Privacy Policy
Last updated: August 29, 2026
# Marshal Privacy Policy
**Last Updated and Effective as of:** August 29, 2026
## 1. Introduction and Scope
Growth Marshal, LLC, doing business as Marshal (**"Marshal," "we," "us,"** or **"our"**), operates the website located at [https://marshal.ing](https://marshal.ing), the Marshal Terminal, and related services.
Marshal is the Managed Agent Operations company that designs, deploys, and operates AI agents as a service for small businesses. Marshal remains the operator of the agents. The Terminal is primarily a customer-facing window into agent activity, completed work, work receipts, approvals, exceptions, and integrations. Authorized users do not use the Terminal to build agents or take over Agent Operations.
This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Information when you:
- Visit our website;
- Create or use a Marshal account;
- Access or interact with the Terminal;
- Start or participate in a 14-day free trial;
- Use paid Managed Agent Operations services;
- Approve or reject an agent action;
- Connect a third-party system or authorize an integration;
- Contact us, schedule a meeting, or request support;
- Receive communications from us; or
- Otherwise interact with Marshal or the services we provide.
This Privacy Policy also explains how we process Personal Information contained in data that a Customer provides or authorizes us to access in connection with the services.
For purposes of this Privacy Policy, **"Personal Information"** means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual or household. It includes "personal data" and similar terms used by applicable privacy laws.
By using our website, Terminal, or services, you acknowledge that you have read and understood this Privacy Policy.
## 2. Who We Are
Growth Marshal, LLC is a New York limited liability company doing business as Marshal.
Marshal is headquartered in New York, United States.
Privacy questions and privacy-rights requests may be sent to [privacy@marshal.ing](mailto:privacy@marshal.ing).
General support questions may be sent to [support@marshal.ing](mailto:support@marshal.ing).
Security reports may be sent to [security@marshal.ing](mailto:security@marshal.ing).
## 3. The Roles We Play
We process Personal Information in different roles depending on the context.
When we operate our website and Terminal, administer accounts, communicate with prospective or current Customers, schedule meetings, provide support, handle billing, protect our systems, publish our own materials, or market our services, we generally act as the business, controller, or other organization responsible for deciding why and how the information is processed.
When we process Personal Information contained in Customer Data on behalf of a Customer to provide Managed Agent Operations, we generally act as a service provider, contractor, processor, or similar role under applicable privacy law. In that context, the Customer generally determines the business purpose of the processing and is responsible for:
- Deciding what data may be provided or connected;
- Giving lawful instructions;
- Providing required privacy notices;
- Obtaining required consents or authorizations;
- Responding to individuals whose information the Customer controls; and
- Ensuring that the Customer has the legal right to authorize our processing.
If a signed data processing agreement, Order, security addendum, or other written agreement between Marshal and a Customer conflicts with this Privacy Policy, the written agreement controls for the specific conflict.
## 4. Key Terms
**"Account Data"** means information used to create, authenticate, administer, or support an account or organizational workspace.
**"Authorized User"** means an individual whom a Customer authorizes to access an account, the Terminal, or other services on the Customer's behalf.
**"Customer"** means a business or organization that creates an account, participates in a free trial, purchases services, or otherwise engages Marshal.
**"Customer Data"** means information, data, records, content, files, instructions, communications, credentials, access information, and other materials that a Customer or Authorized User provides to Marshal, submits through the services, or authorizes Marshal to access from Customer Systems.
**"Customer Systems"** means a Customer's websites, software, accounts, tools, platforms, databases, CRMs, email systems, calendars, communication platforms, APIs, infrastructure, support systems, content management systems, payment systems, and other business systems.
**"Terminal"** means Marshal's customer-facing software interface, which primarily provides visibility into agent activity and limited controls for approvals, instructions, and integrations.
## 5. Personal Information We Collect
We collect different categories of Personal Information depending on how you interact with us and which services a Customer authorizes.
### 5.1 Account, Profile, and Authentication Information
When you create or use an account, we may collect:
- Full name;
- Work email address;
- Password credential, password hash, or similar authentication data;
- Account and user identifiers;
- Organization name and role;
- Profile information;
- Authentication method;
- Login timestamps and session information;
- Multifactor-authentication status; and
- Information received from an identity provider if you use a sign-in option such as Google Sign-In, which may include your name, email address, profile image, provider identifier, and other information within the permissions you grant.
We do not receive your password from an external identity provider when you use that provider to sign in.
