1. Who We Are, and the Two Roles We Play
Molecule Work LLC ("we," "us," or "our") operates My Molecule, a scheduling platform for service businesses such as barbershops. To understand this policy, one distinction matters more than anything else — who is responsible for which data:
- Data we are responsible for (our own role): your account information when you sign up, the technical data our systems generate, and — if you book with more than one business on the platform — a consumer profile that connects your bookings across those businesses (described in Section 3).
- Data a business is responsible for (our service-provider role):when a barbershop or other business enters or collects information about its clients through the platform — names, phone numbers, appointment history, notes, intake forms — that business decides how the information is used. We process it on the business's behalf, under our agreement with them. If you want to know how a specific business uses your information, ask that business; we will help them respond (Section 8).
2. Information We Collect
2.1 Account Information
- Name and email address
- Phone number (if you provide it, or use phone sign-in)
- Password (stored only as a secure hash — we cannot read it)
- Profile details you choose to add
2.2 Business Account Information
- Business name, type, address, and contact information
- Staff and provider details (names, roles, schedules)
- Services offered, pricing, and business settings
2.3 Booking and Client Data (processed for businesses)
- Client names and contact information a business enters or a client provides when booking
- Appointment dates, times, services, and booking history
- Notes, messages, and form responses connected to a business relationship
- Photos and media a business uploads
A business can record clients who have no account with us at all (for example, walk-ins). That information belongs to the business's records; we store and process it on their behalf.
2.4 Payment Information
Payments are processed by Stripe. Card numbers go directly to Stripe and never touch our servers; we store only payment references, statuses, and amounts. Stripe's privacy policy applies to the payment data it handles.
2.5 Technical Data
- IP address, device and browser information
- Log, error, and performance data (see Section 5 on monitoring)
- Session information needed to keep you signed in
3. The Cross-Business Consumer Profile
If you create an account and book with more than one business on the platform, we maintain one consumer profile for you that your bookings connect to. This is what lets you see your appointments across businesses in one place and manage your notification preferences once. We maintain this profile for your use — we do not share one business's records about you with another business, and we do not use the profile to advertise to you.
4. How We Use Information
- Operating the platform: scheduling, reminders, payments, and the features businesses and their clients use
- Sending transactional messages (booking confirmations, reminders, receipts) — with marketing messages sent only under the consent controls described in Section 9
- Securing the platform, preventing fraud and abuse, and debugging problems
- Meeting legal obligations, including keeping records of consent and of privacy requests
We do not currently run third-party product-analytics tools. If we add one, we will update this policy and our subprocessor list first, and any optional analytics will be controlled by the cookie preferences described in Section 10.
5. Who We Share Information With
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:
- Service providers (subprocessors): the vendors that run parts of the platform under contract — hosting, payment processing, email and SMS delivery, file storage, error monitoring, and mapping. The current list, what each one does, and what data it handles is published at mymolecule.ai/subprocessors. We update that page when the list changes.
- The business you interact with: when you book with a business, that business sees the information connected to your bookings with them.
- Mobile messaging information: your phone number doubles as the contact number for your booking, and your SMS choices govern which texts you receive. We will not share or sell your mobile information with third parties for promotional or marketing purposes. Replying STOP to any text ends messages immediately (see the SMS Program & Opt-In notice).
- Services you or a business choose to connect: when a business connects an outside service to its account — for example, syncing its calendar with Google or Microsoft, or connecting its Google Business Profile for reviews — the data needed for that feature flows to that service at the business's direction. Signing in with a social account (where offered) shares sign-in data with that provider.
- Legal requirements: when required by law, legal process, or to protect rights and safety.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.
5.1 Advertising Pixels a Business May Configure
A business can connect its own advertising and analytics tags (such as Google Analytics, Google Ads, Meta, or TikTok pixels) to its public booking pages. Those tags belong to and are configured by the business, run only on that business's booking pages, and send data to the business's own accounts with those providers — not to us. The business is responsible for its use of these tools and for any disclosures they require.
5.2 Error Monitoring
We use Sentry to detect errors and performance problems. Sentry receives technical data such as IP address, device and browser information, and error details. A small random sample of sessions — and sessions in which an error occurs — are recorded for debugging, with text content masked and media blocked in production. If you use the in-product feedback tool, the screenshot you choose to attach is included with your report.
