Privacy Policy
Effective date: August 4, 2026
What changed on August 4, 2026
- Corrected our cookies description: our marketing pages use the Meta Pixel for advertising measurement. We also narrowed where it runs — it no longer loads on booking, invoice, estimate, or client-website pages.
- Corrected our mobile-app description: the app does not access your device's location. The schedule map plots job addresses you enter.
- Removed an inaccurate statement about the National Do Not Call Registry, and clarified who the sender of text messages is.
- Added disclosures: address autocomplete (Geoapify), map providers (Google/Apple), invoice payments through Stripe, how we record consent, toll-free number verification, and a fuller description of our error monitoring.
- Rewrote the retention and deletion sections to describe exactly what happens, including what third parties retain.
Questions about a prior version: support@marathonsimplicity.com.
Who We Are & What This Covers
Marathon Simplicity LLC ("Marathon Simplicity", "we") is a CRM and communications platform based in Arlington, TX. We help trade businesses — HVAC, plumbing, electrical, roofing, landscaping, and similar — manage leads, appointments, invoices, and customer communications.
This policy covers everything we run:
- our marketing website and free trial signup,
- the client portal and our mobile app, used by the businesses that subscribe (each a "Business"), and
- the public pages we host on a Business's behalf — booking pages, single-page business websites, invoice payment pages, estimate approval pages, and job-status pages — used by that Business's own customers.
That last group matters for how to read this policy. When a Business stores its customers' information in Marathon Simplicity, that data belongs to the Business, and we process it on the Business's behalf to provide the service — we do not use it for our own purposes. If you are a customer of a business that uses Marathon Simplicity, your primary relationship is with that business; the sections below tell you what our platform does with your information along the way.
Information We Collect
From Businesses:
- Account and business information — company name, owner name, trade, city and state, phone, and email, provided at signup.
- Account credentials — your login email and a securely hashed password managed by Supabase Auth. Passwords are never stored in plain text.
- Billing information — your subscription plan and payment method (card or, where enabled, bank account via ACH), processed by Stripe. We never see or store full card or bank-account numbers.
- Toll-free number verification details — to register a texting number with carriers, we collect and submit to Twilio your business address, EIN or business registration number, website address, and a description and sample of the messages you send. Carriers require this to approve business texting.
- Terms acceptance and SMS consent records — when you accept our Terms or opt in to texts from us at signup, we record the time, the IP address the request came from, and the exact wording you agreed to. This is deliberate: it is how we can prove consent later.
- Photos and files — images you upload to job records, accounting entries, or your business website.
- Device and push data — if you use our mobile app and enable notifications, we store a push-notification token and the minimum device information needed to deliver alerts.
About a Business's customers (entered by the customer on a booking page, entered by the Business, or captured automatically):
- Contact and appointment details — name, phone number, email, service address, requested service, date and time, and any notes provided.
- Calls and messages — if you call a Business's number and the call isn't answered, we record that a call was missed (your number and the time) so the Business can follow up, and you may receive one automatic text back. Text messages you exchange with a Business through the platform are stored, in full, so the Business can see its conversation history.
- SMS consent records — if you tick the optional texting box on a booking page, we record the time, your IP address, and the exact consent wording shown to you.
- Job photos — before/after photos of work at your property, taken or uploaded by the Business.
From everyone:
- Technical data — IP addresses and request metadata, logged to secure the platform, rate-limit abuse, and diagnose problems.
- Location of addresses (not of you) — street addresses entered into the platform are converted to map coordinates ("geocoded") so jobs can be plotted on a schedule map. While an address is being typed into a job form, the partial text is sent to an autocomplete service to suggest completions. We do not collect GPS or device location from anyone — see Our Mobile App below.
How We Use Information
- To run each Business's dashboard: leads, appointments, invoices, reviews, messages, and reports.
- To send messages a Business initiates or schedules — appointment confirmations, reminders, follow-ups, invoices, and review requests — by text (Twilio) and email (Resend).
- To send Businesses transactional notifications about their own account: new booking alerts, billing notices, and push notifications if enabled.
- To process subscription payments, and to let a Business's customers pay invoices online.
- To secure the platform: authentication, rate limiting, abuse prevention, and error monitoring.
- To measure our own marketing (on our marketing pages only — see Advertising & Analytics).
