Data, Security & Retention

Effective July 2, 2026 · Last updated July 2, 2026

A plain-English summary of how your data is stored and protected, how long we keep it, how to have it deleted, and what we do if something goes wrong. This complements the Privacy Policy.

How your data is stored

Your account and business data live in a Postgres database, and receipt images live in private file storage, both provided by Supabase in the United States. Every row and file is isolated to your account by row-level security, so no other user can read or change your data.

How it's protected

  • Encrypted in transit over HTTPS, and encrypted at rest by our database and storage provider.
  • Access to your data is scoped to your account by the database itself, not just by app code.
  • Receipt files sit in a private bucket that requires a signed, time-limited link to view.
  • We limit which outside services touch your data — see the Sub-Processors list.

No system is perfectly secure. We aim for sound, best-effort security appropriate to a small service, and you should keep your own copies of anything critical.

How long we keep it (retention)

We keep your data while your account is active so the service works. We keep basic security and error logs for a limited period to run and protect the service. When you delete your account, we remove your data as described below.

Deletion

You can export your jobs and costs to CSV any time from Settings. You can delete your account yourself from Settings → Delete account, which immediately removes your account and its jobs, costs, workers, inventory, and receipt images; or email contact@marginhawk.net and we will do it for you. Copies may remain briefly in encrypted backups until those backups rotate out in the ordinary course.

If a data incident happens (breach approach)

If we learn of a security incident affecting your data, our internal steps are to identify and contain it, investigate and preserve evidence, determine what data was affected, bring in security or legal help as needed, notify the services involved, and document our decisions.

We will notify affected users and any authorities as required by applicable U.S. law. Because our founder and earliest users are in Pennsylvania, we start with Pennsylvania’s breach-notification rules; if users are in other states, those states’ rules may also apply. Because a receipt image could contain payment card details, we treat incidents involving receipt images as higher risk.

Contact

Security questions or reports go to contact@marginhawk.net.

Questions about this document? Email contact@marginhawk.net. MarginHawk is offered in the United States only and is intended for business use by adults 18 or older. This document is written in plain English and provided in good faith; it is not legal advice to you.