Legal information
Privacy Policy
The account, project, payment and integration data MarketBase processes, why it is used, its legal bases and its limits.
Last updated: September 30, 2026
1. Introduction
This policy explains how MarketBase.club collects, uses, stores and protects data related to its website, accounts, projects, integrations and purchases. It distinguishes account data, data supplied by the User, data received from third parties and derived data.
2. Controller and contact
The public service name is MarketBase.club. The operator’s legal entity, form and address are injected from production configuration when available; they are not supplied in the repository provided. For data requests, contact [email protected]. For general requests or public-profile corrections, contact [email protected].
3. Categories of data
| Category | Observed examples | Source | Access |
|---|---|---|---|
| Account | email, name, avatar, identifier, role, session | Google OAuth and the application | Private |
| Project and domain | name, description, logo, hostname, organisation | User | Private by default; public depending on project |
| Google Search Console | property, clicks, impressions, CTR, position, queries, pages | Authorised Google API | Private; public aggregates possible by profile |
| Stripe | connected account, identifiers, subscriptions, aggregated invoices, counted customers | Stripe Connect or Stripe Billing | Private; public metrics depending on profile |
| Derived data | MRR, ARR, revenue, churn, scores, rankings, classification | MarketBase calculations | According to project publication status |
| Security and consent | hashed IP, consent choice, jobs, errors, webhooks | Requests and infrastructure | Private |
4. Sources
- the User or authorised members of an organisation;
- Google when a user connects and authorised Search Console calls are made;
- Stripe for MarketBase payments or a connected business account;
- interactions with the site, endpoints and worker;
- internal calculations and, when the live provider is enabled, OpenAI for project classification from its summary.
5. Purposes and legal bases
| Processing | Purpose | Main basis | Observed retention |
|---|---|---|---|
| Account and session | Create the account, authenticate and secure access | Article 6(1)(b) GDPR: contract or pre-contract steps | While the account exists; no self-service deletion |
| Project and integrations | Provide the requested benchmark and synchronise selected sources | Article 6(1)(b) GDPR | While the project or connection exists; no coded purge |
| Payments | Create a subscription, record a report and process webhooks | Article 6(1)(b) and, for legal accounting duties, Article 6(1)(c) | Depends on applicable duties; not configured in code |
| Security and abuse prevention | Rate limiting, validation, attack prevention and diagnosis | Article 6(1)(f) GDPR: legitimate interest | No configured purge period |
| Consent | Remember category choices and retain evidence of the choice | Duty to demonstrate consent where applicable; Article 6(1)(c) or legitimate interest depending on processing | Local storage until cleared; table has no coded purge |
| Publication | Display a profile and aggregates when a project is public | Publication request / contract and legitimate interest depending on context | While the public project exists |
6. Retention
The current code contains no numerical retention policy or purge job for accounts, projects, metrics, logs, consent, Stripe events or tokens. We therefore do not invent a period. Data should be kept for the time necessary for the purpose and then deleted or anonymised where technically and legally possible. Final operational periods remain an audit action.
7. Recipients and access
Access is limited to authorised project members, application components and providers required to operate the service. Human access to private integration data should occur only for security, legal compliance or authorised support. Observed services and open questions are listed in the Data Processing document.
8. Public, private and derived data
A public profile may display a name, description, domain, market, selected metrics, statuses, dates and rankings through the public query layer. Emails, tokens, Search Console queries and pages, Stripe details, billing, logs and dashboard data remain private in the observed controls.
Derived data may be calculated from a private source. Publishing an aggregate does not make the source data freely available and must respect the authorisation, provider terms and project publication rules.
9. Google Search Console
MarketBase requests only the `webmasters.readonly` scope to retrieve the property matching the domain and the Search Analytics data required for benchmarking. Received data may include clicks, impressions, CTR, positions, queries and pages for the authorised project.
Tokens are encrypted at rest. Queries and pages are not rendered in public pages. After this lot’s fix, synchronisation no longer sends GSC queries to the OpenAI provider. MarketBase does not sell Google data, use it for advertising or targeting, or transfer it to a data broker. Use and any transfer must comply with the Google API Services User Data Policy, including Limited Use.
Authorisation can be removed from the Google account. The current repository does not automatically revoke the token or delete the connection through a dedicated interface; a request can be sent to [email protected].
10. Google OAuth sign-in
Google sign-in is separate from Search Console. The authentication flow uses identity information needed for the account, including email, name and image when supplied. Google’s authorisations and policy apply to Google’s processing; MarketBase stores the fields needed for its own account.
11. Stripe and Stripe Connect
For MarketBase purchases, Stripe processes payment and MarketBase receives technical information needed to track a purchase or subscription: identifiers, status, period and signed events. The observed MarketBase schema does not store card data.
For Stripe Connect, the User authorises a read connection to a business account. MarketBase may read subscriptions, paid invoices, customers and amounts to calculate MRR, ARR, revenue, customer count, churn or history. The required metrics and identifiers are stored in project tables. MarketBase does not hold funds, provide Stripe payment services or publish individual customer details in the public layer.
12. AI, email and infrastructure
When the live provider is enabled, OpenAI receives the project summary needed to classify its market and niche. After the fix, no GSC query is included. OpenAI’s external retention and location are not determined by the repository and must be covered by production configuration and contracts.
A Resend adapter exists for transactional email, but no send call was found in the current flow. Infrastructure providers may process technical data according to the operator’s configuration. Their names, regions and log retention are shown when configured.
13. International transfers
The repository does not determine processing regions for Google, Stripe, OpenAI, Cloudflare, Resend or the PostgreSQL host. Any transfer must rely on the mechanism applicable to the provider and destination, such as an adequacy decision or appropriate safeguards. The final contractual list and transfer measures remain an action before definitive publication.
14. Security
The service uses organisation access controls, HTTP-only Auth.js sessions, short-lived signed OAuth state, AES-256-GCM token encryption, Zod validation, PostgreSQL rate limiting, Stripe signature verification, security headers and an SSRF-protected crawler. These measures reduce risk but are not an absolute security guarantee.
16. Your rights
Where GDPR or another applicable law applies, you may request access, rectification, erasure, restriction, portability, objection to certain processing and withdrawal of consent. Practical steps, identity verification and retention limits are described on the dedicated GDPR rights page.
17. Complaints
You may first contact [email protected] so the request can be reviewed. You may also contact the supervisory authority competent for your residence or establishment. In France, information is available from cnil.fr.
18. Policy changes
The update date at the top of this page identifies the published version. A material change may be accompanied by additional notice in the service. Processing remains limited to the purposes described and the authorisations actually requested.
For a question about this document or your data, email [email protected].