Subprocessors

Vendors that process customer data on our behalf to deliver MARGN.PLUS.

Last updated: 2026-09-10

How we choose vendors

Every vendor on this list is contractually bound by a Data Processing Agreement (DPA), holds at minimum a SOC 2 Type II certification (or equivalent), and is restricted to the specific data and purpose listed below. Vendors are not permitted to use customer data for advertising, profiling, or AI model training.

We add vendors when their function is essential to delivering the product, and we remove them when a better, safer, or simpler option becomes available. Material changes to this list are announced in the next weekly Drop email and through our Privacy Policy.

Vendor Purpose Data shared Location Compliance
Cloudflare
DPA / privacy policy
Edge network in front of our host: TLS, caching of public pages, bot protection. Request metadata (IP address, headers) for every visit; sets a bot-protection cookie. Never sees your uploaded data unencrypted beyond serving the request. Global edge, US-based company SOC 2 Type II, ISO 27001
WP Engine
DPA / privacy policy
Application hosting (web server, database, file storage, daily backups, CDN). All customer data uploaded to MARGN.PLUS, encrypted at rest. Not used for anything besides serving our application. United States (US-East) SOC 2 Type II
Anthropic (Claude API)
DPA / privacy policy
AI-generated insights and CSV failure diagnostics. Aggregate metrics and pseudonymized buyer references (e.g., "buyer_a") sent per request. Real buyer @handles never leave our servers; they are substituted back into the insight on our server after Claude responds, before it is stored or shown. United States SOC 2 Type II · API data not used for model training
Stripe
DPA / privacy policy
Subscription billing, payment processing, invoice retrieval. Account email, plan tier, payment method tokens. Card numbers are entered directly into Stripe Elements and never touch our servers. United States PCI-DSS Level 1 · SOC 2 Type II
Microsoft Clarity
DPA / privacy policy
Page analytics: which pages and features get used, with every word and number masked in your browser before anything is sent. Page views and interaction events with text masking; sets analytics cookies when active. Never your uploaded CSV data. United States ISO 27001
Reddit Ads (not currently active)
DPA / privacy policy
Advertising measurement: whether our Reddit ads lead to sign-ups and subscriptions. Browser and device details, page address, and sign-up / purchase events with the plan price — from public pages and the page after registering or subscribing only. Never email addresses or uploaded data. Off for Global Privacy Control, Do Not Track, European time zones, and anyone who opts out. United States
Google (Tag Manager, Analytics, Ads)
DPA / privacy policy
Site analytics and advertising measurement, loaded through Google Tag Manager. Browser and device details, page address, and sign-up / purchase events with the plan price — from public pages and the page after registering or subscribing only. Never email addresses or uploaded data. Off for Global Privacy Control, Do Not Track, European time zones, and anyone who opts out. United States ISO 27001, SOC 2
Google Fonts and jsDelivr (browser-side)
DPA / privacy policy
Your browser fetches the Fraunces/Inter font files from Google Fonts and the Chart.js library from jsDelivr. Your IP address and browser details, as with any CDN request. No account data is ever sent to them. Global CDNs
Google Workspace
DPA / privacy policy
Outbound email (account verification, password resets, weekly digests, admin alerts). Recipient email address, message body. We do not store the message contents after sending. United States ISO 27001 · SOC 1/2/3

What we never share

  • We do not sell, rent, or license personally identifiable customer data. Aggregated, anonymized data may be used for industry benchmark features.
  • We do not share buyer-level transaction data with marketing platforms, ad networks, or data brokers.
  • We do not feed your CSV uploads into AI model training, ours or anyone else’s.
  • We do not retain Stripe card numbers, only the tokenized payment method Stripe returns.

Questions about a specific vendor or their handling of your data? privacy@margn.plus

See also our Privacy Policy and Terms of Service.