Privacy Policy

Effective Date: October 6, 2026

Your privacy is important to us. This Privacy Policy outlines how we collect, use, and protect your personal information when you visit our website or use our services.

1. Information We Collect

We may collect the following information:

  • Name, email address, phone number
  • Payment and billing information (via Stripe)
  • Session scheduling and communication records
  • Website usage and interaction data (e.g., analytics)

2. How We Use Your Information

Your information is used to:

  • Provide and deliver coaching services
  • Communicate with you about appointments, updates, and inquiries
  • Process payments and manage transactions
  • Improve our website and services

3. How We Share Information

We do not sell or rent your personal data. We only share it with:

  • Payment processors (e.g., Stripe)
  • Scheduling and communication platforms
  • Service providers necessary to operate our business

4. Data Security

We implement security measures to protect your data, but no method of transmission over the internet is 100% secure.

5. Your Rights

You may request to access, update, or delete your personal data by contacting us at m1rose28@gmail.com.

6. Google user data

Product by Mark accesses Google user data only after you connect a Google account or sign in with Google. This section describes what we access, how we use it, where we store it, and how you can ask us to delete it.

What we access

  • Google account email address, and the OpenID identifier Google returns with that sign-in, so we know which account you connected.
  • Gmail, read only: message content, headers, and related metadata for the mailbox you connect. We do not send, delete, or change email.
  • Google Calendar: calendars and events on the account you connect, including permission to read events and to create or update them.
  • Google Drive, read only: files the connected account can open.
  • Google Sheets: spreadsheets the connected account can open, including permission to read and edit those spreadsheets.

Signing in to a private Product by Mark page, such as admin or finance, uses only your Google account email. That sign-in does not request Gmail, Calendar, Drive, or Sheets.

How we use it

We use this Google user data to run Product by Mark's customer database for coaching:

  • Read Gmail so coaching-related email can be recorded in the customer database.
  • Read and update Google Calendar so coaching sessions stay on the calendar you connected.
  • Read Google Drive files and read or edit Google Sheets that hold the customer database.
  • Confirm the Google account email before allowing access to private pages.

We use Google user data only to provide and secure these features. We do not use it for advertising. We do not sell it. We do not use it to determine credit-worthiness or for lending. We do not use Google user data, including data from Gmail, Calendar, Drive, or Sheets, to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.

Product by Mark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we store and protect it

OAuth refresh tokens for a connected Google account are stored in our database (Supabase) on servers we control through our host (Vercel). Those tokens are available only to our application server. They are not shown on the public website, and the database is not open to public visitors. Traffic to this site uses HTTPS.

People at Product by Mark may view Google user data only to provide the customer-database and calendar features you authorized, to secure the service, or to comply with law.

Who we share it with

We do not sell, rent, or disclose Google user data to advertisers, data brokers, or information resellers. We do not transfer it for advertising, credit, lending, or to train generalized AI or machine learning models.

We share it only with service providers that host or store it so we can operate Product by Mark: Supabase, for the database, and Vercel, for hosting. They process that data only to provide those services. Google receives the requests we make to Google APIs on your behalf.

How long we keep it, and how to delete it

We keep Google user data and the refresh token for a connected account while that account stays connected and for as long as we need it to operate the customer database described above. When you disconnect the account, or when you ask us to delete the data, we delete the stored refresh token and the Google user data we hold from that account, unless the law requires us to keep a record.

To request access, correction, or deletion, email m1rose28@gmail.com. You can also revoke Product by Mark's access from your Google Account permissions at myaccount.google.com/permissions.

7. Contact Us

If you have any questions, please contact us.