1. The short version
MSP Tenant Launcher is built to hold as little of your data as possible. We collect just enough account information to run billing and support a paid subscription. We never collect, see, or store your Microsoft passwords, access tokens, or anything from inside your customers' tenants. When you sign in, your tenant list (company display names, SharePoint slugs, and optional password-vault links) is synced to our servers so it follows you between machines — nothing more. Microsoft session data and container mappings never leave your browser.
2. What we collect
| Data | Collected? | Where it lives |
|---|---|---|
| Microsoft passwords | Never | — |
| Microsoft access/refresh tokens | Never | — |
| Tenant names, SharePoint slugs & vault links | Yes | Your browser (browser.storage.local); synced to our servers when you're signed in, so your list follows you between machines |
| Firefox container mappings | Yes | Your browser only — never transmitted |
| Account email address | Yes | Our servers |
| Password (for your account) | Yes, hashed | Our auth provider, Supabase |
| Subscription / plan status | Yes | Our servers |
| Portal activity (Enterprise teams only): account email, tenant name, portal type, timestamp | Yes, when you open a portal while signed in to a team account | Our servers — visible to your team's owner in the Team Dashboard activity log |
| IP addresses | Never | — |
| Payment card details | Never directly | Our payment processor, Stripe |
Rows marked "your browser only" are never transmitted to us. Your Microsoft sessions, cookies, and container mappings stay in Firefox; we cannot see inside any customer tenant or observe your browsing.
3. How we use what we do collect
- Your email to identify your account, send billing receipts, and respond to support requests.
- Your subscription status to determine your tenant/seat limits.
- Basic technical logs (e.g., login timestamps, error reports) to keep the Service running and secure.
- On Enterprise team accounts, portal-open events (who opened which tenant's portal, and when) so the team owner can audit their own team's activity. We do not use this data for anything else.
We do not sell your data, and we do not use it for advertising.
4. Third parties we share data with
We use a small number of service providers to operate the Service. Each only receives the minimum data needed to do its job:
- Supabase (auth, database, and functions hosting) — stores your account email, hashed password, synced tenant list, and subscription status.
- Stripe — processes your payment; we receive confirmation of payment status, never your full card number.
- Transactional email delivery — account emails (confirmation, password resets, team invites, receipts) are sent through Supabase and our email delivery provider.
We do not share your data with anyone else, except where required by law.
5. Cookies and tracking
This website does not use advertising or cross-site tracking cookies, and we do not currently use any analytics service. If that changes, we will disclose it here first. The browser extension itself does not use cookies for tracking — it uses Firefox's container/cookie-store APIs solely to keep your customers' admin sessions isolated from each other.
6. Data retention
We retain your account data for as long as your account is active. If you delete your account, we delete your email, synced tenant list, activity records, and billing association within 30 days, except where we're required to retain records for tax or legal purposes. Data stored locally in your browser is entirely under your control — uninstalling the extension or clearing its storage removes it immediately.
7. Your rights
Depending on where you live, you may have the right to:
- Request a copy of the account data we hold about you;
- Request correction or deletion of that data;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at contact@tenantlauncher.com. EU/UK residents also have the right to lodge a complaint with their local data protection authority.
8. Children's privacy
The Service is intended for use by IT professionals and is not directed at children. We do not knowingly collect data from anyone under 16.
9. Security
We rely on our infrastructure providers' security practices (encryption in transit, hashed passwords, access controls) and design the Service to minimize what we hold in the first place — the less we collect, the less there is to protect. No system is perfectly secure, and we can't guarantee absolute security of any data transmitted to us.
10. Changes to this policy
We may update this Privacy Policy from time to time. We'll update the "Last updated" date above and, for material changes, make a reasonable effort to notify active subscribers by email.
11. Contact
Questions about this policy or your data? Contact us at contact@tenantlauncher.com.
This document is a template provided for convenience and does not constitute legal advice. You are responsible for ensuring it accurately describes your actual data practices and complies with the laws that apply to your business and your customers before relying on it.