Privacy Policy
Privacy Policy
Last updated: October 7, 2026
This notice describes how Merxence processes information for Microsoft 365 Files for HighLevel.
Product architecture
Microsoft 365 remains the system of record for customer files. Each customer uses its own Microsoft Entra application and controls the Microsoft permissions and SharePoint site grants used by the product.
The Microsoft connection for a HighLevel Location is configured through HighLevel External Authentication. The current connection uses the customer’s Tenant ID, Client ID, and Client Secret. HighLevel manages that Location connection and its Microsoft token lifecycle. Merxence application code does not maintain a separate customer Microsoft credential or token database.
Files and workflow data
Focused SharePoint actions run inside HighLevel and call Microsoft Graph directly wherever the platform supports the required transport.
Upload File is the explicit binary-transfer exception. File bytes pass through a stateless Merxence-operated Cloudflare Worker only for the duration of the transfer from the HighLevel file source to the Microsoft upload session. The application does not persist customer files in a Merxence file store and does not persist Microsoft bearer tokens in the relay.
Marketplace installation
The HighLevel Marketplace installation callback is separate from Microsoft authentication. The callback exchanges the HighLevel installation authorization code and immediately discards the returned HighLevel access tokens. It does not create a Merxence customer session or token database.
Support information
If you contact support, we process the information you choose to send so we can investigate and respond. Do not send passwords, Client Secret values, access tokens, refresh tokens, private keys, signed/private links, or confidential customer files.
Support communications may be retained in our email service for as long as reasonably needed to resolve the request, maintain service records, prevent abuse, and meet applicable legal obligations.
Website data
The product website does not currently operate advertising or behavioral analytics. Hosting, CDN, DNS, security, and email providers may process routine technical metadata such as IP address, request time, user agent, delivery logs, or security events under their own operational policies.
Service providers
The product depends on third-party platforms including HighLevel, Microsoft, Cloudflare, and our website/email hosting providers. Their handling of information is governed by their own terms and privacy practices where they act independently.
Data minimization
Our architecture is intentionally designed to avoid creating a separate vendor file store or customer Microsoft token database. We process only what is required to execute the requested workflow, provide the service, operate security controls, and support customers.
Your choices and requests
You can revoke Microsoft application access, remove SharePoint site grants, rotate or revoke the Client Secret, disconnect the HighLevel Microsoft connection, uninstall the Marketplace app, or contact us about privacy questions.
Contact
Privacy and support questions: support@merxence.com
This policy may be updated as the product, infrastructure, or legal requirements change. Material changes will be reflected by updating the date above.