// privacy notice
Privacy Notice
Last updated: August 12, 2026
// table of contents
- 01 · Overview
- 02 · Information we collect
- 03 · How we use information
- Google user data + Limited Use
- 04 · Legal bases (GDPR)
- 05 · Sharing + sub-processors
- 06 · Data retention
- 07 · International transfers
- 08 · Your rights
- 09 · Cookies + tracking
- 10 · Security
- 11 · Children's privacy
- 12 · Changes to this notice
- 13 · Contact
// 01 · overview
Overview
Magistry (“Magistry,” “we,” or “us”) takes the protection of personal data seriously. This Privacy Notice describes the personal data we collect, how we use it, with whom we share it, the rights you have in relation to your personal data, and how to contact us about privacy matters.
This notice covers the marketing site at magistry.io, the Magistry application at https://app.magistry.io, and any related software, APIs, and documentation (collectively, the “Service”). Where Magistry processes personal data on behalf of a Customer using the Service, Magistry acts as a processor and the Customer remains the controller. The terms of that processing are described in the Data Processing Addendum.
// 02 · information we collect
Information we collect
Account data. When you sign up we collect a work email address, name, role, the company you represent, and the password or single-sign-on token you authenticate with.
Connected-service tokens. When you authorise the Service to read from or write to a third-party platform, we receive OAuth tokens or API credentials needed to perform those actions on your behalf. We store these in a Vault-encrypted secrets table and limit decryption to the runtime agents that need them for a specific job. Where the platform is a Google service we also record which Google account the connection belongs to — see Google user data and Limited Use below.
Customer Data flowing through the Service. Catalog records, performance metrics, advertising spend, inbox messages, and customer records may be ingested from your Connected Services to support agent decisions. Magistry processes this data as a processor and only for purposes you instruct.
Usage and device data. When you use the Service we collect log data describing pages visited, features used, timestamps, IP address, browser type, operating system, and a hashed session identifier to help us secure your account.
Communications. When you contact us via support@magistry.io, sales@magistry.io, or any in-product messaging, we keep a record of the messages, contact details, and any attachments.
Billing data. Billing and payments for the Service are handled by Shopify. Card details are collected and processed by Shopify and are never stored on Magistry infrastructure; we receive only the billing metadata Shopify makes available to us (such as plan, status, and invoice records).
// 03 · how we use information
How we use information
- To provide and operate the Service, including running the autonomous agents you have authorised.
- To authenticate users and detect, prevent, and investigate fraud, abuse, or security events affecting the Service.
- To bill you for the Service, including issuing invoices and recovering past-due amounts.
- To improve the Service, including analysing aggregated usage patterns and debugging errors via Sentry.
- To send transactional and service-related communications such as receipts, security alerts, and notices required by these terms.
- To send marketing communications where we are permitted to do so, with a clear opt-out in every message.
- To comply with legal obligations and to enforce our Terms of Service.
Magistry does not sell personal data. We do not train foundation models on Customer Data, and the LLM providers we use process Customer Data under zero-retention commitments.
// google user data
Google user data + Limited Use
When you connect a Google account to Magistry— Google Ads, Google Analytics, Merchant Center, Search Console, or Google Sheets — we access only the data covered by the scopes you grant on Google’s consent screen, and we use it only to operate the features you connected it for.
- Account identity(your Google account’s email address, name, and profile picture, from the
openid,email, andprofilescopes). Stored so the dashboard can show which Google account a connection belongs to, and so you can confirm you authorised with the account you intended. Not used for anything else. - Google Ads — campaigns, budgets, keywords, and performance, to report on and manage the advertising you have asked Magistry to run, and to upload your own conversions back to your account.
- Google Analytics — traffic, channel, and engagement reporting for your own property, and the audience and retention settings you ask us to change on it.
- Merchant Center — your product listings and account issues, to detect and fix disapprovals on your own offers.
- Search Console — search queries, positions, and indexing status for sites you control, plus site verification so we can complete that setup for you.
- Google Sheets and Drive— read access to the specific spreadsheet you choose through Google’s own file picker, to import cost and expense data. This is the per-file
drive.filescope: it grants access to that one file and to nothing else, and we cannot list, open, or read anything else in your Drive.
