Margly
FeaturesCalculatorIntegrationsReviewsPricingPartner programHelpBlog
Sign inTry for free
Legal documentation

Privacy Policy

Last updated: July 12, 2026

1. Data Controller

The controller of personal data is the company:

MirandaMedia Group, s.r.o.
Registered office: Jankovcova 1595/14a, 170 00 Praha 7, Czech Republic
Company ID (IČ): 08272930
Tax ID (DIČ): CZ08272930
Registered in the Commercial Register maintained by the Municipal Court in Prague
E-mail: support@margly.io
Web: www.margly.io

(hereinafter referred to as the "Controller" or the "Provider")

Margly (hereinafter referred to as the "Application") is a SaaS analytics platform that helps e-commerce store operators understand their sales, margins, advertising, and customer behavior.

Margly reads your e-commerce and advertising data to show you analytics. We never sell your data or use it for advertising purposes. We only share it with third parties to the extent necessary to operate the service (e.g., AI analyses) — details in Section 4.


2. Scope of Processed Data

2.1 Account Data

Upon registration, we process:

  • E-mail address (for login and communication)
  • Company name and billing address (for invoicing)

2.2 E-commerce Platform Data

When you connect your e-commerce platform (Shoptet, Shopify, and Upgates), we read:

  • Orders — codes, dates, amounts, payment and delivery statuses
  • Order items — product names, quantities, prices, purchase prices
  • Customers — e-mail, name, phone number, billing address (street, city, postal code, country), delivery address, company ID and tax ID (solely for analytical aggregation, not for marketing purposes)
  • Products — names, codes, purchase prices

2.3 Google Ads Data

When you connect your Google Ads account via OAuth, we read:

  • Campaign performance (spend, clicks, impressions, conversions, revenue)
  • Ad group performance
  • Shopping product performance (advertising metrics at the product level)

We only read advertising performance data. We never create, modify, pause, or delete your campaigns or ads.

2.4 Google Analytics 4 Data

When you connect your Google Analytics 4 property via OAuth, we read:

  • Traffic sources and channel performance
  • Session and user metrics (aggregated — without identifying individuals)
  • E-commerce events (add to cart, checkout, purchase — aggregated counts)
  • Device breakdown and demographic data (age groups — aggregated)
  • Landing page performance

2.5 Google Search Console Data

When you connect your Google Search Console property via OAuth, we read:

  • Search queries that bring users to your website
  • Click and impression counts per query and page
  • Average search position
  • Device breakdown

2.6 Meta (Facebook and Instagram) Ads Data

When you connect your Meta Ads account via Facebook Login, we read:

  • Campaign, ad set, and ad performance (spend, clicks, impressions, conversions, revenue)
  • Placement breakdown (Facebook Feed, Instagram Stories, Reels, etc.)
  • Demographic breakdown (age, gender — aggregated)
  • Facebook Page metrics (content impressions and engagement counts)

We only read advertising performance data. We never create, modify, or manage your Meta ads or campaigns.

2.7 Sklik (Seznam.cz) Data

When you connect your Sklik account, we read:

  • Campaign performance (spend, clicks, impressions, conversions)
  • Customer reviews from Zboží.cz (“Verified by Customers”) via the Fénix API — the rating, review text, the reviewer’s username, and the match to a specific order (and thus to the customer)

We only read advertising performance data and customer reviews. We never create, modify, or manage your Sklik campaigns. We reply to reviews only at your instruction — the reply is sent to Zboží.cz on your behalf.

2.8 Heureka.cz and Heureka.sk Data

When you connect your Heureka account (cz and sk), we read:

  • Comparison-shopping and advertising product performance (spend, clicks, impressions, conversions)
  • Product positioning in listings and product-listing advertising metrics
  • Shop and product reviews (“Verified by Customers”) — the rating, review text (pros, cons, summary) and the match to a specific order (and thus to the customer). Heureka reviews are anonymous — they contain no reviewer name

We read advertising and comparison-shopping performance data and customer reviews. We never create, modify or manage your campaigns, product feeds or any advertising on Heureka.cz / Heureka.sk. We reply to reviews only at your instruction — the reply is sent to Heureka on your behalf.

2.9 Customer reviews and satisfaction (Sentiment)

We keep the reviews from Heureka and Zboží.cz (see 2.7 and 2.8) as a complete history and match them to your orders, customers and products. They are used for the satisfaction analysis in the Sentiment section (product and carrier ratings, topics from review texts) and for recommendations. Review texts are written by your customers and may contain personal data — you are their controller, Margly is the processor. Processing is automated (no human reads the data unless you consent or security or law requires it).

