This Privacy Policy explains how BIZY TECHNOLOGIES LLC, a Wyoming limited liability company trading as MightWork ("we," "us"), collects, uses, and protects information when you use our website, client dashboard, Chrome extension, and related services (the "Services"). You can reach us at [email protected] or (201) 770-6046.
Information we collect
- Account information — when you sign in, our authentication provider (Clerk) processes your name, email address, and profile image. If you sign in with Google or Facebook, we receive your name, email, and public profile from that provider.
- Lead and contact information — details you submit through our forms (name, email, phone, company, message).
- Usage data — pages visited, actions taken, and device/browser information, collected via analytics (PostHog and Microsoft Clarity), standard server logs, and the advertising and measurement tags described under Advertising and measurement.
- Business account data: from a Meta or Google account you connect from your dashboard, and from the ad accounts and pixels we create for you, we receive the account names and IDs, the ads, pages and profiles inside them, their performance and spend figures, and, only when you turn it on, the messages and comments your customers send them. See Connected business accounts.
How we use your information
- To provide, secure, and improve the Services and to authenticate your account.
- To respond to inquiries and deliver the leads and reporting you have requested.
- To measure and improve the performance of marketing campaigns.
MightWork Chrome extension
The extension connects to your existing MightWork account to display approvals, requests, leads, customer conversations and, for authorized staff, the team’s work queue. It sends your decisions, replies, selected files and lead-stage changes to MightWork when you take those actions. Access follows your account and workspace permissions.
Clerk uses cookies on our authentication host and extension storage to synchronize your sign-in and maintain authentication. Workspace records and unfinished drafts stay in the panel’s memory while it is open; drafts are discarded when the panel closes. Files you choose or drop into a request are uploaded to private storage and retained with the request under the retention practices described below.
The extension does not read unrelated websites, browsing history, clipboard contents or screenshots. It does not sell user data or use it for advertising. Extension data is used to provide and secure the workspace features you request, with Clerk for authentication and our hosting and storage providers for delivery. Those providers also process connection information, such as your IP address, for security and service delivery. You can sign out or uninstall the extension at any time. To request deletion of stored account, request or uploaded-file data, contact [email protected].
Our use and transfer of data received through the extension follow the Chrome Web Store User Data Policy, including its Limited Use requirements.
Signing in with Google and Facebook
If you choose to sign in with Google or Facebook, we receive basic profile information (name, email, profile picture) solely to create and secure your account. We do not post to your social accounts, and we request only the minimum permissions needed to sign you in. You can revoke access at any time in your Google or Facebook account settings. Connecting a business account, described next, is a separate choice with its own permissions.
Connected business accounts (Meta and Google)
From the client dashboard you can connect business accounts you already own so we can run marketing in them for you: a Meta ad account, Facebook Page and Instagram professional account, a Google Ads account, a Google Business Profile, and a Google Calendar. Each connection is a separate choice, made through the platform’s own consent screen, and each asks only for the permissions that service needs. Who holds an account is a different question from what we do with its data: accounts, pixels and campaigns we set up for you are held in our business accounts, as the “Marketing accounts and assets” section of our Terms describes, and what we do with their data, whose data it is, and the Google API Services commitment below apply to them just the same. “Disconnecting” below is about accounts you connected yourself; what happens to accounts we set up when you leave, including the export of your customer data, is in that same Terms section.
- What we do with it. Create and manage ad campaigns in the ad accounts you connected or we created for you; publish, schedule and reply to posts on your Page and Instagram; keep your Business Profile accurate and reply to reviews; read performance and spend so your dashboard can show what each lead and booked job cost; and offer booking times that do not clash with your calendar. Ad spend stays on your own payment method.
- Messages and comments. If you turn on message handling, we read and reply to conversations your customers start on your Page or Instagram account, on your behalf and in your name, so that no inquiry goes unanswered. Conversation content is kept only for as long as you use that feature and is never used for advertising to those customers.
- Only your own accounts. Data from a connected account is used for that business only. It is never shared with other clients, sold, or used to train our AI models or anyone else’s.
- Disconnecting. You can disconnect any account from the dashboard at any time, or remove MightWork from your Facebook business integrations or Google account permissions. We delete the stored access token immediately and the account’s data within 30 days, except where a law or a signed agreement requires us to keep it longer. Deletion requests are also handled as described on our Data Deletion page.
- Google API Services. MightWork’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as needed to provide the Services, and never for advertising or resale.
Store connections and lead delivery
When a workspace owner connects Shopify or installs our WooCommerce plugin, new orders can create contacts in that workspace’s Leads inbox. We keep the customer’s name, email, phone and company when available, together with the store and order identifiers needed to identify the source and prevent duplicate imports. Shopify customer identifiers also help us handle access and deletion requests. These connectors do not import card numbers, payment credentials or purchased product lists into the Leads inbox.
We process these contacts on the merchant’s behalf to provide the connection and support its customer relationships. Importing an order does not grant consent to marketing texts or email. The merchant is responsible for its customer notices and the permissions needed for any follow-up. If an owner enables Zapier or another lead destination, the contact fields are sent to that destination under the owner’s configuration; its provider’s privacy terms also apply.
Pausing or disconnecting a connector stops future imports or deliveries; it does not by itself remove contacts already imported or copies sent to another service. Shopify customer-deletion requests remove the matching imported contacts, and verified shop removal requests remove that shop’s imported contacts and installation records. If a shop’s installation status cannot be verified automatically, staff review the request before erasure to protect an active or reinstalled connection. Workspace owners can download Shopify customer-access requests from Connections. For access or deletion assistance, follow our Data Deletion instructions.
Setup, data flow and removal instructions are in our Shopify, WooCommerce and Zapier guides. Availability and marketplace approval are stated in each guide.
