Privacy and data handling
Privacy Policy
This policy explains how MarginPilot handles information supplied through customer accounts, the website, CSV Profit Leak Check, checkout, paid reports, and support contact.
Last updated: 15 July 2026
1. Who operates MarginPilot
Margin Pilot is operated by Matthew Wisniewski, an Australian sole trader, ABN 47 418 049 389. Support enquiries can be sent to support.marginpilot@gmail.com.
2. Information we may handle
Depending on how you use MarginPilot, information may include your name, business name, email address, account-security records, support messages, payment confirmation details, order-export CSV files, and the business or order information contained in those files.
MarginPilot does not store account passwords in readable form. Passwords are converted into salted cryptographic hashes. One-time recovery codes are also stored only as hashes. Active sign-in sessions are represented by random server-side records and a browser cookie.
3. CSV uploads
The free CSV Profit Leak Check temporarily stores an uploaded file on the application server while the file is parsed and analysed. The current application deletes the temporary upload after normal processing and known processing errors. A technical interruption may occasionally leave a temporary file until maintenance cleanup occurs.
Only upload files you are authorised to use. Remove unnecessary customer information where practical, and do not upload customer lists, sensitive information, passwords, banking credentials, or unrelated personal data.
4. Why information is used
- To process an uploaded CSV and produce a Leak Score or operational result.
- To create, secure, recover, and manage a MarginPilot customer account.
- To prepare a paid report or respond to a paid-service request.
- To process support, delivery, billing, refund, or cancellation enquiries.
- To protect, maintain, troubleshoot, and improve the service.
- To comply with legal obligations where required.
5. Sharing and service providers
MarginPilot does not sell customer data. Information may be processed by service providers needed to operate the service, including website hosting, Stripe for payment processing, and Google/Gmail for email communication or files deliberately supplied for a paid report. Those providers operate under their own privacy and security terms and may process information in Australia or overseas.
MarginPilot does not receive or store your full payment-card number when payment is made through Stripe.
6. Cookies and sign-in sessions
MarginPilot uses a strictly necessary sign-in cookie to keep an account signed in. The cookie is marked HttpOnly and SameSite so normal website scripts cannot read it and cross-site requests are restricted. The cookie is not used for advertising. Signing out, changing the password, recovering the account, or deleting the account invalidates the relevant server-side session records.
7. Retention
Free-check CSV uploads are not intended to be kept as permanent customer records. Account records are retained while the account remains open and are removed when the customer uses the account-deletion control, subject to information that must reasonably be retained for security, dispute resolution, or legal obligations. Limited security audit records may be retained to investigate misuse or account incidents. Paid-report files, reports, invoices, payment confirmations, and support correspondence may be retained for as long as reasonably needed to deliver the service, keep business records, resolve disputes, or meet legal obligations.
8. Security
Reasonable technical and organisational steps are used to reduce unauthorised access, loss, misuse, or disclosure. These include password hashing, rate limiting, server-side sessions, restricted session cookies, cross-site request protection, temporary upload handling, and restricted access to account storage. No internet service can guarantee absolute security, so customers should use a unique password, keep recovery codes private, and minimise unnecessary personal information before uploading a file.
9. Access, correction, deletion, and questions
A signed-in customer can delete their MarginPilot account from the account page. To ask what other information MarginPilot holds about you, request a correction or deletion where available, or raise a privacy concern, email support.marginpilot@gmail.com. Include enough detail to identify the relevant account, upload, purchase, or conversation without sending a password or recovery code.
10. Changes to this policy
This page may be updated when the service, providers, or information-handling practices change. The date above shows the latest published version.