Privacy Policy
Effective date: 2026-04-12 · Last updated: 2026-04-12
1. Introduction
MSP Genie (“we,” “us,” or “our”) operates an IT management portal that helps small and mid-size businesses monitor devices, manage users, and maintain security posture. This Privacy Policy describes what personal data we collect, why we collect it, how we use and protect it, and the rights you have regarding your data.
By using the MSP Genie portal or any associated services, you acknowledge that you have read and understood this policy. If you do not agree, please do not use the service.
2. Data We Collect
2.1 Account Information
When your organization is onboarded or you are invited to the portal, we collect:
- Name and email address
- Company name and role within your organization
- Hashed password (if using email/password authentication)
2.2 Directory Data
If your organization connects Google Workspace or Microsoft 365 for directory sync, we access and store a read-only mirror of your directory users. This includes names, email addresses, and organizational unit membership. We access this data using OAuth 2.0 with scopes limited to directory read access. We do not access email content, calendar events, or file contents.
2.3 Device Telemetry
We receive device information from Level.io, our endpoint management partner. This includes device hostname, operating system, hardware specifications, software inventory, patch status, and online/offline status. This data is associated with your organization and used to present device health dashboards and trigger management actions.
2.4 Security Scan Data
When domain health or OSINT reports are generated for your organization, we query third-party intelligence services to check for known data breaches, malicious URLs, and other security indicators. Results are stored as part of your security posture report.
2.5 Intake Form Responses
Information submitted through onboarding and project request forms — including company size, platforms in use, IT support needs, and contact details — is stored to provision and configure your portal environment.
2.6 Usage and Log Data
We collect standard server logs including IP addresses, browser type, pages visited, and timestamps. This data is used for security monitoring, debugging, and service improvement.
3. How We Use Your Data
- Provide the service: display dashboards, manage devices, sync directory data, generate reports.
- Authenticate users: verify identity via email/password or single sign-on through Google or Microsoft.
- Security operations: run domain health checks, deploy endpoint protection, and surface security posture data.
- Communications: send onboarding emails, password reset emails, and service notifications.
- Improve the service: analyze usage patterns to improve features and fix bugs.
4. Third-Party Services
We share data with the following third-party services to operate the portal. Each service receives only the data necessary for its function:
- Level.io — endpoint management. Receives and provides device telemetry, executes management actions (updates, reboots, software installs).
- Huntress — endpoint detection and response (EDR). Receives device identifiers for agent deployment and threat monitoring.
- Google (Workspace APIs) — directory sync. Accesses user directory data via OAuth 2.0 with read-only scopes.
- Microsoft (Graph API) — directory sync. Accesses user directory data via OAuth 2.0 with read-only scopes.
- Have I Been Pwned (HIBP) — checks email addresses against known data breach databases.
- Google Safe Browsing — checks URLs and domains for known threats.
- VirusTotal — checks domains and files against malware databases.
- Email delivery provider — sends transactional emails (onboarding invitations, password resets, notifications).
- Hosting provider — the portal infrastructure is hosted on cloud servers. Data is stored in encrypted databases.
We do not sell your data to third parties. We do not use your data for advertising purposes.
5. Data Retention
We retain your organization’s data for as long as your account is active and the service agreement is in effect. Upon termination of service:
- Account and directory data is deleted within 90 days of termination.
- Device telemetry and security scan results are deleted within 90 days of termination.
- Server logs are retained for up to 12 months for security and compliance purposes, then deleted.
- Backup copies may persist for up to 30 additional days beyond the above periods before automatic purge.
6. Data Security
We implement technical and organizational measures to protect your data, including:
- Encryption in transit (TLS) and at rest for sensitive data.
- Hashed and salted passwords (bcrypt).
- Encrypted storage for third-party API credentials and OAuth tokens.
- Role-based access controls and company-scoped data isolation.
- Rate limiting on authentication endpoints.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data, subject to legal retention requirements.
- Data portability: request an export of your data in a structured, machine-readable format.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Objection: object to processing of your data for certain purposes.
- Complaint: lodge a complaint with your local data protection authority (GDPR), or exercise your rights under the California Consumer Privacy Act (CCPA).
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
8. Cookies
The portal uses essential cookies only — specifically, an HTTP-only session cookie for authentication. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
9. Children’s Privacy
The service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For material changes, we will notify affected users via email or an in-portal notice.
11. Contact
For privacy-related inquiries, data requests, or complaints, contact us at:
privacy@mspgenie.io
Change History
| 2026-04-12 | Initial version published. |