6. Data Security
- Encryption in transit (TLS)
- Encryption at rest (AWS KMS-managed keys) for the databases and server volumes our cloud environments are provisioned with
- AES-256-GCM encryption for stored calendar-integration credentials
- Passwords stored only as secure hashes
- Role-based access controls and per-business data isolation
- A tamper-evident audit log of sensitive administrative actions (account impersonation, financial adjustments, review moderation)
- Automated security scanning of our code and dependencies in our development pipeline
No method of transmission or storage is 100% secure. If you believe you have found a security issue, contact [email protected] — it routes directly to our founder.
6.1 If a Breach Happens
If a security breach affects your personal information, we will notify you without undue delay, consistent with the law of your state of residence (for Colorado residents, no later than 30 days after we determine a breach occurred, as Colorado law requires), and we will notify regulators where the law requires it. Where a breach affects data we process on a business's behalf, we will notify that business promptly and cooperate with its response.
7. Data Retention and Deletion
How long data is kept depends on whose records it is:
- Business records(appointments, invoices, payment records, client records a business keeps): retained for as long as the business maintains them — these are the business's operating and financial records.
- Consent and privacy-request records: we keep evidence of consent, opt-outs, and privacy requests for as long as the law gives those events legal significance (for consent records, approximately seven years, matching the limitation periods that apply to messaging claims).
- Account data: kept while your account is active.
What deletion means here.When personal information is deleted through a privacy request, we scrub identifying details (name, contact information) from the affected records and deactivate them. Transactional skeletons — for example, that an appointment occurred on a date, or that an invoice was paid — may be retained where they are part of a business's financial records or ours, without your identifying details attached. To request deletion, see Section 8.
8. Your Privacy Rights and How to Use Them
We operate a request system supporting six kinds of privacy request, tracked with a 45-day response target: access ("right to know"), deletion, correction, a portable copy of your data, opting out of any sale or sharing (noting we do not sell or share), and limiting the use of sensitive information. Depending on your state of residence, some of these are legal rights; we honor reasonable requests of these kinds regardless of where you live. We will verify your identity before acting, and you will not be discriminated against for making a request.
- For information a business holds about you(your appointments, client record, forms): contact that business — they can open and track your request in the platform's privacy request system, and we assist them in fulfilling it.
- For your account or anything else: email [email protected].
9. Communications Preferences
- Marketing messages: marketing is not sent to anyone whose opt-out a business has recorded, and marketing texts are never sent outside the hours the law allows.
- Opting out: tell the business — the opt-out they record stops marketing sends immediately — or reply STOP to any text (the carrier-level block takes effect right away), or email [email protected] and we will record it for you. Marketing emails also carry an unsubscribe link and a preference page; we are completing the wiring that connects those page settings to every send path, and until it lands the routes above are the guaranteed ones.
- Records: consent and opt-outs recorded by a business are kept in an append-only ledger, so recorded choices stick.
10. Cookies, Storage, and Signals We Honor
We use a small set of first-party cookies and browser storage:
- Essential (always on): authentication and session cookies that keep you signed in and secure. These cannot be disabled without breaking sign-in.
- Preferences: your cookie choices and interface settings (such as theme), stored in your browser.
- Analytics: we do not currently set analytics cookies. If we add product analytics, it will be off unless the analytics category in the cookie banner is accepted, and this section will be updated first.
Global Privacy Control. We do not sell or share personal information, so there is nothing a sale-or-sharing opt-out signal needs to stop today. We honor Global Privacy Control anyway: when your browser sends the signal while you are signed in, we automatically record a marketing opt-out in our consent system across the businesses your account is linked to. Appointment confirmations and other messages about services you booked are not affected.
A business's own booking pages may set third-party cookies from advertising tags that business has configured (Section 5.1); those are governed by the business and the tag provider.
11. Children's Privacy
The platform is a business tool and is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact [email protected]and we will delete it. Businesses that record information about minor clients (for example, a parent booking a child's haircut) are responsible for doing so lawfully.
12. Where Data Is Processed
Molecule Work LLC is a United States company, and the platform is operated from the United States. If you use it from outside the US, your information will be transferred to and processed in the US, where privacy laws may differ from those of your country.
13. California and Other State Residents
We do not sell personal information, and we have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising. Residents of states with comprehensive privacy laws (including California, Colorado, Virginia, Connecticut, and Texas) can exercise the rights those laws provide through the channels in Section 8.
14. Changes to This Policy
When we make material changes, we will update the date at the top of this page and notify you by email or in the product. Because this policy describes how the platform actually works, it changes when the platform's data practices change.