Privacy Policy & Data Governance
How MarSimple manages advertising analytics, Meta Marketing API data, and clinic communications with medical-grade encryption, zero cross-tenant commingling, and strict data isolation.
Our Plain-English Privacy Guarantee
MarSimple connects to your clinic's advertising accounts (including Meta and Google) to build campaigns, report booked patients, and optimize conversion efficiency. We never sell, rent, or commingle your business or patient data. Each clinic's data is strictly isolated.
01Overview & Company Information
This Privacy Policy describes how MarSimple(“Make Marketing Simple”, “we”, “us”, or “our”) collects, uses, processes, and protects your information when you access our website at marsimple.com, use our marketing analytics platforms, connect via third-party developer integrations (such as the Meta Marketing API and Google Ads API), or utilize our clinic lead tracking services.
MarSimple operates marketing analytics, automated ad management, and patient attribution software specifically engineered for independent and multi-location healthcare clinics (dental, physiotherapy, chiropractic, and medical practices).
By connecting an advertising account, submitting an inquiry form, or accessing MarSimple tools, you acknowledge the practices outlined in this Policy.
02Information We Collect
We only collect data necessary to configure, measure, and optimize advertising campaigns and clinic lead operations:
Name, professional email, phone number, clinic name, website URL, physical postal location, and billing address provided during demo requests, account onboarding, or service agreements.
Campaign IDs, ad set structures, creative copy, aggregated impressions, clicks, advertising spend, cost-per-lead, and conversion events retrieved from connected ad platforms.
When you authorize MarSimple to manage your Meta Ad Accounts or Pages via Meta Login / OAuth, we retrieve authorized Ad Account metadata, Lead Ad webhook payloads, and performance analytics.
Inbound phone call timestamps, audio recordings (where enabled with patient consent for quality assurance), call transcripts, and web appointment request form submissions for accurate attribution.
03How We Use Advertising & Lead Data
We process your data strictly to deliver contracted advertising and clinic growth services:
- Campaign Creation & Management: Configuring targeted search, maps, and social advertising campaigns for your specific local practice service radius.
- Conversion Tracking & Attribution: Connecting ad clicks to actual booked patients to calculate true cost per booked patient and eliminate unprofitable keywords.
- Audience Synchronization: Synchronizing custom or offline conversion events via Meta Conversions API (CAPI) and Google Enhanced Conversions to improve bidding algorithms.
- Automated Lead Routing: Routing inbound patient inquiries and missed call text follow-ups directly to clinic front-desk teams or our Mary AI reception system.
Strict Data Isolation Guarantee
Every clinic client operates within a strictly isolated, multi-tenant container.
We maintain an ironclad policy: Client and customer data is strictly isolated per clinic/business account and is never commingled.
- No Commingling: Ad performance, lead records, and patient inquiries from Clinic A are logically and cryptographically partitioned from Clinic B.
- Zero Sale or Rental: We never sell, rent, lease, trade, or monetize client or customer data to third-party data brokers, ad networks, or external buyers.
- No Cross-Clinic Retargeting: We do not pool audiences across practices. Custom audiences created for your clinic are used exclusively for your practice.
05Meta Marketing API & Platform Data Compliance
MarSimple integrates with the Meta Marketing API, Meta Graph API, and Meta Lead Ads Webhooks (operating under Meta Platforms, Inc. Developer Terms). When your clinic authorizes our application:
1. Permitted Scopes & Purpose
We request access tokens solely with scopes necessary to read ad performance (ads_read, read_insights), manage campaigns (ads_management), and retrieve authorized lead forms (leads_retrieval).
2. Token Security & Revocation
User and Page access tokens are encrypted using AES-256 before storage in Google Cloud Secret Manager. Tokens are never exposed to browser clients or logs and are immediately revoked when a client disconnects.
3. Adherence to Meta Developer Policies
We strictly comply with Meta's Commercial Terms, Platform Terms, and Developer Policies: we do not transfer Meta user data to ad networks, do not use Meta data to profile users outside your clinic's direct ad account, and adhere to all data minimization mandates.