Service Providers We Use
We use the following services to operate the platform. Each receives only what its function requires and handles data under its own privacy policy:
- Supabase — database, authentication, and file storage (supabase.com)
- Stripe — payment processing: our subscription billing, and invoice payments made to Businesses through their own connected Stripe accounts. Stripe holds all card and bank details under its PCI-compliant systems (stripe.com)
- Twilio — text messaging and call forwarding on a Business's behalf, and carrier verification of business texting numbers (twilio.com)
- Resend — transactional email delivery (resend.com)
- Anthropic — AI features use Anthropic's Claude API; see AI-Powered Features (anthropic.com/privacy)
- Vercel — web hosting, deployment, performance monitoring, and analytics on our marketing pages (vercel.com)
- Railway — hosting for our Twilio relay server, which carries message content and phone numbers when sending texts (railway.app)
- Upstash — rate limiting and background job queues; a queued text retry includes the message and phone numbers until it is delivered (upstash.com)
- Sentry — error monitoring. We configure it not to capture request data by default, but diagnostic context attached to an error report can include identifiers such as an email address, a phone number, or an excerpt of a message involved in the failure (sentry.io)
- Expo — push-notification delivery for our mobile app, which passes through Apple's and Google's notification services; a notification's content (for example a customer name and appointment time) transits these systems (expo.dev)
- OpenStreetMap / Nominatim — converts full addresses to map coordinates (openstreetmap.org)
- Geoapify — address autocomplete: suggests completions for the partial address text typed into a job form. Requests go through our server, so Geoapify does not see who is typing (geoapify.com)
- Google / Apple — map display in our mobile app (Google Maps on Android, Apple Maps on iOS) renders the job addresses a Business has entered; and their push-notification services deliver alerts (google.com, apple.com)
- Meta — advertising measurement on our marketing pages only; see Advertising & Analytics (meta.com)
We do not share data with these services beyond what is required to provide the platform.
Advertising & Analytics
Our own marketing pages — the homepage, the free-trial signup, and the product demo — use the Meta Pixel to measure whether our advertising works. On those pages, Meta receives standard web-request information (IP address, browser details, the page URL) and sets cookies (_fbp, and _fbc when you arrive from a Meta ad) used to attribute signups to ads. We also use Vercel Web Analytics on the same pages to count visits and funnel steps.
These tools do not run anywhere else. Booking pages, invoice and estimate pages, job pages, hosted business websites, and the signed-in portal load no advertising or analytics scripts. If you are a customer of a business using Marathon Simplicity, we do not track you for advertising.
To limit Meta's tracking generally, you can use your browser's tracking protections or adjust your settings at Meta's Ad Preferences. Site-wide, we use Vercel Speed Insights for anonymous page-performance measurement.
We Do Not Sell Your Data
Marathon Simplicity does not sell, rent, or trade personal information — yours or your customers'. Your CRM data (leads, contacts, appointments, messages, photos, invoices) is never shared with anyone for marketing or advertising, full stop. The only advertising technology anywhere in our product is the pixel on our own marketing pages, described above, and it measures our ads — it never touches CRM data.
Text Messaging
Texts sent through the platform to a Business's customers are sent by that Business — it is their number, their customer relationship, and their message; our platform is the tool. Two kinds of messages exist:
- Responses to something you did — for example, a confirmation after you request an appointment, a reply in an ongoing conversation, or an on-my-way update for a job you booked. These are sent because you asked for the underlying service.
- Automated messages — reminders, follow-ups, and review requests. These are sent only where consent or an existing customer relationship supports them, and every automated message includes opt-out wording.
Reply STOP to any message to stop receiving texts from that number — this is honored automatically and immediately, across all message types. Reply HELP for assistance. Message and data rates may apply, and message frequency varies with your appointment activity.
Where consent is collected — the optional box on a booking page, or the optional box at our own trial signup — we record when it was given, from which IP address, and the exact wording shown, so that consent is provable rather than assumed. Marathon Simplicity itself texts only Businesses that opted in at signup, about their own account.
Payments: Your Subscription
Marathon Simplicity is a monthly subscription billed through Stripe, with a 14-day free trial. You can pay by card or, where enabled, by bank transfer (ACH). Your payment method is stored by Stripe — we never see or store your full card or bank-account number. You can manage, upgrade, or cancel your subscription at any time from the Account page in your portal; if you cancel, access continues to the end of the billing period and the account is then paused.
Payments: Invoices You Pay to a Business
If you pay an invoice online that a business sent you through Marathon Simplicity, you are paying that business, through the business's own Stripe account — not us. Your card or bank details go directly to Stripe; we never see them. To start the payment we pass Stripe the invoice amount and, when the business has it on file, your email address so Stripe can send you a receipt.
