Customer data remains yours
Customers retain ownership of data they connect, upload, and generate through the Service.
This policy explains what personal data Marcenta collects, why we collect it, how we use and share it, and the rights available under applicable privacy laws.
Effective Last updated
Policy overview
Customers retain ownership of data they connect, upload, and generate through the Service.
Marcenta processes customer source data to provide and secure the Service on the customer’s behalf.
We do not sell personal data or use customer data for cross-context behavioural advertising.
AI outputs may be inaccurate and should be reviewed by people before important decisions.
Marcenta ("we", "us", or "our") operates marcenta.ai and the Marcenta product (the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and your rights under applicable privacy laws, including the GDPR and the CCPA/CPRA where applicable.
Marcenta is a business-to-business service. In many cases, we process customer data on behalf of the organisation using Marcenta. For connected third-party source data, your organisation is typically the controller or business and Marcenta acts as a processor or service provider for the limited purpose of delivering the Service.
Questions can be sent to legal@marcenta.ai.
Marcenta is the data controller for account, billing, website, and relationship data that we collect directly from you. For customer source data that you connect to the Service, Marcenta generally acts as a processor or service provider on your organisation's behalf.
Marcenta is currently operated by the founding team under the Marcenta brand unless a specific Marcenta legal entity is identified in your order form, invoice, or other commercial agreement.
Contact: legal@marcenta.ai
Website: marcenta.ai
When you sign up for Marcenta or are invited to a workspace, we may collect:
When you connect supported third-party sources such as Google Analytics 4, Google Search Console, Google Ads, LinkedIn Ads, or HubSpot, Marcenta ingests marketing, sales, and performance data so we can provide analytics, reporting, anomaly detection, and AI-assisted analysis.
Marcenta is designed to process aggregated marketing analytics data. Depending on the source and your organisation's configuration, connected data may also include limited business contact or CRM-related data, such as contact counts, form submission metadata, campaign names, owner names, pipeline stages, landing pages, or similar records.
You are responsible for ensuring you have the right to connect and disclose data from those sources to Marcenta, and for ensuring you do not send prohibited, sensitive, or unnecessary personal data through integrations.
We collect data about how the Service is used, including pages viewed, features used, browser and device information, IP-derived technical metadata, request logs, error events, and service telemetry. We use this data to secure, operate, troubleshoot, and improve the Service.
If you subscribe to a paid plan or trial, we may process subscription and billing metadata such as plan tier, trial status, billing period dates, payment customer identifiers, and subscription status. Payment processing is handled by our billing provider; we do not intentionally store full payment card numbers in Marcenta.
If you contact us, send support requests, invite teammates, or use product features that send emails or share reports, we process the relevant communication data, including sender and recipient email addresses and the content needed to deliver the message.
Marcenta is not designed for the intentional collection of special-category or highly sensitive personal data such as health data, government identifiers, or full payment card data. Please do not use the Service to upload such data unless we have expressly agreed to support that use case in writing.
Customers retain ownership of data they connect, upload, and generate through the Service, including source data, configuration data, and AI-assisted outputs.
For customer data processed through connected sources and workspace activity, Marcenta acts as a processor or service provider on the customer's behalf and processes that data to provide and secure the Service.
Customers control what integrations, workspaces, and datasets are connected to Marcenta and can disconnect integrations or remove data according to available product controls.
Where GDPR applies, we rely on the following legal bases:
Contract performance
To provide the Service, manage accounts, process connected source data, and deliver paid subscriptions or trials.
Legitimate interests
To secure, maintain, troubleshoot, monitor, and improve the Service, including fraud prevention, diagnostics, and customer support.
Consent
Where required for non-essential cookies, certain marketing communications, or specific optional product actions.
Legal obligation
Where we need to comply with applicable law, lawful requests, tax, accounting, or enforcement obligations.
We use personal data to:
We do not: sell personal data, share personal data with third parties for their own direct marketing, or use your customer source data to train third-party AI models for general-purpose model improvement without your explicit consent.
We do not use customer data for advertising profiling or cross-context behavioural advertising.
Authorised Marcenta personnel may access account, billing, diagnostic, and customer source data when reasonably necessary to operate the Service, respond to support requests, investigate incidents, enforce our terms, or comply with law.
We limit that access to authorised personnel and to the information reasonably required for the task at hand. We do not access customer data for resale or unrelated commercial exploitation.