### 5.2 Organization, Onboarding, and Free-Trial Information
When you create an organizational workspace, request a trial, or begin onboarding, we may collect:
- Organization name;
- Company website and business information;
- The work, job, workload, or process you want Marshal to handle;
- Descriptions of how the work is performed today;
- The software systems and tools involved;
- Policies, procedures, rules, approval requirements, and exceptions;
- Examples of completed work;
- Internal owner and approver information;
- Responses to onboarding questions;
- Trial activation and status information;
- Meeting and scheduling information; and
- Other information you choose to provide during scoping, configuration, onboarding, support, or account management.
### 5.3 Terminal and Account-Usage Information
When an Authorized User accesses the Terminal or another authenticated service, we may collect:
- Login and logout events;
- IP address and approximate location derived from IP address;
- Browser, device, and operating-system information;
- Session identifiers;
- Pages, screens, features, buttons, and controls used;
- Dates, times, and duration of activity;
- Approvals, rejections, comments, and instructions;
- Changes to permissions, policies, settings, and integrations;
- Support interactions;
- Error, diagnostic, performance, and security information; and
- Audit and activity records associated with the account.
### 5.4 Agent Operations Information
When Marshal configures, operates, monitors, or supports an agent, we may process information such as:
- Tasks, triggers, instructions, and business context;
- Source records and knowledge used for a task;
- Inputs, prompts, retrieved context, and intermediate processing;
- Drafts, classifications, summaries, recommendations, and completed work;
- Work receipts and action records;
- Tool calls and integration events;
- Actions proposed, approved, rejected, completed, failed, or escalated;
- Approval records and exception queues;
- Agent status, runtime, timestamps, and model or provider metadata;
- Quality checks, testing records, corrections, and human feedback;
- Error records, incident records, and troubleshooting information; and
- Operational logs reasonably necessary to run, secure, maintain, and improve the Customer's agent.
Agent Operations Information may contain Personal Information about Authorized Users, Customer personnel, Customer contacts, prospects, customers, vendors, partners, or other individuals, depending on the work the Customer authorizes.
### 5.5 Information from Customer Systems and Integrations
When a Customer authorizes Marshal to connect to a Customer System, we may access, receive, create, update, transmit, or otherwise process information made available through that connection. Depending on the Customer's systems and instructions, this may include:
- CRM contacts, accounts, notes, activities, deals, and pipeline records;
- Email messages, headers, participants, attachments, labels, and related metadata;
- Calendar events, attendees, availability, and scheduling data;
- Customer-support tickets, messages, account context, and help-center information;
- Documents, files, folders, knowledge bases, and collaboration content;
- Slack or other communication-workspace content and metadata;
- Marketing, advertising, website, analytics, and campaign information;
- Sales, lead, prospecting, enrichment, and public-business information;
- Finance, accounting, invoice, payment, and transaction records;
- Project-management, task, operations, and workflow records;
- Website, content-management, directory, structured-data, and publishing information; and
- Other information reasonably necessary to perform the work the Customer assigns.
The information available to Marshal depends on the permissions, scopes, settings, and instructions chosen by the Customer.
For example, if a Customer authorizes the Marshal Slack app, we may receive Slack workspace identifiers, Authorized User and channel information, messages, files, reactions, event data, and other content within the permissions granted and the configured workflow. We may also post, update, or route information in Slack at the Customer's direction.
### 5.6 Integration Credentials and Connection Information
To create and maintain integrations, we may process:
- OAuth grants and tokens;
- API keys;
- Service-account credentials;
- Application passwords;
- Webhook secrets;
- Workspace, tenant, account, or connection identifiers;
- Permission scopes;
- Connection status and timestamps;
- Token-refresh information; and
- Authentication, authorization, and error logs.
Where reasonably practical, we use scoped permissions, OAuth, API keys, service accounts, role-based access, secrets management, and other limited-access methods rather than shared human passwords.
### 5.7 Files, Content, Instructions, and Communications You Submit
We may collect information contained in text, files, links, code fragments, images, records, documents, instructions, prompts, comments, approvals, support messages, and other content submitted through the website, Terminal, email, Slack, integrations, or other service channels.
We may analyze submitted content to provide the services, detect malicious code or abuse, investigate security issues, enforce our Terms of Service, and comply with law.
Customers and Authorized Users must not submit passwords, private keys, full payment-card numbers, government identification numbers, or other restricted information through general Terminal fields, prompts, uploaded files, or support messages unless Marshal specifically authorizes the method used.