Limited Use. Magistry’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not transfer it except as necessary to provide or improve the features you connected, to comply with applicable law, or as part of a merger or acquisition, and we do not use it for advertising outside your own connected accounts. We do not use Google user data to develop, improve, or train generalised artificial-intelligence or machine-learning models; where an LLM sub-processor listed below is used to operate a feature, it processes the data under zero-retention terms and does not train on it. Humans do not read Google user data except where you explicitly ask us to, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Magistry’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Magistry does not use Google user data — raw, aggregated, or derived — to create, train, or improve generalised or foundational machine-learning or artificial-intelligence models. Magistry uses third-party AI models to operate features you have connected, on your instruction and for your account only; those providers process the data under zero-retention terms and do not train on it.
Google tokens are held in a Vault-encrypted secrets table and decrypted only by the job that needs them. You can disconnect any Google integration at any time from Settings in the dashboard, which deletes the stored credentials, and you can revoke Magistry’s access directly at myaccount.google.com.
// 04 · legal bases (gdpr)
Legal bases for processing
Where the EU or UK General Data Protection Regulation applies, we process personal data on the following legal bases:
- Contract. To take steps at your request before entering into a contract and to perform the contract under which we provide the Service to you.
- Legitimate interests. To secure the Service, prevent fraud, improve our product, and run direct marketing to business contacts in a manner consistent with their reasonable expectations. You can object to processing on this basis at any time.
- Legal obligation. To retain billing records, respond to lawful requests from authorities, and comply with tax, accounting, and other statutory obligations.
- Consent. For non-essential cookies, marketing emails outside an existing business relationship, and any processing for which consent is the most appropriate basis. You can withdraw consent at any time without affecting the lawfulness of prior processing.
// 05 · sharing + sub-processors
Sharing and sub-processors
We engage a limited number of sub-processors to deliver the Service. Each sub-processor is bound by a written agreement that imposes data-protection obligations no less protective than this Privacy Notice and the Data Processing Addendum. The current list of sub-processors is:
| Provider | Purpose | Region |
|---|---|---|
| Shopify | Commerce platform, billing, and payments. Card data is handled by Shopify and never reaches Magistry. | Global |
| Supabase | Primary Postgres database, auth, storage, and Vault-encrypted secrets. | EU (eu-west-1) |
| Vercel | Hosting for the dashboard and marketing website, with edge delivery. | Global edge · EU primary |
| Railway | Compute for the backend worker and scheduled jobs. | EU-West |
| Anthropic | LLM inference for the agents and the assistant, including customer-service reply drafting over inbound mail bodies and customer photographs. No training on customer data. | United States |
| OpenAI | Embeddings, classification, translation of customer-service text, and image generation. No training on customer data. | United States |
| Resend | Transactional and customer-service email delivery. | EU/US |
| Microsoft | Outlook / Microsoft 365 mailbox access and sending for connected customer-service inboxes (Graph API); Bing Ads and Bing Webmaster where connected. | EU/US |
| Gmail mailbox access for connected inboxes; Google Ads, Data Manager (hashed e-mail/phone and click ids on conversion upload), Analytics, Merchant Center, Search Console and Sheets when you connect them; Google Public DNS for domain checks. | EU/US | |
| Meta | Meta Ads and Conversions API (hashed identifiers) — when you connect them. | United States |
| TikTok | TikTok for Business ads and events (hashed identifiers) — when you connect them. | EU/US |
| Pinterest Ads and conversions — when you connect them. | United States | |
| Stripe | Subscription billing and invoicing for non-Shopify tenants (merchant billing identity; card data handled by Stripe). | EU/US |
| Sentry | Error monitoring and crash reporting for the dashboard. | EU instance |
| DataForSEO | Search and market data for the Researcher and competitor intelligence (keywords, domains — no personal data). | United States |
| SerpApi | Search-result pages for market research (keywords only). | United States |
| Bright Data | Proxy and unblocking for fetching public web pages (storefronts, marketplaces). No personal data of yours is sent. | Israel/US |
| Exa | Neural web search for research (queries only). | United States |
| Jina AI | Readable-text extraction of public web pages (URLs only). | EU/US |
| 17TRACK | Parcel tracking status for shipments the desk is asked about (tracking numbers only). | Global |
| Slack | Notifications to a Slack channel you configure (incoming webhooks). | United States |
| Cloudflare | DNS-over-HTTPS lookups when verifying domains. | Global |
| PayPal | Affiliate payouts (payee e-mail and payout amounts) — affiliates only. | United States |
| Wise | Affiliate payouts by bank transfer (payee name, bank details) — affiliates only. | EU/UK |
| Tax1099 | US tax-form filing for affiliates (name, address, tax id) — affiliates only. | United States |
| Publishing to a LinkedIn page you connect (post content only). | United States | |
| DHL | Parcel tracking status for shipments the desk is asked about (tracking numbers only). | EU |
| GoDaddy | Domain-name availability checks for the Researcher (candidate names only). | United States |
| IP geolocation (ipinfo.io, ipapi.co) | Country lookup of an IP address: the worker's own proxy egress (ipinfo.io) and the Shield script's visitor check (ipapi.co) — an IP address is personal data. | United States |
| Public data feeds | Weather (Open-Meteo), macro data (ECB, St. Louis Fed FRED), exchange rates (ER-API), news (NewsAPI), Hacker News (Algolia), UK Companies House — queries only, no personal data. | Global |
| Pushover | Push notifications of platform health alerts to the operator's own devices (alert text only). | United States |
| Telegram | Push notifications of platform health alerts to an operator-configured chat (alert text only). | Global |
Connected Services are not sub-processors.When an agent writes a decision back to a platform you connected — a bid change in Google Ads, an audience in Google Analytics, a price in Shopify, a reply from your own mailbox — that data goes to an account you control, on your instruction, and its use there is governed by that platform’s own terms rather than by Magistry. We do not route data from one Connected Service to a different customer’s account, and we do not share data received from a Google API with any third party beyond what is needed to operate the feature you connected it for.
