Legal

Privacy Policy

Last updated 1 June 2026

This Privacy Policy explains how MarketLin AB (“MarketLin”, “we”, “us”), org.nr 559549-8915, Kungängsgatan 17, 753 22 Uppsala, Sweden, handles personal data. It covers two contexts: (1) your use of our marketing website and early-access waitlist at marketlin.com, and (2) your use of the MarketLin application at app.marketlin.com. We act as the data controller in both cases, except where noted.

Contact: privacy@marketlin.com. We are not required to appoint a Data Protection Officer and have not appointed one; privacy questions go to that address.

Part 1 — Marketing website and early-access waitlist (marketlin.com)

This part applies when you visit marketlin.com and/or join our early-access waitlist.

What we collect (website)

When you join the waitlist we collect:

  • Your email address (required).
  • Your company name (optional).
  • The number of clients you manage (optional).
  • Your marketing-newsletter preference (optional).
  • Proof of consent: the exact consent wording version you agreed to, and a timestamp.
  • Technical data for security and spam-prevention: your IP address and similar request metadata at submission (used to rate-limit and screen for bots, not stored as a marketing attribute).

Why we use it — legal basis (website)

  • To contact you about early access — based on your consent (GDPR Art. 6(1)(a)).
  • To send product and marketing emails — only if you opted in; consent is withdrawable at any time.
  • To keep the site secure and prevent abuse — our legitimate interests (Art. 6(1)(f)).

Who we share it with (website)

We use a small number of trusted third-party processors. We do not sell your personal data.

Sub-processors for the marketing website
ProcessorWhat it receivesPurposeActive?
Attio (Attio, Inc.)Email, company, client count, newsletter preference, consent proofCRM of record — stores your waitlist contact and signup detailsAlways
Google (Tag Manager + GA4)Pseudonymous usage events; only after you accept analytics cookiesConsent-gated, privacy-preserving site analyticsOnly with analytics consent
Cloudflare (Turnstile)A challenge token and your IP at submissionBot screening on the waitlist formOnly when Turnstile is enabled
ResendYour email addressSending the early-access confirmation emailOnly when the confirmation email is enabled

Retention (website)

We keep your waitlist data for as long as we need it to manage your early-access invitation and, if you opted in, to send you product updates. You can ask us to delete it at any time.

Part 2 — The MarketLin application (app.marketlin.com)

This part applies when you use the MarketLin application. It supplements the Data Processing Agreement (DPA), which governs our processing of personal data contained in the advertising and analytics accounts you connect.

Our roles: controller and processor (app)

We handle two kinds of data in different capacities:

  • As a controller — for your account, authentication, billing, and usage data, and for operating and securing the Service. This policy describes that processing.
  • As a processor — for the personal data contained in the advertising and analytics accounts you connect (“Platform Data”). There, you are the controller (or a processor for your own clients), you decide the purposes, and we process on your instructions under our Data Processing Agreement. This policy describes that processing at a high level; the DPA governs it in detail.

Data we process (app)

  • Account and user data (we are controller): name, work email, password/authentication data, organisation and workspace details, role, and team-invitation data.
  • Billing data (we are controller): where you subscribe to a paid plan, billing contact details and transaction data. Card data is handled by our payment processor, not stored by us.
  • Usage and device data (we are controller): log data, IP address, actions in the Service, and diagnostic data, used to operate, secure, and improve the Service.
  • Platform Data (we are processor): data we read from the marketing and analytics accounts you connect via their official APIs, such as campaign, ad, audience, conversion, and performance data. This data is pseudonymous and aggregated; we do not retrieve directly identifying end-user personal data from connected accounts, though the data may include online identifiers.

Connected sources (app)

Currently: Google Ads, Google Analytics 4, Google Search Console, and Meta Ads. Additional connectors (such as LinkedIn Ads, TikTok, and CRM/commerce sources) are planned, and this policy will be updated as each goes live.

We do not ingest special-category data (such as health, political opinions, or biometric data) or criminal-offence data.

How we access connected accounts (app)

We connect to platforms using OAuth 2.0 and request the minimum scope each platform makes available for our read use case. In all cases we use this access only to read data; we do not create, modify, or delete anything in your accounts. You can disconnect an account at any time in the Service, or revoke access in the platform’s own settings.

OAuth scopes requested per platform
PlatformScope requestedNotes
Google Analytics 4https://www.googleapis.com/auth/analytics.readonly
Google Search Consolehttps://www.googleapis.com/auth/webmasters.readonly
Metaads_read, business_managementWe do not request ads_management. business_management is used only to read account and business structure.
Google Adshttps://www.googleapis.com/auth/adwordsGoogle does not offer a read-only scope; we request the standard scope and use it solely to read data.
All Google connectorsopenid, https://www.googleapis.com/auth/userinfo.emailRequested by every Google connector to identify the granting account.
LinkedIn Adsr_ads, r_ads_reportingWe do not request rw_ads.

