Legal
Privacy Policy
Effective date: July 14, 2026 · Last updated: July 14, 2026
1. Who We Are
The Mark Platform ("Company", "we", "our", or "us") is a web-based marketing platform operated by its authors and contributors. Our registered business address is available upon written request. For all privacy-related matters, contact us at privacy@themarkplatform.com.
2. Scope of This Policy
This Privacy Policy applies to all information collected through the website at themarkplatform.com, any related subdomains, APIs, mobile applications, and any other services that link to this policy (collectively, the "Service"). It does not apply to information collected by third-party websites or services that we may link to. We are not responsible for the privacy practices of any third party.
3. Information We Collect
3.1 Information you provide directly
- Account registration data (name, email address, hashed password)
- Profile information you voluntarily add to your account
- Platform content you create (products, personas, offers, execution logs, funnels, campaigns, and other marketing data)
- Messages you send us via the contact form, email, or any support channel
- Payment and billing information (processed securely by our third-party payment processor — we do not store full card numbers, CVVs, or bank account details on our servers)
- OAuth tokens and profile data if you sign in via Google, Facebook, or other third-party authentication providers
3.2 Information collected automatically
- Log data (IP address, browser type and version, operating system, referring URL, pages visited, timestamps, and request metadata)
- Session identifiers stored in httpOnly, Secure cookies
- Aggregated and anonymized usage analytics to understand how the platform is used
- Device identifiers and screen resolution for responsive design optimization
3.3 Information from third parties
If you connect third-party integrations (analytics, payment processors, social media, advertising platforms), we may receive data from those services as described in our integration setup. You authorize this data transfer when you connect an integration. We store integration credentials using AES-256-GCM encryption.
3.4 Conversion data you choose to send to Meta
This is off by default and never turns on by itself. If you switch on “Sending conversions to Meta” in your Privacy Centre, and separately grant the “Send Conversions to Meta” permission on your Meta Ads integration, we send Meta a record of the conversions you report to us so your ad reporting can show what your spend produced.
What is sent, for each conversion you report: your customer’s email address, phone number, first and last name, city and country — each hashed with SHA-256 before it leaves our servers — together with their IP address and browser user agent (sent unhashed, as Meta’s specification requires), the event name, and the value and currency where you provide them.
Hashing is not anonymisation. The purpose of the hash is to let Meta match it against its own users. Meta cannot read the email address, but it can identify the person. You should treat this as sharing your customer’s identity with Meta, because in substance that is what it is.
Your responsibility. The people in this data are your customers, not ours. You need your own lawful basis to share their details with Meta, and your own privacy policy must say that you do. We provide the mechanism and the record; we cannot provide your legal basis.
Turning it off. Revoking the permission in your Privacy Centre stops all sending immediately and deletes the records of what was previously sent. It cannot retrieve what Meta already received — for that, contact Meta directly. We never send conversion data for accounts that have not switched this on.
4. How We Use Your Information
- To provide, operate, maintain, and improve the Service
- To authenticate your identity and maintain your session
- To process billing, manage subscriptions, and handle refunds
- To send transactional communications (account verification, password resets, billing receipts)
- To send product updates, feature announcements, and educational content (you can unsubscribe at any time)
- To respond to your support requests and contact form submissions
- To detect, investigate, and prevent fraud, abuse, and security incidents
- To enforce our Terms of Service and other agreements
- To comply with applicable legal obligations, court orders, and regulatory requirements
- To produce aggregated, anonymized analytics that cannot be used to identify you
5. How We Share Your Information
We do not sell, rent, lease, or trade your personal information to any third party for marketing or advertising purposes. We share data only in these limited circumstances:
- Service providers: Third-party vendors that process data on our behalf to provide the Service (e.g., payment processing, email delivery, cloud hosting, error monitoring). These providers are contractually obligated to use your data only as necessary to perform their services and are bound by confidentiality obligations.
- Legal requirements: When required by applicable law, regulation, legal process, or enforceable governmental request; to protect the rights, property, or safety of the Company, our users, or the public; or to detect, prevent, or address fraud, security, or technical issues.
- Business transfers: In connection with a merger, acquisition, reorganization, bankruptcy, asset sale, or similar transaction. If such a transfer occurs, we will use reasonable efforts to notify affected users via email or a prominent notice on the Service before personal data is transferred and becomes subject to a different privacy policy.
- With your consent: We may share information with third parties when you have given explicit, informed consent.