### 5.8 Communications, Meetings, and Support Information
When you contact us, book a meeting, respond to a message, request support, or communicate with our team, we may collect:
- Name and contact information;
- Company and role;
- Message content and attachments;
- Meeting date, time, attendees, and calendar metadata;
- Responses to scheduling or intake questions;
- Support history and troubleshooting information; and
- Information you choose to share during discovery, configuration, onboarding, or account management.
We may use scheduling providers, email providers, customer-relationship tools, and communication platforms to process this information.
### 5.9 Billing and Payment Information
For paid services, we may collect:
- Customer billing name and contact information;
- Billing address;
- Subscription, plan, invoice, and transaction information;
- Payment status and payment-method metadata; and
- Tax or accounting information reasonably necessary for billing.
Payments may be processed by a third-party payment processor. We do not store full payment-card details on our own systems when the payment processor collects that information directly.
### 5.10 Website, Device, Cookie, and Analytics Information
When you visit our website or use the Terminal, we may automatically collect:
- IP address;
- Browser type and version;
- Device type and identifiers;
- Operating system;
- Referring and exit pages;
- Pages viewed and interactions;
- Dates and times of visits;
- Approximate location derived from IP address;
- Cookie, local-storage, and session identifiers;
- Performance and diagnostic information; and
- Security and fraud-prevention signals.
We may use cookies, pixels, scripts, tags, analytics tools, and similar technologies as described in Section 12.
### 5.11 Public and Business Information
For business development, enrichment, research, content, Generative Engine Optimization, answer-engine visibility, structured data, and other authorized services, we may collect or process business information and publicly available information from sources such as:
- Company websites;
- Search engines and answer engines;
- Public databases and directories;
- Social and professional profiles;
- Review platforms;
- Media, podcasts, articles, and public research;
- Government and regulatory sources;
- Structured-data sources and knowledge graphs;
- Business-data and enrichment providers; and
- Other publicly accessible or lawfully licensed sources.
This information may include names, business contact details, job titles, company affiliations, public statements, professional history, public profile information, business characteristics, and other business-to-business information.
### 5.12 Information We Derive or Generate
We may derive or generate information from the categories above, such as:
- Account and organization attributes;
- Lead or account classifications;
- Workflow state and task status;
- Operational patterns and performance metrics;
- Security-risk indicators;
- Product and feature usage insights;
- Suggested actions or exceptions; and
- Aggregated or de-identified statistics.
## 6. Sources of Personal Information
We may obtain Personal Information from:
- You directly;
- The Customer or Customer administrator that authorizes your access;
- Other Authorized Users;
- Customer Systems and integrations;
- Identity, authentication, scheduling, payment, analytics, security, communication, and other service providers;
- Publicly available sources;
- Lawfully licensed business-data providers;
- Third parties that refer or introduce you; and
- Information generated through operation of the website, Terminal, agents, and other services.
## 7. How We Use Personal Information
We may use Personal Information to:
- Operate, maintain, secure, and improve our website, Terminal, and services;
- Create, authenticate, administer, and support accounts and organizational workspaces;
- Verify identity, authority, and account access;
- Provide and manage the 14-day free trial;
- Understand Customer requirements and configure agents around Customer processes, tools, policies, and approval rules;
- Design, deploy, operate, monitor, maintain, test, troubleshoot, and improve Customer-specific agents;
- Receive tasks, retrieve authorized context, use tools, generate Customer Output, complete work, and create work receipts;
- Display agent activity, status, completed work, approvals, exceptions, and connection information in the Terminal;
- Process approvals, rejections, instructions, escalations, and policy changes;
- Establish, maintain, secure, and troubleshoot integrations;
- Access, update, transmit, publish, or otherwise process information in Customer Systems as authorized;
- Provide support, communicate about the services, and respond to inquiries;
- Schedule meetings and manage Customer relationships;
- Process subscriptions, invoices, payments, and approved costs;
- Send administrative, transactional, security, service, and marketing communications;
- Perform research, enrichment, business-development, communication, content, public-facing, or answer-engine visibility work when authorized;
- Analyze performance, feature usage, capacity, reliability, and service quality;
- Detect, prevent, investigate, and respond to fraud, malicious code, abuse, unauthorized access, security incidents, and Terms of Service violations;
- Protect Marshal, Customers, Authorized Users, third parties, and the public;
- Establish, exercise, or defend legal rights;
- Comply with law, legal process, government requests, and contractual obligations;
- Complete a business transaction such as a financing, merger, acquisition, reorganization, or sale; and
- Carry out another purpose disclosed at the time of collection or authorized by you or the Customer.