We may also share personal data with our professional advisers (lawyers, auditors, insurers), with parties to a merger, acquisition, or financing transaction subject to confidentiality, and where required by law or court order.
// 06 · retention
Data retention
We keep personal data only as long as needed for the purposes described in this notice, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Indicative retention periods are:
- Account profile data — for the life of your Account plus thirty (30) days.
- Connected-service tokens — for as long as the integration is authorised, then deleted on revocation.
- Customer Data ingested into the Service — per the retention rules you configure in your workspace, with a default of twenty-four (24) months.
- Decision-log entries — retained for the life of the workspace and then thirty (30) days post-termination, as an immutable audit trail.
- Billing records — for seven (7) years to comply with tax-and-accounting law.
- Support correspondence — for two (2) years from the last interaction.
- Web-analytics events — for fourteen (14) months, then aggregated.
// 07 · international transfers
International transfers and SCCs
Our primary data residency for Customer Data is the European Union. Some of our sub-processors are based outside the European Economic Area, including providers of LLM inference. Where personal data is transferred outside the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (Module 2, controller-to-processor, or Module 3 where applicable) supplemented by additional technical and organisational measures such as encryption in transit and at rest, access controls, and contractual restrictions on government-access requests.
We have completed transfer-impact assessments for each non-EEA sub-processor and keep these records available for review under the Data Processing Addendum. A copy of the SCCs in force can be requested from privacy@magistry.io.
// 08 · your rights
Your rights
Where the GDPR or a similar regime applies, you have the following rights in relation to your personal data:
- Access. Confirm whether we process personal data about you and obtain a copy of that data.
- Rectification. Have inaccurate personal data corrected and incomplete data completed.
- Erasure. Have personal data deleted where there is no longer a legal basis for processing it.
- Restriction. Restrict processing in defined situations, for example while the accuracy of personal data is being verified.
- Portability. Receive personal data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
- Objection. Object to processing based on legitimate interests, including direct marketing.
- Withdraw consent. Withdraw consent at any time without affecting the lawfulness of prior processing.
- Complain. Lodge a complaint with a supervisory authority. The lead authority for Magistry is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Where Magistry processes personal data as a processor on behalf of a Customer, you should direct your request to that Customer, who is the controller. We will assist the Customer in responding within the timeframes required by law.
// 10 · security
Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, use, disclosure, alteration, and destruction. Highlights include TLS-1.3 transport encryption, AES-256 encryption at rest for primary data stores, Vault-encrypted secrets, role-based access controls, mandatory two-factor authentication for staff, separation of production and development environments, and continuous logging via Sentry.
We are an early-stage company and are not SOC 2 certified today; we build to the same controls and will pursue formal certification as we grow. No information system is perfectly secure; we encourage you to report any suspected vulnerability to security@magistry.io.
// 11 · children
Children's privacy
The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal data from children under the age of sixteen (16). If you believe a child has provided us with personal data, please contact privacy@magistry.io and we will take appropriate steps to delete it.
// 12 · changes
Changes to this notice
We may update this Privacy Notice from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will update the “Last updated” date at the top of this notice and, where appropriate, notify you by email or via an in-product banner. Continued use of the Service after the effective date of an updated notice constitutes acceptance of the updated notice.
// 13 · contact
Contact
For questions about this Privacy Notice or to exercise your rights, write to our privacy contact at privacy@magistry.io. We aim to acknowledge privacy requests promptly and to respond within the timeframes required by law.