Text messages (SMS)
If you give us your mobile number, we text you from (201) 770-6046, (209) 315-3622 or (833) 377-2603 about the thing you asked for — your consultation, your report, an appointment you booked, or a reply to your question. You can stop it at any moment by replying STOP. Offers and marketing are a separate yes. Every form that asks for a number carries a box for each, and neither is ticked for you. Consent to texts is never a condition of buying anything. These are recurring messages: message frequency varies, typically fewer than 6 per month, and message and data rates may apply. Reply STOP to end messages or HELP for help. Full detail is in our SMS Terms & Conditions.
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. In plain terms: we share your number only with the subcontractors who carry the message on our behalf, and only for that purpose. None of the sharing categories below covers your text-messaging opt-in data or consent.
How we share information
We do not sell your personal information for money. We share it with service providers who process it on our behalf, including Clerk (authentication), Vercel (hosting), PlanetScale (database), Cloudflare (delivery and security), PostHog and Microsoft Clarity (analytics), and Resend (email); with Meta and Google through the advertising and measurement tags described next; and where required by law.
Advertising and measurement
Our website uses tags from Meta (the Meta Pixel), Google Ads, and Google Analytics. These set cookies or similar identifiers in your browser and tell those companies which of our pages you visited and what you did there, for example whether you started a form, sent an inquiry, or booked a call. Meta and Google can collect this information over time and across other websites, and use it to measure our ads and to show you ads, including ours.
When you send us an inquiry or create an account, we also give Meta a scrambled (hashed) copy of the contact details you entered, such as your email address, phone number, and name, from your browser and from our server, so Meta can tell which of our ads led to it. Hashing turns each detail into a code that Meta can only match against information it already holds; we never send it the details in readable form.
With that inquiry or purchase, our server also sends Meta your IP address, your browser type, the Meta Pixel's cookie, and the page you were on, the same details your browser sends Meta directly. We keep them for 30 days for this purpose only. If your browser sends a Global Privacy Control signal, our server does not collect or send them.
On a website or funnel we run for one of our clients, that business chooses which of these tags run, and its own privacy policy applies.
Your choices. You can block or delete cookies in your browser settings, and you can control ads from these companies at Meta ad preferences, Google My Ad Center, and the Digital Advertising Alliance opt-out. Google offers a browser add-on that stops Google Analytics.
How we protect your information
Security procedures are in place to protect the confidentiality of your data, including the Google user data and Meta data we receive from a connected account.
- Encryption in transit. Every connection to the Services, and every call we make to Google, Meta and our service providers, uses HTTPS (TLS). We do not accept plain HTTP.
- Encryption at rest. The access and refresh tokens that let us act in a connected Google or Meta account are encrypted with AES-256-GCM before they are written to our database, using a key that is held outside the database and is never stored in our source code. Plaintext tokens exist only in memory for the length of the request that needs them. The database itself, and our backups of it, are encrypted at rest by our database provider.
- Access control. Each connected account belongs to one client organization, and every request to read or act in it is checked against the signed-in user’s membership of that organization. Staff access is limited to the people who operate the Services for you, and goes through the same authenticated sign-in as yours.
- Minimum permissions. We request only the scopes a feature needs, and nothing runs until you have granted them on the platform’s own consent screen. Tokens are deleted from our systems when you disconnect, as described above.
- Secrets and infrastructure. API keys and encryption keys are stored encrypted and injected into the running service, never committed to source control. Our hosting, database, and delivery providers (Vercel, PlanetScale, and Cloudflare) maintain their own SOC 2 programs and physical security.
- Incidents. If we learn of a breach affecting your data, we will notify you without undue delay, and within any period the applicable law sets, with what we know and what we are doing about it.
Data retention and deletion
We keep personal information only as long as needed to provide the Services or as required by law. You can request access to or deletion of your data at any time — see our Data Deletion instructions or email [email protected].
Session replay
On our own public pages we record how the page was used: clicks, scrolling, the pages visited, and what you type into our forms, so we can see where a form is confusing or broken. Passwords are never recorded. Recording does not run on our clients' sites, on your own dashboard once you are signed in, or on any page reached through a private link. PostHog strips query strings from recorded links. Microsoft Clarity provides heatmaps and recordings with input boxes and dropdowns masked. It also collects device information, interactions, full page URLs and link destinations. URL query parameters may include prefilled names, email addresses or analytics identifiers. The answers you send us are already held as your inquiry, described above; the recording adds no new category of data about you.
Our own sign-up is the one exception, and we record it all the way through, including the steps after you create an account, because where a sign-up gets stuck is a question no other page can answer. The same rules apply: your password and email sign-in code are never recorded, and your card is entered in Stripe's own frame, which we block from every recording, so we never see a card number. Nothing about your workspace is recorded once you leave the sign-up.
Cookies
We use essential cookies to keep you signed in and to secure the Services, analytics cookies to understand usage, and advertising cookies from Meta and Google, described under Advertising and measurement. You can control cookies through your browser settings.
Changes to this policy
We review this policy at least once a year and update it when our practices change. The date at the top of the page is when it last changed, and the current version applies from the day it is posted.
Using information we already hold in a materially different way from the purpose it was collected for is not something a posted edit can do on its own, and we do not treat it as though it were. We will email you before a change like that takes effect, and where the law requires your consent we will ask for it rather than assume it.
Two things do not change by being edited. The mobile-information carve-out quoted above is not narrowed by any later version of this policy, and your right to request an export or deletion of your data survives every change to it.
Contact us
Questions about this policy? Email [email protected], call (201) 770-6046. Postal mail: BIZY TECHNOLOGIES LLC, 15442 Ventura Blvd, Ste 201-2355, Sherman Oaks, CA 91403, USA.