Privacy Policy

Last updated: 20 June 2026

This Privacy Policy explains how Margeny (“Margeny”, “we”, “us”), operated by Diego Bermejo (sole trader / autónomo), Calle de Velázquez 15, 28001 Madrid, Spain, processes personal data. Margeny is a profit and margin analytics service for Shopify merchants.

1. Two roles: controller and processor

We act in two different capacities depending on the data:

  • As a controller for the personal data of the people who sign up for and use Margeny (our customers — merchants and their team members): your name, email address and authentication identifiers.
  • As a processor for the data we ingest from your connected store and ad accounts on your instruction — including your end customers’ personal data (name, email, order history). For that data you, the merchant, are the controller and we process it only to provide the analytics you asked for. See our Data Processing Addendum.

2. What we collect

  • Account data: your store name, contact email and the Shopify identifiers needed to link your store to your Margeny account. You access Margeny through your Shopify admin session; we run no separate login system.
  • Billing data: subscription status and identifiers. Charges are billed by Shopify on your Shopify invoice; we never see or store payment card details.
  • Connected store data: via the Shopify connection you authorise — orders, customers (including email), products, variants, refunds and payment transactions.
  • Connected ad data: aggregate advertising spend from ad platforms (e.g. Meta) when you connect them.
  • Technical data: standard logs needed to operate and secure the service.

3. Why we process it and legal basis

  • To provide the service (performance of our contract with you).
  • To take payment and prevent abuse (legitimate interests; legal obligation for accounting).
  • End-customer store data is processed to produce your analytics, on your documented instructions as controller.

4. Where data is stored

Our primary database is hosted in the European Union (Supabase, EU region). Some sub-processors are located outside the EU; where that happens, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.

5. Sub-processors

We rely on the following providers to run Margeny:

  • Supabase — database hosting (EU region)
  • Vercel — web application hosting
  • Railway — background data-sync workers
  • Resend — transactional email
  • Shopify — app distribution, authentication and subscription billing, and (with Meta, Google and TikTok) the platforms you connect as data sources

6. Retention

We keep account and store data for as long as your account is active. When you disconnect a store or close your account, we delete or anonymise the associated data within 30 days, except where we must retain limited records for legal or accounting reasons.

7. Your rights

Subject to applicable law, you may request access to, correction or deletion of your personal data, and object to or restrict certain processing. For end customers’ data we process on a merchant’s behalf, requests should be directed to that merchant; we will assist them as their processor. To exercise your rights, contact us at privacy@margeny.com.

8. Changes

We may update this policy; we will revise the “last updated” date above and, for material changes, notify account holders.

9. Contact

Questions about this policy: privacy@margeny.com.