2.10 Uploaded Files

You may upload files to the Application for cost tracking:

  • Logistics costs (XLSX spreadsheets)
  • Invoices in PDF format (processed by artificial intelligence to extract cost items)

Uploaded files are processed and the extracted data is stored. Original files are not permanently retained after processing.

2.11 Technical Data

  • IP address (solely for security and rate limiting — not stored long-term)
  • Browser and device information (for debugging purposes)

3. Purposes and Legal Basis for Processing

Purpose of ProcessingData ProcessedLegal Basis
Displaying analytical dashboardsE-commerce, advertising, analytics dataPerformance of a contract (Art. 6(1)(b) GDPR)
Advisor — recommendationsAggregated business metricsPerformance of a contract
Invoicing and payment processingE-mail, billing addressPerformance of a contract
Service status e-mail notificationsE-mail addressLegitimate interest (Art. 6(1)(f) GDPR)
Security (rate limiting, fraud prevention)IP addressLegitimate interest
Service improvementAggregated, anonymized usage patternsLegitimate interest

4. Data Sharing with Third Parties

We do not sell, rent, or share your business data with any third parties for their own purposes.

To operate the Application, we use the following data processors, who process data solely based on our instructions:

ProcessorPurposeData ProcessedLocation / Region
HetznerApplication and database hostingAll application dataEU (Germany)
StripePayment processing (direct Customers)Billing informationUSA (EU data in EU)
Shopify Inc.Payment and subscription processing (Customers installed from Shopify App Store)Subscription identifier, status, billing period dates, shop owner e-mail, shop domain, countryCanada (Ottawa) / Ireland (EU operations)
ResendTransactional e-mailsE-mail addressUSA
Artificial intelligence service providerAI invoice and cost import, Advisor recommendationsContents of uploaded invoices and Excel files and aggregated business metrics (no customer personal data)USA

We have concluded data processing agreements with all processors pursuant to Art. 28 GDPR.

By concluding the Margly Terms of Service, the User simultaneously enters into a data processing agreementpursuant to Art. 28 GDPR (Section 16 of the Terms). The Provider is the processor of personal data of the User's customers; the User is the controller and is solely responsible for the lawful legal basis of such processing and for fulfilling information obligations to the data subjects.


5. Specific Provisions for Google API Data

The use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use data from Google solely to provide and improve the analytical features of Margly
  • We do not transfer Google data to third parties except where necessary for operating the service
  • We do not use Google data for advertising purposes
  • Google data is not read by humans unless you give explicit consent, it is required for service security, or it is required by law

6. Specific Provisions for Meta Platform Data

Data obtained through the Meta Marketing API is used exclusively to display advertising analytics within the Application. We comply with the Meta Platform Terms and Developer Policies. Specifically:

  • We only read advertising performance data — we never manage or modify your ads
  • We do not sell or share Meta data with third parties
  • We do not use Meta data to create user profiles for advertising
  • All Meta data will be deleted when you disconnect your account or cancel your Margly account

7. Data Retention Period

  • Active account: We retain data for the entire duration of your account
  • After subscription termination: Data is retained in read-only mode for 30 days, after which it is irreversibly deleted
  • Account deletion request: All data is irreversibly deleted within 30 days of your request
  • OAuth tokens: Encrypted using AES-256. Deleted immediately upon disconnecting a service
  • IP addresses: Retained for a maximum of 30 days for security purposes
  • Statutory archiving: Accounting and tax records (invoices, payment documents) are retained for the period prescribed by Czech Act No. 563/1991 Coll. on Accounting (typically 5 years; up to 10 years for documents under Act No. 235/2004 Coll. on VAT). Such records are stored separately from the application database and are not used to provide the Application.
  • Backups: Data may persist briefly (typically up to 30 days) in backup systems before being automatically rotated out. Access to backups is limited to a small group of administrators.
  • Security event logs:Records necessary to demonstrate compliance with the Provider's obligations (authorization, login attempts, security incidents) are retained for the period necessary to fulfil legal duties and to defend against claims.

