Marechal

Privacy Policy

Revision of

Draft: the final wording is being prepared with our lawyers.

1. What this policy covers

This policy explains what personal data Marechal processes when a business uses the platform, and what happens to the data of the payers that business serves.

For data about your own employees who use the dashboard we act as the controller. For data about your customers, which you send us to process a payment, you are the controller and we act on your behalf.

2. Data about dashboard users

We store the name, work email address, role and preferences of every person you invite to the dashboard, together with sign-in records: time, IP address, and whether two-factor authentication was used.

We need this data to give access, to keep the account secure, and to show you who did what with money and settings.

3. Data about payers

To process a payment we receive the payer's name, contacts, country, IP address, the requisite of the payment method and the amount. Card numbers are stored masked: the full number never reaches our database.

This data is passed to the payment provider that processes the payment, and to no one else, except where the law or a card scheme requires disclosure.

4. Where the data is kept

Data is stored on servers of our infrastructure providers. Access credentials and payment provider keys are kept encrypted; they are not readable from a database dump alone.

Exported registers you order in the dashboard are kept in file storage for a limited time and then deleted.

5. How long we keep it

Payment records and related personal data are kept for as long as financial and anti-money-laundering law requires us to keep them, and then deleted or anonymised.

Dashboard accounts are kept while the account exists; after it is closed we keep only what the law requires.

6. Your rights

People whose data we process can ask what we hold about them, ask for it to be corrected or deleted, and object to processing. Requests about payers are answered through the business that sent us the data.

Where consent is the basis for processing — for example product emails — it can be withdrawn at any time without affecting anything done before.

7. Changes

We update this policy when the way we handle data changes. The current version is always available at this address, with the date of the revision at the top.

Questions about this document: support@marechal.dev