Scope and purpose
We collect only data needed to deliver websites, dashboards, mobile apps, APIs, support and project communication. Processing follows lawful, fair, transparent and purpose-limited use.
How we collect, use, protect and retain account, project, API and contact data.
Last updated: June 22, 2026This document is a software-focused policy summary for Marshmallow Technology. Mandatory rights under applicable law continue to apply.
We collect only data needed to deliver websites, dashboards, mobile apps, APIs, support and project communication. Processing follows lawful, fair, transparent and purpose-limited use.
Forms and systems request only information relevant to the service, such as name, email, phone, project requirements, account role, logs and consent choices.
API keys, access tokens and passwords are treated as sensitive secrets. They must not be shared publicly and are protected by role-based access and secure authentication practices.
Administrative accounts use least-privilege access. We review access when team roles change and remove access that is no longer needed.
We use appropriate technical and organisational controls such as access limits, secure storage, backups, monitoring and incident response planning.
Data is kept only as long as needed for delivery, support, accounting, legal obligations, security evidence or dispute resolution, then deleted or anonymised.
We do not sell personal data. Trusted providers may process data only for agreed services and under confidentiality and security expectations.
Where applicable, users may request access, correction, deletion, restriction or objection. Some records may remain where law, security or contract requires it.
We monitor APIs for abnormal activity, excessive requests, broken authorization patterns and automated abuse that may affect customers or systems.
Privacy questions can be submitted through official contact channels. Requests should be clear and should not include unnecessary sensitive information.