Privacy

This notice describes what information Megatrix collects through the client portal, how it is used, who it is shared with, and the rights you have over it.

Information we collect

Account information: your name, email address, phone number, and password (stored as a salted hash — Megatrix never has access to your plaintext password). Workspace content: tasks, projects, requests, conversations, notes, and files you or your team create in the portal. Billing information: invoices and payment status are synced from our CRM; card details are entered directly into Stripe's own hosted fields and never pass through Megatrix's servers.

How we use it

To operate the portal (authentication, displaying your projects and conversations, sending you notifications you've configured), to process payments, and to communicate with you about your account or services.

Who we share it with

We use a small number of processors to run the portal: Supabase (database and authentication), Stripe (payment processing), and GoHighLevel (our CRM, used to sync contact records, invoices, notes, and documents). We do not sell your personal information to anyone.

Connected advertising & analytics accounts

If your workspace connects a Google Ads, Google Analytics (GA4), Meta (Facebook/Instagram) Ads, or GoHighLevel account for reporting, Megatrix pulls aggregate campaign performance data from that account — spend, clicks, impressions, conversions, and similar metrics — to display in your Reports dashboard. We do not access individual ad viewers' personal data, browsing history, or any information about people targeted by your ads; only account-level and campaign-level performance figures are retrieved. Connecting is optional, workspace-specific, and can be disconnected at any time from Integrations, which immediately revokes Megatrix's access to that account and deletes the stored credentials.

Data retention

We keep account and workspace data for as long as your account is active, plus a limited period afterward to satisfy legal, billing, and security-log obligations. You can request earlier deletion — see below.

Your rights (GDPR / CCPA)

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Megatrix does not sell personal information, so there is nothing to opt out of in that sense. You can exercise these rights yourself from Settings → Privacy & data (export or request deletion), or by emailing privacy@megatrix.io. We respond to verified requests within 30 days.

Payment card security (PCI-DSS)

Megatrix never receives, transmits, or stores your raw card number. Card entry happens inside Stripe's own hosted UI (Stripe Elements), which tokenizes the card before anything reaches our application — this keeps our servers out of PCI-DSS cardholder-data scope.

Security

All traffic is encrypted in transit (HTTPS/HSTS). Passwords are hashed, never stored in plaintext. Every login requires a follow-up email verification code. Sessions are re-validated on the server on every request so a stolen or expired token can't be replayed.

Contact

Questions about this notice, or a privacy request you'd rather send by email: privacy@megatrix.io.