Plain-English summary
MSP2MVP is a free, business-oriented set of educational resources and interactive tools for managed service providers (MSPs). You can browse most of the site without an account. Some features — for example the AI-enabled mini-apps, the Book Companion progress tracker, and admin/team surfaces — collect information you submit or generate as you use them.
- We use a small set of trusted service providers to run the product: Supabase (database, authentication, storage, edge functions), Resend (transactional email), Segment (product analytics), Snitcher and ReB2B (company/visitor identification for business analytics), OpenAI, Perplexity and Google Gemini (AI model providers for the mini-apps), and Apollo.io (business contact data for the Ideal Target Locator).
- We do not sell personal information, we do not run advertising trackers, and we do not use behavioural advertising cookies.
- MSP2MVP is a business tool. Do not submit passwords, secrets, regulated data (e.g. PHI, payment card data), or personal data you do not have authority to share.
1. Scope of this policy
This policy covers information processed through the MSP2MVP website(s) (including msp2mvp.com and any related domains), the user accounts and admin/team features, the marketplace and mini-apps (analyzers, benchmarks, planners, generators), the assessments and Book Companion progress features, downloadable PDF reports, transactional and notification emails, feedback and support submissions, and any embedded tools we host.
It does not cover third-party websites we link to, third-party AI or business-data providers when you use them independently, or products you purchase directly from third parties such as ScalePad.
2. Who we are
MSP2MVP is operated by Top Down Founders Fund I Limited Partnership, Top Down Founders Fund I GP Ltd., Top Down Founders Fund Management Ltd., and their affiliated companies (collectively, the “Top Down Group”, “Top Down”, “we”, “us”, or “our”). Corporate information about the Top Down Group is published at topdown.com and topdown.com/privacy.
Canada HQ: 3200–1021 W Hastings St., Vancouver, BC V6E 0C3, Canada. U.S. office: 4343 N Scottsdale Rd #150, Scottsdale, AZ 85251, USA. Privacy and legal contact: info@topdown.com.
3. Information we collect
The categories below reflect what MSP2MVP actually processes today. We distinguish authenticated users from anonymous visitors.
Account and profile data
- Email address, display name, password (stored as a salted hash by Supabase Auth), OAuth identifiers where you sign in via Google, and account role.
- Team / organization association, invitations you send or receive, and administrative roles you have been granted.
- Profile preferences you configure in the Profile Settings and Profile Integrations screens.
User-submitted inputs
- Business inputs you type or paste into the mini-apps — for example your MSP or client website URL, target job description, catalog description, market/ZIP inputs, or documents you upload for analysis.
- Assessment answers, Book Companion progress (chapters read, badges claimed, action-plan motions marked done), and comments or notes you add to your own worksheets.
- Feedback and “report an issue” submissions, including the content of the feedback and any email address you choose to share.
AI prompts, results, and run metadata
- The inputs described above are sent to our AI service providers (see §7) so they can generate the analysis, questionnaire, benchmark, or draft you requested.
- We store the generated result, together with run metadata (start/end times, status, error codes, model identifier, heartbeats), in our database so you can view and re-open past runs and so we can operate, secure, and improve the service.
Assessment / Book Companion progress
- Anonymous visitors: we generate a random visitor identifier stored in your browser’s local storage so your assessment responses, Book Companion progress, and action-plan state persist across page refreshes on the same device.
- Authenticated users: this progress is linked to your account. When an anonymous visitor later signs in, we link their existing local progress to the new account so nothing is lost.
Feedback, support and email delivery metadata
- Content of the feedback form, contact form, or support message.
- Transactional email delivery metadata (send status, bounce, delivery timestamps) produced by our email provider Resend.
Technical, log and device data
- IP address, user-agent, referrer, timestamps, requested URL, and error diagnostics captured by our servers and edge functions for security, abuse prevention, and debugging.
- Product-analytics events fired by Segment (page views, key clicks, mini-app step transitions, downloads). These events are keyed to a Segment anonymous ID and, once you sign in, to your user ID.
- Company-level identification (industry, company name, size) inferred from your IP by Snitcher and ReB2B for aggregated business analytics.
Payment data
MSP2MVP does not currently sell subscriptions or accept payments through the site. We do not process payment card data.
4. How we use information
- Deliver the service. Authenticate you, generate the AI analysis you requested, render the assessment or Book Companion, produce your downloadable PDF reports, and send the confirmation or delivery email.
- Improve and secure the service. Fix bugs, debug failed runs, tune prompts, detect abuse, rate-limit, prevent fraud, and maintain platform integrity. We aggregate run metadata to understand which mini-apps are useful and where users get stuck.
- Communicate with you. Send transactional emails (account, password reset, admin/team invitations, analysis completion, feedback acknowledgement, assessment reports).
- Comply with law. Meet legal, tax, audit, and regulatory obligations and respond to lawful requests.
5. Legal bases (EEA / UK users)
Where the EU or UK GDPR applies, we rely on the following legal bases:
- Contract — to provide the account, run mini-apps you request, and deliver reports.
- Legitimate interests — to secure the service, prevent abuse, keep logs, aggregate usage analytics, and improve our tools. We limit these to what a reasonable business user of a professional-tools site would expect.
