Marrow Privacy Policy
Last Updated: July 29, 2026 This draft is adapted from the reviewed Hologrow Pulse privacy policy to Marrow’s product and service model, and is provided for review by qualified counsel before publication.1. Introduction
HOLOGROW INC, a Delaware corporation with registered address at 8 The Green, Ste A, Dover, DE 19901 (“Hologrow”, “we”, “our”, or “us”) operates Marrow (also referred to as Hologrow Marrow), a data middle layer for commerce and advertising operators. Marrow connects your store and advertising accounts — such as Amazon Seller, Amazon Vendor, Amazon Ads, Shopify, Shoplazza, Google Ads, Google Analytics (GA4), Google Search Console, Facebook Ads (Meta), and Lingxing ERP — via read-only authorization, syncs and normalizes that data into governed tables, and makes it available to the AI platforms you choose (such as Codex, Claude, ChatGPT, Cursor, Gemini CLI, and other MCP-compatible clients) through OAuth connections and Marrow’s MCP server. This Privacy Policy explains what information we collect when you use Marrow, how we use it, how we protect it, and the rights you have. It is designed to comply with the General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA), and to align with Amazon’s SP-API Data Protection Requirements, the Meta Platform Terms, and the Google API Services User Data Policy. By creating an account, connecting a data source or AI platform, or otherwise using Marrow, you acknowledge the practices described in this policy.2. Information We Collect
We collect the following categories of information:2.1 Account data
When you register, we collect your name, email address, and authentication credentials. If you sign in with Google or Microsoft single sign-on, we receive basic profile information from that identity provider as permitted by your settings. This is the minimum required to identify you and secure your account.2.2 Connected platform data
You connect store and advertising accounts to Marrow via OAuth authorization or API credentials issued to you by each platform. We never receive or store your platform login passwords — only the OAuth tokens or API keys the platform issues to us. Through these authorized connections we receive business data such as:- Commerce data — orders and order items, listings and catalog, inventory and logistics, returns, settlements and finance data, promotions, seller or store performance, vendor purchase orders and shipments (from Amazon Seller, Amazon Vendor, Shopify, Shoplazza, Lingxing ERP);
- Advertising data — campaigns, ad groups, ads, keywords, targeting, search terms, and daily performance metrics (from Amazon Ads, Google Ads, Facebook Ads);
- Web and search analytics data — traffic, page, event, and search performance metrics (from GA4, Google Search Console);
- Mailbox data — where you connect Gmail, order- and notification-related message content parsed for the connected workflows.
2.3 User-uploaded data
Marrow lets you maintain manual tables (for example, cost of goods sold or supplier prices) that you upload or edit yourself. You control the content of these tables; Marrow never overwrites them.2.4 Usage data
We collect MCP tool calls, OAuth connection sessions, queries and prompts your AI clients submit through Marrow, sync activity and freshness logs, exports, and your activity within the product (such as pages viewed and features used). This helps us operate the service, meter usage for plan limits, debug issues, ensure security, and improve features.2.5 Technical data
We log device information, browser type, IP address, and platform usage and performance logs for security, reliability, and diagnostic purposes.2.6 Billing data
Payments are handled by our payment processor (currently Stripe). We receive limited billing metadata (subscription status, invoice records, last four digits of the payment card) but do not store your full payment card number.3. How We Use Your Information
We use the information we collect strictly to operate and improve Marrow:- Service provision — authorizing connections, extracting data from platform APIs on your behalf, normalizing it into your data layer, keeping it fresh through scheduled syncs, and delivering it to the AI platforms, MCP clients, and tools you connect;
- User-directed delivery — transmitting your synced data to the AI platforms you explicitly authorize via OAuth or MCP, at your direction;
- Communications — service updates, security notices, billing notices, and platform announcements;
- Platform security — fraud prevention, abuse monitoring, access control, and audit logging;
- Product improvement — aggregated, de-identified usage analytics that do not identify you or any individual.
