This Privacy Policy explains how Marvyn, operated by Eleven Square Labs, collects, uses, stores, and shares information when you use our website, application, and connected integrations. By using Marvyn, you agree to the practices described here.
1. Who We Are
Marvyn is an AI-powered marketing workspace operated by Eleven Square Labs, 648/A OM Chambers, 4th Floor, Binnamangala 1st Stage, Indiranagar, Bangalore – 560038, India.
General support: support@marvyn.tech
Privacy and data requests: dataofficer@marvyn.tech
2. Information We Collect
Account and authentication data
- Name, email address, and password when you register directly.
- OAuth identity and profile metadata when you connect supported third-party platforms.
Billing and usage data
- Subscription status, selected plan, billing profile, legal name, GSTIN where provided, billing address, city, state, PIN code, invoice records, credit-note records, refund records, and product usage records.
- Razorpay subscription IDs, payment IDs, refund IDs, webhook delivery records, and payment status metadata needed to operate billing, invoices, refunds, dispute handling, accounting, and fraud prevention.
- Razorpay processes card, UPI, bank mandate, and other payment credentials. Marvyn does not store full card numbers, CVV, UPI credentials, or bank account details.
Workspace and brand data
Brand profile information, competitor lists, generated content, campaign notes, SEO data, analytics preferences, alert settings, and any content you create or upload inside Marvyn.
Connected platform data
When you connect Google, Meta, LinkedIn, Microsoft Clarity, or other supported services, we store access tokens, refresh tokens where applicable, and operational metadata such as account IDs, page IDs, customer IDs, site URLs, and GA4 property IDs.
Usage, logs, and support data
- Feature usage, request logs, diagnostics, browser/device data, timestamps, and IP-related logs.
- Support communications and account-related notifications.
- Session and behavior analytics on Marvyn’s own website and app, as described below.
3. How We Use Information
- To operate, secure, and improve the Marvyn platform.
- To authenticate users, manage subscriptions, issue invoices, process refunds, and administer billing.
- To connect to third-party platforms you authorize and fetch or publish data on your behalf.
- To generate AI-powered outputs using your prompts, workspace context, and connected data.
- To send transactional notifications, billing communications, and support responses.
- To diagnose incidents, prevent abuse, and comply with legal obligations.
We do not sell your personal data. We also do not use your connected platform data for our own advertising targeting beyond the actions you explicitly authorize inside Marvyn.
4. AI Processing and Model Providers
Marvyn uses Anthropic to generate certain AI-powered outputs, analysis, and recommendations. Anthropic acts as a service provider or processor for these features. Prompts and the minimum workspace context required to provide the requested user-facing feature may be transmitted to Anthropic for processing.
We do not permit Anthropic to use your connected-platform data, including Google user data, to train generalized models. We send only the minimum information required to produce the requested output and only when you invoke a feature that requires AI processing.
You remain responsible for reviewing all AI-generated outputs before publication, distribution, or business use.
5. Third-Party Platform Connections
Marvyn uses the following Google scopes when authorized by you:
- Read Google Ads performance and selected customer-account data.
- Read Google Search Console site and query performance data.
- Read GA4 property, session, channel, conversion, and landing-page analytics.
- Read and manage authorized Google Business Profile location data that you connect to Marvyn.
This may include customer-account identifiers, site URLs, GA4 property identifiers, Google Business Profile location identifiers, campaign performance metrics, query and landing-page performance data, sessions, channels, conversions, business profile data, and related reporting fields exposed by the Google APIs you authorize.
How Google Data Is Displayed in the Product
Data retrieved via Google APIs, including Google Ads, Google Search Console, Google Analytics 4, and Google Business Profile, is displayed within user-facing Marvyn product surfaces such as the Ads workspace, SEO workspace, Analytics dashboards, local/profile reporting surfaces, summaries, and reports. Users can view campaign metrics, traffic, engagement, query performance, landing-page performance, business profile/location data, and conversion insights directly inside the application. We do not use Google user data outside these product features except as necessary for support, security, legal compliance, and service operations consistent with applicable law and Google's policies.
