Legal

Privacy

This page is maintained by MarginMap to answer common privacy and data-handling questions about the product. It describes what the application actually does today.

What we collect

Account data: the email address you sign in with, or the identifier returned by Google or Apple if you use social sign-in. Passwords, when used, are handled by the authentication provider and are never stored by the application.

Profile data you enter: display name, country, preferred currency and default role mode.

Workspace data you create: searches, watchlists, deal evaluations, pipeline items, alerts and generated research reports.

We do not collect payment card details in the application; if and when billing is enabled it is handled by a payment processor.

Workspaces are shared, not personal

MarginMap is organised around workspaces, not individual accounts. Every search, deal evaluation, watchlist, pipeline item, price alert, analyst report and activity-log entry you create belongs to the workspace you created it in, and is visible to every member of that workspace according to their role: owners and admins can manage everything, editors can create and change records, auditors have read-only access.

This is enforced in the database with row-level security scoped to workspace membership, not to your user ID alone. If you do not want a record seen by your colleagues, do not create it in a shared workspace.

Workspace owners and admins can invite and remove members. Removing a member revokes their access to the workspace but does not delete the records they created, because those records belong to the workspace.

Owners and admins can also see an append-only activity log that records who performed which action, and when.

How your data is used

Workspace data is used to render your workspace and to compute the scores you request.

We do not sell workspace data, do not share it with advertisers, and do not use your sourcing activity to build a public dataset.

Catalog data — products, offers, completed sales and market snapshots — is shared platform data and is not derived from any individual workspace.

Where it is stored

The application runs on Lovable Cloud, which provides managed Postgres, authentication and server-side execution. Data is stored in that managed database with access restricted by row-level security.

AI analyst reports are generated by sending computed figures and the associated catalog evidence rows to a model provider through the Lovable AI Gateway. The prompt contains your question, the selected product variant and the catalog evidence; it does not contain your name, email or account identifier. The resulting report is stored against your workspace and is therefore visible to other members of that workspace.

Retention and deletion

Workspace records persist until you delete them or delete your account. Deleting a watchlist, evaluation, pipeline item or alert removes the row.

To request export or full deletion of your account and associated workspace data, use the contact form and select the security or privacy topic. We action deletion requests within 30 days.

Cookies, analytics and advertising

The application stores an authentication session in browser storage so you stay signed in, and a small preference value for your selected role mode. These are functional.

Advertising measurement: we use Google Ads to measure whether our ads lead to account sign-ups and to optimise ad delivery. When allowed, the Google tag sets advertising cookies and sends Google a sign-up event (no email, name or workspace data) when you create an account, together with standard device and page information Google collects. The recipient is Google Ads; the purposes are conversion measurement and ad optimisation.

Consent: visitors in the EEA, UK, Switzerland and Canada see a cookie banner, and no Google Ads tag or event loads until they accept. Rejecting is as easy as accepting. We keep a record in your browser of which choice you made, when, and the notice version shown. Elsewhere, measurement runs without a banner; you can still turn it off.

Withdrawing: use the Cookie settings link in the site footer at any time to change or withdraw your choice. Withdrawal takes effect immediately and stops further events.

How Google uses data from sites that use its services: https://business.safety.google/privacy/

Shared responsibility

The hosting platform provides infrastructure controls including managed authentication, transport encryption and database access control. MarginMap, as the application owner, is responsible for the schema, access policies, and how data is used inside the product.

You are responsible for keeping your credentials secure and for the lawfulness of any data you enter into your workspace.

This page describes current practice. It is not an audit, a certification, or a statement of compliance with any specific regulatory framework.

Questions about any of the above? Contact us.