Privacy Policy — Margo
Last updated: 22 August 2026
Status: Pre-launch. Margo is in active development and not yet generally available.
This page still has business and legal decisions missing. Every highlighted mark like Placeholder, needs input: THIS is a placeholder that needs to be filled in — including an entire clause in the Terms — before this can be relied on as a finished policy.
1. Who we are
Margo is operated by Placeholder, needs input: LEGAL ENTITY NAME, registered in Placeholder, needs input: JURISDICTION at Placeholder, needs input: REGISTERED ADDRESS (“we”, “us”).
For the personal data described in §3.1 and §3.3 we are the data controller. For the customer business data described in §3.2 we act as a data processor on behalf of the customer, who remains the controller.
Contact: sales@switchpointpartners.com
2. What Margo does
Margo is a business analytics tool for companies that sell products to Amazon as vendors. Customers upload their own commercial reports — purchase orders, shipped and sold figures, costs, chargebacks — and Margo analyses profitability, pricing and inventory.
Margo is not a consumer product and is not intended for personal use.
3. What we collect
3.1 Account data
When you sign in with Google or Microsoft we receive your email address, name and a stable account identifier from that provider. We use the identifier — never the email — to key your account internally. We do not receive or store your password.
We also record the company name, address, and your role at that company that you provide at signup, and a referral code if you enter one.
3.2 Customer business data
The reports you upload. This is commercial data about products and trade, not personal data — SKUs, costs, prices, volumes, margins. If you upload a file that happens to contain personal data, you are responsible for that under §7.
3.3 Usage and technical data
Sign-in times, sign-in counts, actions taken in the application, and standard server logs (IP address, request path, timestamp, user agent). We keep an audit trail of security-relevant events — sign-ins, permission changes, subscription changes, administrative access.
3.4 Payment data
Payments are handled entirely by Stripe. Card numbers never reach our servers and we never store them. We hold a Stripe customer reference, your subscription status, and your billing address for tax purposes.
3.5 Pilot waitlist
If you sign up for pilot interest through the waitlist form at /signup, we collect your email address, name and role. We use this only to get in touch about the pilot — a legitimate interest, and, if the conversation leads to an engagement, a pre-contractual step. We keep it until the pilot waitlist is closed, then delete it. Contact: sales@switchpointpartners.com.
4. Why we process it, and our lawful basis
| Purpose | Lawful basis (UK/EU GDPR) |
|---|---|
| Providing the service | Performance of a contract |
| Authenticating you and securing accounts | Legitimate interests — keeping accounts safe |
| Taking payment, tax compliance | Contract, and legal obligation |
| Detecting abuse and controlling costs | Legitimate interests |
| Service emails (billing, security) | Contract |
We do not sell personal data, and we do not use customer business data to train models for anyone other than that customer.
5. Where your data is stored
Primary storage is in the European Union: Google Cloud Firestore (EU multi-region) and Google Cloud Run (Belgium, europe-west1).
Two honest exceptions:
- Operational server logs are currently held in Google Cloud’s default logging location, which is not EU-restricted. We are moving these to an EU-located bucket.
- SerpAPI (§6) is a US service and receives product identifiers and search terms.
6. Who else processes your data (sub-processors)
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, database, storage | EU (Belgium / EU multi-region) |
| Google LLC | Sign-in (OAuth) | US |
| Microsoft | Sign-in (OAuth), if you use it | US/EU |
| Stripe | Payments, invoicing, tax | US/EU |
| Keepa GmbH | Amazon market data | Germany |
| SerpAPI | Retailer price lookups | US |
| Cloudflare | Bot protection on signup | US/global |
Transfers outside the UK/EEA rely on Standard Contractual Clauses and the UK Addendum where applicable.
We will give customers notice before adding a sub-processor. Placeholder, needs input: CONFIRM NOTICE PERIOD — 30 DAYS IS TYPICAL
7. Your responsibilities as a customer
Margo is built for commercial data. If you upload files containing personal data, you confirm you have a lawful basis to do so, and you remain its controller. Please do not upload personal data you do not need Margo to process.
8. How long we keep it
| Data | Retention |
|---|---|
| Uploaded source files | 180 days |
| Processed analytics data | Life of the contract, then deleted |
| Account and audit records | Life of the contract, plus Placeholder, needs input: RETENTION WINDOW |
| Invoices and tax records | As required by law — typically 6–7 years |
9. Your rights
Under UK/EU GDPR you may request access, correction, deletion, restriction, portability, or object to processing. Under the CCPA/CPRA, California residents may request to know, delete, correct, and to opt out of sale or sharing — we do not sell or share personal information as those terms are defined.
Email sales@switchpointpartners.com. We respond within 30 days. We have tooling to carry out deletion across every store, including backups of uploaded files.
You may also complain to your supervisory authority — in the UK, the ICO.
10. Security
Access is authenticated through your identity provider; we never handle passwords. Data is encrypted in transit and at rest. Each customer’s data is isolated, and access is checked on every request. We keep audit logs of security-relevant events. Payment card data never touches our systems.
No system is perfectly secure. If a breach affects your personal data we will notify the relevant supervisory authority within 72 hours and you without undue delay.
11. Cookies
We use strictly necessary cookies only — to keep you signed in and to protect against cross-site request forgery. We do not use advertising or analytics cookies, which is why you are not being asked to accept a cookie banner.
12. Children
Margo is a business product and is not directed at anyone under 18.
13. Changes
We will post changes here and update the date above. For material changes affecting customers we will give notice by email.
14. Contact
Placeholder, needs input: LEGAL ENTITY NAME, Placeholder, needs input: REGISTERED ADDRESS — sales@switchpointpartners.com