---
title: "MCP Connector Privacy Policy | Dumpster Controls"
url: "https://dumpstercontrols.io/developers/mcp/privacy"
description: "Privacy policy for the Dumpster Controls MCP connector: what the connector collects when you connect an AI assistant, how it is used and stored, what is shared with the assistant vendor, how long records are kept, your controls and how to contact us."
type: pillar
tokens: 2146
token_budget: 4000
format: markdown for AI agents, generated at build from the same content as the HTML page
---

[![Dumpster Controls](https://dumpstercontrols.io/assets/logo-dumpster-controls-CwF8l_NG.png)](https://dumpstercontrols.io/)

Developers

# MCP connector privacy policy

Last updated: September 28, 2026

This policy covers the [Dumpster Controls MCP connector](https://dumpstercontrols.io/developers/mcp), the service at `mcp.dumpstercontrols.io` that lets an AI assistant such as Claude act on your Dumpster Controls account. It supplements the general [Privacy Policy](https://dumpstercontrols.io/privacy) of Dumpster Controls, which continues to govern the data you keep in the platform. Where the two differ for the connector, this page is more specific.

Dumpster Controls is built and operated by Prime Systems and Controls LLC, a Florida company. For the data described here, Dumpster Controls acts on behalf of the company whose user connects the assistant.

## 1. What the connector collects

### 1.1 When you connect

- **Who is connecting.** Your Dumpster Controls user identifier, the company you belong to, the identifier of the login session you used to approve the connection, and whether that session used a second factor.
- **Which client is connecting.** The identifier of the assistant client (for Claude, the URL of the Client ID Metadata Document published by Anthropic) and its callback address.
- **What you approved.** The list of capabilities granted to the connection (account context, order and invoice reads, customer reads, receipt reads, money reports, task completion, driver assignment, order edits, invoice sending, customer creation and edits, price proposals, cancellation proposals), the time it was created and when it expires.
- **Sign-in flow records.** A short-lived record of the authorization attempt, keyed by a one-way hash and bound to your browser, so the flow that started in Claude can only be finished by the same browser. It expires within minutes.
- **Token material.** The authorization code, access token and refresh token that let the client call the server on your behalf, and the session used to run your requests. These are stored sealed (encrypted with AES-256-GCM) and looked up through a keyed one-way hash; the plain values are not kept in the database.

### 1.2 When the assistant uses a tool

- **Your request parameters.** The arguments the assistant sends to a tool: order numbers, customer names, dates, filters and, for proposals, the values to change (for example a new date, a new address, customer contact details, a discount amount or a cancellation reason). They are processed to answer the call.
- **Proposals.** When the assistant proposes a change (completing a step, assigning a driver, editing an order, sending an invoice, saving a customer, changing a price or canceling an order), a proposal record is stored in your company's account with those values, the user and connection that created it, its expiry (10 minutes) and its outcome (executed, failed, expired or canceled).
- **Changes you confirm.** A confirmed change is saved in your account like the same action in the app, and leaves the same order history and audit log entries, marked as coming from the connector where applicable.
- **Server logs.** Technical logs kept by the hosting provider for a limited window contain timestamps, routes, status and error codes. They do not contain your conversation, the tool results or token values.

### 1.3 What the connector does not collect

- It does not read or store your conversation with the assistant, and it never asks the assistant for your chat history, memory or files. The server receives only the tool calls the assistant makes.
- It sets no cookies on the MCP endpoint. The sign-in and consent pages use the normal Dumpster Controls session on dumpstercontrols.io.
- It does not receive passwords: sign-in happens on dumpstercontrols.io through the platform's identity provider, never inside the assistant.
- It does not create a copy of your operational data. Every tool call reads the live database with your own permissions and returns the answer to the assistant.

## 2. How the information is used

- To authenticate you and verify the client, and to issue and refresh the credentials that keep the connection working until it expires or you revoke it.
- To run each tool call with your own permissions, so the assistant sees exactly what you would see in the app, and nothing from other companies.
- To require and record your confirmation before any change is made, to send the notifications that the confirmed action sends in the app (for example the invoice email or the driver SMS), and to prevent a proposal from being executed twice.
- To protect the service: detecting abuse, rate limiting, troubleshooting and security investigation.
- To support you when you write to us about the connector.

