← MarginPilot

Privacy Policy

Last updated: 2026-07-27

MarginPilot ("we", "us") helps e-commerce businesses understand their advertising and content performance. This policy explains what data we collect, why, and the control you keep over it.

What we collect

Account data: your email address, name and password hash, managed by our authentication provider (Supabase). If you sign in with Google, we receive your email and basic profile from Google.

Advertising and page data from Meta: when you connect a Meta ad account or Facebook Page, we read campaign, ad-set, ad, audience and spend data, and your page's published posts and their engagement and video metrics — via Meta's official APIs, with the permissions you approve on Meta's consent screen. We request READ access; MarginPilot does not modify your ads unless and until you grant write access and approve a specific action.

Billing data: payments are processed by Stripe. We store your plan, subscription status and a Stripe customer reference — never your card number.

Usage analytics: we use Umami (a privacy-focused, cookieless analytics tool) to understand aggregate page usage.

How we use it

To show you your own numbers: spend, cost per result, audience performance, content scores and profit-oriented recommendations.

AI analysis: portions of your advertising and content data (for example campaign metrics, post captions and post thumbnails) are sent to Anthropic's Claude models to generate the reports and recommendations you request. Anthropic processes this data to provide the service and, per their commercial terms, does not train models on it.

We do not sell your data. We do not share it with advertisers or data brokers. Ever.

Storage and security

Data is stored in Supabase (PostgreSQL) with row-level security isolating every organization — your data is scoped to your organization at the database layer, not just in application code.

Meta access tokens are stored server-side and are not readable from the browser. Traffic is encrypted in transit (HTTPS).

Cookies and analytics

We keep cookies to the minimum needed to run the product. Authentication cookies (set by Supabase) keep you signed in. One functional cookie, mp-lang, remembers your language choice (English or Arabic) for one year. Neither is used for tracking or advertising.

For usage analytics we run Umami, a privacy-focused tool configured cookieless: it sets no cookies, respects your browser's Do Not Track setting, and gives us only aggregate page statistics — never a profile of you. Because no tracking cookies exist, we don't show a consent banner; this disclosure is the complete picture.

Retention and deletion

Your data stays while your account is active. You can delete your organization and ALL its data at any time from Settings → Delete organization — see our Data Deletion page for the exact steps. Deletion is immediate in the live database; residual copies in encrypted backups expire within 30 days.

Disconnecting Meta removes the stored access tokens immediately.

Your rights

You may access, correct, export or delete your personal data. Contact us at support@marginpilot.ai for any request you can't complete in-app; we respond within 30 days.

Contact

MarginPilot — support@marginpilot.ai

© 2026 MarginPilot · Privacy · Terms · Data deletion