MarkAndRun ("we", "our", or "us") operates the MarkAndRun web application (the "Service"), a project-management platform for small residential contractors. This Privacy Policy explains exactly what personal data we collect, how we use it, and what rights you have over it.
By creating an account or using the Service you agree to the practices described here. If you do not agree, please do not use the Service.
1. Who operates this Service
The Service is operated by MarkAndRun. For privacy-related questions, contact us at privacy@markandrun.com.
2. What data we collect
Data you give us directly
- Registration details: your email address, display name (optional), and a password. Your password is never stored in readable form — it is hashed with bcrypt (cost 12) before being saved.
- Project data: client names, job addresses, project type, status, scope items, contract text, budget entries, draw requests, punch-list items, closeout checklist items, inspections, lien waivers, field notes, and referral records you create inside the app.
- Support messages: any email or in-app message you send to our support address.
Data collected automatically when you use the Service
- Server request logs: your IP address, the HTTP method and URL path of each request (query strings are stripped), the HTTP response status code, and a timestamp. These are written to application logs and are not stored in the database long-term.
- Session token: after you log in, a server-side session is created and stored in our PostgreSQL database. A session cookie named mar.sid is placed in your browser. It is flagged httpOnly (JavaScript cannot read it), secure in production (HTTPS-only), SameSite: Lax, and expires after 7 days of inactivity.
- Audit log: certain privileged actions (such as a Founder changing a user's role, or a Staff member updating a project status) are recorded in an internal audit table with the actor's user ID, action type, target record ID, request IP address, and timestamp. This log is visible only to Founder-role users.
Data we do not collect
- Payment card or bank details. MarkAndRun has no payment processing integration. Payment schedule fields inside project contracts are free-text notes only.
- Device fingerprints, browser storage, or client-side analytics. We run no analytics SDK, tracking pixel, or advertising tag.
- Location data beyond the job address you type in yourself.
- Any data from minors. The Service is intended for adults 18 and over.
3. How we collect data
Data is collected in two ways: (a) directly, when you type information into forms in the app; and (b) automatically, as a side-effect of normal HTTP communication — your browser sends your IP address and a user-agent string with every request.
We do not use cookies for advertising, cross-site tracking, or any purpose other than maintaining your login session.
4. How we use your data
- To provide the Service: store and display your projects, contracts, punch lists, inspections, lien waivers, and other records you create.
- To authenticate you: verify your email and password at login, issue and validate session tokens.
- Security and accountability: the audit log lets Founder-role users review privileged actions taken within their account, and helps us investigate potential abuse.
- Service improvement: aggregate, anonymised usage patterns (e.g. which features are used most) may inform product decisions.
- Support: to respond to questions or bug reports you submit.
- Legal compliance: to satisfy obligations imposed by applicable law.
We do not sell your personal data to any third party. We do not use your project data to train machine-learning models.
5. Data sharing and service providers
We share personal data only in these limited circumstances:
- Cloud infrastructure: the database and application server are hosted on cloud infrastructure. Your data resides on servers managed by our hosting provider under a standard data-processing agreement.
- Legal obligations: if we receive a valid legal request (court order, subpoena, law-enforcement demand) we may be required to disclose specific data.
- Business transfer: if MarkAndRun is acquired or merged, user data may transfer to the new operator. We would notify affected users with reasonable advance notice.
- With your explicit consent: for any purpose not listed here.
We currently use no third-party analytics, advertising, or email-marketing services.
6. Data retention and deletion
While your account is active
All account and project data is retained for as long as your account exists and you continue to use the Service.
Session data
Login sessions are stored in our database and automatically expire after 7 days. Logging out destroys your session immediately.
Application logs
Server request logs (containing IP addresses) are retained for a short rolling window for operational troubleshooting and are not archived indefinitely.
Audit log
The internal audit log — which records privileged actions by Founder and Staff users — is retained for the lifetime of the account for security and accountability purposes. Audit entries reference users by internal ID; if your account is deleted, references to your ID in the audit log are retained but your email and name are removed.
Account deletion
When you request deletion of your account, we permanently remove your email address, display name, and password hash from the users table. Your project data (projects, contracts, punch lists, inspections, lien waivers, field notes, and referrals) is also deleted. Audit log entries where your account was the actor retain the action record but are anonymised by removing your personal identifiers.
7. How to request account or data deletion
To delete your account
Email privacy@markandrun.com with the subject line "Delete my account" from the email address registered to your account. We will confirm and process your request within 10 business days.
You can also visit the Account Deletion page for full details on what is removed and what is retained for legal or security reasons.
To request a copy of your personal data before deleting, include "Data export request" in your email. We will provide a structured export of your account and project records.
8. Security measures
We take reasonable precautions to protect your data:
- Passwords are hashed with bcrypt (cost factor 12) and never stored in plaintext.
- All data in transit is protected by TLS (HTTPS).
- Session cookies are httpOnly, SameSite: Lax, and marked Secure in production.
- Access to project data is controlled by role-based permissions: regular users see only their own projects; Staff see all projects; Founders additionally have access to the admin dashboard and audit log.
- Privileged actions are recorded in an audit log so Founders can detect unexpected activity.
No system is perfectly secure. If we become aware of a security incident that is likely to put your personal data at risk, we will take prompt action and notify affected users as quickly as practicable.
9. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate information (you can update your display name and email from your account settings).
- Delete your account and personal data (see Section 7 above).
- Object to or restrict certain uses of your data.
- Lodge a complaint with the data protection authority in your jurisdiction.
To exercise any of these rights, contact privacy@markandrun.com.
10. Children's privacy
The Service is intended for professional use by adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, please contact us at privacy@markandrun.com and we will delete the account promptly.
11. Changes to this policy
We may update this Privacy Policy when the Service changes in ways that affect data collection or use. When we do, we will post the revised version here with an updated effective date. For material changes, we will display a prominent notice inside the app. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
12. Contact
For privacy questions, data requests, or account deletion:
Email: privacy@markandrun.com
Subject: include "Privacy" or "Delete my account" so your message is routed correctly.
Response time: within 10 business days.
For general support questions, see our Support page.
