MarkAndRun ("we", "our", or "us") operates the MarkAndRun native mobile app and web application (collectively, the "Service") — an AI-powered job management platform for small residential contractors. This Privacy Policy explains exactly what personal data we collect, how we use it, and what rights you have over it.
By creating an account or using the Service you agree to the practices described here. If you do not agree, please do not use the Service.
1. Who operates this Service
The Service is operated by MarkAndRun. For privacy-related questions, contact us at privacy@markandrun.com.
2. What data we collect
Data you give us directly
- Account credentials: your email address and a password. Your password is never stored in readable form — it is hashed with bcrypt before being saved.
- Client and project data: client names, phone numbers, email addresses, job addresses, project type, status, scope items, contract text, draw schedules, budget entries, draw requests, lien waivers, change orders, punch-list items, closeout records, daily logs, field notes, cost entries, and inspection records you create inside the app.
- Walkthrough audio: when you use the AI walkthrough feature, the audio you record is transmitted to our AI processing pipeline (see Section 5). Raw audio is not retained after the scope is generated.
- Photos: photos you upload as part of daily logs, field notes, issue reports, and change orders are stored and associated with your project.
- Appointment information: dates, times, and contact details entered when scheduling client walkthroughs.
- Support messages: any email or in-app message you send to our support address.
Data collected automatically when you use the Service
- Server request logs: your IP address, HTTP method and URL path (query strings stripped), HTTP response status code, and timestamp. These are written to rolling application logs and are not archived indefinitely.
- Session token: after you log in, a server-side session is stored in our PostgreSQL database. A session cookie is placed in your browser (httpOnly, Secure in production, SameSite: Lax, expires after 7 days of inactivity). On native mobile, an equivalent HMAC bearer token is stored in device secure storage.
- Audit log: certain privileged actions (role changes, project status updates) are recorded with the actor's user ID, action type, target record ID, IP address, and timestamp.
Data we do not collect
- Payment card or bank details. Subscription billing is handled by a third-party payment processor; we do not store card numbers.
- Device fingerprints, advertising identifiers, browser storage beyond the session cookie, or any third-party analytics or tracking pixels.
- Location data beyond the job address you type in yourself.
- Any data from minors. The Service is intended for adults 18 and over.
3. How we collect data
Data is collected in three ways: (a) directly, when you enter information into forms in the app; (b) automatically, as a side-effect of normal HTTP communication; and (c) via device hardware, when you grant microphone or camera permission for the walkthrough recording and photo features.
We do not use cookies for advertising, cross-site tracking, or any purpose other than maintaining your login session.
4. How we use your data
- To provide the Service: store and display your projects, estimates, contracts, lien waivers, change orders, daily logs, and all other records you create.
- To authenticate you: verify credentials at login, issue and validate session tokens.
- AI-powered features: your walkthrough audio, project notes, and scope text are sent to our AI pipeline to generate estimates, draft contracts, write progress reports, and draft change orders (see Section 5).
- Transactional email: we send appointment confirmations, estimate share links, contract notifications, pre-work checklists, draw approval requests, and change order notifications to clients and contractors via email.
- Security and accountability: the audit log lets Founder-role users review privileged actions and helps us investigate potential abuse.
- Support: to respond to questions or bug reports you submit.
- Legal compliance: to satisfy obligations imposed by applicable law.
We do not sell your personal data to any third party. We do not use your project data to train machine-learning models.
5. AI processing and third-party service providers
To power AI features, we transmit certain data to third-party AI services:
- Walkthrough transcription and scope generation: audio recordings are sent to OpenAI's API for transcription. The resulting transcript and project context are used to generate a priced scope estimate. Raw audio is discarded after transcription; the transcript and scope are saved to your project.
- Pricing research: to produce local material and labour price estimates, we send anonymised scope descriptions to a web-search API (Perplexity) to retrieve current market pricing. No personal identifiers are included in these queries.
- Contract and report generation: project scope, client name, job address, and relevant project details are sent to OpenAI's API to generate contract text, AI progress reports, and change order drafts.
- Transactional email: we use Resend to deliver appointment confirmations, estimate links, and other notifications. Resend receives the recipient email address and message content necessary to deliver each email.
- Cloud infrastructure: the database and application server are hosted on cloud infrastructure under a standard data-processing agreement.
We share personal data with these providers only to the extent necessary to deliver the features described. We do not share data with advertising networks or data brokers.
We may also disclose data when required by a valid legal request (court order, subpoena, law-enforcement demand), or in the event of a business transfer (acquisition or merger), with advance notice to affected users.
6. Data retention and deletion
While your account is active
All account and project data is retained for as long as your account exists and you continue to use the Service.
Audio recordings
Raw walkthrough audio is transmitted to our AI pipeline for transcription and is not stored on our servers after processing. Transcripts are retained with the project.
Photos
Photos uploaded to daily logs, field notes, and change orders are retained with the project for as long as the account is active. They are deleted when the account or project is deleted.
Session data
Login sessions expire after 7 days. Logging out destroys your session immediately.
Application logs
Server request logs are retained for a short rolling window for operational troubleshooting and are not archived indefinitely.
Account deletion
When you request deletion, we permanently remove your email address, display name, and password hash. Project data — scopes, contracts, photos, lien waivers, change orders, daily logs, and all related records — is deleted. Anonymised audit log entries (action type, timestamp, internal IDs) may be retained for up to 24 months for security purposes; your personal identifiers are removed from them.
7. How to request account or data deletion
To delete your account
Email privacy@markandrun.com with the subject line "Delete my account" from the email address registered to your account. We will confirm and process your request within 10 business days.
You can also visit the Account Deletion page for full details on what is removed and what is retained.
To request a copy of your personal data before deleting, include "Data export request" in your email.
8. Security measures
- Passwords are hashed with bcrypt and never stored in plaintext.
- All data in transit is protected by TLS (HTTPS).
- Session cookies are httpOnly, SameSite: Lax, and marked Secure in production. Mobile auth tokens are stored in device secure storage.
- Access to project data is controlled by role-based permissions: crew members access only their assigned projects; staff see all company projects; founders additionally have admin and audit access.
- Privileged actions are recorded in an audit log.
- AI API calls are made server-side — raw audio and project data never pass through the client browser to third-party services.
No system is perfectly secure. If we become aware of a security incident likely to put your personal data at risk, we will take prompt action and notify affected users as quickly as practicable.
9. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate information.
- Delete your account and personal data (see Section 7).
- Object to or restrict certain uses of your data.
- Lodge a complaint with the data protection authority in your jurisdiction.
To exercise any of these rights, contact privacy@markandrun.com.
10. Children's privacy
The Service is intended for professional use by adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, contact us at privacy@markandrun.com.
11. Changes to this policy
We may update this Privacy Policy when the Service changes in ways that affect data collection or use. We will post the revised version here with an updated effective date. For material changes, we will display a prominent notice inside the app.
12. Contact
Email: privacy@markandrun.com
Subject: include "Privacy" or "Delete my account" so your message is routed correctly.
Response time: within 10 business days.