6. Data Security
We implement commercially reasonable administrative, technical, and physical security measures to protect your personal information, including:
- HTTPS/TLS encryption for all data in transit
- AES-256-GCM encryption for stored integration credentials (API keys, OAuth tokens) where an encryption key is configured for the deployment
- Bcrypt password hashing with per-user salts
- HttpOnly, Secure, SameSite=Lax session cookies, with tokens stored only as hashes
- Rate limiting on authentication endpoints
- CSRF token protection on state-changing form submissions
- A Content Security Policy restricting which scripts may run
- Outbound request filtering to prevent access to internal network addresses
- Dependency vulnerability audits
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Account data and platform content: Retained until you delete your account
- Sessions and sign-in records: 7 days after expiry
- API call history: 90 days
- Data exports: Deleted when the download link expires
- Billing records: 7 years, as required by tax and accounting law
- Consent records and security logs: Kept after account deletion as evidence that permissions were given and that the deletion itself was authorised
The complete, current list — every table, its purpose, and how long it is kept — is shown in your Privacy Centre, generated from the same registry the platform code uses. It therefore describes what actually happens rather than a separately maintained summary of it.
Upon account deletion, your data is removed within 30 days, except where we are legally required to retain it — those exceptions are listed above and shown individually in your Privacy Centre with the reason. Deletion is paused only where a rights request, a complaint, or a legal hold is open about that data, in which case we tell you and confirm within one month.
8. Your Rights
Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your account and all associated personal data
- Portability: Export your platform data in JSON or CSV format from your account settings
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to processing of your data for certain purposes, including direct marketing
- Withdrawal of consent: Withdraw consent at any time where we rely on consent as the legal basis for processing
To exercise any of these rights, contact us at privacy@themarkplatform.com. We will respond within 30 days. We may ask you to verify your identity before processing your request. Exercising these rights will not result in any discriminatory treatment.
9. Cookies & Tracking Technologies
We use the following categories of cookies:
- Strictly necessary cookies: Session authentication cookies (httpOnly, Secure, SameSite=Lax) and your cookie preference itself. These are required for the Service to function and cannot be disabled.
- Functional cookies: Preferences such as the selected project and dismissed UI elements.
- Analytics cookies: Google Analytics, which records your IP address and a persistent identifier for your browser. These are off unless you turn them on. No analytics script loads until you consent.
We do not use advertising cookies or behavioural retargeting. You can change or withdraw your choice at any time using the Privacy settings link in the footer of any page, or in your Privacy Centre. Withdrawing is one click, exactly like granting.
10. International Data Transfers
Your data may be processed and stored in countries other than your own. By using the Service, you consent to the transfer, processing, and storage of your information in these jurisdictions, which may have different data protection laws than your country of residence. We take commercially reasonable steps to ensure your data receives an adequate level of protection in the jurisdictions in which we process it.
11. Children’s Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, contact us at privacy@themarkplatform.com and we will delete it promptly.
12. Third-Party Links & Integrations
The Service may contain links to third-party websites, services, or integrations that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services. We strongly advise you to review the privacy policy of every third-party site you visit or service you connect. The Company shall not be liable for any loss or damage arising from your use of third-party services.
13. Limitation of Liability for Data Processing
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY, ITS AUTHORS, OWNERS, DIRECTORS, OFFICERS, EMPLOYEES, CONTRACTORS, AFFILIATES, AND AGENTS (COLLECTIVELY, THE "PROTECTED PARTIES") SHALL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM OR RELATED TO:
- ANY UNAUTHORIZED ACCESS TO OR USE OF YOUR PERSONAL DATA
- ANY DATA BREACH, SECURITY INCIDENT, OR SYSTEM COMPROMISE
- ANY LOSS, CORRUPTION, OR DESTRUCTION OF DATA
- ANY INTERRUPTION OR CESSATION OF THE SERVICE
- ANY ACTIONS OF THIRD-PARTY SERVICE PROVIDERS
THIS LIMITATION APPLIES REGARDLESS OF THE LEGAL THEORY ON WHICH THE CLAIM IS BASED, WHETHER THE PROTECTED PARTIES HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, AND EVEN IF A REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED ITS ESSENTIAL PURPOSE.
14. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. We will notify you of material changes by email or a prominent notice on the Service at least 14 days before the changes take effect, unless a shorter notice period is required by law. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy. If you do not agree with the revised policy, you must discontinue use of the Service and delete your account.
15. Contact Us
For privacy questions, data requests, or concerns about this policy, contact us at:
- Email: privacy@themarkplatform.com
- Contact form: themarkplatform.com/contact
We aim to respond to all privacy-related inquiries within 30 days.