## 8. Organization Accounts and Administrator Access
If you access the services through a Customer organization, the Customer controls the organizational relationship and may designate administrators.
Customer administrators may be able to:
- Add, remove, or suspend Authorized Users;
- View Authorized User identity and activity information;
- Manage roles, permissions, integrations, and approval authority;
- Access Customer Data, Customer Output, work receipts, and operational records within the workspace;
- Approve or reject agent actions;
- Request data export, correction, restriction, or deletion; and
- Control or terminate the organizational account.
If you create an account using a work email address, the organization associated with that address may have rights in the account and related information. If your relationship with that organization ends, the organization may retain control of the workspace and business records, and your access may be removed.
Questions about an organizational account should generally be directed first to the relevant Customer administrator.
## 9. Integrations and Customer-Directed Transfers
When a Customer authorizes an integration, the Customer directs us to exchange information with the selected Third-Party Service within the approved permissions and workflow.
Information may flow both ways. For example, Marshal may retrieve a record from a Customer System, use it to perform a task, display information in the Terminal, and write an authorized update back to the Customer System.
The Customer is responsible for reviewing requested permissions and deciding whether to connect a Third-Party Service. The third party's privacy policy and terms apply to information processed in that service.
Disconnecting an integration generally stops new access after the disconnection takes effect. It does not automatically:
- Delete information already retrieved or processed by Marshal;
- Delete information already written to the Third-Party Service;
- Reverse actions already completed; or
- Remove records that Marshal must retain for security, legal, billing, dispute, or contractual purposes.
We may retain connection records and limited logs after disconnection as reasonably necessary to document authorization, protect security, troubleshoot, and comply with law.
### 9.1 Google API Data
If a Customer or Authorized User connects a Google account or Google Workspace service, we may access Google user data only within the scopes the user authorizes and only to provide or improve the user-facing features and Customer-directed agent workflows associated with that connection. Depending on the scopes granted and the assigned work, this may include Gmail messages and metadata, calendar information, Drive files and metadata, contacts, profile information, or other Google data described in the authorization screen.
Marshal's access, use, storage, and disclosure of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. In particular:
- We do not sell Google user data or use it for advertising, retargeting, creditworthiness, lending, or surveillance;
- We disclose Google user data only as needed to provide or improve the authorized Customer-facing features, protect security, comply with law, or complete another transfer expressly permitted by Google policy and authorized as required;
- Marshal personnel do not read Google user data unless the user has affirmatively authorized the relevant human review, access is necessary for security or legal compliance, or the data has been aggregated and anonymized for lawful internal operations;
- We request only the permissions reasonably necessary for the connected features and assigned work; and
- This Privacy Policy does not expand the permissions shown in the Google authorization screen.
A user may revoke Google's authorization through the user's Google account settings or disconnect the integration through Marshal where that control is available. Revocation stops new access after it takes effect but does not automatically delete records already processed or retained for a lawful purpose. A deletion request may be sent to [privacy@marshal.ing](mailto:privacy@marshal.ing).
## 10. Artificial Intelligence and Model Training
We use artificial intelligence systems, large language models, automation tools, APIs, and other technologies to provide Managed Agent Operations.
These systems may process Customer Data, Customer instructions, authorized integration data, public business information, and other information reasonably necessary to perform the assigned work.
### 10.1 No General-Purpose Model Training with Customer Data
We do not use Customer Data, Customer content, integration data, or Customer Output to train general-purpose artificial intelligence models unless the Customer expressly authorizes that use and we agree to it in writing.
We seek to use commercial and API offerings under terms and configurations that do not permit providers to use Customer Data submitted through the services to train their general-purpose models. Providers may process data to deliver, secure, monitor, and support their services, subject to their applicable terms and our agreements with them.
### 10.2 Customer-Specific Operation and Improvement
We may process Customer Data and Agent Operations Information to configure, test, troubleshoot, secure, and improve the Customer's specific agent and the services provided to that Customer.
Authorized Marshal personnel and service providers may review inputs, outputs, logs, and operational records when reasonably necessary to provide support, investigate an incident, correct an error, enforce the Terms of Service, or improve the Customer-specific service. Human access to Google user data is further limited as described in Section 9.1.