4. How Marrow Shares Data
We do not sell, trade, or rent your personal information. We disclose information only in the following circumstances:4.1 AI platforms you connect (at your direction)
The core function of Marrow is to make your synced data available to the AI clients you choose. When you connect an AI platform via OAuth or MCP — such as Anthropic (Claude), OpenAI (ChatGPT, Codex), Google (Gemini), Anysphere (Cursor), or another MCP-compatible client — your data is transmitted to that platform at your direction, and that platform processes it under its own terms and privacy policy. You can revoke an OAuth session or rotate and revoke an MCP key at any time, after which no further data is delivered through that connection. These platforms are independent third parties, not our subprocessors.4.2 Vetted subprocessors
We share data only with the following categories of vetted subprocessors, each contractually bound by confidentiality and data-protection obligations consistent with this policy and applicable law:
We may also disclose information where required by law, court order, or valid governmental request, or to protect the rights, property, or safety of Hologrow, our users, or others.
4.3 Business transfers
If Hologrow is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this policy. We will notify you of any change in ownership or control of your personal information.5. Storage, Security, and Retention
5.1 Where and how data is stored
Your data is processed and stored on Google Cloud Platform (GCP) infrastructure in the us-central1 region of the United States. All data is encrypted at rest using AES-256-GCM and in transit using TLS 1.3. Secrets, OAuth tokens, and API keys are held in dedicated secret management, never hardcoded in source. Access to production data is restricted to employees with a strict need-to-know basis, governed by Google Workspace SSO, GCP IAM role-based access control (RBAC), and multi-factor authentication (MFA). All access events are logged. Access is individually identified, reviewed quarterly, and automatically revoked upon employee offboarding. Anomalous access patterns (for example, new geolocation or off-hours bulk exports) trigger automated alerts to our security team.5.2 General retention
We retain your synced data for the duration of your use of the service, consistent with the history window of your plan, and for 30 days after termination of your account, after which it is permanently and securely deleted from our active systems. Backups containing residual data are overwritten on our standard backup rotation. Non-PII transactional metadata necessary for billing, audit trails, or legal compliance may be retained in de-identified or aggregated form as permitted by law.5.3 Platform-specific retention
Where any Amazon-related personal data is processed, it is retained no longer than 30 days from collection or fulfillment of the authorized purpose, consistent with Amazon’s Data Protection Requirements (see Section 7). Data from other platforms is retained according to the applicable platform’s policies and your plan’s history window.5.4 Security and audit logs
We retain access, event, and security logs for a minimum of 12 months. Logs are scrubbed of PII where not legally required and are protected against unauthorized access and tampering.6. Security Program
We operate the service with reference to industry frameworks including ISO/IEC 27001, ISO/IEC 27002, and the NIST Cybersecurity Framework. Key controls include:- Encryption — TLS 1.3 in transit; AES-256-GCM at rest;
- Multi-factor authentication required for all administrative and cloud access;
- Least-privilege role-based access via cloud IAM; no shared admin accounts;
- Secrets management — credentials, OAuth tokens, API keys, and database secrets held in managed secret stores and never hardcoded;
- Quarterly access reviews; access revoked promptly upon employee or contractor termination;
- Segregated test and production environments with code review and deployment gating;
- Annual security training covering PII handling, phishing, and incident reporting;
- Documented incident management plan, reviewed at least every six months.
7. Amazon Data
This section applies specifically to data Hologrow receives from Amazon via the Selling Partner API (SP-API) and the Amazon Ads API — including order and order-item data, settlements, inventory, listings, catalog, Brand Analytics, advertising performance, and any Personally Identifiable Information incidentally included (“Amazon Data”) — and supplements the rest of this Privacy Policy. In the event of any conflict between this section and other provisions of this Privacy Policy, this section governs with respect to Amazon Data.- Collection. We collect Amazon Data solely via Amazon’s authorized APIs (SP-API and Amazon Ads API) under read-only permissions you grant, for the purpose of syncing, normalizing, and making your commerce and advertising data available to you and to the AI platforms you explicitly connect. We do not collect Amazon Data for any other purpose. Marrow’s standard schema is designed to exclude buyer PII, and we do not request Restricted Data Tokens for standard synchronization.
- Use limitation. Amazon Data is used exclusively to provide the service to the customer that authorized the connection. We do not use Amazon Data for advertising, marketing, building customer profiles, or any purpose unrelated to the authorized service. We do not use Amazon Data to train, fine-tune, or improve any AI or machine-learning models, including foundation models, unless expressly authorized in a separate written agreement with the relevant customer and in compliance with Amazon’s Data Protection Requirements.
