MarpinMarpin← Back to home

Privacy Policy

Effective: 25 June 2026

This Privacy Policy explains how Marpin ("Marpin", "we", "us") collects, uses, stores, and protects your personal data, and the rights you have. Marpin is operated by Gabriel Rahbani, an individual based in Barcelona, Spain, who acts as the data controller. You can reach us at rahbanigabriel@gmail.com.

Marpin is an AI marketing assistant. It is in active development (beta). We aim to collect only what we need to provide the service, and we never sell your personal data.

1. Information we collect

  • Account information — when you sign up, your name and email address (handled by our authentication provider) and your workspace details.
  • Connected-account data — if you connect a marketing or analytics platform (e.g. Google Ads, Google Analytics, Search Console, Meta, LinkedIn, TikTok), we receive and store OAuth access/refresh tokens for that account, the account identifier, and the marketing metrics we sync on your behalf (such as spend, conversions, ROAS, CPA, and campaign names).
  • Content you provide — the questions, prompts, website URLs, and instructions you enter, and any assets you upload.
  • Usage and technical data — basic product-analytics and error/diagnostic data (e.g. pages viewed, feature usage, crash logs) used to operate and improve the service.
  • Billing data — if you subscribe, our payment processor handles your card details; we store only your subscription status, never your full card number.

2. How we use your data

We process your data to:

  • Provide, operate, and maintain the service — including syncing your connected-account metrics and generating analyses, plans, and content.
  • Authenticate you and secure your account.
  • Process payments and manage subscriptions, where applicable.
  • Monitor, debug, and improve the service.
  • Communicate with you about the service and respond to your requests.

Our legal bases under the GDPR are: performance of our contract with you (to provide the service); your consent (e.g. when you connect a platform); and our legitimate interests (to secure and improve the service), balanced against your rights.

3. Connected platforms & limited use

When you connect a platform, you authorise Marpin to access the data covered by the permissions (scopes) shown on that platform's consent screen — read-only access to your advertising and analytics data, used solely to provide the features you ask for. We do not use this data for advertising, and we do not sell it.

Google user data. Marpin's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google APIs is used only to provide and improve the user-facing features you request, is not transferred to third parties except as needed to provide those features (or for security/legal reasons), is not used for advertising, and is not read by humans except with your consent, for security, or as required by law.

Data obtained from Meta, LinkedIn, TikTok, and other platforms is likewise used only to provide the service and handled in accordance with each platform's developer terms.

4. How we share your data

We do not sell your personal data. We share it only with service providers (sub-processors) that help us run Marpin, under contracts that require them to protect it:

  • Hosting & infrastructure (application hosting and serverless functions).
  • Database (a managed, EU-region Postgres database where your data is stored).
  • Background job processing (to run scheduled and event-driven data syncs).
  • Authentication (to manage sign-in and accounts).
  • AI processing (to generate analyses and content from your prompts).
  • Payments (to process subscriptions, where applicable).
  • Product analytics & error monitoring (to operate and improve the service).
  • Email delivery (for transactional messages).

We may also disclose data where required by law, to protect rights and safety, or in connection with a business transfer. A current list of sub-processors is available on request.

5. International transfers

Your data is stored in the European Union where possible. Some of our sub-processors may process data outside the EU; where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

6. How we protect your data

Connected-account tokens are encrypted at rest using authenticated AES-256-GCM encryption and are never stored in plain text. All traffic is served over HTTPS. We apply access controls and feature-detect credentials so that data is only processed when properly secured.

7. How long we keep it

We keep your data for as long as your account is active and as needed to provide the service. When you disconnect a platform, we revoke and delete its stored tokens. When you delete your account or request erasure, we delete your personal data (subject to any limited retention required by law), as described on our Data Deletion page.

8. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”).
  • Restrict or object to certain processing.
  • Data portability — receive your data in a portable format.
  • Withdraw consent at any time (e.g. by disconnecting a platform), without affecting prior processing.

To exercise any of these, email rahbanigabriel@gmail.com. You also have the right to lodge a complaint with your local data protection authority — in Spain, the Agencia Española de Protección de Datos (AEPD).

9. Children

Marpin is not intended for, and may not be used by, anyone under 18 years of age.

10. Changes to this policy

We may update this policy from time to time. We will post the new version here and update the date at the top. Material changes will be communicated where appropriate.

11. Contact

Questions about this policy or your data? Contact Gabriel Rahbani at rahbanigabriel@gmail.com, Barcelona, Spain.