### 10.3 Aggregated and De-Identified Information
We may use aggregated or de-identified information for security, analytics, capacity planning, benchmarking, research, and service improvement, provided that the information does not identify a Customer or individual and is not used to reconstruct confidential Customer information.
We do not attempt to re-identify information that we maintain as de-identified except as permitted by law to test whether de-identification controls are effective.
### 10.4 Automated Decision-Making
We do not use Personal Information about website visitors or Authorized Users to make solely automated decisions that produce legal or similarly significant effects about those individuals.
A Customer may instruct an agent to process information about individuals as part of a Customer workflow. In that context, the Customer determines the purpose and permitted use and is responsible for deciding whether notices, consent, human review, impact assessments, appeal rights, or other safeguards are required.
Unless expressly agreed in writing, the services are not intended to be the sole basis for decisions concerning employment, credit, housing, insurance, medical care, education, legal rights, access to essential services, or similarly significant interests.
## 11. Legal Bases for Processing
Where a law requires us to identify a legal basis, we may process Personal Information based on:
- **Contract:** to enter into or perform a contract, administer an account, provide a free trial, or deliver services;
- **Legitimate interests:** to operate, secure, support, improve, and market our business and services, prevent fraud and abuse, protect rights, and communicate with business contacts, where those interests are not overridden by applicable rights;
- **Consent:** where we request and receive consent, including for certain marketing, cookies, integrations, or other optional processing;
- **Legal obligation:** to comply with law, legal process, tax, accounting, security, and regulatory duties; and
- **Vital or public interests:** in limited circumstances where processing is necessary to protect a person or address an urgent public interest and applicable law permits it.
Where we process Customer Data on behalf of a Customer, the Customer is generally responsible for identifying the legal basis for that processing.
## 12. Cookies and Similar Technologies
We may use cookies and similar technologies to:
- Keep you signed in;
- Maintain sessions and security controls;
- Remember preferences;
- Prevent fraud and abuse;
- Measure website and Terminal performance;
- Understand how features are used;
- Diagnose errors; and
- Improve our website and services.
These technologies may include:
- **Essential cookies:** required for authentication, security, session management, and core functionality;
- **Preference cookies:** used to remember settings and choices;
- **Analytics cookies:** used to understand website and feature usage; and
- **Security technologies:** used to detect suspicious activity and protect accounts and systems.
We may use third-party analytics, infrastructure, and security providers. Those providers may receive device, network, usage, and diagnostic information as needed to provide their services.
You can configure your browser to block or delete cookies. Blocking essential cookies may prevent account access or cause parts of the website or Terminal to stop working correctly.
We do not currently use cookies or similar technologies to sell Personal Information or share Personal Information for cross-context behavioral advertising.
## 13. Communications and Marketing
We may send:
- Account, authentication, onboarding, trial, support, billing, security, and service communications;
- Notices about agent activity, approvals, exceptions, integrations, or completed work;
- Product updates, resources, research, event invitations, and other marketing communications; and
- Messages responding to your inquiry or relationship with Marshal.
You may opt out of marketing emails by using the unsubscribe method in the message or contacting [privacy@marshal.ing](mailto:privacy@marshal.ing).
Opting out of marketing does not stop transactional, administrative, account, security, legal, or service communications.
## 14. How We Disclose Personal Information
We may disclose Personal Information in the following circumstances.
### 14.1 Service Providers and Subprocessors
We may disclose Personal Information to vendors, contractors, advisors, and technology providers that help us operate our business and provide the services. Categories may include:
- Hosting, cloud infrastructure, databases, storage, and delivery;
- Authentication and identity management;
- AI and large language model providers;
- Automation, orchestration, and integration providers;
- Secrets management and security providers;
- Monitoring, logging, error tracking, and incident response;
- Email, Slack, messaging, and communications;
- Scheduling and calendar services;
- Payment processing, invoicing, accounting, and tax;
- Customer-relationship, support, and project-management tools;
- Analytics and performance measurement;
- Data enrichment and business research;
- Development, source control, and deployment;
- Professional advisors, auditors, insurers, and legal services; and
- Other providers reasonably necessary to deliver or protect the services.
These providers may process information only as needed to perform services for us or as otherwise permitted by their agreements and applicable law.
Current information about Marshal's core service providers and security posture is available at [https://marshal.ing/security](https://marshal.ing/security).
### 14.2 Customer and Organizational Administrators
We may disclose information within a Customer organization to Authorized Users and administrators based on permissions, business need, and the operation of the workspace.