Sharing and Transfer of Google User Data
Marvyn processes Google user data inside our application and may transfer Google user data to Anthropic only when needed to provide a user-requested feature inside Marvyn, such as analysis, summaries, recommendations, or reports shown to the authorized user inside the product. We do not sell Google user data. We do not share Google user data with data brokers. We do not use Google user data to train generalized AI or machine learning models.
Google user data is not transferred to Anthropic for unrelated advertising, model improvement for generalized systems, or any purpose other than providing the specific feature you invoke inside Marvyn. Access to Google user data is limited to the authenticated user, authorized workspace members, and authorized personnel or service providers with a legitimate operational need.
Marvyn's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Meta
Marvyn uses these Meta permissions when authorized by you:
- Read Meta ad accounts, campaign structure, campaign insights, and related advertising performance data.
- Manage authorized Meta ad-account connection operations required to maintain the integration, including webhook or account-subscription setup where enabled.
- Read Meta Business account and asset metadata needed to identify the ad accounts, Facebook Pages, and Instagram business accounts you choose to connect.
- List Facebook Pages you administer and read Page engagement or Page metadata for reporting inside Marvyn.
- Publish Facebook Page posts only when the publishing feature is enabled and you initiate the action inside Marvyn.
- Read Instagram business account profile information and Instagram insights for connected accounts.
Marvyn uses these LinkedIn scopes when authorized by you:
- Identify your profile and save basic profile metadata.
- Fetch LinkedIn ad accounts where available.
- Publish LinkedIn UGC posts when you initiate publishing in Marvyn.
Shopify
When you connect your Shopify store to Marvyn, we access the following data via the Shopify Admin API using these scopes:
- Order data (read_orders): Order IDs, order dates, revenue, subtotal, shipping, tax, discounts, refunds, order source, financial status, cancellation status, and shop currency.
- Product and line-item data (read_products): Line item IDs, product IDs, product titles, quantities, line revenue, and line discounts, used for product performance reporting.
- Checkout data (read_checkouts): Checkout IDs, checkout dates, checkout value, and whether a checkout was completed or abandoned, used to report abandoned-checkout leakage and recovery opportunity.
- Customer analytics (read_customers): Order counts, lifetime spend, first and last order dates, and country, used for new-versus-returning, repeat purchase rate, and cohort/LTV reporting.
- Customer and storefront event data (read_customer_events): Aggregate daily counts of storefront events such as product viewed, added to cart, checkout started, and purchase, used to report the conversion funnel.
- Discount and price rule data (read_discounts, read_price_rules): Discount and price rule names, types, values, status, schedule, and usage counts, used to report promotion performance and discount leakage.
- Return data (read_returns): Return IDs, return dates, status, quantities, refund amounts, and Shopify's return reason codes, used to report return rate and returned products.
- Analytics data (read_analytics): Aggregate store sessions, visitors, and conversion rate reported by Shopify.
- Store metadata: Shop domain, shop name, and store currency needed to display Shopify reporting inside Marvyn.
Protected Customer Data. The read_customers and read_customer_events scopes are classed by Shopify as Protected Customer Data, and we hold them on a deliberately restricted basis. We do notstore Shopify customer names, email addresses, phone numbers, street addresses, or raw Shopify customer IDs. A customer's identity is converted into a salted, irreversible hash at the point we receive it, before anything is written to our database, so that we can count repeat purchases and build cohorts without holding a record of who your customers are. That hash cannot be reversed by us or by anyone who obtained our data, and it cannot be used to contact a customer. Geography is retained only at country level, never as an address. Storefront events are stored as aggregate daily counts, never as an individual person's browsing history.