06Disclosed Third-Party Service Providers
To operate our high-reliability platform, MarSimple partners with industry-leading infrastructure and API providers. Each partner is bound by strict Data Protection Agreements (DPAs):
| Provider | Role / Service | Data Transferred | Privacy Reference |
|---|---|---|---|
| Meta Platforms, Inc. | Marketing API, Lead Ads, Conversions API | Ad account metrics, campaign objects, hashed offline conversion signals | Meta Policy |
| Google Cloud & Google Ads | Cloud Hosting, KMS Encryption, Ads API, GA4 | Application database, encrypted tokens, website analytics, keyword metrics | Google Privacy |
| Twilio Inc. | Telephony routing, call tracking, SMS notifications | Clinic phone numbers, call metadata, caller phone number, SMS body | Twilio Legal |
| Stripe, Inc. | PCI-DSS compliant subscription billing & payments | Client credit card details (tokenized directly by Stripe, never stored on MarSimple servers) | Stripe Privacy |
User Data Deletion Instructions
In accordance with the Meta Platform Terms, GDPR (Article 17 “Right to Erasure”), and PIPEDA, MarSimple provides a clear, accessible process for users and businesses to request permanent deletion of any data associated with their accounts.
AHow to Revoke Permissions & Disconnect via Facebook
You can remove MarSimple's authorization from your Facebook account at any time:
- Log in to your Facebook profile or Meta Business Suite account.
- Navigate to Settings & Privacy > Settings.
- In the left menu, select Apps and Websites.
- Find MarSimple in the list of active applications.
- Click Remove to immediately revoke all tokens and permissions.
- (Optional) Check the box to request that Facebook notify MarSimple to delete past data collected.
BHow to Request Complete Data Purge via Email
To request that MarSimple permanently delete all personal data, cached Meta Lead Ads records, or account records:
- Send an email from your authorized account address to: privacy@marsimple.com (with CC to support@marsimple.com).
- Use the subject line:
Data Deletion Request - [Your Clinic Name]. - Include your full name, business email, connected Facebook Ad Account ID / Page ID (if applicable), and phone number.
Timeline & Confirmation Confirmation Guarantee
Upon receipt of your request, our privacy officer will verify identity and permanently delete all tokens, leads, and contact records across production databases within 30 calendar days. We will reply to your request with an official Confirmation of Data Erasure report and transaction reference code.
08Healthcare Privacy & Patient Records
For our clinic partners, MarSimple operates strictly as a Service Provider / Data Processor. All patient records, incoming calls, treatment inquiries, and appointments generated through advertising campaigns belong solely and exclusively to your clinic.
- No PHI on Public Ad Networks: We never transmit Protected Health Information (PHI) or identifiable clinical diagnoses to advertising ad pixels or social ad platforms.
- Encrypted Call Recordings: Audio records are stored with AES-256 encryption at rest on Google Cloud Storage and automatically expire according to clinic-configured retention policies.
- Compliance Alignment: Our infrastructure workflows align with HIPAA (Health Insurance Portability and Accountability Act) and PIPEDA (Personal Information Protection and Electronic Documents Act) standards.
09Data Security & Retention Limits
We implement robust technical and organizational security controls to protect client information against unauthorized access, alteration, disclosure, or destruction:
All data moving between web browsers, APIs, and microservices is encrypted with modern TLS 1.3 ciphers.
Databases, storage buckets, and credentials are encrypted at rest with hardware-backed KMS encryption keys.
Role-based access controls and mandatory multi-factor authentication (MFA) on all production operational environments.
Retention Policy: We retain marketing campaign performance data for the duration of the active client relationship to provide longitudinal performance trends. If an account is closed, operational data is purged within 90 days, except for legal accounting records required by commercial tax statutes.
10Contact Information & Data Protection Officer
If you have questions regarding this Privacy Policy, wish to exercise your data subject rights, or need assistance with Meta developer token revocation, please contact our dedicated Privacy Office:
Attn: Data Protection Officer (DPO) & Compliance Team
Privacy inquiries and data deletion requests are reviewed within 48 business hours and fulfilled within 30 days.