Legal · 01 of 02

Privacy Policy

Last updated September 21, 2026 Supersedes May 12, 2026 ≈ 9 min read 11 sections

What we hold, why we hold it, and how to get rid of it.

We don't sell

Your data isn't a product

We have never sold or rented personal data, and we don't share it with advertisers or data brokers.

Embed visitors

Counted, not tracked

Visitors who see your embeds are measured in aggregate. No cookies, no cross-site profiles, nothing traceable back to a person.

Deletion

Immediate, not queued

Delete your account and it goes straight away — account, live images, stored files and analytics. No grace period, nothing to restore. Anything already in trash follows its own 30-day clock.

Your rights

Export or erase

Download everything we hold as JSON, or erase it — both self-service. Anything else, we answer within 30 days.

Summaries set in serif throughout this page are a plain-English convenience. Where they differ from the numbered text, the numbered text governs. This policy covers markspot.app and the embeds we serve from our own domains — not the third-party sites those embeds appear on.

01Who We Are & Scope

This covers the Markspot app and the embeds it serves. We're the controller for account data; you're the controller for what you upload.

Markspot ("we", "us") operates markspot.app and the embed delivery service that renders your shoppable images on third-party sites (together, the "Service"). This policy explains what personal data we collect, why, and what you can do about it.

For data about your own account — your email, your organisation, your billing details — we are the data controller. For personal data that may appear inside content you upload, or that we process on your behalf when serving your embeds, you are the controller and we are a processor acting on your instructions. Hotspot text is free-form, so anything personal you type into a product title, label or link is content you control.

This policy does not cover the third-party sites that display your embeds. Those sites have their own privacy practices, and their operator — often you — is responsible for them.

02What We Collect

Who you are, what you upload, what you pay with, and how the product is used.

Category
Why we collect it
Retention

Account data

Email address, name, avatar, organisation name and your role in it

To create and secure your account, apply role permissions, and contact you about your subscription. Authentication is delegated to Supabase Auth — we never store your password, in any form.
Until you delete it no grace period

Your content

Uploaded images, hotspot positions, product titles, prices and links, project structure

To store, render and publish the shoppable embeds you create.
Until you delete it trash sweeps at 30 days

Billing data

Plan, subscription state, and a Stripe customer identifier

To process subscription payments and manage your billing relationship. Card numbers and invoices are held by Stripe and never reach our servers.
Held by Stripe per tax law

Usage & logs

Pages viewed in the app, feature events, IP address, browser and device type, the approximate timezone captured at sign-in, and rate-limit counters keyed on your user ID

To diagnose faults, prevent abuse, enforce plan and rate limits, and understand which features earn their place.
12 months then aggregated

Audit log

Security-relevant actions — plan changes, ownership transfers, publish and delete events — with the IP address and user agent behind them. The same table also records anonymous pricing-page interactions from visitors who never sign in.

To investigate fraud and security incidents, and to reconstruct who changed what.
12 months

Watermark reports

Free tier only — an embed ID and the domain an embed was loaded on

Reported by the embed script when the “Made with Markspot” watermark is removed or hidden, so we can enforce the Free-plan condition in our Terms. It records how our software was deployed: it collects nothing about your site’s visitors, sets no cookies, and does not run on paid plans.
12 months

Support

Messages you send through our contact forms, with the IP address and user agent of the submission

To answer your question, keep a record of the resolution, and mitigate form spam.
24 months

We do not collect special-category data — health, biometrics, political opinions and the like — and we ask that you do not upload it. We do not knowingly collect data from anyone under 16.

03Embed Visitors

Someone clicking a hotspot on your site isn't being profiled. We count the click and forget the person.

When a visitor loads a page containing a Markspot embed, our embed script requests the image and hotspot configuration from our servers. That request necessarily carries the visitor's IP address and browser user-agent, which we use to serve the content, apply rate limits and detect abuse.

We record aggregate counts — impressions, hotspot opens and outbound product clicks — so you can see how your marks perform. Those counts are stored against your embed, never against an identified visitor, and the requests that carry them are sent without credentials.

Where you have heatmaps switched on, cursor traces are keyed to a random identifier minted in the visitor's own browser for that page view. It is not a cookie, it is not reused across pages or sites, and it is not linked to anything else we hold.

If you run an A/B test, the embed writes one local-storage entry on your domain recording which variant that browser was shown, so a returning visitor keeps seeing the same one. It never leaves your domain and it is not sent to us as an identifier. The embed does not currently act on Do‑Not‑Track or Global Privacy Control signals.

What we don't do

No advertising cookies, no cross-site identifiers, no fingerprinting, and no sale or sharing of visitor data. Embed analytics store counters only — no IP address, no user agent, nothing joined back to a person.

If you embed Markspot on a site subject to consent requirements, you remain responsible for the consent notice your own jurisdiction requires — including for the local-storage entry described above.

04How We Use Data

To run the product, bill for it, keep it up, and tell you when something changes. Nothing else.

  • To provide the Service: rendering your editor, storing your marks, and serving published embeds.
  • To authenticate you and enforce organisation roles, plan limits and rate limits.
  • To process payments and to handle failed-payment and pause states.
  • To send service email — receipts, security notices, plan changes, organisation lifecycle notices, and material updates to these policies.
  • To investigate abuse, fraud and violations of the Terms, including verifying that Free-tier watermarks are being displayed.
  • To improve the product through aggregated usage analysis.
  • We do not run a marketing list. Everything we send is service email tied to your account, and it continues for as long as the account exists.

We do not use your content or your visitors' behaviour to train machine-learning models, and we do not licence either to third parties.

05Legal Bases

For users in the UK and EEA: which lawful basis covers which activity.