Legal bases (data we control, app)

  • Providing the Service to you — performance of our contract with you (Art. 6(1)(b) GDPR).
  • Securing the Service, preventing abuse, and improving the product — our legitimate interests (Art. 6(1)(f)).
  • Billing and complying with accounting/tax law — legal obligation and contract (Art. 6(1)(c), (b)).
  • Optional product communications — your consent, where required (Art. 6(1)(a)).
  • For Platform Data, the legal basis is determined by you as the controller; we process it only on your instructions.

AI processing and Limited Use commitments (app)

The Service uses AI to generate analysis, recommendations, and reports. We handle Platform Data in accordance with the Google API Services User Data Policy (including its Limited Use requirements) and the Meta Platform Terms. Specifically:

  • We use Platform Data only to provide and improve the user-facing features of the Service shown to you.
  • We do not sell Platform Data and do not act as a data broker.
  • We do not use Platform Data for personalised or targeted advertising.
  • We do not use Platform Data to develop, improve, or train generalised or non-personalised AI or machine-learning models.
  • Our AI sub-processors — Anthropic, OpenAI, and Google (Gemini via Vertex AI) — process your data through their APIs solely to generate outputs for you, and do not train their models on it.
  • We do not allow our personnel to read Platform Data except where you have consented, where necessary for security or to comply with law, or where the data is aggregated and anonymised.
  • We do not carry out automated decision-making that produces legal or similarly significant effects; AI outputs are recommendations that you review and act on.

Sub-processors (app)

We use vetted sub-processors under written data protection terms. We do not sell your data. An up-to-date list is maintained at marketlin.com/subprocessors.

Sub-processors for the application
Sub-processorPurposeLocation
Google Cloud PlatformHosting, database, object storage, and key management (europe-north1)Stockholm, Sweden (EU)
Anthropic PBCAI generation of analysis and recommendations (no model training on your data)USA
OpenAI, L.L.C.AI generation of analysis and recommendations (no training on API data)USA
Google (Gemini via Vertex AI)AI generation of analysis and recommendations (no training on your data)USA
StripePayment processing (paid plans)USA / Ireland
Brevo (Sendinblue)Transactional and product emailFrance (EU)
AWS S3Uploaded and mirrored assetsFrance (EU)
SentryError telemetry only; request bodies, cookies, and authentication headers are stripped before transmissionUSA

Retention (app)

  • Raw Platform Data is deleted automatically within 90 days of you disconnecting the account or terminating the Service, except where law requires longer.
  • Database backups are retained for 7 days, after which residual copies of deleted data are overwritten and no longer restored to production.
  • Account and usage data is kept for the life of your account and deleted or anonymised within a reasonable period afterwards.
  • Billing records are kept as required by Swedish accounting law (generally seven years).
  • Derived outputs you have generated (reports, recommendations) remain available to you and exportable until deletion.

Security (app)

  • Encryption in transit — TLS/SSL enforced on API servers and all datastores.
  • Encryption at rest — with keys managed via Google Cloud KMS.
  • Data residency — production data stored in the EU (Stockholm, europe-north1).
  • Tenant isolation — enforced by a central authorisation layer (SpiceDB) with deny-by-default; OAuth tokens are stored encrypted and owned at the organisation level.
  • Access control — least-privilege internal access on a need-to-know basis.
  • Breach detection — monitoring that enables notification to affected controllers within 72 hours.

International transfers

Production data is hosted and stored within the EU/EEA — on Google Cloud Platform in Stockholm (europe-north1), with email via Brevo (France) and asset storage via AWS S3 (France). Certain sub-processors are located in the United States: Anthropic, OpenAI, Google (Gemini), Stripe, Attio, and Sentry. Transfers to them are safeguarded by the EU–U.S. Data Privacy Framework (where the recipient is certified) and/or the European Commission’s Standard Contractual Clauses, with additional measures where appropriate. Copies of the relevant safeguards are available on request at privacy@marketlin.com.

Your rights

Where we act as controller, you may request to access, correct, delete, port, or restrict your data, object to processing, and withdraw consent. You may also lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY).

Where we act as processor (Platform Data), please direct requests to the relevant controller (usually your organisation or your client); if a data subject contacts us directly, we forward the request to the controller and act only on their instruction.

To exercise any right, email privacy@marketlin.com.

Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date above and, where the change is material, take reasonable steps to notify you. The version in force is always the one published at marketlin.com/privacy.

Contact

MarketLin AB, Kungängsgatan 17, 753 22 Uppsala, Sweden — privacy@marketlin.com