Privacy Policy
Effective date: 2026-09-21
This Privacy Policy explains how Myrvold Marketing ("we", "us") processes personal data when you use Marketing Panel (the "Service"). We comply with applicable privacy laws, including the GDPR.
1. Controller and Contact
Controller: Myrvold Marketing (sole proprietorship), Lundveien 4A, 1673 Kråkerøy, Norway.
Organisation number: 931 027 344, registered in the Norwegian VAT register. Contact: sebastian@myrvold.marketing.
When you connect your own customers’ accounts to the Service, you are the
controller for that data and we act as your processor. Those terms are set out
in our Data Processing Agreement,
which forms part of the Terms of Service.
2. Data We Process
- Account and contact data: name, email, configurations and preferences.
- Usage data: sign‑in events, basic error logs and UI selections such as which business you have selected.
- Integration data: KPIs and insights from connected sources (e.g., Google Analytics 4/Search Console/YouTube, Meta/Facebook/Instagram, WooCommerce). Content is limited to what’s needed to compute and display statistics.
- Authentication and access tokens: OAuth tokens stored encrypted. We request minimal scopes and you can disconnect at any time.
- Generation/AI data: text and uploaded images/files you ask us to process to generate content or insights.
- Payment data: when you subscribe, Stripe processes your payment details, billing address and VAT number. We never see or store your card number.
- Integrations you may add later: further ad, email/SMS and CRM providers. Data will be processed the same way when you choose to connect them.
3. Purposes and Legal Bases
- Provide the Service: fetch and display insights, generate content, store setups. Legal basis: performance of a contract (GDPR art. 6(1)(b)).
- Improvement and security: troubleshooting, aggregated analytics, abuse prevention. Legal basis: legitimate interests (art. 6(1)(f)).
- Communication/marketing: only with your consent. Legal basis: consent (art. 6(1)(a)); you may withdraw at any time.
- Legal compliance: to meet legal obligations. Legal basis: legal obligation (art. 6(1)(c)).
4. Sharing and Recipients
We do not sell personal data and we do not share it beyond what is necessary to run the Service. Our processors are:
| Processor |
Purpose |
Location |
| Railway | Application hosting and database | USA (San Francisco region) |
| Vercel | Frontend hosting and CDN | USA, served from edge locations worldwide |
| Stripe | Payments, invoicing, VAT | Ireland and the USA |
| Resend | Transactional email and reports | USA |
| Sentry | Error monitoring | USA |
| OpenAI | Generating text and content suggestions you ask for | USA |
| Anthropic | Generating text and content suggestions you ask for | USA |
We have a data processing agreement with each of them. The current list is kept
up to date here; we will tell you before we add a processor that handles your
customers’ data, so you can object.
Third‑party APIs you connect yourself: Google (Analytics 4, Search Console, YouTube, Google Ads, Business Profile),
Meta (Facebook and Instagram), TikTok, Shopify, WooCommerce and Mailchimp. These are not our processors — they are your own accounts,
and we read from them under the access you grant and can withdraw at any time.
We never send content you generate to an AI provider for that provider’s own model training.
5. Transfers outside the EEA
The Service is hosted in the United States. Our application
and database run on Railway in its San Francisco region, and the other processors listed above are
likewise established in the USA. This means personal data you bring into the Service is transferred
out of the EEA and stored there.
We rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) with each processor,
and, where the provider is certified, on the EU–US Data Privacy Framework. If EU or EEA hosting is a
requirement for you or your clients, tell us before you connect anything — we would rather say so up
front than have you find out later.
6. Security
- Encryption of access tokens and sensitive keys at rest.
- TLS in transit for API calls.
- Least‑privilege principles, access controls, and integration audits.
- Rate limiting and monitoring to detect abuse.
7. Storage and Deletion
| Data |
Retention |
| Account, businesses and settings | Until you delete the account, then removed immediately |
| Integration tokens | Until you disconnect, or immediately on account deletion |
| Cached statistics and daily snapshots | Deleted with the account; cached API responses expire within 24 hours |
| Generated content and uploaded files | Until you delete them, or on account deletion |
| Error logs (Sentry) | 90 days |
| Invoices and accounting records | 5 years after the financial year, required by the Norwegian Bookkeeping Act |
| Anonymised, aggregated statistics | No time limit — these are no longer personal data |
A deletion takes effect in the live database immediately. Where a copy exists in a
backup, it is removed as that backup is rotated out.
You can delete the account yourself under Settings, which erases everything above
apart from the records we must keep by law. You can also use this form or email us.
8. Your Rights
- Access, rectification, erasure, restriction, data portability, and the right to object.
- Do it yourself: Settings → Download your data gives you everything we store about you as a JSON file (art. 15 and 20), and Settings → Delete account erases it (art. 17). Neither requires you to contact us.
- Withdrawal of consent where processing is based on consent, and disconnecting any integration at any time.
- We answer a written request within 30 days.
- You may complain to your data protection authority. In Norway that is Datatilsynet, Postboks 458 Sentrum, 0105 Oslo — datatilsynet.no.
9. Cookies and Local Storage
- Strictly necessary cookies for sign‑in and security.
- Functional local storage for your own preferences: language, selected business, and which accounts you picked for each integration.
- Any analytics/tracking only with your consent and in line with applicable law.
- You can manage cookies via your browser and in‑app settings.
10. Data Breaches
If personal data is lost or exposed, we notify Datatilsynet within 72 hours of becoming
aware of it, as required by GDPR art. 33. Where the breach is likely to be a high risk
to you, we notify you directly and without undue delay, and tell you what happened,
what data was involved and what we are doing about it. Where we act as your processor
we notify you rather than the authority, so that you can report it.
11. Children’s Privacy
The Service is not intended for children under 16. We do not knowingly collect data about children. Contact us if you believe we hold such information and we will delete it.
12. Changes
We may update this Policy as needed. Material changes will be announced in‑app or via email. Continued use after the effective date constitutes acceptance.