MinMax Pro  /  Privacy Policy

MinMax Pro Privacy Policy

Effective September 18, 2026Last updated September 19, 2026

MinMax Pro is a product of MinMax Strategies LLC, a single-member limited liability company organized under the laws of the State of Michigan and based in Grand Rapids, Michigan. MinMax Strategies is the company you contract with, the company that holds your data, and the company to contact about any of it. “We”, “us” and “our” below mean MinMax Strategies LLC.

This policy covers the MinMax Pro product: your account and the records you keep in it. MinMax Strategies’ company-wide Privacy Policy covers everything else the firm does, including the main website and consulting engagements, and governs anything this document does not address. Where the two overlap, they are written to say the same thing; if they ever disagree, the company-wide policy controls.

1.The two roles we play, and why it matters

Almost every question about privacy in a product like this comes down to one distinction.

  • Account data is what we collect in order to give you an account and bill you: your name, business name, email address, phone number, sign-in credentials, who holds which seat, your subscription and payment records, and technical logs. We decide what account data we need, so for account data we are the controller.
  • Customer Data is everything you put into the workspace: your customers and clients, jobs, projects, quotes, invoices, documents, photographs, time entries, messages, and anything else you or your team enters or uploads. We do not choose what goes in there and we do not use it for our own purposes. You decide; we process it on your instructions. For Customer Data we are a processor and you are the controller.

That is this policy in one line: the business records you keep in MinMax Pro are yours.


2.Information we collect

  • Account and billing information: the fields above, your subscription status, and your invoice history.
  • Usage and technical information: IP address, browser and device type, the pages and features used, timestamps, and error diagnostics. We use this to keep the service running, to find defects, and to detect abuse. During signup this includes a first-party analytics identifier stored in your browser, the steps of the signup you complete or abandon, and the campaign (UTM) parameters on the link you arrived from - used only to understand and improve the signup itself, never shared, and never tied to advertising.
  • Communications: messages you send us for support, and our replies.
  • Payment information: see section 4.
  • Texting registration: if your business registers to send text messages, the legal business name, EIN, business address and the name, title, email and phone number of an authorized representative that carriers require. We pass these to Twilio, which submits them to The Campaign Registry and the mobile carriers to register your business and messaging campaign.
  • Connected Google and Microsoft accounts: see section 6.
  • Customer Data: whatever you and your team put into the workspace. Two kinds of it deserve a specific mention:
    • Field Portal location. When a crew member checks in, advances a job stage or submits a form in the Field Portal, the device’s approximate location (latitude, longitude and accuracy) is recorded against that step, if the device’s browser permits it. Refusing the browser’s location prompt does not stop the step from being recorded; it is simply recorded without a location. Location is captured only at those moments, not tracked continuously.
    • Vendor Portal documents. Vendors and subcontractors can upload documents such as certificates of insurance, licenses and W-9 forms, and a W-9 may contain a taxpayer identification number or Social Security number. Uploaded files are held in private, per-business file storage that has no public address, are downloaded only through a link that expires after 60 seconds and is issued to a signed-in user of that business or to the vendor who is entitled to the file, and are encrypted in transit and at rest.

We do not buy personal information about you from data brokers, and we do not enrich your account with information from third-party sources.


3.How we use information

We use account data to provide and secure the service, authenticate sign-ins, take payment, answer support requests, notify you about changes that affect your account, and meet our legal, tax and accounting obligations. We use aggregated or de-identified usage data to decide what to build next.

We use Customer Data only to provide the service to you and to support you when you ask. We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use your Customer Data to train artificial-intelligence or machine-learning models, ours or anyone else’s.


4.Payments

Paying us. MinMax Pro subscriptions are billed through Stripe. When you enter card details at signup or in the billing portal, those details go from your browser directly to Stripe and are never received, processed or stored on our systems. We keep the card brand, the last four digits and the expiry date so you can recognize your own payment method, together with the invoice and payment records we are required to keep.