- Security. Amazon Data is processed and stored in Google Cloud Platform (GCP) in the us-central1 region, encrypted at rest using AES-256-GCM and in transit using TLS 1.3. Access is restricted to employees with a strict need-to-know basis, governed by Google Workspace SSO, GCP IAM RBAC, and MFA. All access events are logged. Quarterly access reviews are conducted, access is automatically revoked upon offboarding, and anomalous access patterns trigger automated alerts to our security team.
- Sharing. Amazon Data is shared only (a) with the AI platforms and MCP clients you explicitly authorize, at your direction as the data controller; (b) with subprocessors essential to providing the service, bound by equivalent data-protection obligations; and (c) where required by law. We do not sell, rent, license, or otherwise commercialize Amazon Data, and we do not combine or commingle one customer’s Amazon Data with another customer’s data.
- Retention. Where Amazon PII is processed, it is retained for a maximum of thirty (30) days from collection or completion of the authorized purpose, whichever is later, consistent with Amazon’s Data Protection Requirements, after which it is purged through automated deletion and cryptographic erasure. Non-PII data follows the general retention rules in Section 5.
- Data subject requests. Where Amazon Data includes personal information of data subjects (for example, end customers), Hologrow processes such data solely as a processor on behalf of the customer that authorized the connection. Individuals seeking to exercise rights (access, correction, deletion, restriction, or portability) should contact that customer; we will assist the customer in responding as required by our agreement.
- Incident notification. In the event of a security incident involving unauthorized access to, disclosure of, or loss of Amazon Data, we will notify the affected customer and Amazon promptly and in any case within twenty-four (24) hours of discovery, or as otherwise required by Amazon’s Data Protection Requirements, and will cooperate fully with Amazon and applicable authorities.
- Compliance. Hologrow agrees to comply with the Amazon Services Business Solutions Agreement, Amazon Data Protection Requirements, and all applicable SP-API and Amazon Ads API policies in connection with the collection, processing, storage, use, sharing, and disposal of Amazon Data, and will promptly implement any required security updates or policy changes communicated by Amazon.
8. Meta Data
This section applies specifically to data Hologrow receives from Meta Platforms, Inc. and its affiliates (“Meta”) via the Meta Marketing API, Business Manager API, Conversions API, or any other Meta Platform interface, including advertising account identifiers, Business Manager metadata, campaign structures, ad sets, ads, creatives, spend, impressions, clicks, conversions, audience attributes, Pixel event data, access tokens, app secrets, and Meta user identifiers (“Meta Data”), and supplements the rest of this Privacy Policy. In the event of any conflict between this section and other provisions of this Privacy Policy, this section governs with respect to Meta Data.- Tech Provider. For purposes of the Meta Platform Terms, Hologrow acts as a Tech Provider. We access and process Meta Data solely on behalf of and at the direction of our customers to help them use Meta Products in accordance with Meta’s terms and policies.
- Collection and permissions. We collect Meta Data solely via read-only permissions granted through Meta’s authorized connection flows (for example, OAuth through Meta Business Manager), and only to provide advertising analytics, reporting, dashboards, performance monitoring, and AI-assisted outputs within Marrow, as configured and authorized by the customer. We request only the minimum permissions necessary and do not request permissions to write, modify, or manage Meta advertising assets, nor Restricted Platform Data, unless specifically requested by the customer and justified by a permitted use case under Meta’s Developer Docs.
- Use limitation. Meta Data is used exclusively to provide the authorized services to the customer that granted the connection. We do not use Meta Data in any manner that would violate the Meta Platform Terms or Meta Developer Policies, including for our own advertising, marketing, or product-development purposes unrelated to the customer’s authorized use.
- Security. Meta Data is processed and stored in GCP in the us-central1 region, encrypted at rest using AES-256-GCM and in transit using TLS 1.3, with need-to-know access governed by SSO, RBAC, MFA, logged access events, quarterly access reviews, automatic offboarding revocation, and anomaly alerts.
- Sharing and separation. Meta Data is shared only (a) with the AI platforms and MCP clients the customer explicitly authorizes, at the customer’s direction; (b) with service providers essential to the service that have agreed in writing to equivalent data-protection obligations; and (c) where required by law. We do not sell, rent, license, or otherwise commercialize Meta Data. We maintain each customer’s Meta Data separately and do not combine or commingle it with another customer’s data. We maintain an up-to-date list of customers and will provide it to Meta if asked.
