01Who We Are & Scope
This covers the Markspot app and the embeds it serves. We're the controller for account data; you're the controller for what you upload.
Markspot ("we", "us") operates markspot.app and the embed delivery service that renders your shoppable images on third-party sites (together, the "Service"). This policy explains what personal data we collect, why, and what you can do about it.
For data about your own account — your email, your organisation, your billing details — we are the data controller. For personal data that may appear inside content you upload, or that we process on your behalf when serving your embeds, you are the controller and we are a processor acting on your instructions. Hotspot text is free-form, so anything personal you type into a product title, label or link is content you control.
This policy does not cover the third-party sites that display your embeds. Those sites have their own privacy practices, and their operator — often you — is responsible for them.
02What We Collect
Who you are, what you upload, what you pay with, and how the product is used.
Account data
Email address, name, avatar, organisation name and your role in it
Your content
Uploaded images, hotspot positions, product titles, prices and links, project structure
Billing data
Plan, subscription state, and a Stripe customer identifier
Usage & logs
Pages viewed in the app, feature events, IP address, browser and device type, the approximate timezone captured at sign-in, and rate-limit counters keyed on your user ID
Audit log
Security-relevant actions — plan changes, ownership transfers, publish and delete events — with the IP address and user agent behind them. The same table also records anonymous pricing-page interactions from visitors who never sign in.
Watermark reports
Free tier only — an embed ID and the domain an embed was loaded on
Support
Messages you send through our contact forms, with the IP address and user agent of the submission
We do not collect special-category data — health, biometrics, political opinions and the like — and we ask that you do not upload it. We do not knowingly collect data from anyone under 16.
03Embed Visitors
Someone clicking a hotspot on your site isn't being profiled. We count the click and forget the person.
When a visitor loads a page containing a Markspot embed, our embed script requests the image and hotspot configuration from our servers. That request necessarily carries the visitor's IP address and browser user-agent, which we use to serve the content, apply rate limits and detect abuse.
We record aggregate counts — impressions, hotspot opens and outbound product clicks — so you can see how your marks perform. Those counts are stored against your embed, never against an identified visitor, and the requests that carry them are sent without credentials.
Where you have heatmaps switched on, cursor traces are keyed to a random identifier minted in the visitor's own browser for that page view. It is not a cookie, it is not reused across pages or sites, and it is not linked to anything else we hold.
If you run an A/B test, the embed writes one local-storage entry on your domain recording which variant that browser was shown, so a returning visitor keeps seeing the same one. It never leaves your domain and it is not sent to us as an identifier. The embed does not currently act on Do‑Not‑Track or Global Privacy Control signals.
What we don't do
No advertising cookies, no cross-site identifiers, no fingerprinting, and no sale or sharing of visitor data. Embed analytics store counters only — no IP address, no user agent, nothing joined back to a person.
If you embed Markspot on a site subject to consent requirements, you remain responsible for the consent notice your own jurisdiction requires — including for the local-storage entry described above.
04How We Use Data
To run the product, bill for it, keep it up, and tell you when something changes. Nothing else.
- To provide the Service: rendering your editor, storing your marks, and serving published embeds.
- To authenticate you and enforce organisation roles, plan limits and rate limits.
- To process payments and to handle failed-payment and pause states.
- To send service email — receipts, security notices, plan changes, organisation lifecycle notices, and material updates to these policies.
- To investigate abuse, fraud and violations of the Terms, including verifying that Free-tier watermarks are being displayed.
- To improve the product through aggregated usage analysis.
- We do not run a marketing list. Everything we send is service email tied to your account, and it continues for as long as the account exists.
We do not use your content or your visitors' behaviour to train machine-learning models, and we do not licence either to third parties.
05Legal Bases
For users in the UK and EEA: which lawful basis covers which activity.
08Retention & Deletion
Delete your account and it's gone at once — no grace period. Unpaid organisations follow the pause schedule below.
We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires. The specific periods are in What We Collect.
Deleting an image moves it to trash. It stops being served immediately and its published embed begins returning a not-found response; a scheduled job then removes the database row and the stored file 30 days later. Within those 30 days you can restore it.
Deleting your account is immediate and irreversible. Your account, your live images, their stored files and their analytics are removed straight away — there is no grace period and nothing to restore afterwards. One exception, and we would rather state it than round it off: images you had already moved to trash are not swept with the rest. They are removed by the scheduled trash job on their own 30-day clock, so they can outlive the account by up to 30 days. You confirm with your password, or by typing DELETE if you only ever signed in with a third-party identity provider. If you own an organisation with other members you must transfer ownership first; if it carries a paid subscription you must cancel that first. A member who is not the owner can choose to hand their images to another member rather than delete them.
Unpaid organisations follow a fixed schedule. Deletion at the end of it is irreversible.
Day 0
Paused
Payment failed. Data retained, paid features off.
Day 30
Queued for deletion
Still recoverable by settling the balance.
Day 90
Permanently deleted
Organisation, images and stored files. Cannot be restored.
09Your Rights
Ask and we act — within 30 days, free, and without penalising you for asking.
Access
Get a copy
Download everything we hold about you as JSON, from your profile under Your data.
Rectification
Fix what’s wrong
Name and avatar from your profile. Changing your email address currently needs a request to us.
Erasure
Delete it
Delete your account and content yourself, from your profile under Your data.
Portability
Take it elsewhere
The same JSON export is structured and machine-readable, with image files referenced by URL.
Objection
Say no
Object to processing we base on legitimate interests.
Restriction
Pause processing
Limit how we use your data while a dispute is resolved.
Access, portability and erasure are self-service from your profile page, under Your data. For anything else, use the contact page. We respond within 30 days and will not charge you or degrade your service for making a request. If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority.
10Security & Transfers
Encrypted in transit and at rest, access limited to the people who need it, and standard safeguards for data leaving the EEA.
All traffic to markspot.app and our embed endpoints is encrypted with TLS, and data at rest — database records and stored image files alike — is encrypted by our infrastructure provider. We store no passwords of any kind: authentication is delegated entirely to Supabase Auth, and two-factor authentication with recovery codes is available on every account. Access is enforced twice over, by row-level rules at the database and ownership checks on every mutation endpoint, and administrative credentials never reach the browser. Security-relevant actions are written to an audit log.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify affected users and the relevant supervisory authority without undue delay, and within 72 hours where that is required. If you discover a potential vulnerability, please report it responsibly via our contact page before public disclosure.
Our servers and our database and storage provider operate in both EU and US regions; product analytics are sent to an EU region. Where personal data is transferred outside the UK or EEA, we rely on Standard Contractual Clauses or an equivalent approved transfer mechanism, and you can request details of the safeguards we use by contacting us.
11Changes & Contact
Material changes get 14 days' notice. Questions go through the contact page.
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and notify active account holders in-app or by email at least 14 days before the changes take effect. Continued use of Markspot after that date constitutes acceptance of the updated policy.
Questions, requests or complaints about this policy? Reach us via the contact page and mark the subject "Privacy" — data-rights requests are routed to whoever can action them.