Your customers paying you. That is a different arrangement, and we are not a party to it. When you put a payment link on the invoices you send, or connect your own payment account, your customer pays you through your processor. When they pay in the client portal, they enter their card details into secure payment fields that your processor hosts and that are embedded in the portal; when they follow a payment link, they pay on the processor’s own page. Either way those details go straight to the processor. Their card, bank and routing numbers never reach our servers. What we record is the result - whether an invoice was paid, when, how much, the last four digits of the card where the processor returns them, and the processor’s own reference for the payment - because that is what your books in here have to show. Your processor holds the payment itself under its own privacy policy and its own agreement with you, and the relationship with the customer is yours. Section 4 of the Terms of Service sets out who is responsible for what.

Do not type a full card number, bank account number or routing number into a MinMax Pro field. Nothing in the product needs one, and no field in it is built to hold one.


5.Service providers we rely on

A small number of providers process information, including Customer Data, in the course of running MinMax Pro. Each is under contract, each may use the information only to provide its service to us, and none may use it for its own purposes.

Subprocessors
ProviderWhat it doesLocation
NetlifySite delivery and the serverless functions behind the applicationUnited States
SupabaseDatabase hosting, and private file storage for uploaded documents and photographs. Sign-in is run by MinMax Pro itself, not by SupabaseUnited States
StripeSubscription billing and card processing for what you pay us; and, where you connect your own Stripe account, the invoice and payment records for invoices you raise here and send to your own customersUnited States
Stripe.jsStripe’s payment script, which loads on the signup page, in billing settings and on the client portal’s payment screen. It hosts the card fields and collects device, browser and interaction signals that Stripe uses to detect fraud, under Stripe’s own privacy policyUnited States
ResendTransactional email: sign-in links, password resets, invoices, quotes, job reports and notifications - the addresses, subjects, bodies and attachments of the messages sentUnited States
TwilioText messaging, where a workspace has texting enabled: the phone numbers texted and the full message bodies, both directions. When a business registers for texting, also its legal name, EIN, business address and authorized representative’s contact details, which Twilio passes to The Campaign Registry and the mobile carriers to register the business and its messaging campaignUnited States
GoogleOnly when a user connects a Google account (section 6): Google Calendar, to write your jobs to that calendar and read busy time from it, and Gmail, to send mail from that mailbox. Separately, only for a business that enters its own Google Places API key: Google Places, which our server queries with that key to pull the business’s own public reviews and ratingUnited States
MicrosoftOnly when a user connects a Microsoft account (section 6): Microsoft Graph, for the same calendar and mail functions as GoogleUnited States
Intuit (QuickBooks Online)Only when a workspace connects QuickBooks (section 6): at the business’s direction, after an admin connects the business’s own QuickBooks Online company and presses Start Sync, the customers, vendors, invoices, payments, bills and employee time entries the business records here are sent to that company. Intuit also tells us when a record we sent is deleted, voided or merged in QuickBooksUnited States
Geoapify (KEPTAGO LTD)Converts the addresses you enter into map positions. The lookup goes through our own server, so Geoapify receives the address text but not your account, your name or your IP address. Its results are built from OpenStreetMap dataCyprus
OpenStreetMap FoundationConverts addresses into map positions in the public demo only, which has no account to hold a session, so there the lookup goes from your browser directly to OpenStreetMapUnited Kingdom
OpenStreetMap tile serversDraw the map on the staff scheduling page. Your browser fetches the map images directly from OpenStreetMap’s tile servers, not through ours, so those servers see your IP address and the area of the map you are viewingUnited Kingdom, served through a global CDN
GIPHY or Tenor (Google)Only where a deployment has the GIF picker enabled: the search term a staff member types in team chat, which goes through our own server, so the provider receives the words searched but not your account, your name or your IP address. A GIF somebody then posts is stored as a link, so every browser that later reads that message fetches the image directly from the provider, which sees that browser’s IP addressUnited States, served through a global CDN
unpkgContent delivery network that serves the Leaflet map library to signed-in staff; receives the standard request data any web server sees, including your IP addressGlobal CDN
Have I Been PwnedChecks a new password against known data breaches. Only the first five characters of a one-way hash of the password leave our server; the password itself, and anything that identifies you, never doGlobal CDN
Google FontsServes the typefaces on our public pages; receives the standard request data any web server sees, including your IP addressUnited States

If we add or replace a provider that handles Customer Data, we will update this page.