Contract
Account creation, hosting and serving your content, subscription billing, and support. We cannot provide the Service without processing this data.
Legitimate interests
Security, abuse prevention, rate limiting, aggregated product analytics, and watermark verification — balanced against your rights and limited to what those purposes require.
Legal obligation
Retaining invoice and tax records, and responding to valid legal requests.
Consent
Reserved for anything we introduce that needs it. We do not currently run a consent banner — section 07 sets out exactly what loads without one and how to prevent it.

06Sharing & Processors

A short list of vendors that run parts of the product. No advertisers, no brokers.

We share personal data with the service providers below, each under a data processing agreement limiting them to our instructions:

Supabase

Database, auth, storage

Your account, your images and their metadata. Also issues the session cookies that keep you signed in.

Stripe

Payments

Subscriptions, invoices and card details. Card numbers never touch our servers.

PostHog

Product analytics

Page views and feature events inside the app, sent to PostHog’s EU region.

Resend

Transactional email

Sends receipts, security notices and account lifecycle email.

Our own servers

Hosting

The app runs on servers we manage ourselves behind a reverse proxy — not on a third-party application platform.

Inside your organisation, every member — including the lowest-privilege viewer role — can see the other members' names and email addresses in the members list, alongside project names, image metadata and publish status. Billing details are visible only to the Owner.

Published embeds are public by design. Once you publish an image, anyone holding the embed ID can request the hotspot data needed to render the widget.

We may also disclose data where required by law, court order, or to protect the rights, property or safety of Markspot, our users or the public — or as part of a merger or acquisition, in which case we will notify you before your data becomes subject to a materially different privacy policy.

07Cookies

Essential cookies keep you signed in, analytics load with the app, and the embed sets nothing at all.

Essential
First-party, HttpOnly session cookies set by our authentication layer (Supabase Auth) to keep you signed in. They expire when you sign out or when the session lifetime ends, and the app cannot work without them.
Analytics
PostHog, sent to its EU region, measures product usage inside the app. It loads with the app rather than behind a consent step. Anonymous visitors are not given a person profile — one is created only once you sign in. A tracker blocker prevents it entirely, and you can ask us to delete your analytics record at any time.
Preferences
Small local-storage entries remembering UI choices such as a billing-cycle toggle or a collapsed sidebar. They stay in your browser and are never sent to us.
Embeds
The Markspot embed script sets no cookies on your visitors' browsers. Where an A/B test is running it writes one local-storage entry on your own domain — see section 03.

08Retention & Deletion

Delete your account and it's gone at once — no grace period. Unpaid organisations follow the pause schedule below.

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires. The specific periods are in What We Collect.

Deleting an image moves it to trash. It stops being served immediately and its published embed begins returning a not-found response; a scheduled job then removes the database row and the stored file 30 days later. Within those 30 days you can restore it.

Deleting your account is immediate and irreversible. Your account, your live images, their stored files and their analytics are removed straight away — there is no grace period and nothing to restore afterwards. One exception, and we would rather state it than round it off: images you had already moved to trash are not swept with the rest. They are removed by the scheduled trash job on their own 30-day clock, so they can outlive the account by up to 30 days. You confirm with your password, or by typing DELETE if you only ever signed in with a third-party identity provider. If you own an organisation with other members you must transfer ownership first; if it carries a paid subscription you must cancel that first. A member who is not the owner can choose to hand their images to another member rather than delete them.

Unpaid organisations follow a fixed schedule. Deletion at the end of it is irreversible.

Day 0

Paused

Payment failed. Data retained, paid features off.

Day 30

Queued for deletion

Still recoverable by settling the balance.

Day 90

Permanently deleted

Organisation, images and stored files. Cannot be restored.

09Your Rights

Ask and we act — within 30 days, free, and without penalising you for asking.

Access

Get a copy

Download everything we hold about you as JSON, from your profile under Your data.

Rectification

Fix what’s wrong

Name and avatar from your profile. Changing your email address currently needs a request to us.

Erasure

Delete it

Delete your account and content yourself, from your profile under Your data.

Portability

Take it elsewhere

The same JSON export is structured and machine-readable, with image files referenced by URL.

Objection

Say no

Object to processing we base on legitimate interests.

Restriction

Pause processing

Limit how we use your data while a dispute is resolved.

Access, portability and erasure are self-service from your profile page, under Your data. For anything else, use the contact page. We respond within 30 days and will not charge you or degrade your service for making a request. If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority.

10Security & Transfers

Encrypted in transit and at rest, access limited to the people who need it, and standard safeguards for data leaving the EEA.

All traffic to markspot.app and our embed endpoints is encrypted with TLS, and data at rest — database records and stored image files alike — is encrypted by our infrastructure provider. We store no passwords of any kind: authentication is delegated entirely to Supabase Auth, and two-factor authentication with recovery codes is available on every account. Access is enforced twice over, by row-level rules at the database and ownership checks on every mutation endpoint, and administrative credentials never reach the browser. Security-relevant actions are written to an audit log.

No system is perfectly secure. If a breach affecting your personal data occurs, we will notify affected users and the relevant supervisory authority without undue delay, and within 72 hours where that is required. If you discover a potential vulnerability, please report it responsibly via our contact page before public disclosure.

Our servers and our database and storage provider operate in both EU and US regions; product analytics are sent to an EU region. Where personal data is transferred outside the UK or EEA, we rely on Standard Contractual Clauses or an equivalent approved transfer mechanism, and you can request details of the safeguards we use by contacting us.

11Changes & Contact

Material changes get 14 days' notice. Questions go through the contact page.

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and notify active account holders in-app or by email at least 14 days before the changes take effect. Continued use of Markspot after that date constitutes acceptance of the updated policy.

Questions, requests or complaints about this policy? Reach us via the contact page and mark the subject "Privacy" — data-rights requests are routed to whoever can action them.