Privacy Policy.
This policy explains what personal and business data MarginLabs collects, why we collect it, how we keep it safe, and the rights you have over it. We ask for unusually sensitive information — bank statements, financial accounts — so we hold ourselves to a high standard in how we handle it.
1 · Who we are
MarginLabs (“we”, “us”, “our”) is an Ireland-based commercial advisory and credit-broking practice serving eCommerce and retail businesses in Ireland, the United Kingdom and the United States. For the purposes of data protection law, we are the data controller of the information described in this policy. As we are established in Ireland, our lead supervisory authority is the Irish Data Protection Commission (DPC).
| Legal entity | [REGISTERED COMPANY NAME LTD] |
|---|---|
| Company no. | [COMPANIES HOUSE NUMBER] |
| Registered address | [REGISTERED ADDRESS] |
| Lead authority | Irish Data Protection Commission — dataprotection.ie |
| Contact | privacy@getmarginlabs.com |
2 · What we collect
Depending on how far you progress with us, we may collect:
Information you give us directly
- Identity & contact — your name, work email, the legal entity name and company number of your business, and your website URL.
- Financial documents — bank statements, monthly profit & loss statements, balance sheets, and management accounts you upload.
- Commerce data — store KPI exports (e.g. from Shopify) and, if you choose to connect them in future, data from accounting or banking integrations.
Information we gather to prepare your Read
- Public records — Companies House filings and other publicly available information about your business.
- Digital footprint — publicly visible details of your website, SEO and social presence.
Information collected automatically
- Authentication data — we use passwordless “magic link” sign-in; we store your email and session tokens to keep you signed in securely.
- Basic technical data — standard server logs needed to operate and secure the service.
3 · Why we collect it & our lawful basis
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Prepare your funding-readiness “Read” and advise you | Financial, commerce & public-record data | Performance of a contract / steps prior to a contract |
| Introduce you to lenders & credit products (broking) | Financial & identity data you authorise us to share | Consent & performance of a contract |
| Operate sign-in & secure the service | Email, session tokens, logs | Legitimate interests (security) |
| Comply with legal & regulatory duties | As required | Legal obligation |
Where we rely on consent (for example, to share your file with a specific lender), you can withdraw it at any time — see Your rights.
4 · Who we share it with (sub-processors)
We do not sell your data. We share it only with the service providers that help us run MarginLabs, and only as far as needed. Each is bound by a data-processing agreement.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, encrypted file storage & authentication | EU (Ireland) region |
| Vercel | Website & application hosting | Global CDN |
| Resend | Sends sign-in & notification emails | EU region |
| [AI PROVIDER, if used for analysis] | Assists with preparing your Read | [REGION] |
| Lenders & finance providers | Only those you explicitly authorise, to assess you for funding | UK / as applicable |
5 · Which law applies (Ireland · UK · USA)
We serve customers in three regions and apply the protections of each:
- Ireland & the EU — the EU General Data Protection Regulation (GDPR) applies, supervised by the Irish Data Protection Commission. This is our baseline standard for everyone.
- United Kingdom — the UK GDPR applies to UK customers, supervised by the UK Information Commissioner's Office (ICO). Its protections are materially equivalent to the EU regime.
- United States — where applicable, US state privacy laws (such as the California Consumer Privacy Act) apply. US customers have the same access, correction and deletion rights described below.
Wherever you are, we extend GDPR-level protection as our single standard rather than applying a weaker one by region.
6 · Where it's stored & how it's secured
- Your documents are stored in a private storage bucket hosted by Supabase in the EU (Ireland) region.
- Data is encrypted in transit (HTTPS/TLS) and encrypted at rest.
- Access is controlled by row-level security: each client can only ever access their own folder, and only named MarginLabs analysts on an internal allow-list can access client files.
- We sign in with passwordless magic links, so there are no passwords for us to lose.
7 · How long we keep it
| Data | Retention |
|---|---|
| Financial documents of a client we work with | Duration of engagement + [e.g. 6 years] for legal/tax records, then deleted |
| Documents of a prospect who does not proceed | Deleted within [e.g. 90 days] of last contact, or sooner on request |
| Account & contact data | Until you ask us to delete it, subject to legal duties |
8 · Your rights
Under the GDPR (and equivalent UK and US-state laws) you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and to withdraw consent. You also have the right to complain to your data protection regulator — the Irish Data Protection Commission (dataprotection.ie), the UK ICO (ico.org.uk), or your relevant US state authority.
The easiest way to exercise any of these is our Data Rights page, or email privacy@getmarginlabs.com. We respond within one month, as the law requires.
9 · Cookies
We keep cookies to a minimum. We use only what's needed to keep you securely signed in and to operate the service — we do not use advertising or third-party tracking cookies. [Confirm with your solicitor whether a cookie banner is required for your final setup.]
10 · Changes & contact
We may update this policy as our service evolves. The “last updated” date at the top always reflects the current version, and we'll notify you of material changes.