Privacy policy
Updated October 3, 2026
Our role
For your account data (name, email, billing), Margin is the controller. For your stores' customer data (orders, contacts, messages, calls), you are the controller and Margin is the processor: we process it only to provide the service you configured (GDPR art. 28; LGPD art. 39).
What we collect
Sign-up and access data; data sent by the integrations you connect (checkouts, Meta, WhatsApp, email); events from the tracking script on your pages; AI call transcripts; and technical logs for security.
How we use it
To calculate profit and attribution, send the messages and calls you enabled, bill the subscription, provide support, prevent fraud and meet legal obligations. We do not sell data.
Who we share it with
Providers required to run the service: Supabase, Vercel, Resend, Meta, OpenAI, Anthropic and Whop. Some are outside your country; we rely on contractual clauses and appropriate safeguards.
How long we keep it
While your account is active. Raw webhook records are deleted after 90 days and technical logs within 14 days. After closure, we delete data within 90 days unless the law requires otherwise.
Security
Account isolation in the database, credentials in an encrypted vault, role-based access and change logs.
Your rights
You can request access, correction, portability and deletion. Your stores' customers exercise their rights with you; we help you handle those requests. Contact us through in-app support.