Legal information

Privacy Policy

The account, project, payment and integration data MarketBase processes, why it is used, its legal bases and its limits.

Last updated: September 30, 2026

1. Introduction

This policy explains how MarketBase.club collects, uses, stores and protects data related to its website, accounts, projects, integrations and purchases. It distinguishes account data, data supplied by the User, data received from third parties and derived data.

2. Controller and contact

The public service name is MarketBase.club. The operator’s legal entity, form and address are injected from production configuration when available; they are not supplied in the repository provided. For data requests, contact [email protected]. For general requests or public-profile corrections, contact [email protected].

3. Categories of data

CategoryObserved examplesSourceAccess
Accountemail, name, avatar, identifier, role, sessionGoogle OAuth and the applicationPrivate
Project and domainname, description, logo, hostname, organisationUserPrivate by default; public depending on project
Google Search Consoleproperty, clicks, impressions, CTR, position, queries, pagesAuthorised Google APIPrivate; public aggregates possible by profile
Stripeconnected account, identifiers, subscriptions, aggregated invoices, counted customersStripe Connect or Stripe BillingPrivate; public metrics depending on profile
Derived dataMRR, ARR, revenue, churn, scores, rankings, classificationMarketBase calculationsAccording to project publication status
Security and consenthashed IP, consent choice, jobs, errors, webhooksRequests and infrastructurePrivate

4. Sources

  • the User or authorised members of an organisation;
  • Google when a user connects and authorised Search Console calls are made;
  • Stripe for MarketBase payments or a connected business account;
  • interactions with the site, endpoints and worker;
  • internal calculations and, when the live provider is enabled, OpenAI for project classification from its summary.

5. Purposes and legal bases

ProcessingPurposeMain basisObserved retention
Account and sessionCreate the account, authenticate and secure accessArticle 6(1)(b) GDPR: contract or pre-contract stepsWhile the account exists; no self-service deletion
Project and integrationsProvide the requested benchmark and synchronise selected sourcesArticle 6(1)(b) GDPRWhile the project or connection exists; no coded purge
PaymentsCreate a subscription, record a report and process webhooksArticle 6(1)(b) and, for legal accounting duties, Article 6(1)(c)Depends on applicable duties; not configured in code
Security and abuse preventionRate limiting, validation, attack prevention and diagnosisArticle 6(1)(f) GDPR: legitimate interestNo configured purge period
ConsentRemember category choices and retain evidence of the choiceDuty to demonstrate consent where applicable; Article 6(1)(c) or legitimate interest depending on processingLocal storage until cleared; table has no coded purge
PublicationDisplay a profile and aggregates when a project is publicPublication request / contract and legitimate interest depending on contextWhile the public project exists

6. Retention

The current code contains no numerical retention policy or purge job for accounts, projects, metrics, logs, consent, Stripe events or tokens. We therefore do not invent a period. Data should be kept for the time necessary for the purpose and then deleted or anonymised where technically and legally possible. Final operational periods remain an audit action.

7. Recipients and access

Access is limited to authorised project members, application components and providers required to operate the service. Human access to private integration data should occur only for security, legal compliance or authorised support. Observed services and open questions are listed in the Data Processing document.

8. Public, private and derived data

A public profile may display a name, description, domain, market, selected metrics, statuses, dates and rankings through the public query layer. Emails, tokens, Search Console queries and pages, Stripe details, billing, logs and dashboard data remain private in the observed controls.

Derived data may be calculated from a private source. Publishing an aggregate does not make the source data freely available and must respect the authorisation, provider terms and project publication rules.

9. Google Search Console

MarketBase requests only the `webmasters.readonly` scope to retrieve the property matching the domain and the Search Analytics data required for benchmarking. Received data may include clicks, impressions, CTR, positions, queries and pages for the authorised project.

Tokens are encrypted at rest. Queries and pages are not rendered in public pages. After this lot’s fix, synchronisation no longer sends GSC queries to the OpenAI provider. MarketBase does not sell Google data, use it for advertising or targeting, or transfer it to a data broker. Use and any transfer must comply with the Google API Services User Data Policy, including Limited Use.

Authorisation can be removed from the Google account. The current repository does not automatically revoke the token or delete the connection through a dedicated interface; a request can be sent to [email protected].

10. Google OAuth sign-in

Google sign-in is separate from Search Console. The authentication flow uses identity information needed for the account, including email, name and image when supplied. Google’s authorisations and policy apply to Google’s processing; MarketBase stores the fields needed for its own account.

11. Stripe and Stripe Connect

For MarketBase purchases, Stripe processes payment and MarketBase receives technical information needed to track a purchase or subscription: identifiers, status, period and signed events. The observed MarketBase schema does not store card data.

For Stripe Connect, the User authorises a read connection to a business account. MarketBase may read subscriptions, paid invoices, customers and amounts to calculate MRR, ARR, revenue, customer count, churn or history. The required metrics and identifiers are stored in project tables. MarketBase does not hold funds, provide Stripe payment services or publish individual customer details in the public layer.

12. AI, email and infrastructure

When the live provider is enabled, OpenAI receives the project summary needed to classify its market and niche. After the fix, no GSC query is included. OpenAI’s external retention and location are not determined by the repository and must be covered by production configuration and contracts.

A Resend adapter exists for transactional email, but no send call was found in the current flow. Infrastructure providers may process technical data according to the operator’s configuration. Their names, regions and log retention are shown when configured.

13. International transfers

The repository does not determine processing regions for Google, Stripe, OpenAI, Cloudflare, Resend or the PostgreSQL host. Any transfer must rely on the mechanism applicable to the provider and destination, such as an adequacy decision or appropriate safeguards. The final contractual list and transfer measures remain an action before definitive publication.

14. Security

The service uses organisation access controls, HTTP-only Auth.js sessions, short-lived signed OAuth state, AES-256-GCM token encryption, Zod validation, PostgreSQL rate limiting, Stripe signature verification, security headers and an SSRF-protected crawler. These measures reduce risk but are not an absolute security guarantee.

15. Cookies and local storage

The observed mechanisms are Auth.js cookies, OAuth state cookies described in the Cookie Policy and the `localStorage` key `mb_cookie_consent`. No analytics tool, advertising pixel or marketing script is present in the repository. Details, duration and choice management are described in the Cookie Policy.

16. Your rights

Where GDPR or another applicable law applies, you may request access, rectification, erasure, restriction, portability, objection to certain processing and withdrawal of consent. Practical steps, identity verification and retention limits are described on the dedicated GDPR rights page.

17. Complaints

You may first contact [email protected] so the request can be reviewed. You may also contact the supervisory authority competent for your residence or establishment. In France, information is available from cnil.fr.

18. Policy changes

The update date at the top of this page identifies the published version. A material change may be accompanied by additional notice in the service. Processing remains limited to the purposes described and the authorisations actually requested.

For a question about this document or your data, email [email protected].