Legal

Privacy

This page is maintained by MarginMap to answer common privacy and data-handling questions about the product. It describes what the application actually does today.

What we collect

Account data: the email address you sign in with, or the identifier returned by Google or Apple if you use social sign-in. Passwords, when used, are handled by the authentication provider and are never stored by the application.

Profile data you enter: display name, country, preferred currency and default role mode.

Workspace data you create: searches, watchlists, deal evaluations, pipeline items, alerts and generated research reports.

We do not collect payment card details in the application; if and when billing is enabled it is handled by a payment processor.

How your data is used

Workspace data is used to render your own workspace and to compute the scores you request. It is private to your account and enforced at the database layer with row-level security policies scoped to your user ID.

We do not sell workspace data, do not share it with advertisers, and do not use your sourcing activity to build a public dataset.

Catalog data — products, offers, completed sales and market snapshots — is shared platform data and is not derived from any individual user's private workspace.

Where it is stored

The application runs on Lovable Cloud, which provides managed Postgres, authentication and server-side execution. Data is stored in that managed database with access restricted by row-level security.

AI analyst reports are generated by sending computed figures and the associated evidence rows to a model provider through a gateway. Report inputs are the catalog evidence and your requested variant; your account identity is not part of the prompt.

Retention and deletion

Workspace records persist until you delete them or delete your account. Deleting a watchlist, evaluation, pipeline item or alert removes the row.

To request export or full deletion of your account and associated workspace data, use the contact form and select the security or privacy topic. We action deletion requests within 30 days.

Cookies and analytics

The application stores an authentication session in browser storage so you stay signed in, and a small preference value for your selected role mode. These are functional, not advertising, and there is no cross-site tracking.

Shared responsibility

The hosting platform provides infrastructure controls including managed authentication, transport encryption and database access control. MarginMap, as the application owner, is responsible for the schema, access policies, and how data is used inside the product.

You are responsible for keeping your credentials secure and for the lawfulness of any data you enter into your workspace.

This page describes current practice. It is not an audit, a certification, or a statement of compliance with any specific regulatory framework.

Questions about any of the above? Contact us.