### 14.3 Customer-Directed Integrations and Actions
We may disclose, transmit, publish, or write information to Customer Systems and Third-Party Services as directed or authorized by the Customer. This includes disclosures made through approved workflows, communications, CRM updates, Slack activity, public-facing work, reports, and other service actions.
### 14.4 Public Distribution
When a Customer authorizes public-facing services, information may be published or distributed through websites, structured data, directories, profiles, databases, articles, research, listings, communications, or other public sources.
Customers are responsible for ensuring that information intended for public distribution is accurate, lawful, authorized, non-infringing, and not confidential unless publication is intended.
### 14.5 Business Transactions
We may disclose or transfer information in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, change of control, diligence process, or similar transaction. Where required, the recipient will be subject to appropriate confidentiality or use restrictions. Data received from a Third-Party Service remains subject to applicable provider policies and any consent requirements, including the requirements applicable to Google API data.
### 14.6 Legal Compliance, Security, and Protection
We may disclose information when we reasonably believe disclosure is necessary or appropriate to:
- Comply with law, legal process, court orders, subpoenas, or government requests;
- Enforce our agreements and policies;
- Collect amounts owed;
- Detect, investigate, prevent, or respond to fraud, malicious code, abuse, unauthorized access, or security incidents;
- Protect the rights, property, systems, safety, and integrity of Marshal, Customers, Authorized Users, third parties, or the public; or
- Establish, exercise, or defend legal claims.
### 14.7 With Consent or at Direction
We may disclose information with your consent or at the direction of the Customer that controls the relevant information.
## 15. No Sale of Personal Information
We do not sell Personal Information for money or other valuable consideration.
We do not currently share Personal Information for cross-context behavioral advertising or targeted advertising based on activity across unaffiliated businesses.
We do not knowingly sell or share Personal Information of individuals under 16.
If our practices change, we will update this Privacy Policy and provide legally required notices and choices before engaging in the changed practice.
## 16. Sensitive and Regulated Information
We do not intentionally request sensitive, regulated, or highly confidential Personal Information unless it is necessary for an agreed service, lawfully authorized, and addressed in an applicable written agreement.
Sensitive or regulated information may include:
- Government identification numbers;
- Financial-account information and authentication credentials;
- Full payment-card information;
- Precise geolocation;
- Health and medical information;
- Biometric information;
- Information about children or students;
- Consumer reports and criminal-history information;
- Employment decision information;
- Privileged legal information;
- Private keys, access secrets, and similar credentials; and
- Other information subject to heightened legal or contractual protection.
Customers must notify us before connecting a system that contains regulated data or assigning work that requires regulated processing.
Unless expressly agreed in writing, Marshal does not act as a HIPAA business associate, financial institution service provider, consumer reporting agency, law firm, legal professional, employment decision-maker, education records processor, insurance professional, or other regulated professional-service provider.
## 17. Data Retention
We retain Personal Information for only as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain accounts, support Customers, protect security, troubleshoot issues, satisfy contractual commitments, comply with law, resolve disputes, and enforce agreements.
Retention depends on factors such as:
- The type, sensitivity, and volume of information;
- The purpose for which it was collected or processed;
- Whether an account, free trial, or paid service remains active;
- Customer instructions and contractual terms;
- Security, fraud-prevention, backup, and incident-response needs;
- Applicable statutes of limitation;
- Legal, tax, accounting, and regulatory requirements; and
- Whether the information is needed to establish, exercise, or defend legal claims.
We generally retain Account Data while an account remains active and for a reasonable period afterward. We retain Customer Data and Agent Operations Information for the service term and a reasonable wind-down period unless an Order, data processing agreement, Customer instruction, or legal obligation requires a different period.
Integration credentials and active tokens are retained only as reasonably necessary to maintain the authorized connection. We may retain limited connection and authorization records after disconnection for security, audit, legal, and dispute purposes.
Some information may remain for a limited period in backups, logs, archives, fraud-prevention systems, and immutable security records after deletion from active systems.
We may retain aggregated or de-identified information that does not identify a Customer or individual.
A Customer may request closure of an Account or deletion of Customer Data by contacting [privacy@marshal.ing](mailto:privacy@marshal.ing). Subject to Customer instructions, contractual requirements, legal obligations, security needs, and applicable exceptions, we will delete or de-identify the affected information from active systems within a reasonable period. Residual copies may remain temporarily in backups, logs, archives, and immutable security records until they expire or are overwritten through ordinary retention processes.
