1. Who we are
Marqab is provided by Arvyo (Arvyo Limited, 292 Nasir Garden, West Shewrapara, Mirpur, Dhaka-1216, Bangladesh) (“we”, “us”). This policy covers the Marqab web app, the iPhone and Android apps, and this website. It sits alongside our Terms of Service.
2. Your workspace, your data
Marqab is a business tool. For content that an organisation puts into its workspace, such as products, owners, teams, notes and imported activity, the organisation decides what goes in and who sees it. We process that content on its behalf and on its instructions (as a “processor”). If you’re a member of someone else’s workspace, contact that organisation first about your data in it; we will help them respond.
For account, billing and usage data that we need to run Marqab itself, we are responsible (as a “controller”).
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, email address, sign-in method, language and appearance preferences, workspace role | You, or Google / Microsoft if you sign in with them |
| Workspace content | Products, components, relations, teams, people and contact details you add, notes, imports, and activity pulled from connected tools (GitHub, GitLab, Jira, Slack) | You, your colleagues, and integrations you connect |
| Billing | Billing contact, company name and address, plan, invoices (MQB-####), payment status, card brand and last four digits, and Lemon Squeezy order and subscription references | You and Lemon Squeezy. We don’t receive or store full card numbers. |
| Usage and logs | IP address, device and browser type, app version, pages and features used, timestamps, and error reports | Collected automatically when you use Marqab |
| Communications | Emails you send to support, sales, billing or legal | You |
4. How we use it
- To provide Marqab. This covers running your workspace, syncing across devices, answering Ask questions from your data, and sending invites and notifications. Basis: performing our contract with you.
- To bill you. This covers taking payments through our merchant of record, Lemon Squeezy, which processes and invoices orders, and handling refunds. Basis: contract and legal obligations, such as tax and accounting records.
- To keep Marqab secure and reliable. This covers detecting abuse, investigating errors and monitoring performance. Basis: our legitimate interest in a safe, working service.
- To improve Marqab. We use aggregated, de-identified usage information to understand which features are used. Basis: legitimate interest. We don’t use workspace content to train machine-learning models.
- To communicate with you. This covers service and billing emails, and product updates you can opt out of at any time. Basis: contract, legitimate interest or consent, as applicable.
- To meet legal obligations and respond to lawful requests from authorities.
We don’t sell personal data, share it for cross-context advertising, or use it to build advertising profiles.
5. Who processes it
We use a small number of service providers (sub-processors) under contracts that limit their use of data to providing their service to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Lemon Squeezy | Merchant of record: checkout, payment processing, invoicing, sales tax and VAT, and refunds | Billing contact, email address, country, amount, and transaction details. Lemon Squeezy and its payment processors handle card data directly; Lemon Squeezy is an independent controller for the order data it processes. |
| Mailgun | Transactional email: invites, sign-in links, billing notices | Name, email address, and email content |
| Google / Microsoft | Sign-in, only if you choose it | Name, email address, and account identifier |
| Cloud hosting provider | Application hosting, database and backups | All categories above |
| Cloudflare | Content delivery (CDN) and file storage (R2) for images and assets, DNS and network protection | IP address, request metadata, and files you upload |
| Sentry | Error monitoring | Error reports, device and app details, and account identifier. We configure Sentry to scrub workspace content where practical. |
Integrations you connect, such as GitHub, GitLab, Jira and Slack, receive and send data at your direction under their own privacy policies. We may also disclose data if the law requires it, to protect rights and safety, or as part of a merger or acquisition. If that happens, this policy will continue to apply, or you will be notified.
6. How long we keep it
| Data | Kept for |
|---|---|
| Workspace content | While the workspace exists. It is deleted from live systems within 30 days of workspace deletion or closure, and from backups within 90 days. |
| Account data | While your account exists, then deleted or anonymised within 30 days of account deletion |
| Billing records and invoices | As long as tax and accounting law requires (currently 6 years) |
| Server and access logs | 30–90 days |
| Error reports (Sentry) | 90 days |
| Support emails | Up to 2 years after the conversation ends |
7. Security
- All traffic to Marqab is encrypted in transit with TLS.
- Secrets such as integration tokens and API keys are encrypted at rest.
- Access to production systems is limited to staff who need it, and is logged.
- Workspace permissions let owners restrict what each member can see.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected customers without undue delay, and as the law requires. To report a security issue, email privacy@marqab.dev.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data (most of it you can edit yourself in Settings);
- export your data in a portable format. Workspace owners and admins can export the whole workspace as JSON, or tables as CSV, at any time;
- delete your account, or, for workspace owners, the whole workspace, from Settings or by asking us;
- object to or restrict certain processing, and withdraw consent where we rely on it;
- complain to your local data protection authority.
Email privacy@marqab.dev to exercise any of these. We may need to verify your identity, and we aim to respond within 30 days. If your request is about content in an organisation’s workspace, we may refer you to that organisation.
9. Cookies
Marqab uses one essential session cookie to keep you signed in. The apps may also store sign-in tokens and preferences, such as language and theme, on your device. We use no advertising or cross-site tracking cookies, and no third-party analytics cookies.
This website (marqab.dev) sets one first-party cookie, mq_attr, that records how you first found us: the campaign tags in the link you followed (such as utm_source and ad click IDs), the website that referred you (without its query string), the page you landed on and when. If you later sign up, we use it to attribute the signup to a marketing channel. It holds no name, email or other contact details, is readable only by marqab.dev and our app at dash.marqab.dev, is never shared with third parties, and expires after 90 days. Apart from this cookie, we only use strictly necessary storage.
10. Children
Marqab is for businesses and isn’t directed at children. We don’t knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
11. International transfers
Arvyo is based in Bangladesh, and our providers may process data in other countries, including the United States and the European Union. Where the law requires it, we rely on appropriate safeguards for these transfers, such as standard contractual clauses. Enterprise customers can request a data processing agreement (DPA).
12. Changes to this policy
We will update this page when our practices change, and revise the date at the top. For material changes, we will notify workspace owners by email or in the app before they take effect.
13. Contact
Privacy questions and requests: privacy@marqab.dev.
Legal: legal@marqab.dev
Arvyo Limited
292 Nasir Garden, West Shewrapara, Mirpur
Dhaka-1216, Bangladesh