What we keep is bookkeeping, not payment data: the invoice, its status (paid or unpaid), and a reference to the Stripe payment session. Refunds and disputes are between you, the business, and Stripe — the business's contact details are on the invoice.
Website Hosting for Businesses
A Business may publish a single-page website through our platform. That site is hosted on our infrastructure and is publicly accessible, as are the images uploaded to it, which are served from public storage URLs. Anyone with the link can view the site and its images, and an image URL that has been shared may continue to work until the image is deleted, even if the site is later unpublished. Businesses are responsible for the accuracy of what they publish and for having rights to the photos they upload.
Our Mobile App
The mobile app is for Businesses managing their account on the go. It stores your login session in your device's secure storage (iOS Keychain or Android Keystore), not in plain text. With your permission, it can send push notifications, take photos with your camera, and attach photos from your library to job records. You can revoke any of these permissions in your device settings. Account signup and billing happen on the web, not through in-app purchases.
The app does not request or collect your device's location. The schedule map plots the job addresses you entered, geocoded on our server — not where your phone is. The map itself is drawn by Apple Maps on iOS and Google Maps on Android.
Push notifications can include job details — a customer's name, the service, and the time — and are delivered through Expo and then Apple's or Google's notification services. If you would rather that content not transit those systems, leave notifications off.
AI-Powered Features
Two features use Anthropic's Claude API. Review-reply suggestions send the review text and business name to generate a draft reply, which the Business approves before anything is posted. An internal CRM assistant, available only to our own admin staff — not to Businesses or their customers — can query CRM context (such as contact names, appointment times, and review text) to answer operational questions.
Under Anthropic's commercial terms, data sent to the API is used to generate the response and is not used to train Anthropic's models. All AI output is a suggestion; a person decides what is sent or published.
Data Security
Data is stored in Supabase (PostgreSQL) with Row Level Security enforced, so one Business can never read another's data. Connections are encrypted in transit (HTTPS/TLS). Passwords are hashed, never stored. Job and receipt photos live in private storage buckets and are served through short-lived signed links; payment webhooks are cryptographically verified before anything is marked paid.
Cookies & Similar Technologies
The portal uses essential cookies to keep you securely signed in. Your light/dark theme choice is stored in your browser's local storage, not a cookie. The only third-party cookies we use are Meta's, on our marketing pages only, as described in Advertising & Analytics — no advertising or tracking cookies exist on booking pages, payment pages, hosted business websites, or in the portal.
Data Retention
We keep a Business's data for as long as its account exists — including its customer records, messages, and appointment history, which are the Business's working records. We do not automatically age data out.
Deleting an account is immediate and self-serve from the mobile app (Settings → Delete Account), or by emailing us — see our account deletion page for the exact steps. Deletion cancels the subscription, removes the Stripe billing record, deletes the CRM database records (contacts, appointments, messages, invoices, estimates) and job photos, and removes the login.
Two honest caveats. First, records some parties must keep, they keep: Stripe retains transaction records, Twilio retains carrier message logs, and our infrastructure providers retain server logs for a limited period. Consent records may also be retained where they are the legal evidence that a past message was lawful to send. Second, images that were published to a public business website may remain at their URLs until removed — ask us and we will remove them.
Your Rights & Choices
If you are a Business, you can:
- access and correct your data directly in the portal;
- ask us what we hold about your account and how it is used;
- delete your account and its data, immediately, as described above;
- turn off push notifications in your device settings, and opt out of our texts by replying STOP.
If you are a customer of a business that uses Marathon Simplicity, the business you dealt with controls your records, so the fastest route is to contact them directly — their details are on the booking page, invoice, or messages you received. You can also contact us at the address below and we will help route your request or, where the record is ours, handle it. Reply STOP to any text to stop texts, at any time, without contacting anyone.
We respond to requests at support@marathonsimplicity.com and verify that a request comes from the account owner (or the person the record is about) before acting on it.
Children's Privacy
Marathon Simplicity is a tool for businesses and is not directed to children. We do not knowingly collect personal information from children under 13, and our Terms require account holders to be at least 18. If you believe a child has provided us information, contact us and we will delete it.
Changes to This Policy
When we update this policy we update the effective date above and summarize material changes in the "What changed" note at the top. For material changes we also notify subscribing Businesses by email. Continued use of the platform after a change means you accept the updated policy.
Contact Us
Questions about this policy, or a data request:
