Privacy Policy
Effective date: July 10, 2026
MStoGo LLC (“MStoGo,” “we,” “us,” or “our”) operates the software available at https://sales.mstogo.com (the “Service”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By using the Service you agree to this Policy.
1. Information we collect
a. Information you provide
- Account data: name, email, password (hashed), agency/organization name.
- Agency configuration: logo, brand colors, service offerings, pricing, scheduling links, and team members you add.
- Prospect and client data: business names, addresses, phone numbers, websites, notes, and any content you or your clients submit through intake forms.
- Payment information: handled by our payment processor; we do not store full card numbers.
- Support communications: messages you send us.
b. Information collected automatically
- Log data (IP address, browser, device, pages viewed, timestamps).
- Cookies and similar technologies used to keep you signed in and to measure product usage.
c. Information from third parties
- Google (Sign-In & APIs): when you choose “Continue with Google” or connect a Google Workspace account, we receive basic profile information (name, email, avatar, Google account ID) and — if you grant them — scoped OAuth tokens for Google Calendar and related services.
- Microsoft / Zoom: similar identity and calendar/meeting data if you connect those integrations.
- Google Maps Platform: we use Google Maps and Places to help you search for local businesses; your use of those features is also subject to Google’s policies.
- Publicly available data: when generating audits we fetch information that businesses have made publicly available on their websites and public listings.
2. How we use information
- Provide, operate, and improve the Service.
- Authenticate you and secure your account.
- Generate marketing audit reports, proposals, and client portals on your behalf.
- Send transactional emails (account, billing, proposals you initiate).
- Provide customer support and respond to requests.
- Detect, investigate, and prevent abuse, fraud, and security incidents.
- Comply with legal obligations.
We do not sell your personal information, and we do not use it for advertising or for training generalized AI/ML models.
3. Google API Services — Limited Use disclosure
MStoGo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through Google OAuth (including Calendar and profile data) is:
- Used only to provide user-facing features you explicitly requested (sign-in, calendar scheduling, meeting creation).
- Not transferred to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger/acquisition with appropriate notice.
- Not used to serve advertisements.
- Not read by humans, unless we have your affirmative consent for specific messages, it is necessary for security purposes (e.g. investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
4. Sharing of information
We share information only in these limited situations:
- Service providers that host, store, email, and process payments on our behalf under confidentiality obligations (e.g., Supabase/Lovable Cloud, Cloudflare, our transactional email provider, our payment processor).
- Your own clients, when you choose to share a report or grant them access to a client portal.
- Legal and safety reasons — to comply with law, enforce our Terms, or protect rights, property, and safety.
- Business transfers — as part of a merger, acquisition, financing, or sale of assets, with notice consistent with this Policy.
5. Data retention and deletion
We retain account and content data for as long as your account is active. If you close your account, we delete or anonymize your personal data within 30 days, except for records we are legally required to keep (e.g. billing/tax) which are retained for up to 7 years and then deleted. Application logs are retained for up to 90 days.
OAuth tokens (including Google Calendar tokens): stored encrypted at rest with AES-256-GCM and deleted immediately when you disconnect the integration from Settings → Connectors, revoke access from your Google Account permissions page, or delete your account.
To request deletion of your account and associated data, email mstogollc@gmail.com from the address on your account, or use the “Delete account” action in Settings → Account. We will confirm completion within 30 days.
6. Security
We use industry-standard safeguards including TLS in transit, encryption at rest, row-level access controls, and per-organization data isolation. OAuth refresh tokens are encrypted with AES-256-GCM. No system is 100% secure; you use the Service at your own risk.
7. International users
The Service is operated from the United States. If you access it from elsewhere, you consent to processing of your information in the United States.
8. Your rights and choices
- Access, update, or delete your account and data from Settings, or by emailing us.
- Revoke Google access at any time from your Google Account permissions page or from Settings → Connectors inside MStoGo.
- Depending on your jurisdiction (e.g., California, EEA/UK), you may have additional rights such as data portability, correction, and the right to object. Contact us to exercise those rights.
9. Children
The Service is not directed to children under 13 and we do not knowingly collect their information.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with a new effective date and, where appropriate, notified to you by email.
11. Contact
Questions or requests? Email us at mstogollc@gmail.com.
MStoGo LLC · https://sales.mstogo.com