Marginal

Data Processing Agreement

Last updated September 2, 2026.

Who this is between

This Data Processing Agreement (“DPA”) is between the merchant installing Marginal (“Merchant”, the controller of their own customers' personal data) and Marginal (“we”, “us”, the processor acting on the Merchant's instructions). It supplements our Privacy Policy and applies automatically from the moment a Merchant installs Marginal -- there's no separate signature step, the same way installing any Shopify app constitutes agreement to that app's terms.

Subject matter and duration

We process personal data on the Merchant's behalf for as long as Marginal stays connected to their Shopify store, solely to provide the analytics functionality described in our Privacy Policy. Processing ends when the Merchant disconnects or uninstalls Marginal, at which point their data is deleted per the retention terms in our Privacy Policy.

What we process, and why

Categories of data subjects: the Merchant's own customers (people who've placed an order in their Shopify store).

Categories of personal data: the Shopify customer ID attached to each order record, used only to tell first-time and repeat customers apart. We don't collect or process customer names, email addresses, phone numbers, physical addresses, or payment details -- Marginal never requests those Shopify scopes.

Purpose: computing revenue, margin, and ad-spend analytics, and matching orders to the same customer over time (e.g. to tell first-time from returning customers). We don't use this data for any purpose beyond providing the Merchant their own analytics -- see our Privacy Policy's “How we use it” section.

Our obligations

  • We process personal data only on the Merchant's instructions (i.e., to provide the app's functionality), never for our own separate purposes.
  • We keep it confidential -- access is limited to what's needed to operate and support Marginal, and today that access is limited to a single operator. We maintain a written security incident response policy covering how we'd contain, investigate, and disclose any breach of that.
  • We implement the security measures described below, and update them as the app and its real risk surface grow.
  • We help the Merchant respond to their own customers' data subject requests (access, correction, deletion) -- contact us and we'll act on it directly, per our Privacy Policy's “Your rights” section.
  • We delete or return personal data when the Merchant disconnects Marginal, and don't retain copies beyond the backup rotation window described in our Privacy Policy.
  • We'll notify affected Merchants without undue delay, and no later than required by applicable law, if we become aware of a breach involving their customers' personal data.

Security measures

Concretely, as of this DPA's last-updated date:

  • Data is encrypted in transit (HTTPS/TLS) and at rest.
  • OAuth access tokens for Shopify and connected ad platforms are separately encrypted (AES-256-GCM) before storage, not stored in plaintext even within our own database.
  • Database backups are encrypted and kept on a rolling 14-day window.
  • Local development and production use separate databases -- test activity never touches real Merchant data.
  • Access to the production database and infrastructure is limited to Marginal's single operator; no third-party staff have access.

Sub-processors

We use the following sub-processors to run Marginal -- each only processes data as needed to provide their part of the service:

  • Supabase (database hosting)
  • Vercel (application hosting)
  • Windsor.ai (retrieves Meta Ads, TikTok Ads, and Pinterest Ads -- and Google Ads for connections made before the Google Ads script -- campaign-level spend, impressions, and clicks -- never any personal customer data)
  • Anthropic (generates the plain-language explanations in the app -- receives only aggregate computed figures, never raw customer records, per our Privacy Policy)

If we add or change a sub-processor in a way that changes where or how personal data is handled, we'll update this page and the date at the top.

International transfers

Our infrastructure (Supabase, Vercel) may process and store data outside the Merchant's or their customers' country. Where this involves a transfer out of the EU/EEA or UK, we rely on our sub-processors' own standard contractual safeguards for that transfer.

A note on scope

Marginal is currently a small, single-operator app. This DPA reflects what's actually true about how we handle data today, in plain language, rather than a maximally broad legal template. If your organization needs a more formal, individually negotiated agreement, contact us and we'll work through it directly.

Contact

Questions about this agreement: support@usemarginal.com.