Privacy

Privacy Policy

Marlow is where teams record how their operations actually work. That is sensitive material, and we treat it that way. This policy explains what we collect, why, how long we keep it, and the choices you have.

Last updated August 1, 2026

The short version

  • We do not sell or share your personal data for advertising. Selling customer data is not part of Marlow's business model, and we have no plans to do so.
  • Your organization owns the content you create in Marlow.
  • We collect what's needed to run the product: your account details, the content you create, and basic operational logs.
  • We use a small, named set of subprocessors — hosting, email delivery, and Stripe for billing.
  • We don't use advertising or analytics cookies. Only strictly necessary cookies for signing in.
  • You can access, correct, export, or delete your data at any time.

Who we are

This policy covers makeitmarlow.com and the Marlow application ("Marlow", "we", "us"). For content you create inside a workspace, your organization is typically the data controller and Marlow acts as processor on its behalf. For your account and billing information, we are the controller. For any privacy question, contact security@makeitmarlow.com.

Your content

Your organization retains ownership of the maps, documentation, attachments, and other content you create in Marlow. We do not claim ownership of it, and we do not use it to train advertising or third-party models.

We access customer content only when necessary to operate, support, troubleshoot, secure, or improve the service, or when required by law.

What we collect

Account dataName, email address, password hash (or Google/Apple identifier if you use social sign-in), avatar colour, and notification preferences.
Content you createMaps, nodes, descriptions, custom fields, owners, comments, questions, assumptions, decisions, attachments, and version history.
Workspace and map dataWorkspace names, membership, roles, invitations, per-map permissions, and audit or activity events showing who changed what and when.
Guest share linksFor content shared by link with people who have no account: the link's scope and capability, a hash of the link token (never the token itself), and — on comment-enabled links — the display name a guest types alongside their comment.
Billing dataPlan, subscription status, and billing contact. Payment card details go directly to Stripe; we never receive or store full card numbers.
Technical and log dataIP address, browser and device type, timestamps, requested URLs, and error diagnostics, generated automatically when you use the service.
CommunicationsEmails you send us and support requests.

We don't ask for special-category data (health, biometric, political, religious, or similar information) and Marlow is not designed to hold it. Please don't put it into your maps.

Why we use it

  • Providing the service: authenticating you, storing and syncing your maps, and showing collaborators the right content.
  • Collaboration features: invitations, mentions, comments, questions, and notification emails you can control in your settings.
  • Security and abuse prevention: detecting unauthorized access, investigating incidents, and maintaining audit trails.
  • Support: answering your questions and debugging problems you report.
  • Billing: managing subscriptions, invoices, and tax records.
  • Product improvement: understanding aggregate usage patterns and fixing errors. We do not build advertising or behavioural profiles.

Legal bases (EU/UK)

  • Contract — to provide the service you or your organization signed up for.
  • Legitimate interests — to keep the service secure, prevent abuse, and improve reliability, balanced against your privacy.
  • Legal obligation — to retain billing and tax records.
  • Consent — where we ask for it explicitly, such as optional product-update emails. You can withdraw consent at any time.

Who we share data with

We share personal data only with the subprocessors below, each bound by contract to process it on our instructions and only for the stated purpose.

Lovable CloudHosting, managed database, authentication, file storage, and backend functions. Processes all account and content data.
Transactional email providerDelivery of account, invitation, and notification emails. Processes recipient email addresses and message content.
StripePayment processing and billing for paid plans. Processes billing contact and payment details.

We keep this list current and will update it when our subprocessors change. We may also disclose data if legally required by valid legal process, or in connection with a merger or acquisition — in which case this policy continues to apply to the transferred data. We do not sell personal data and do not share it for cross-context behavioural advertising, and selling customer data is not part of Marlow's business model.

Cookies and analytics

Marlow does not use advertising cookies, third-party analytics, or tracking pixels. We use only strictly necessary storage — a session cookie or local session token that keeps you signed in, and preference storage that remembers interface choices. Because we set no non-essential cookies, we don't show a consent banner. If that changes we will update this policy and ask for consent where the law requires it.

How long we keep it

Active account dataFor as long as your account is active.
After you delete your accountHeld for 30 days so it can be recovered on request, then permanently deleted.
Archived mapsRetained until permanently deleted by you. Permanent delete is immediate and irreversible.
Map version history and auto-backupsRetained according to the current application configuration.
Audit and activity eventsRetained according to the current application configuration.
Encrypted database backupsApproximately 14 days, rolling. Deleted data can persist in backups until it rolls out of that window.
Support and email delivery logsUp to 12 months.
Billing and tax recordsUp to 7 years, as required by law.

Retention periods are targets for how long we keep each category of data, not guarantees of instant deletion at the moment a period ends. Where deletion happens on a schedule, data may persist briefly beyond the stated window before it is removed.

International transfers

Marlow is hosted in the United States. If you are in the EU, UK, or Australia, your data is transferred to and processed in the US. For EU and UK transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our subprocessors, together with the technical measures described on our Security page. You can request a copy of the relevant transfer terms by emailing us.

Your rights

  • Access — get a copy of the personal data we hold about you.
  • Correction — fix inaccurate or incomplete data, most of which you can edit directly in your account.
  • Deletion — delete your account and associated content, subject to the retention periods above.
  • Portability — export your maps and receive your data in a machine-readable format.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it.
  • Withdraw consent — for anything we process on the basis of consent.
  • Complain — to your local data protection authority (in the UK, the ICO; in Australia, the OAIC).

Email security@makeitmarlow.com to exercise any of these. We respond as promptly as we can and within the time limits required by applicable law, and we never charge a fee or discriminate against you for asking. If your data sits inside an organization's workspace, we may need to route the request through that organization as controller — we'll tell you if so.

Regional disclosures

  • EU / UK (GDPR, UK GDPR): legal bases, transfer mechanisms, and rights are described above. We can enter into a Data Processing Addendum with business customers where one is required.
  • California (CCPA/CPRA): in the past 12 months we have not sold personal information and have not shared it for cross-context behavioural advertising, and we will not do so. We collect the categories of identifiers, commercial information, and internet activity described above. California residents have rights to know, delete, correct, and limit use of sensitive personal information; we do not use or disclose sensitive personal information for purposes beyond providing the service.
  • Australia (Privacy Act, APPs): we handle personal information in line with the Australian Privacy Principles, disclose it overseas only to the subprocessors listed above, and will notify you and the OAIC of any eligible data breach.

Security

All traffic is served over HTTPS with TLS, data is encrypted at rest, access to customer content is enforced at the database level by row-level security, and we run automated security and dependency scanning. Our full security posture, backup practice, and incident response approach are described on our Security page. If personal data is ever affected by a breach, we notify affected customers without undue delay and comply with applicable legal notification requirements.

Children

Marlow is a business tool and is not directed at children. You must be at least 16 years old to create an account. If we learn we've collected data from someone under 16, we delete it.

Changes to this policy

We'll update this page when our practices change and revise the "last updated" date. For material changes — a new category of data, a new purpose, or a new subprocessor that processes customer content — we'll notify account holders by email.

Contact

Privacy and security questions, data requests, and DPA requests: security@makeitmarlow.com.