Dumpster Controls does not use the data handled by the connector to train models, for advertising, or for any purpose unrelated to operating the service.

## 3. Where it is stored

Connection records, sealed token material and sign-in flow records are stored in the same managed PostgreSQL database that runs Dumpster Controls (operated by Supabase on AWS infrastructure, encrypted in transit and at rest), in a dedicated schema that application users cannot read. Proposals and audit entries are stored with your company's records in the same database. The connector server itself runs on Fly.io and holds no database of its own; its configuration secrets are kept outside of source control.

## 4. Sharing with third parties

- **The assistant vendor you connect.** The results of each tool call (for example, an order's address, a customer's phone number, a landfill weight) are sent to the assistant that requested them, so it can answer you. From that point the data is handled under the vendor's own privacy terms (for Claude, Anthropic's). We send nothing to the vendor except in response to a tool call made through your connection, and you decide which capabilities the connection has.
- **Service providers.** Supabase (database, authentication and storage), Fly.io (hosting of the connector server) and Cloudflare (DNS). When you confirm an action that sends a message, the message goes out through the same providers the app uses: Resend for email, ClickSend for SMS and Firebase Cloud Messaging for driver push notifications. When a cancellation you confirm inside the app includes a refund, Stripe processes it as it would for the same action in the app.
- **Legal requirements.** We may disclose information when required by law or to protect the rights and safety of users and of the service.

We do not sell this information and we do not share it with advertisers.

## 5. Retention

- **Sign-in flow records and authorization codes:** expire within minutes and are purged automatically.
- **Access and refresh tokens:** access tokens last 5 minutes. Sealed token material is kept until the connection expires or is revoked (during the pilot, at most one hour) and is then erased by a scheduled clean-up.
- **Connection records:** after the tokens are erased, a record of the connection (user, company, client, granted capabilities and dates) is kept so that a revoked or expired connection can never be reused and so that actions can be traced. It is deleted when your user or your company is deleted.
- **Proposals and audit entries:** a proposal can be confirmed for 10 minutes. The record of the proposal, its outcome and the audit entries of confirmed changes stay with your company's data as part of the order history, under the retention rules of the general [Privacy Policy](https://dumpstercontrols.io/privacy).
- **Server logs:** retained by the hosting provider for a limited window and used only for troubleshooting and security.
- **Your operational data** (orders, customers, receipts) is not copied by the connector, so nothing new is retained about it beyond the records above.

## 6. Your controls and rights

- **Disconnect at any time.** Remove the connector in the assistant's settings. The server refuses further calls from a removed connection, and connections also expire on their own.
- **Revoke on our side.** Email support@dumpstercontrols.io and we will revoke the connection and erase its tokens.
- **Choose what is granted.** A connection only carries the capabilities approved on the consent screen; a capability that was not granted is not offered to the assistant.
- **Access, correction and deletion** of your personal information follow the general [Privacy Policy](https://dumpstercontrols.io/privacy). Account deletion is available on the [account deletion page](https://dumpstercontrols.io/delete-account).

## 7. Children

The connector is a business tool for Dumpster Controls accounts and is not directed at children under 16. We do not knowingly collect information from them.

## 8. Changes to this policy

When the connector gains or loses a capability, or when the way it stores information changes, this page and its date change with it. Material changes are also noted on the [connector documentation](https://dumpstercontrols.io/developers/mcp) page.

## 9. Contact

Privacy questions and requests: privacy@dumpstercontrols.io. Connector support: support@dumpstercontrols.io. Security reports: see the [Security page](https://dumpstercontrols.io/security).

---

Source: https://dumpstercontrols.io/developers/mcp/privacy (human version of this page).
Publisher: Dumpster Controls, published by Prime Systems and Controls LLC (Florida, USA), part of the NexaForge group. Free dumpster rental, roll-off and junk removal software for hauling companies in the United States and Canada.
Facts for AI assistants: https://dumpstercontrols.io/ai . Site index for agents: https://dumpstercontrols.io/llms.txt . Product manual: https://dumpstercontrols.io/help .
