Operating boundary

Use the least data needed to make the path work.

The written implementation scope must identify the inquiry source, destination, required access, stored fields, processors, exclusions, and deletion or handoff expectations.

Typical data in scope

Inquiry event

Source identifier, timestamp, customer-supplied contact details, service-request text, and workflow status needed to acknowledge and route the inquiry.

Operational routing

Agreed staff destination, provider identifiers, delivery status, follow-up timing, suppression status, and acceptance-test evidence.

Commercial records

Buyer contact, written scope, selected plan, payment-path identifier, invoice or receipt status, and support history.

Website measurement

Session identifier, buyer reference when present, page path, dwell time, scroll depth, selected source and route, plan view, checkout click, referrer, UTM values, device viewport, language, timezone, and a hashed network identifier.

Operating rules

Least privilege

  • Request only the access required for the accepted path.
  • Prefer provider-native tokens, scoped credentials, or dedicated destinations where supported.
  • Do not request broad CRM or administrator access when a narrower route is sufficient.

Purpose limitation

  • Use customer inquiry data only to operate, test, support, and document the accepted service.
  • Do not sell customer or prospect data.
  • Any AI processing or additional processor must be identified in the written scope when applicable.

Excluded by default

  • Protected health information, payment-card data, government identifiers, passwords in email, and regulated or highly sensitive data.
  • Open-ended access to unrelated systems.
  • Unsupported sources or destinations not named in writing.

Retention and handoff

  • Retention follows the accepted service, support, legal, and evidence needs.
  • At cancellation, credentials and active routes are removed or handed back as the written scope requires.
  • Deletion requests can be sent to the company inbox and are evaluated against operational and legal obligations.

Current service providers

Mercury currently uses established infrastructure providers for hosting, database and workflow execution, email, outreach delivery, and payment processing. Depending on the accepted scope, these can include Vercel, Supabase, Google Workspace, Instantly, and Stripe. A buyer can ask which providers touch the specific accepted path before payment.
Ask about a specific data path