margin

Privacy policy

Updated October 3, 2026

Our role

For your account data (name, email, billing), Margin is the controller. For your stores' customer data (orders, contacts, messages, calls), you are the controller and Margin is the processor: we process it only to provide the service you configured (GDPR art. 28; LGPD art. 39).

What we collect

Sign-up and access data; data sent by the integrations you connect (checkouts, Meta, WhatsApp, email); events from the tracking script on your pages; AI call transcripts; and technical logs for security.

How we use it

To calculate profit and attribution, send the messages and calls you enabled, bill the subscription, provide support, prevent fraud and meet legal obligations. We do not sell data.

Who we share it with

Providers required to run the service: Supabase, Vercel, Resend, Meta, OpenAI, Anthropic and Whop. Some are outside your country; we rely on contractual clauses and appropriate safeguards.

How long we keep it

While your account is active. Raw webhook records are deleted after 90 days and technical logs within 14 days. After closure, we delete data within 90 days unless the law requires otherwise.

Security

Account isolation in the database, credentials in an encrypted vault, role-based access and change logs.

Your rights

You can request access, correction, portability and deletion. Your stores' customers exercise their rights with you; we help you handle those requests. Contact us through in-app support.