8. Data Security

We implement the following security measures:

  • All data encrypted in transit (TLS/HTTPS) and sensitive data encrypted at rest (AES-256)
  • OAuth tokens stored exclusively in encrypted form (AES-256-GCM) — never in plaintext. This applies to Shopify, Google, Meta, Sklik, Heureka, and Upgates tokens.
  • Passwordless login using one-time codes (OTP) sent via e-mail
  • Rate limiting and IP blocking upon repeated failed login attempts
  • Strict data isolation between tenants — each e-shop's data is completely separated
  • Security HTTP headers (CSP, HSTS, X-Frame-Options) on all responses
  • Regular security audits

9. Data Subject Rights

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), you have the right to:

  • Access — request a copy of your personal data
  • Rectification — request correction of inaccurate data
  • Erasure— request deletion of your data ("right to be forgotten")
  • Portability — obtain your data in a machine-readable format
  • Restriction of processing — request restriction of processing under certain circumstances
  • Objection — object to processing based on legitimate interest
  • Withdrawal of consent — if processing is based on consent, you may withdraw it at any time

To exercise your rights, contact us at support@margly.io. We will respond to your request within 30 days.

If you believe that we are processing your personal data in violation of the GDPR, you have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection (UOOU)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
Web: www.uoou.cz


10. Cookies

Margly uses only essential cookies necessary for login and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.


11. Data Transfers Outside the EU/EEA

Some of our processors (Stripe, Resend and an artificial intelligence service provider) are located in the USA. Data transfers to the USA are carried out on the basis of the European Commission's adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

For Customers who installed the Application from the Shopify App Store, Shopify Inc., headquartered in Canada (Ottawa) with EU operations in Ireland, is additionally involved in payment processing. Personal data transfers to Canada are carried out on the basis of the European Commission's adequacy decision No. 2002/2/EC of 20 December 2001; no standard contractual clauses are required for this transfer. The relationship with Shopify Inc. is further governed by a data processing agreement forming part of the Shopify Partner Program Agreement.


12. Automated Decision-Making

The Application does not use automated decision-making or profiling within the meaning of Art. 22 GDPR. The AI Advisor provides recommendations based on aggregated business data, but all decisions are made by the user.


13. Protection of Children's Data

Margly is a B2B tool intended exclusively for business entities and entrepreneurs. The Application is not directed at minors and does not knowingly target users under 15 years of age(the threshold for an individual's independent consent under Section 7 of Czech Act No. 110/2019 Coll. on Personal Data Processing). If you believe that data of a person under 15 has been inadvertently collected, please contact us at support@margly.io and we will delete the data immediately.


14. Changes to This Policy

We may update this policy from time to time. We will notify the User of material changes by e-mail or by a notification in the Application reasonably in advance, typically 14 days before the changes take effect. The "Last updated" date in the document header always reflects the current version. Continued use of the Application after the changes take effect constitutes the User's acceptance of the updated policy.


15. Disclaimer of Liability for Processing

15.1.The Provider processes personal data exclusively on the User's instructions as controller. The User is solely responsible for having a valid legal basis under Article 6, or where applicable Article 9, GDPR for transferring personal data to Margly, for fulfilling information obligations to data subjects, and for the accuracy, completeness and timeliness of such data.

15.2. The Provider bears no liability for:

  • inaccuracy, incompleteness, unlawfulness or untimeliness of personal data provided by the User or third-party platforms (Shoptet, Shopify, Upgates, Google, Meta, Sklik, Heureka);
  • claims by data subjects caused by the User's breach of controller obligations (in particular absence of legal basis, failure to fulfil information obligations, insufficient security on the User's side);
  • delays or failures in exercising data subject rights caused by third parties, where erasure or transfer of data takes place in their systems (in particular Google, Meta);
  • damages arising from the User's breach of third-party platform terms;
  • damages caused by misuse of the User's credentials by third parties as a result of negligent handling.

15.3. To the extent permitted by law, the limitation of liability set out in the Terms of Service (Section 13) applies analogously to the processing of personal data under this Policy. This is without prejudice to liability under Article 82 GDPR to the extent it cannot be contractually excluded.


16. Contact

For any questions regarding the protection of personal data, please contact us:

MirandaMedia Group, s.r.o.
Jankovcova 1595/14a, 170 00 Praha 7, Czech Republic
Company ID (IČ): 08272930 | Tax ID (DIČ): CZ08272930
E-mail: support@margly.io
Web: www.margly.io

margly
Product
  • Features
  • Leak calculator
  • Integrations
  • Pricing
  • Reviews
  • Partner program
  • Blog
Support
  • Help center
  • Getting started with Margly
  • Integration guides
  • FAQ
Legal
  • Terms & Conditions
  • Privacy Policy
  • Data deletion
© 2026 Margly · Analytics and recommendations for e-shops · Data in EU
support@margly.io
in𝕏▶