Privacy Policy

Last updated: June 1, 2026

marge.studio is committed to protecting your personal data. This policy describes what data is collected, why, and how it is protected, in accordance with the General Data Protection Regulation (GDPR — EU 2016/679).

1. Data controller

Publisher of marge.studio — French sole trader currently being registered
Email: contact@marge.studio

2. Data collected

When using marge.studio, we collect the following data:

  • Identification data: email address (when creating an account).
  • Business data: quotes (project names, clients, rates, team profiles), projects, time entries, agency settings.
  • Technical data: connection logs, session cookies necessary for the service to function.
  • Anonymised usage data: interface interactions (via PostHog, hosted in Europe), without personal identification.

We do not collect banking data. No card number is stored on our servers.

3. Purposes of processing

Your data is used exclusively to:

  • Provide the profitability management service (margin calculation, project tracking, quotes).
  • Ensure the security and proper functioning of your account.
  • Send you account-related communications (password reset, budget drift alerts).
  • Improve the service through anonymised usage statistics.

Your data is never sold, rented, or transferred to third parties for commercial purposes.

4. Data access

Your business data (quotes, projects, profiles) is accessible only by you. It is isolated by a Row Level Security policy on Supabase: technically, no other user can access your data.

The service publisher may access data for technical support or debugging purposes, only at your explicit request.

4bis. Legal basis

The processing of your data is based on the performance of the contract (service provision) for account and business data. Anonymised usage data is based on our legitimate interest in improving the service.

5. Sub-processors

marge.studio uses the following sub-processors to provide the service:

  • Supabase (Ireland, EU) — database hosting and authentication.
  • Vercel (United States, EU–US DPF compliant) — web application hosting.
  • PostHog (EU) — anonymised usage analytics, hosted on European servers.
  • Resend — transactional email delivery (sign-in links, notifications).

These sub-processors were selected for their GDPR compliance. No identifying data is shared with third parties for advertising purposes.

6. Retention period

Your data is retained as long as your account is active. If your account is deleted, all your data is erased within 30 days, unless there is a legal obligation to retain it.

Billing data is retained for 10 years in accordance with French accounting obligations.

7. Your rights

Under the GDPR, you have the following rights:

  • Right of access: obtain a copy of your data.
  • Right to rectification: correct inaccurate data.
  • Right to erasure: request the deletion of your data.
  • Right to data portability: receive your data in a structured format.
  • Right to object: object to certain processing activities.

To exercise these rights: contact@marge.studio. We respond within 30 days. You may also lodge a complaint with the CNIL (French Data Protection Authority) (cnil.fr).

8. Cookies

marge.studio uses two types of cookies:

  • Session cookies (Supabase) — strictly necessary for authentication to function. Cannot be disabled.
  • Analytics cookies (PostHog) — measure service usage in an anonymised way (pages visited, interactions). Can be disabled via your browser settings or by objecting to the processing by email.

No advertising or commercial tracking cookies are set.