## 18. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect Personal Information from unauthorized access, acquisition, loss, misuse, alteration, disclosure, and destruction.
Depending on the system and information involved, safeguards may include:
- Individual administrative accounts;
- Multifactor authentication for privileged access;
- Role-based and limited-access permissions;
- Scoped integration credentials;
- Centralized secrets management;
- Encryption in transit and, where supported and appropriate, at rest;
- Production code maintained through controlled source management and deployment processes;
- Logging, monitoring, and audit records;
- Incident-response and containment procedures;
- Vendor and service-provider review; and
- Business-continuity and recovery planning.
Current information about our security posture, including controls that are operational, documented, or still in progress, is available at [https://marshal.ing/security](https://marshal.ing/security).
No method of transmission, storage, authentication, or security control is completely secure. We cannot guarantee absolute security.
Customers are responsible for securing Customer Systems, user devices, email accounts, identity-provider accounts, permissions, backups, credentials, and Authorized User access.
If you believe an account or integration has been compromised, contact [security@marshal.ing](mailto:security@marshal.ing) immediately.
Where required by law or contract, we will provide notice of a qualifying security incident.
## 19. International Data Transfers
Marshal is based in the United States. Personal Information may be transferred to, stored in, or processed in the United States and other countries where Marshal or its service providers operate.
Those countries may have privacy and data-protection laws that differ from the laws where you live.
Where required, we use contractual, organizational, and other transfer mechanisms intended to provide appropriate protection for international transfers. If a Customer requires specific international transfer terms, those terms must be addressed in an applicable written agreement.
## 20. Your Privacy Rights
Depending on where you live and how applicable law applies, you may have the right to:
- Request confirmation that we process your Personal Information;
- Request access to Personal Information;
- Request correction of inaccurate Personal Information;
- Request deletion of Personal Information;
- Request a portable copy of Personal Information;
- Object to or restrict certain processing;
- Opt out of certain sales, sharing, targeted advertising, or profiling where applicable;
- Limit certain uses or disclosures of sensitive Personal Information where applicable;
- Withdraw consent where processing is based on consent;
- Appeal a privacy-rights decision where required by law; and
- Receive equal service and treatment without unlawful discrimination for exercising privacy rights.
To submit a request, email [privacy@marshal.ing](mailto:privacy@marshal.ing) and describe the request.
We may need to verify your identity and authority before responding. Verification may require confirming control of an email address, account, organization, or other information reasonably related to the request.
An authorized agent may submit a request where permitted by law. We may require proof of the agent's authority and direct verification from the individual.
We may deny or limit a request where permitted by law, including where information is needed to provide services, protect security, prevent fraud, comply with law, preserve legal claims, protect another person's rights, or maintain records subject to an exception.
### 20.1 Requests Concerning Customer Data
If your request concerns Personal Information that we process on behalf of a Customer, the Customer generally controls that information. We may direct you to the Customer or coordinate with the Customer before responding.
### 20.2 European Economic Area, United Kingdom, and Similar Jurisdictions
Where applicable, you may also have the right to complain to the data-protection authority in your jurisdiction.
## 21. State Privacy Rights and California Notice
State privacy laws may provide additional rights to residents of certain U.S. states. We honor applicable rights as required by law.
### 21.1 California Categories of Personal Information
The following table describes categories of Personal Information that we may have collected during the preceding 12 months, depending on the relationship and services involved.