- Consent — for optional email captures and optional feature dialogs where a checkbox or explicit action is presented. You can withdraw consent at any time; withdrawing does not affect prior processing.
- Legal obligation — where processing is required by applicable law.
6. AI features and prompts
Many mini-apps use large-language-model providers to analyze the business inputs you submit. Today those providers are OpenAI (privacy), Perplexity (privacy), and Google Gemini (privacy).
When you run a mini-app, the inputs you submit — for example the URL you asked us to analyze, the questionnaire answers you provided, or the document you uploaded — are sent to the applicable AI provider via a server-side edge function so the model can produce the requested output. The generated result is returned to your browser and stored in our database against your account (or against the anonymous run if you were not signed in).
Do not submit passwords, API keys, credentials, secrets, health or medical information, payment-card data, government identifiers, special-category personal data, trade secrets, or any information you do not have authority to share. AI outputs are probabilistic and can be inaccurate or outdated; verify anything you plan to rely on for a decision. See our Terms of Service — AI Terms.
We do not sell your AI inputs and we do not authorize our AI providers to use them to train publicly-available foundation models. Each provider’s own terms and privacy policy also apply to their processing of that data.
9. Service providers
Current material service providers:
- Supabase — database, authentication, storage, and serverless edge functions. Data is stored in Supabase-managed infrastructure. Privacy.
- Resend — transactional email delivery (account, invitations, notifications, assessment reports). Privacy.
- Segment (Twilio) — product-usage analytics events. Privacy.
- Snitcher — IP-based company identification for business analytics. Privacy.
- ReB2B — IP-based visitor identification for business analytics. Privacy.
- OpenAI — LLM provider for AI mini-apps. Privacy.
- Perplexity — real-time web-research AI provider. Privacy.
- Google Gemini — structured content extraction AI provider. Privacy.
- Apollo.io — business-contact data used by the Ideal Target Locator mini-app. Privacy.
- Cloud hosting and CDN providers that serve the site’s static assets and edge network.
This list may change as the product evolves. Material changes will be reflected here and, where required, in advance notice.
10. Data retention
We retain information for as long as needed to run the service and for legitimate business or legal purposes. In practice:
- Account and profile data are retained while your account is active and for a reasonable period afterwards for security, dispute, tax and audit purposes.
- Mini-app run logs and generated results are retained so you can re-open them and so we can debug and improve the service.
- Anonymous progress stored in your browser is retained by your browser until you clear it.
- Server logs and analytics events are retained for a rolling operational window sufficient for security, debugging, and aggregated reporting.
You can request deletion of your account and its associated content by emailing info@topdown.com. We will honour deletion requests to the extent required by applicable law. Some information may persist in encrypted backups for a limited time before being overwritten, and information we are legally required to keep will be retained until that obligation ends.
11. International transfers
We are headquartered in Canada, with an office in the United States, and use service providers located in Canada, the United States, the European Union and other jurisdictions. When personal data is transferred internationally, we rely on lawful transfer mechanisms available under applicable law (for example, the European Commission’s Standard Contractual Clauses and the UK Addendum, or equivalent safeguards).
12. Security
We use administrative, technical and organizational safeguards designed to protect information, including encryption in transit, role-based access controls, row-level security policies on our database, security definer functions for privileged operations, audit logs for admin actions, and least-privilege API keys held in server-side secrets. No system is perfectly secure — please use a strong, unique password and enable available account protections.
13. Third-party links
The site links to third-party resources (for example ScalePad product pages, methodology articles, referenced research). Their privacy practices are governed by their own policies.
14. Children
MSP2MVP is a business tool intended for professional use. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, please contact us and we will delete it.
15. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, port, or object to certain processing of your personal information, and to withdraw consent where processing is based on consent. To exercise these rights, email info@topdown.com. We may need to verify your identity before acting on a request.
16. California residents
Under the CCPA/CPRA, California residents have rights to know, delete, correct, and limit the use of certain personal information, and to opt out of “sale” or “sharing” for cross-context behavioural advertising. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. You will not be discriminated against for exercising these rights.
17. Canadian residents
If you are in Canada, PIPEDA and any applicable provincial privacy laws (including Quebec Law 25) govern our processing. You may request access to and correction of your personal information and file a complaint with the applicable regulator (in Canada, the Office of the Privacy Commissioner of Canada at priv.gc.ca) if we do not resolve a concern.
18. EEA / UK residents
In addition to the rights above, EEA/UK residents may lodge a complaint with their local supervisory authority (in the UK, the Information Commissioner’s Office at ico.org.uk).
19. Do Not Track / Global Privacy Control
Because MSP2MVP does not perform cross-context behavioural advertising and does not sell personal information, browser Do Not Track or Global Privacy Control signals have no additional effect on our processing beyond what this policy already describes.
21. Changes to this policy
We may update this policy from time to time. When we do, we will update the “Last updated” date at the top and, for material changes, provide additional notice as required by law.
Contact
Questions, privacy requests, or legal notices for the Top Down Group can be sent to:
- Email: info@topdown.com
- Canada HQ: 3200–1021 W Hastings St., Vancouver, BC V6E 0C3, Canada
- U.S. office: 4343 N Scottsdale Rd #150, Scottsdale, AZ 85251, USA
- Web: topdown.com