6.Connected Google and Microsoft Accounts

A member of a business’s team can choose to connect their own Google or Microsoft account to MinMax Pro, so that jobs appear on their calendar, their busy time is respected when work is booked, and email to customers can be sent from their own mailbox. Nobody has to connect an account to use the product.

What we ask for. For Google: calendar.events (create, update and remove the events MinMax Pro puts on your calendar, and read events to find your busy time) and gmail.send (send mail on your behalf; it cannot read your inbox), together with openid and email to identify which account you connected. For Microsoft: Calendars.ReadWrite and Mail.Send for the same two purposes, together with openid, email and offline_access so the connection keeps working without asking you to sign in again. A calendar connection and a mail connection are separate, and you can make one without the other.

What we store. The access and refresh tokens the provider issues, encrypted at rest; the email address of the account you connected; and, from a connected calendar, the start and end time of each event, whether it is busy or tentative, and its title where the calendar provides one, so the schedule can show when you are unavailable.

What we send out. To a connected calendar we write the jobs assigned to you: the appointment title, the customer’s name, the service address and the start and end time. Prices and invoice amounts are never written to a calendar. Through a connected mailbox we send the emails you or your business send from MinMax Pro, and they appear in that mailbox’s sent items.

What we never do with it. We do not sell information from a connected account, do not use it for advertising, and do not use it to train artificial-intelligence or machine-learning models. It is used only to provide the calendar and email features described above. No person at MinMax Strategies reads it except with your consent, where it is necessary for security (such as investigating abuse), or where the law requires it.

Disconnecting. You can disconnect an account at any time from Settings in MinMax Pro, or revoke access from your Google or Microsoft account settings. Disconnecting in MinMax Pro revokes our access with the provider and deletes the stored tokens. Events already written to your calendar and emails already sent stay where they are, because they now live in your account, not ours.

MinMax Pro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

QuickBooks Online. A business can also connect its own QuickBooks Online company, which is a connection made for the workspace rather than for one person. Nothing is shared with Intuit until an admin of that business connects the company and presses Start Sync. From then on, and only at the business’s direction, MinMax Pro sends that company the customers, vendors, invoices, payments, bills and employee time entries recorded here. It sends hours, never pay rates. An admin can pause the sync or disconnect QuickBooks from Settings at any time, and what was already sent stays in its QuickBooks company, under Intuit’s own terms and privacy policy.


7.When we share information

Beyond the providers above, we share information only with our professional advisers under confidentiality obligations; with a government body or court where we are legally required to respond (and where we are permitted to tell you, we will); and with a successor if the business is merged or sold, in which case we will give account holders notice before their data moves. Nobody else.


8.How long we keep information

Retention
WhatHow long
Customer Data after a subscription endsAvailable for export for 30 days after termination. We delete it from active systems when you ask us to, and otherwise within 90 days after the account ends
Connected Google and Microsoft account tokensDeleted when the account is disconnected; otherwise on the same basis as Customer Data above
Account and contact recordsKept while the account is open, then deleted on the same basis
Invoices, payment records and signed agreementsKept as long as tax, accounting and limitation periods require
Encrypted backupsPurged on our infrastructure providers’ normal backup rotation. A backup copy can persist for a period after data is deleted from active systems
Authentication and security logsKept only as long as needed to investigate abuse and keep the service secure; expired sign-in tokens and rate-limit records are purged on a rolling schedule
Signup analyticsThe pseudonymous signup events described in section 2 are purged after 13 months

You can request earlier deletion at any time by emailing info@minmaxstrategiesllc.com. We will honor it except where we are required to retain records by law, or where the data belongs to a business customer rather than to you; see section 11.


9.Security and breach notification

Data is stored in the United States, with the exceptions the table in section 5 shows: address lookups are served by Geoapify in Cyprus, demo address lookups and map images by the OpenStreetMap Foundation in the United Kingdom, and page assets and the password breach check are served from global content delivery networks. It is encrypted in transit with TLS and encrypted at rest by our hosting provider. Access is scoped per organization at the database level, so one account cannot read another’s records. Our staff reach production data only when you ask us to as part of support, or where it is necessary to keep the service running, and that access is logged.