Shopify data is used solely to generate store performance reporting, marketing insights, attribution analysis, and recommendations within Marvyn. We do not share, sell, or use your store data to train AI models or for any purpose beyond delivering the product features you have authorised. You can disconnect your Shopify store at any time from Settings, which removes Marvyn's access token. You may also revoke access directly from your Shopify admin under Apps & sales channels. On disconnection, or on a Shopify shop-redact request, we delete the store's data keyed by shop domain; customer-redact requests are honoured against the hashed identity.
Slack
When you connect a Slack workspace to Marvyn, Slack becomes a place to talk to Marvyn — it is never used as a marketing data source. We receive only the messages that mention Marvyn (and, if enabled, direct messages sent to the Marvyn app), and we use those messages solely to generate a reply from your connected Marvyn data. We do not read or store your other channel messages, and we do not read channel history.
We store installation metadata for the connection (workspace ID and name, the connecting account, granted scopes), the workspace access token encrypted at rest, and the minimal per-question trace (the question asked and a preview of the answer) that we keep for every Marvyn conversation to operate and debug the service. You can disconnect Slack at any time from Integrations, which deactivates the connection; you can also remove the app from your workspace in Slack's admin.
Microsoft Clarity
If you connect Clarity, Marvyn reads project-level behavioral analytics including sessions, scroll depth, dead clicks, rage clicks, and device/browser breakdowns.
DataForSEO
Marvyn uses DataForSEO for SEO crawl, keyword, competitor, and SERP-related analysis. Domains, URLs, and search-analysis inputs you submit may be sent to DataForSEO for processing.
You can disconnect supported platforms from Settings. You may also revoke access directly from the provider’s own security or app-permissions controls.
6. Analytics and Tracking on Marvyn’s Own Website and App
Separate from customer-connected accounts, Marvyn may use first-party analytics and advertising technologies on its own website and application, including Microsoft Clarity, Google analytics or tagging, Meta Pixel, and LinkedIn Insight Tag, to understand product usage, measure campaigns, and improve the service.
These tools may collect browser, device, interaction, page-view, and conversion-related information on Marvyn-owned properties. They do not grant us access to your third-party business accounts unless you separately connect those accounts inside the product.
7. Cookies and Similar Technologies
We use cookies, local storage, pixels, tags, and similar technologies for authentication, preferences, analytics, and marketing measurement. See our Cookie Policy for details.
8. Storage, Security, and Retention
Marvyn stores account, workspace, and integration data in infrastructure that includes MongoDB and other supporting service providers. OAuth tokens and operational credentials are stored with access controls and used only to provide the features you authorize.
We retain data for as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. When accounts are deleted or platform connections are removed, related data is deleted or deactivated according to operational and legal requirements. Connected-platform tokens are invalidated or removed when you disconnect the platform or when retention is no longer required for the authorized feature.
We protect sensitive data using encryption in transit, restricted access controls, authenticated internal systems, and operational safeguards designed to limit who can access connected-platform data and credentials. Access to production data is limited to authorized personnel with a legitimate operational need and is subject to role-based access controls.
We do not permit routine human review of individual connected-platform data, including Google user data, except where access is necessary for support requested by the user, security investigation, fraud prevention, legal compliance, or other internal operations permitted by applicable law and platform rules.
9. Your Rights and Data Deletion
You may request access, correction, deletion, or export-related assistance for your personal data.
- General support: support@marvyn.tech
- Privacy and deletion requests: dataofficer@marvyn.tech
Disconnecting a platform from Settings removes Marvyn’s active access for that integration. Some provider-side permissions may also need to be revoked directly from the provider dashboard.
10. International Processing
Some of our processors and integrated platforms may process data outside India. By using Marvyn and connecting third-party services, you understand that information may be transferred internationally as necessary to provide the service.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app, email, or both. Continued use of Marvyn after an update takes effect means you accept the revised policy.
12. Contact
Eleven Square Labs
648/A OM Chambers, 4th Floor, Binnamangala 1st Stage,
Indiranagar, Bangalore – 560038, India
Support: support@marvyn.tech
Data protection and deletion: dataofficer@marvyn.tech
