Privacy Policy
Last updated July 14, 2026 · The plain-language version — this is how we operate today. Counsel review is in progress; account owners get an email when the final text is stamped.
On this page
MarginLeaks exists to protect restaurant margins, not to collect data. This policy says plainly what we collect, why, who touches it, and what you can do about it. It covers the marginleaks.com website and the MarginLeaks application.
What we collect
Account details — your name, email, and restaurant name(s), used to sign you in, run your team's access, and send the emails you've asked for (invites, the weekly report). Business data you enter or upload — ingredients, recipes, prices, supplier invoices, payout statements, sales figures. This is business operations data about your restaurant; we don't ask for and don't want your customers' personal information. Usage basics — logs and diagnostics needed to keep the service reliable and secure. For advertising measurement we record a few conversion milestones — a page or sample-report view on the public site, that you created an account, and that a subscription started — so we can tell which ads led to real customers (see "Advertising measurement" below). If you arrived from a campaign link, the tags on that link (utm_source, utm_medium, utm_campaign, utm_content, utm_term, fbclid) and the page you landed on are kept in your browser's local storage and, if you go on to create an account, stored once on that account record — so we can tell which ad produced it. Your recipes, costs, margins, and uploaded documents are never part of that.
How we use it
To run MarginLeaks for you: compute your costs and margins, build your weekly Margin Health Report, email it to the people you've chosen, and improve the reliability of the product. When you upload a document, automated extraction (including AI models run by our platform provider) reads it to propose entries for your review. Your data is not used to train AI models, is never sold, and is never shared with other customers or data brokers.
Who touches it (service providers)
We run on a small set of providers under contract: Base44 (application platform, database, authentication, file storage, document extraction, and email delivery) and Stripe (payments — we never see or store full card numbers). For advertising measurement we share conversion signals with Meta (see below); we send a one-way hashed version of your email so Meta can match a conversion to an ad click, never your business data. Each provider gets only what its job requires.
Security
Data is encrypted in transit, access inside the team is limited to what's needed to support you, and your workspace is isolated per organization with role-based access you control. The Security page describes this in more detail. No honest vendor promises unbreakable security; if an incident affects your data we'll tell you promptly and plainly.
Retention & your choices
We keep your data while your account is active. You can export it anytime (recipes as CSV, full account as JSON). If you cancel, it stays exportable for 30 days and is then deleted in the ordinary course; you can also request deletion at any time and we'll complete it within 30 days, except where the law requires us to keep specific records. Emails we send about your account are part of the service; the weekly report's audience is controlled in your Settings.
Advertising and analytics
We use the Meta Pixel and the Meta Conversions API to measure our ads. Plainly: they tell us which ads lead to real customers. What they collect — page views on marginleaks.com, actions you take on the site (viewing the sample report, starting setup, creating an account, subscribing), and at purchase a one-way hashed version of your email so Meta can match the purchase to an ad click. Never your recipes, costs, margins, or any document you uploaded. We send the same event from your browser and from our server with a shared identifier so it's counted once, not twice. Meta may use this data under its own privacy policy. The cookies involved are Meta's _fbp and _fbc, plus our own ml_attribution local-storage entry, which never leaves your device except as the campaign tags saved on your account; the full list is on the cookie declaration. We run no other third-party trackers.
How to opt out: use the “Cookie settings” or “Do Not Sell or Share My Personal Information” link in any footer, or . Turning ad measurement off removes the pixel and deletes its cookies. If your browser sends a Global Privacy Control signal, we treat it as an opt-out automatically and never load the pixel.
Your privacy choices (California, Texas, and other US states)
We don't sell personal information for money. Sharing it with Meta for ad measurement can count as “sharing” or “targeted advertising” under some state laws, so you have the right to opt out: use the Do Not Sell or Share My Personal Information link in any footer (it opens the same one-toggle panel), or send a Global Privacy Control signal from your browser. You can also request access to or deletion of your data at security@marginleaks.com; we won't treat you differently for exercising these rights.
Changes & contact
If this policy changes materially we'll email account owners before the change takes effect. Questions about your data — or a deletion request — go to security@marginleaks.com (or hello@marginleaks.com for anything else).
