Last updated: September 26, 2026
Molecule Work LLC ("we," "us," or "our") operates My Molecule, a scheduling platform for service businesses such as barbershops. To understand this policy, one distinction matters more than anything else — who is responsible for which data:
A business can record clients who have no account with us at all (for example, walk-ins). That information belongs to the business's records; we store and process it on their behalf.
Payments are processed by Stripe. Card numbers go directly to Stripe and never touch our servers; we store only payment references, statuses, and amounts. Stripe's privacy policy applies to the payment data it handles.
If you create an account and book with more than one business on the platform, we maintain one consumer profile for you that your bookings connect to. This is what lets you see your appointments across businesses in one place and manage your notification preferences once. We maintain this profile for your use — we do not share one business's records about you with another business, and we do not use the profile to advertise to you.
We also use product analytics to understand how the platform is used and to improve it. It is optional: it runs only if you accept the analytics category in the cookie banner (Section 10). Section 5.3 describes what it collects and where it runs, and the vendor is on our subprocessor list.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:
A business can connect its own advertising and analytics tags (such as Google Analytics, Google Ads, Meta, or TikTok pixels) to its public booking pages. Those tags belong to and are configured by the business, run only on that business's booking pages, and send data to the business's own accounts with those providers — not to us. The business is responsible for its use of these tools and for any disclosures they require.
We use Sentry to detect errors and performance problems. Sentry receives technical data such as IP address, device and browser information, and error details. A small random sample of sessions — and sessions in which an error occurs — are recorded for debugging, with text content masked and media blocked in production. If you use the in-product feedback tool, the screenshot you choose to attach is included with your report.
We use Amplitude to understand how people use My Molecule so we can improve it. Amplitude runs only after you accept the analytics category in our cookie banner. If you have not decided yet, or you choose Essential Only, it does not load. Once you accept, Amplitude receives usage events (such as the pages you view and the buttons you click, with the page address), device and browser information, and an identifier it keeps in a cookie in your browser.
On our marketing site and in the signed-in app, Amplitude Session Replay also records how the page changes during your visit, so we can see and fix problems. A recording can be made of any session in which you accepted analytics. Passwords and other sensitive form fields are masked before a recording leaves your browser; other information shown on the screen can appear in a recording. Session Replay never runs on a business's booking pages, in the accounts of businesses in health-related categories (such as clinics, dental, therapy, chiropractic, medspa, and massage), or on pages opened from a link that works as a key, such as an invoice, quote, receipt, or form link. Analytics does not run on those link pages at all.
On a business's booking pages, analytics (without Session Replay) follows that business's cookie-banner setting: it waits for you to accept analytics in the business's banner, unless the business has turned that banner off.
No method of transmission or storage is 100% secure. If you believe you have found a security issue, contact [email protected] — it routes directly to our founder.
If a security breach affects your personal information, we will notify you without undue delay, consistent with the law of your state of residence (for Colorado residents, no later than 30 days after we determine a breach occurred, as Colorado law requires), and we will notify regulators where the law requires it. Where a breach affects data we process on a business's behalf, we will notify that business promptly and cooperate with its response.
How long data is kept depends on whose records it is:
What deletion means here. When personal information is deleted through a privacy request, we scrub identifying details (name, contact information) from the affected records and deactivate them. Transactional skeletons — for example, that an appointment occurred on a date, or that an invoice was paid — may be retained where they are part of a business's financial records or ours, without your identifying details attached. To request deletion, see Section 8.
We operate a request system supporting six kinds of privacy request, tracked with a 45-day response target: access ("right to know"), deletion, correction, a portable copy of your data, opting out of any sale or sharing (noting we do not sell or share), and limiting the use of sensitive information. Depending on your state of residence, some of these are legal rights; we honor reasonable requests of these kinds regardless of where you live. We will verify your identity before acting, and you will not be discriminated against for making a request.
We use a small set of first-party cookies and browser storage:
Global Privacy Control. We do not sell or share personal information, so there is nothing a sale-or-sharing opt-out signal needs to stop today. We honor Global Privacy Control anyway: when your browser sends the signal while you are signed in, we automatically record a marketing opt-out in our consent system across the businesses your account is linked to. Appointment confirmations and other messages about services you booked are not affected.
A business's own booking pages may set third-party cookies from advertising tags that business has configured (Section 5.1); those are governed by the business and the tag provider.
The platform is a business tool and is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact [email protected] and we will delete it. Businesses that record information about minor clients (for example, a parent booking a child's haircut) are responsible for doing so lawfully.
Molecule Work LLC is a United States company, and the platform is operated from the United States. If you use it from outside the US, your information will be transferred to and processed in the US, where privacy laws may differ from those of your country.
We do not sell personal information, and we have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising. Residents of states with comprehensive privacy laws (including California, Colorado, Virginia, Connecticut, and Texas) can exercise the rights those laws provide through the channels in Section 8.
When we make material changes, we will update the date at the top of this page and notify you by email or in the product. Because this policy describes how the platform actually works, it changes when the platform's data practices change.
Molecule Work LLC
1500 N Grant St, Denver, CO 80203, USA
Privacy requests and questions: [email protected]
Security: [email protected]