Skip to content
Madison Point

REVIEW BY COUNSEL — this page states what the product actually does; it has not been reviewed by a lawyer.

Privacy Policy

Last updated September 26, 2026

Who we are

Madison Point (“we”, “us”) is a social media planning product for restaurants, spas, and salons. This policy covers the client portal you sign into and the account it’s attached to. This marketing website is a separate, static set of pages that sets no cookies of its own and runs no analytics — everything below describes the portal, not the page you’re reading right now.

What we collect

  • Your business profile — your business’s name, its web address on our system, your email, your business type, your timezone, your city and state, the brand voice you’ve told us to write in, and your booking link.
  • Details for everyone you add to the account — name, email, a hashed password (never the password itself), their role, and whether the account is currently locked out after too many failed sign-ins.
  • The photos and documents you upload — the files themselves, held in Cloudflare R2 (see below); what our vision model records about a photo (things it sees, the setting, the mood, suggested categories); any alt text or notes you add; and the file’s size and dimensions.
  • What you sell — your menu items or services: name, description, price, category — whether you typed them in yourself or they came from a document you uploaded and then approved. If it came from a document, we also keep a record of every line that document produced, including the lines you chose not to add — visible on your own import history page.
  • Billing state Stripe hands back to us — once a subscription exists, we keep Stripe’s own customer and subscription ids, your subscription’s status (trialing, active, past due, canceled, or unpaid), and the time of the last billing event we’ve processed. This is separate from what we send Stripe in the first place, described below.
  • An account-level API key, hashed — generated when your account is created; we store only its hash, the same way we store a password. Nothing in the product uses this key yet.
  • What you ask for when you request a set of options — the period and posting cadence you chose, plus anything you typed into the request: any notes, and the name, date range, and detail line for any holiday, special, or event you added. This is kept and shown back to you on your own plans page, the same as everything else here.
  • The plans, captions and schedules generated for you — each strategy’s name and rationale, its calendar, and each entry’s caption, hashtags, call to action, and scheduled time.
  • The numbers you type in yourself — reach, likes, comments, and saves, for something you’ve shared after you published it — we don’t receive this data from Instagram or Facebook.
  • Security and audit records — a log of sign-ins, password resets, and account changes; and a separate error log that helps us fix problems, whose entries can include an email address when the problem happened while we were trying to send you mail.

How we use it

We use this to plan your calendar, tag your photos so a caption can be matched to the right shot, draft entries grounded in your own catalog and photos, and show you how a period actually went once you’ve worked it. The vendors below are the only outside parties your information reaches, and each one receives only what’s described next to its name — we don’t sell it, and we don’t hand it to anyone else.

Who else processes it

  • Anthropic, the AI provider behind tagging and planning — in three separate calls, each scoped narrowly:
    • Tagging a photo: the image bytes and a prompt naming your business type (restaurant, spa, or salon) — never your account or user identifier.
    • Reading a menu or service-list document you upload: the document’s bytes (a PDF or a photo of it) and that same kind of prompt — again, no account or user identifier.
    • Planning a period, or rewriting a single entry’s caption: your brand voice, city and state, booking link, any notes you added to the request, your catalog, and the tags already recorded on your photos — sent as text, not the photos themselves.
  • Cloudflare R2 — where your uploaded files are actually stored. Your browser sends them there directly, using a short-lived signed link, so the upload itself never passes through our own web server. Our background worker later reads those bytes back out of storage when it’s time to tag a photo or read a document — including sending them on to Anthropic, described above, for exactly that purpose.
  • SendGrid — for exactly two kinds of email. A password reset: your address and the reset link, which expires after 30 minutes. A welcome, set-your-password invite, sent only when our staff set your account up for you: your address, your account’s display name, and the invite link, which expires after 7 days.
  • Stripe — your billing email, and your account’s id and web address, when a subscription is created.
  • Sentry, for error monitoring — errors only, configured to leave personal data out by default; as of this writing it isn’t even turned on in production, so nothing reaches it today.

Cookies

The portal sets four cookies, and nothing else:

  • madisonpoint_session — signed, HttpOnly, and expires after 8 hours. This is what keeps you signed in.
  • madisonpoint_acting_as — signed, HttpOnly, and expires after 30 minutes. It’s only ever set while a member of our staff is acting as your account to help troubleshoot something, and it’s always visible on screen as a banner while it’s active.
  • reset_token — HttpOnly, and expires after 30 minutes or as soon as you finish using it, whichever comes first. It only appears on the page you land on right after clicking a password-reset or account-invite link, holds that link’s own token so it doesn’t sit exposed in your browser’s address bar or history, and is removed the moment you’re done.
  • csrf_token — expires after 24 hours. It is not HttpOnly, because the page itself has to read it and send it back with every form you submit, to prove the submission came from our own page rather than somewhere else.

We use no analytics or advertising cookies. There are none to disclose.

How long we keep things, and how to delete them

We keep your account’s information for as long as the account is open, plus a reasonable period afterward for our own records. You can delete an individual photo or an individual catalog item yourself, at any time, from inside your account. For exactly where to do that, and for how to have an entire account and everything in it removed, see Data Deletion.

How to reach us

Questions about this policy, or about your own data? Email us at hello@madisonpoint.co.