Privacy Policy
Effective: 23 September 2026 · Controller: Reachmark (“we”, “us”) · Contact: reachmarkofficial@gmail.com
This policy explains what personal data Reachmark collects, why, who sees it, and the rights you have. The service is for people aged 18 and over.
1. Data we collect
- Account data. When you sign up: your name, e-mail address, and a salted hash of your password (we never store the password itself). If you sign in with Google or Microsoft we receive your name and e-mail address from them — never your provider password.
- Business lead data. The workspace stores business information you add or discover: business names, categories, cities, e-mail addresses, phone numbers, websites, notes, and your outreach history with them.
- Networking content. Digital business cards you create, event records, scanned card photos you upload, booking requests visitors submit on your booking page, and webhook delivery logs.
- Communications. E-mails you send through the service (kept in the mail log with the contact basis you confirm), enquiry messages, and support chats.
- Technical data. Hashed IP identifiers used only for rate-limiting and abuse prevention, and strictly-necessary cookies (session, CSRF token, language preference). We run no cross-site tracking of our own; pages that show Google AdSense are subject to Google's own cookies (see Disclosures).
- Payments. Paid plans are processed by Paystack. Card details go directly to Paystack — we only keep the plan, amount, currency, and payment status.
2. Why we use it (legal bases)
- To provide the service you signed up for (contract): accounts, workspace, lead tools, e-mail sending, bookings.
- With your consent: verification e-mails, marketing/newsletter where you opt in (unsubscribe any time).
- Legitimate interests: security, abuse prevention, and product improvement — balanced against your rights and never involving sale of data.
- Legal obligations: tax/accounting records and complying with lawful requests.
3. Who sees your data
- Google / Microsoft — only to verify your identity when you choose social sign-in.
- Your SMTP provider — to deliver e-mails you approve for sending.
- Railway (hosting) — where the service and its database run.
- Paystack — to process plan payments.
- Webhook endpoints you configure — lead events are pushed only to URLs you add yourself.
We do not sell personal data, and we do not share it for third-party advertising.
4. Your rights
You may request access, correction, export, or deletion of your personal data at any time by e-mailing reachmarkofficial@gmail.com. Clients can also export or close their account directly from the app, which removes the account record. Opt-outs are permanent: addresses on the suppression list are never mailed again, even if re-imported.
5. Retention
Account and workspace data is kept while your account is active. Mail logs and suppression entries are kept for legitimate-interest and compliance purposes (to prove consent/basis and to honour opt-outs). Backups age out on the host's normal cycle.
6. Security
Transport is encrypted (TLS), passwords are salted hashes, owner areas are credential-gated, and webhook calls carry HMAC signatures. No system is perfectly secure; if we discover a breach affecting your data we will notify you and take reasonable remediation steps.
7. International transfers
The service is operated from Lagos and hosted on cloud infrastructure that may process data outside your country. By using the service you consent to such transfers as needed to provide it.
8. Children
Reachmark is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has provided data, contact us and we will delete it.
9. Changes
We will post material changes here with a new effective date. Continued use after changes take effect constitutes acceptance.