Marcenta uses AI models to help generate insights, summaries, charts, anomaly explanations, diagnostic prompts, and other AI-assisted outputs. To provide those features, we may send prompts and structured source data or metric summaries to API-based model providers that are necessary to generate the requested result.
Marcenta provides assistive analytics and recommendations. Humans remain responsible for reviewing outputs and for all business decisions and actions taken from those outputs.
We share personal data only with service providers and subprocessors that help us operate the Service, such as infrastructure providers, authentication and database providers, AI providers, email providers, billing providers, and monitoring providers.
Current details are available in our Subprocessor List.
We use third-party service providers for infrastructure and operations, including providers such as Supabase, Vercel, Railway, Modal, OpenAI, Resend, Dodo Payments, IPinfo, and Sentry. These providers process data only to provide services on Marcenta's behalf under applicable contractual and platform controls.
We may update our subprocessors from time to time. Where changes are material, we may provide notice through the Service, by email, or by updating our published subprocessor information.
We may also disclose personal data if required by law, regulation, court order, or valid governmental request, or where necessary to protect rights, safety, and the security of the Service.
If Marcenta is involved in a merger, acquisition, financing, reorganisation, bankruptcy, asset sale, or similar business transfer, customer and user data may be transferred as part of that transaction, subject to this Privacy Policy and applicable law.
Marcenta uses providers that may process data in multiple countries, including India and the United States. If you are located in a jurisdiction that restricts international transfers, we rely on appropriate transfer mechanisms such as contractual safeguards and, where available, recognised adequacy or certification mechanisms.
Enterprise customers may request a Data Processing Addendum (DPA) where required by applicable law.
| Data type | Retention period |
|---|---|
| Account and workspace data | For the duration of the account and for a reasonable period afterward for security, support, and compliance purposes |
| Connected source data | For the duration of the subscription or workspace relationship unless deleted earlier, plus reasonable backup and incident-recovery periods |
| Billing and subscription data | For as long as necessary for billing, accounting, audit, and legal compliance |
| Usage, logs, and diagnostics | For as long as reasonably needed for security, debugging, service monitoring, and abuse prevention |
| Support and communications | For as long as needed to manage the relationship and resolve issues, then archived or deleted under our retention practices |
Deleted data may remain in encrypted backups or disaster recovery systems for a limited retention period before permanent removal.
If GDPR applies, you may have rights to access, correct, delete, restrict, object to, or port certain personal data.
If California law applies, you may have rights to know, access, correct, delete, and limit certain uses of personal information, subject to applicable exceptions.
To exercise applicable rights, contact us at legal@marcenta.ai. We may need to verify your identity before acting on a request.
Depending on your plan and role, you can also request or manage practical account controls, including data export requests, account deletion, workspace deletion, AI conversation or output deletion where technically feasible and subject to applicable legal, security, or operational retention requirements, and integration disconnect controls.
We may send marketing communications where permitted by law. You can opt out at any time using the unsubscribe mechanism in the message or by contacting legal@marcenta.ai. Transactional and service-related messages are not marketing opt-in dependent.
We use technical and organisational safeguards designed to protect personal data, including encryption in transit and at rest, organisation-scoped tenant isolation, role-based access controls, infrastructure and vendor controls, and operational monitoring. Access is restricted to authorised personnel who need it for legitimate service operations.
We maintain operational and activity logging for key product and system events, monitor systems for misuse and security events, and maintain incident handling processes designed to investigate, contain, and remediate material incidents. Marcenta infrastructure is hosted through trusted cloud providers. No system is completely secure, and we cannot guarantee absolute security.
Customers are responsible for managing workspace access permissions, protecting account credentials, and maintaining appropriate internal access controls.
Marcenta is not directed to children, and we do not knowingly provide the Service to children under 13, or under 16 where a higher local age applies.
The Service connects to third-party platforms and data providers such as Google Analytics 4, Google Search Console, Google Ads, LinkedIn Ads, HubSpot, CRM systems, analytics platforms, advertising platforms, and related business tools. Their privacy practices are governed by their own terms and policies, not this Privacy Policy.
Connecting third-party integrations may permit Marcenta to access, import, process, and analyse data made available by those services according to your configuration, permissions, and account settings.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the date above and, where appropriate, by providing in-product or email notice.
Email: legal@marcenta.ai
Website: marcenta.ai
Contact us to ask about this policy or exercise an applicable privacy right.
Email legal@marcenta.ai