or connect to M1COS, including data about their employees and customers.
Margin One does not use Tenant Data to compete with Tenants or to sell Tenant Data to third parties.
────────────────────────────────────────────────────────
7. DATA RETENTION
────────────────────────────────────────────────────────
We retain information for as long as reasonably necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law.
• Account and profile data — retained while the account is active and for a reasonable period thereafter to resolve disputes, enforce agreements, and comply with legal obligations;
• Tenant Data — retained according to the Tenant's subscription or agreement and deleted or returned upon termination, subject to backup cycles and legal holds;
• Contact form and lead data — retained as needed for sales, consulting follow-up, and recordkeeping;
• Logs and audit records — retained for security, troubleshooting, and compliance for a limited period consistent with operational needs;
• Integration tokens and sync logs — retained while an integration is active and for a limited period after disconnection for security and support purposes.
Backups may persist for a limited time after deletion from active systems. De-identified or aggregated data that cannot reasonably identify an individual may be retained longer.
────────────────────────────────────────────────────────
8. SECURITY
────────────────────────────────────────────────────────
We implement administrative, technical, and organizational measures designed to protect information, including:
• Encrypted transport (HTTPS/TLS) for data in transit;
• Authentication through Supabase Auth with server-side session handling;
• Role-based access control and tenant-scoped database policies (RLS);
• Restricted access to production systems and service-role credentials kept server-side only;
• Webhook authentication for inbound integration callbacks;
• Audit logging for certain administrative actions.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and for configuring integrations and user permissions appropriately within your organization.
────────────────────────────────────────────────────────
9. YOUR RIGHTS AND CHOICES
────────────────────────────────────────────────────────
Depending on your location and relationship with Margin One, you may have certain rights regarding personal information, which may include:
• Access — requesting confirmation of whether we process your personal information and obtaining a copy;
• Correction — requesting correction of inaccurate personal information;
• Deletion — requesting deletion of personal information, subject to legal exceptions;
• Opt-out of certain processing — including, where applicable, opt-out of "sale" or "sharing" as defined under California law (Margin One does not sell personal information as defined by the CCPA/CPRA);
• Limit use of sensitive personal information — where applicable under state law;
• Data portability — where technically feasible and required by law.
California residents (CCPA/CPRA): In the preceding twelve months, we may have collected the categories of information described in Section 2 for the business purposes in Section 3. We do not sell personal information. We may disclose information to service providers and integration partners as described in Section 5. To exercise California privacy rights, contact us using the information in Section 15.
If you are an employee or user of a Tenant organization, many requests relating to Tenant Data should be directed to your organization's administrator, who controls the primary copy of that data in M1COS. We will assist Tenants in responding to such requests as required by applicable law and contract.
We will verify requests to the extent required by law before responding. Authorized agents may submit requests on your behalf where permitted.
────────────────────────────────────────────────────────
10. CHILDREN'S PRIVACY
────────────────────────────────────────────────────────
The Site and Platform are intended for business use and are not directed to children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will take appropriate steps to delete it.
────────────────────────────────────────────────────────
11. INTERNATIONAL TRANSFERS
────────────────────────────────────────────────────────
Margin One is based in the United States and our primary service providers (including Supabase and Vercel) may process information in the United States and other countries. If you access our services from outside the United States, you acknowledge that your information may be transferred to, stored in, and processed in jurisdictions that may not provide the same level of data protection as your home country. Where required, we use appropriate safeguards for cross-border transfers.
────────────────────────────────────────────────────────
12. THIRD-PARTY SERVICES AND INTEGRATIONS
────────────────────────────────────────────────────────
The Platform allows Tenants to connect third-party services. Margin One does not control and is not responsible for the privacy or security practices of those third parties. Their collection and use of information is governed by their own policies. You connect integrations at your own discretion and should review each provider's terms and permissions.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, MARGIN ONE DISCLAIMS LIABILITY FOR ACTS OR OMISSIONS OF THIRD-PARTY INTEGRATION PROVIDERS, INCLUDING DATA BREACHES, SERVICE OUTAGES, INACCURATE DATA, OR CHANGES TO API TERMS — EXCEPT TO THE EXTENT SUCH LIABILITY CANNOT BE DISCLAIMED UNDER APPLICABLE LAW OR IS EXPRESSLY ASSUMED IN A WRITTEN AGREEMENT WITH MARGIN ONE.
────────────────────────────────────────────────────────
13. USER CONTENT, COPYRIGHT, AND DMCA
────────────────────────────────────────────────────────
Tenants and users may upload documents, images, and other content to the Platform. You represent that you have the rights necessary to provide such content. If you believe content stored on our Platform infringes your copyright, send a notice to support@margin.one with:
• Identification of the copyrighted work;
• Identification of the material and its location within the Platform;
• Your contact information;
• A statement of good-faith belief that use is not authorized; and
• A statement, under penalty of perjury, that the information is accurate and you are authorized to act on behalf of the copyright owner.
We may remove or disable access to allegedly infringing material and terminate repeat infringers where appropriate.
────────────────────────────────────────────────────────
14. INDEMNITY AND MISUSE
────────────────────────────────────────────────────────
You agree to use the Site and Platform in compliance with applicable law and our Terms of Service. To the extent permitted by applicable law and your agreement with Margin One, you agree to indemnify and hold harmless Margin One and its officers, directors, employees, and agents from claims, damages, losses, and expenses (including reasonable attorneys' fees) arising from your misuse of the Platform, unauthorized access using your credentials, violation of third-party rights through content you submit, or connection of integrations without proper authority from your organization.
If you are accessing the Platform on behalf of a Tenant, indemnity obligations may be governed by your organization's agreement with Margin One.
────────────────────────────────────────────────────────
15. CHANGES TO THIS POLICY
────────────────────────────────────────────────────────
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or services. When we make material changes, we will post the updated policy on the Site with a revised "Last Updated" date and, where appropriate, provide additional notice. Continued use of the Site or Platform after the effective date of an update constitutes acknowledgment of the revised policy, subject to applicable law.
────────────────────────────────────────────────────────
16. CONTACT US
────────────────────────────────────────────────────────
For privacy questions, data subject requests, or security concerns:
Margin One Consulting
Email: support@margin.one
Website: https://www.margin.one/contact
Please include sufficient detail for us to identify your account or organization and understand your request. We aim to respond within a reasonable timeframe and as required by applicable law.
For enterprise agreements, DPAs, or subprocessor documentation, contact support@margin.one with the subject line "Privacy / Enterprise Inquiry."