Legal

Privacy Policy

Effective from 20 July 2026 · Margyn Labs Pvt Ltd
Margyn helps you see your business's financial health by reading data you choose to connect — your Tally exports, bank information, and GST figures. This page explains, in plain terms, what we collect, why, and what rights you have over it under India's Digital Personal Data Protection Act, 2023 ("DPDPA"). If anything here is unclear, email us at business@margynlabs.com and we'll explain it directly.

01Who this policy covers

This policy applies to anyone who creates an account on Margyn (margynlabs.com and the Margyn application at margynlabs.com/app.html), operated by Margyn Labs Pvt Ltd ("Margyn," "we," "us"). It covers both your personal account information and the business financial data you choose to upload or connect.

02What we collect

CategoryExamples
Account informationEmail address, password (encrypted, never stored in plain text)
Business profileCompany name, revenue range, industry, city, GSTIN
Financial data you provideBank balances, receivables and payables ledgers, revenue, net profit, monthly operating expenses, GST payable and unclaimed input tax credit — entered manually or via an uploaded Excel/Tally export
Financial data via future connected accountsWhere you choose to connect a bank account (via RBI Account Aggregator) or the GST portal (via a licensed GSP), the read-only data those rails provide
Usage dataWhich parts of the app you use, timestamps, and general interaction events, used only to improve the product
CommunicationsWhatsApp number and opt-in status, if you choose to provide it for Opening Bell / Closing Bell briefings (feature not yet live)

We do not collect more than what's needed to calculate your Pulse Score, generate your briefing, and operate your account.

03How we use it

We never use your financial data to train external AI models, and we never sell it. Full stop — this isn't a "unless you opt out" clause, it's a standing rule.

04What we don't do

05Third parties who process data on our behalf

ProviderPurposeWhat they see
SupabaseDatabase hosting and authenticationAll account and financial data, protected by row-level security so only you can read your own records
Anthropic (Claude API)Generating your AI executive briefingYour vitals and Pulse Score for a single request — not your raw ledger, and not retained by Margyn for model training
VercelApplication hostingStandard web request logs

Each of these providers is a data processor acting on our instructions, not an independent owner of your data. As we add bank (Account Aggregator) and GST (GSP) connectivity, this table will be updated before those integrations go live.

06The Financing tab, specifically

Margyn is not a lender and does not currently have a signed agreement with any lending partner. If you submit the Financing tab's interest form, you are consenting to us storing your business's Pulse Score and vitals and sharing them with a lending partner only once one is formally onboarded, and only for the purpose of a funding introduction. You can withdraw this consent at any time by emailing business@margynlabs.com — we will delete the associated lead record on request.

07Your rights under the DPDPA

As a person whose data we process ("Data Principal" under the DPDPA), you have the right to:

To exercise any of these rights, email business@margynlabs.com with the subject line "DPDPA request." We will respond within a reasonable time and in any case within the period required under the DPDPA.

08Data retention

We retain your account and financial data for as long as your account is active, so your Pulse Score history remains meaningful. If you request account deletion, we will delete your personal and business data within a reasonable period, except where we're required to retain records for legal, tax, or audit purposes.

09Cookies

margynlabs.com uses essential cookies required for the site to function, and — only if you accept them via the cookie banner — analytics cookies to understand how the site is used. We do not use third-party advertising cookies, and Margyn does not run ads.

10Security

Data is encrypted in transit (HTTPS/TLS) and at rest. Access to your records is enforced at the database level through row-level security, so your data is only ever readable by your own authenticated account. No system is perfectly secure, and we will notify affected users without undue delay in the event of a data breach materially affecting their information, as required under applicable law.

11Children's data

Margyn is a business tool intended for use by adults operating or advising an SME. We do not knowingly collect data from anyone under 18.

12Changes to this policy

We may update this policy as the product evolves — particularly as bank (Account Aggregator) and GST (GSP) integrations go live. Material changes will be notified via email or an in-app notice before they take effect.

13Contact

For any question about this policy or how your data is handled, email business@margynlabs.com. Until we formally designate a Grievance Officer under the DPDPA, this address serves that function.