No system is perfectly secure and we will not claim otherwise. If a breach affects your personal information we will notify affected account holders without undue delay and in any case as required by applicable law.


10.Your rights and choices

You can access, correct, export or delete your information, and close your account, at any time. Most of it you can do yourself inside the workspace; for anything you cannot, email info@minmaxstrategiesllc.com and we will respond within 30 days, or sooner where the law requires. Where a request is unusually complex we may extend that period as the law allows, and we will tell you if so. We do not charge for a reasonable request and we will not treat you differently for making one.

Depending on where you live - including under state privacy laws such as California’s - you may have specific rights to know what personal information we hold, to correct or delete it, to receive it in a portable form, and to appeal a refused request. We honor those rights through the same address above, and an authorized agent may submit a request for you with proof of authorization. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. If we deny a request, our response will tell you how to appeal it.


11.If a business uses MinMax Pro to serve you

If you are a homeowner in a contractor’s client portal, a client of a consulting firm, or a vendor or subcontractor signed in to a business’s Vendor Portal, your relationship is with that business, not with us. They chose what to record about you and they control it; we hold it on their instructions. Send your access, correction or deletion request to them. We will help them act on it, and we will not act on it independently unless the law requires us to.

Texts and emails a business sends you through MinMax Pro. Reply STOP to any text to stop that business texting you; we keep a suppression record so the block holds even if their records change. Marketing emails carry an unsubscribe link that works the same way. Booking confirmations and receipts for work you ordered may still arrive, because they are part of the service you asked that business for. If a business is unresponsive to a privacy request and you cannot resolve it with them, you can also write to us at info@minmaxstrategiesllc.com and we will raise it with them.


12.Cookies and similar technologies

MinMax Pro sets what it needs to keep you signed in and to remember your preferences in your own browser, such as which industry view you last used. During signup it also stores the first-party analytics identifier described in section 2. There are no advertising cookies, no cross-site tracking, no third-party analytics services, and no third-party advertising pixels. Because we do not track you across other sites, there is no consent banner to dismiss. Our public pages load typefaces from Google Fonts, which receives the standard request data any web server sees, as the table in section 5 discloses.

Two third-party components run in your browser on specific pages, and both are listed in section 5:

  • Stripe.js loads on the signup page, in billing settings and on the client portal’s payment screen. Stripe may set its own cookies and collect device, browser and interaction signals there to prevent fraud, under Stripe’s own privacy policy. It is part of taking a payment securely, not advertising or analytics.
  • Map images on the staff scheduling page are fetched by your browser directly from OpenStreetMap’s tile servers, which see your IP address and the area of the map you are viewing. The map library itself is served by unpkg.
  • GIFs in team chat, where the GIF picker is enabled, are fetched by your browser directly from GIPHY or Tenor, which see your IP address and which GIF you are looking at. The search itself goes through our server, so they do not see who searched.

13.Automated decisions

MinMax Pro contains features that rank, suggest, forecast and alert: the order people are offered work in, overrun warnings, capacity and margin figures. These are decision support for the account holder, who sets the rules, can override any result, and can switch the features off. We do not use them to make decisions that produce legal or similarly significant effects about an individual without human review.


14.Children

MinMax Pro is business software, is not directed to children, and does not knowingly collect personal information from children under 13. If you believe a child’s information has reached us, tell us and we will delete it. You must be at least 18 to create an account, and do not enter a minor’s personal information into a workspace unless you have the right to hold it.


15.Changes to this policy

When we update this policy we will change the effective date at the top of the page. If a change materially reduces your rights or materially expands how we use personal information, we will give account holders at least 30 days’ notice by email or in-product notice before it takes effect.


16.Governing law

This policy is governed by the laws of the State of Michigan and applicable federal law. Disputes arising from it are subject to the jurisdiction of the state and federal courts located in Kent County, Michigan.


17.Contact us

Questions, concerns or requests regarding this policy, including privacy rights requests and security reports:

MinMax Strategies LLC
Grand Rapids, Michigan
info@minmaxstrategiesllc.com

See also the MinMax Pro Terms of Service and MinMax Strategies’ company-wide Privacy Policy.