| Category | Examples | Sources | Business or Commercial Purposes | Categories of Recipients |
| --- | --- | --- | --- | --- |
| Identifiers | Name, work email, phone number, IP address, account ID, organization ID, identity-provider ID | You, Customers, Authorized Users, identity providers, Customer Systems, service providers | Accounts, authentication, services, support, security, communications, billing | Service providers, Customer administrators, Customer-directed integrations, advisors |
| Customer records information | Contact information, account details, signatures or acceptance records, billing address, service relationship information | You, Customers, payment and service providers | Contracting, onboarding, billing, support, legal compliance | Payment providers, service providers, advisors, Customer administrators |
| Commercial information | Services requested or purchased, subscription, plan, transaction, invoice, usage, and Customer relationship information | You, Customers, payment providers, service activity | Billing, account management, service delivery, analytics, legal compliance | Payment providers, accounting providers, advisors, Customer administrators |
| Internet or electronic network activity | Website and Terminal activity, browser and device data, referral information, interactions, logs, authentication events, integration events | Website, Terminal, Customer Systems, analytics, security, and infrastructure providers | Operation, analytics, security, debugging, support, product improvement | Analytics, infrastructure, security, and support providers |
| Approximate geolocation | Approximate location derived from IP address | Website, Terminal, analytics and security providers | Security, fraud prevention, regional configuration, analytics | Infrastructure, security, and analytics providers |
| Professional or employment-related information | Company, role, title, business contact details, professional profiles, organizational permissions | You, Customers, public sources, business-data providers, Customer Systems | B2B services, account administration, research, enrichment, support, communications | Customers, service providers, Customer-directed integrations |
| Communications and submitted content | Messages, files, instructions, prompts, comments, approvals, support requests, email or Slack content, documents, Customer Output | You, Customers, Authorized Users, Customer Systems, integrations | Service delivery, support, agent operation, approvals, security, legal compliance | Service providers, Customer administrators, Customer-directed integrations |
| Sensitive Personal Information | Account login credentials, integration credentials, financial-account information, precise geolocation or regulated information when expressly authorized | You, Customers, Customer Systems, identity and payment providers | Authentication, integration access, security, service delivery, legal compliance | Identity, security, payment, infrastructure, and Customer-directed providers |
| Inferences | Account attributes, lead classifications, workflow state, operational patterns, security-risk indicators, performance insights | Service activity, Customer Data, public sources, service providers | Service delivery, reporting, security, analytics, improvement | Customers, service providers, Customer-directed integrations |
| Other Personal Information | Meeting information, scheduling responses, public-business information, troubleshooting details, agent logs and work receipts | You, Customers, public sources, service providers, Customer Systems | Communications, services, support, research, security, legal compliance | Customers, service providers, advisors, Customer-directed integrations |
We retain each category according to the criteria described in Section 17.
### 21.2 California Rights and Disclosures
Where the California Consumer Privacy Act, as amended, applies, California residents may have rights to know, access, correct, delete, and obtain a copy of Personal Information, and to opt out of sale, sharing, or certain profiling. They may also have a right to limit certain uses of Sensitive Personal Information and a right to non-discrimination.
We do not sell Personal Information. We do not currently share Personal Information for cross-context behavioral advertising.
We use and disclose Sensitive Personal Information only for purposes permitted by applicable law, such as authentication, security, service delivery, authorized integrations, fraud prevention, and legal compliance. We do not use Sensitive Personal Information to infer characteristics about individuals except as lawfully necessary for an authorized service.
To exercise applicable California or other state rights, contact [privacy@marshal.ing](mailto:privacy@marshal.ing).
## 22. Global Privacy Control and Do Not Track
Some browsers and tools transmit Global Privacy Control, "Do Not Track," or other preference signals.
There is no uniform standard for all "Do Not Track" signals, and our services may not respond to every signal.
We do not currently sell Personal Information or share Personal Information for cross-context behavioral advertising. If we engage in processing that requires recognition of a legally valid opt-out preference signal, we will honor the signal as required by applicable law.
## 23. Third-Party Websites and Services
Our website, Terminal, communications, and services may link to or integrate with Third-Party Services that we do not control.
This Privacy Policy does not govern a third party's independent collection, use, disclosure, or security practices. We encourage you to review the third party's privacy policy and terms before authorizing access or providing information.
## 24. Children's Privacy
The website, Terminal, free trial, and services are intended for business users who are at least 18 years old. They are not directed to children.
We do not knowingly allow an individual under 18 to create an account or knowingly collect Personal Information directly from a child through an account-registration flow.
If you believe a child has provided Personal Information directly to Marshal, contact [privacy@marshal.ing](mailto:privacy@marshal.ing), and we will take appropriate steps.
If a Customer seeks to use the services to process information about children, students, or other protected groups, the Customer must notify Marshal in advance, ensure the processing is lawful, and enter into any required written terms before providing the information.
## 25. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When we update it, we will revise the "Last Updated and Effective as of" date. Changes apply prospectively unless otherwise stated.
For a material change that meaningfully affects how we use Personal Information, we will make commercially reasonable efforts to provide notice through the website, Terminal, email, or another appropriate method.
We will not use a retroactive policy change to grant ourselves materially broader rights to use Customer Data for general-purpose AI model training without the Customer's express authorization.
## 26. Contact Us
Questions, privacy requests, and complaints may be sent to:
Growth Marshal, LLC, doing business as Marshal
New York, United States
Email: [privacy@marshal.ing](mailto:privacy@marshal.ing)