Privacy Policy.
This policy explains what personal and business data MarginLabs collects, why we collect it, how we keep it safe, and the rights you have over it. We ask for unusually sensitive information — bank statements, financial accounts — so we hold ourselves to a high standard in how we handle it.
1 · Who we are
MarginLabs (“we”, “us”, “our”) is an Ireland-based provider of merchant cash advances to eCommerce and retail businesses in Ireland, the United Kingdom and the United States. We provide upfront funding by purchasing a portion of a business's future receivables, and we prepare a funding-readiness assessment (a “Read”) to inform our decision. For the purposes of data protection law, we are the data controller of the information described in this policy. As we are established in Ireland, our lead supervisory authority is the Irish Data Protection Commission (DPC).
| Legal entity | Luro Ventures Advisory Limited |
|---|---|
| Company no. | 815861 (registered in Ireland) |
| Registered address | Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland |
| Lead authority | Irish Data Protection Commission — dataprotection.ie |
| Contact | privacy@getmarginlabs.com |
2 · What we collect
Depending on how far you progress with us, we may collect:
Information you give us directly
- Identity & contact — your name, work email, the legal entity name and company number of your business, and your website URL.
- Financial documents — bank statements, monthly profit & loss statements, balance sheets, and management accounts you upload.
- Connected bank account (via Plaid) — if you choose to link a bank account through Plaid, we receive your account details (such as account name, type and balances) and transaction history. You enter your bank credentials with Plaid directly; MarginLabs never sees or stores your bank login. You can disconnect at any time — see Your rights.
- Connected store & accounting (via Rutter) — if you choose to link your e-commerce, marketplace or accounting platforms (such as Shopify, Amazon, QuickBooks or Xero) through Rutter, we receive read-only sales, order, payout and financial-statement data. You authorise the connection with each platform directly through Rutter; MarginLabs never sees or stores your platform login. You can disconnect at any time — see Your rights.
- Commerce data — store KPI exports (e.g. from Shopify) and, if you choose to connect them, data from accounting integrations.
Information we gather to prepare your Read
- Public records — Companies House filings and other publicly available information about your business.
- Digital footprint — publicly visible details of your website, SEO and social presence.
Information collected automatically
- Authentication data — we use passwordless “magic link” sign-in; we store your email and session tokens to keep you signed in securely.
- Basic technical data — standard server logs needed to operate and secure the service.
3 · Why we collect it & our lawful basis
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Prepare your funding-readiness “Read” | Financial, commerce & public-record data | Performance of a contract / steps prior to a contract |
| Assess, decide on and provide funding (merchant cash advance — purchase of future receivables) | Financial & identity data | Performance of a contract / steps prior to a contract |
| Operate sign-in & secure the service | Email, session tokens, logs | Legitimate interests (security) |
| Comply with legal & regulatory duties (incl. anti-money-laundering) | As required | Legal obligation |
Where we rely on consent (for example, to connect your bank account through Plaid, or your store and accounting platforms through Rutter), you can withdraw it at any time — see Your rights.
4 · Who we share it with (sub-processors)
We do not sell your data. We share it only with the service providers that help us run MarginLabs, and only as far as needed. Each is bound by a data-processing agreement.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, encrypted file storage & authentication | EU (Ireland) region |
| Vercel | Website & application hosting | Global CDN |
| Resend | Sends sign-in & notification emails | EU region |
| Plaid | Securely connects your bank account, at your request, so we receive your balances & transactions (you enter your bank login with Plaid, not us). Governed by Plaid's End User Privacy Policy. | US / UK / EU |
| Rutter | Securely connects your commerce & accounting platforms (e.g. Shopify, Amazon, QuickBooks, Xero), at your request, so we receive read-only sales, payout & financial-statement data (you authorise each platform through Rutter, not us). Governed by Rutter's Privacy Policy. | United States |
| Anthropic (Claude) | AI assistance with preparing your Read (analysis & drafting) | United States |
5 · Which law applies (Ireland · UK · USA)
We serve customers in three regions and apply the protections of each:
- Ireland & the EU — the EU General Data Protection Regulation (GDPR) applies, supervised by the Irish Data Protection Commission. This is our baseline standard for everyone.
- United Kingdom — the UK GDPR applies to UK customers, supervised by the UK Information Commissioner's Office (ICO). Its protections are materially equivalent to the EU regime.
- United States — where applicable, US state privacy laws (such as the California Consumer Privacy Act) apply. US customers have the same access, correction and deletion rights described below.
Wherever you are, we extend GDPR-level protection as our single standard rather than applying a weaker one by region.
6 · Where it's stored & how it's secured
- Your documents are stored in a private storage bucket hosted by Supabase in the EU (Ireland) region.
- Data is encrypted in transit (HTTPS/TLS) and encrypted at rest.
- Access is controlled by row-level security: each client can only ever access their own folder, and only named MarginLabs analysts on an internal allow-list can access client files.
- We sign in with passwordless magic links, so there are no passwords for us to lose.
7 · How long we keep it
| Data | Retention |
|---|---|
| Financial documents of a client we work with | Duration of engagement + 6 years for legal/tax records, then deleted |
| Documents of a prospect who does not proceed | Deleted within 90 days of last contact, or sooner on request |
| Account & contact data | Until you ask us to delete it, subject to legal duties |
8 · Your rights
Under the GDPR (and equivalent UK and US-state laws) you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and to withdraw consent. You also have the right to complain to your data protection regulator — the Irish Data Protection Commission (dataprotection.ie), the UK ICO (ico.org.uk), or your relevant US state authority.
The easiest way to exercise any of these is our Data Rights page, or email privacy@getmarginlabs.com. We respond within one month, as the law requires.
9 · Cookies
We keep cookies to a minimum. We use only what's strictly necessary to keep you securely signed in and to operate the service — we do not use advertising, analytics, or third-party tracking cookies. Because we set only essential cookies, no cookie-consent banner is required.
10 · Changes & contact
We may update this policy as our service evolves. The “last updated” date at the top always reflects the current version, and we'll notify you of material changes.