- Retention and deletion. Unless required by law, we will delete Meta Data upon the customer’s request, upon deauthorization of the connection, or when it is no longer necessary for the authorized purpose, and will make reasonable efforts to ensure our service providers do the same. If we are required to retain Meta Data by law, we will retain proof of the requirement and provide it to Meta if asked. If we receive Meta Data in error, we will report it to Meta via Meta’s incident channel, delete it, and provide proof of deletion if asked.
- Data subject requests. Where Meta Data includes personal information of end users, Hologrow processes such data solely as a processor or Tech Provider on behalf of the customer. Individuals should direct rights requests to the customer operating the relevant ad account; we will assist the customer as required.
- Incidents. In the event of any unauthorized access to, disclosure of, loss of, or other compromise of Meta Data, we will promptly notify the affected customer and Meta, investigate, remediate, and cooperate with Meta and applicable authorities as required by the Meta Platform Terms.
- Compliance. Hologrow agrees to comply with the Meta Platform Terms, Meta Developer Policies, Meta Business Tools Terms, and Meta Advertising Guidelines in connection with the collection, processing, storage, use, sharing, and disposal of Meta Data, and will promptly implement any required security updates or policy changes communicated by Meta.
9. Google API Data (Limited Use)
Marrow’s use and transfer to any other application of information received from Google APIs — including the Google Ads API, Google Analytics Data API, Google Search Console API, and Gmail API — will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:- We use Google API data only to provide or improve the user-facing features of Marrow that you authorize (syncing, normalizing, and delivering your data to the tools you connect);
- We do not use Google API data for serving advertisements or for our own marketing purposes;
- We do not allow humans to read Google API data except (a) with your affirmative consent for specific data, (b) as necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for internal operations where the data has been aggregated and anonymized;
- We do not transfer Google API data to third parties except (a) to the AI platforms you explicitly connect, at your direction, (b) to subprocessors as necessary to provide the service, (c) for security or abuse-investigation purposes, (d) to comply with applicable law, or (e) as part of a merger, acquisition, or sale of assets with notice to you;
- We do not use Google API data to train, fine-tune, or improve any AI or machine-learning models, including foundation models.
10. Your Rights
Under GDPR, the UK GDPR, the CCPA, and comparable laws, you have the following rights, subject to legal limitations:- Access — request a copy of the personal data we hold about you;
- Correction — ask us to correct inaccurate or incomplete data;
- Deletion — request that we delete your personal data (subject to legal retention requirements);
- Restriction — limit how we process your data in specific circumstances;
- Portability — receive your data in a structured, commonly used format;
- Opt-out of data sales or sharing — we do not sell your data;
- Withdraw consent — where processing is based on consent, you may withdraw it at any time, including by disconnecting a data source or AI platform;
- Non-discrimination — we will not discriminate against you for exercising your rights;
- Lodge a complaint with your local data protection authority.
11. International Data Transfers
Hologrow is operated from the United States, and personal data — including connected platform data — is stored and processed on infrastructure located in the United States. If you are located in the EU/EEA, the UK, Switzerland, or another jurisdiction whose laws restrict cross-border transfers, your data will be transferred to the United States. For such transfers, we rely on appropriate transfer mechanisms — including the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum — when executing a Data Processing Addendum (DPA) with customers acting as data controllers. Contact privacy@hologrow.ai to request our standard DPA.12. Children’s Privacy
Marrow is a business product intended for users 18 years of age or older. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact privacy@hologrow.ai and we will delete it.13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the product before the changes take effect. The “Last Updated” date at the top reflects when this version was published. Continued use of Marrow after a policy update means you accept the revised policy.14. Contact
Questions about this policy or your data? For data subject requests under GDPR, UK GDPR, or CCPA, or for security and privacy matters:- Company: HOLOGROW INC (Marrow)
- Email: privacy@hologrow.ai
- Registered address: 8 The Green, Ste A, Dover, DE 19901, USA
- Mailing address: 160 Tasman Dr, Suite 125, San Jose, CA 95134, USA
Drafting notes — confirm before publication: (1) privacy contact mailbox (privacy@hologrow.ai assumed; Pulse pages used an obfuscated hologrow.ai mailbox); (2) production cloud stack and region (carried over from the vetted Pulse policy: GCP us-central1); (3) payment processor (Stripe assumed for self-serve billing); (4) publication URL (marrow.ai assumed; master brand is hologrow.ai).