MarginOS Privacy Policy

Last Updated: March 2, 2026

1. Introduction

This Privacy Policy describes how MarginOS (“we,” “us,” or “our”) collects, uses, and protects data in connection with your use of the MarginOS analytics application (the “Service”). Our Service integrates data from your Shopify store, advertising accounts, and uploaded business documents to provide unified business analytics.

This policy covers three types of data:

  • Merchant Data: Information we collect directly from you when you create an account or contact us.
  • Customer Data: Personal data of your customers processed on your behalf from Shopify.
  • Business Operational Data: Marketing performance data and information extracted from uploaded business documents.

2. Data We Process and Why

A. Merchant Data

  • What we collect: Your name, email address, Shopify store URL, and support communications.
  • Purpose: Account maintenance, billing, and customer support.

B. Customer Data (Processed on Your Behalf)

  • What we process: We access Customer Identifiers (name, email), Addresses (shipping/billing), Consent status, and Order history via the Shopify API.
  • Stated Purpose: Generating analytics reports, customer segmentation, and automated predictions for your store.

C. Google User Data (OAuth & Ads)

  • Authentication: We collect your Google email and basic profile info to authenticate your identity.
  • Marketing Data: If you connect your Google Ads account, we retrieve SKU-level performance and cost data.
  • Purpose: To calculate and display your advertising ROI and product-level profitability.

D. Business Operational Data (Document Parsing)

  • What we process: We process uploaded invoices, tenant documents, and inventory lists.
  • Purpose: We utilize third-party tools to extract SKU, quantity, and cost data to provide inventory and margin analytics.

3. Customer Consent and Opt-Out

As the Data Controller, you are responsible for obtaining appropriate consent from your Customers.

Consent Enforcement: Our Service respects Customer consent. We will only process data for Customers who have provided the necessary consent, as indicated by the emailMarketingConsent and smsMarketingConsent fields in your Shopify data.

Customer Opt-Out: Your Customers have the right to opt-out of processing, especially for automated decision-making (like predictions). If a Customer requests to opt-out, you are responsible for notifying us at support@marginos.com. Upon receiving your request, we will manually flag that Customer in our system to be excluded from all future automated predictions and profiling.

4. Data Retention

  • Merchant/Account Data: Retained for as long as your account is active.

  • Google User Data: Retained only for as long as your account is active and necessary to provide the Service. Upon account deletion or your revocation of Google OAuth access, all associated Google User Data is permanently deleted from our systems.

  • Uploaded Documents: Raw documents (e.g., invoices, inventory lists) uploaded for parsing are retained for up to 90 days by our processing partners to ensure successful extraction and error handling, after which they are deleted. Extracted business data is retained as part of your account records to provide the Service.

  • Customer Data: Protected Customer Data is automatically purged from our production systems 24 months after receipt.

5. Data Security

We implement robust technical measures:

  • Encryption: Data is encrypted in transit (SSL/TLS) and at rest (AES-256).
  • Infrastructure: Our application is hosted on Railway, utilizing secure GitHub-integrated deployment pipelines.
  • Access Control: Staff access is strictly limited to a “need-to-know” basis and logged.

6. Data Sharing (Subprocessors)

We do not sell personal data. We share data only with necessary Subprocessors:

  • Railway: Cloud hosting and infrastructure.
  • Parseur: Automated extraction of data from business documents.
  • Google Cloud/Ads API: Retrieval of marketing performance metrics.
  • Shopify: Data synchronization for store analytics.

7. Your Rights

As a Merchant, you have the right to access, correct, or request the deletion of your Merchant Data by contacting us. You may also request the deletion of your entire account, which will result in the purging of all associated Customer Data from our systems.

8. Changes to This Policy

We may update this policy from time to time. We will notify you of any significant changes by email or through the app interface.

9. Contact Us

If you have any questions about this Privacy Policy, please contact us at support@marginos.com.

10. Google API Disclosure

MarginOS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We strictly use and transfer Google User Data solely to provide the MarginOS Service, and we do not use, transfer, or share this data for serving advertisements, retargeting, or any other purposes outside of providing the user-facing analytics of the MarginOS Service.