Effective: 20 August 2026 (previous version: 15 July 2026)
Marqly is operated by Box02 LLC, a Wyoming limited liability company. Our registered address is:
Box02 LLC
30 N Gould St., #5377
Sheridan, WY 82801
United States
Contact: hello@marqly.app
This policy explains how we collect, use and protect personal data when you use the Marqly Shopify app or visit marqly.app.
From the Shopify app, we receive: the store URL and the store owner's name and email (provided by Shopify), which we store to run the App; and a per-store monthly counter of AI-suggestion usage. The compliance configuration you enter in Marqly (manufacturer details, EU responsible-person details, warnings) and - if you choose to add one - your own Anthropic API key are stored inside your own Shopify store as app metafields, not in Marqly's database; your API key is shown only in masked form and can be removed at any time. We do not access customer orders, customer personal data or payment data.
From this website, we collect standard server logs (IP, user agent, page accessed) for security and operational purposes.
Marqly offers an optional AI-suggestion feature. When you click "Suggest with AI" (or run AI auto-fill in bulk), the following product data is sent to Anthropic PBC (provider of the Claude model, based in the United States) to generate the suggestion: product title, description, vendor, product type, tags, and the product's featured image. No customer personal data is ever involved - the feature only processes merchant-authored catalog data.
AI processing happens only when you actively request a suggestion; nothing is sent in the background. Suggestions are never saved automatically - you review and apply them yourself. If you prefer Anthropic to process requests under your own agreement, you can add your own Anthropic API key in the app's Settings page; requests then run against your Anthropic account. Anthropic's handling of API data is described in their privacy policy; API inputs are not used to train Anthropic's models by default.
We process merchant data under the legal basis of performance of a contract (Article 6(1)(b) GDPR) when you install and use Marqly. Server logs are processed under legitimate interests (Article 6(1)(f)). AI processing is performed only at your request as part of operating the App (Article 6(1)(b)).
Your GPSR configuration data (manufacturer and responsible-person details, warnings) and any Anthropic API key you add are stored inside your own Shopify store as app metafields - not in Marqly's database. Marqly's own database holds only your store's login sessions, AI-usage counters, and a change-history (audit) log. This application server and database are operated by Box02 LLC and hosted with Render in its Frankfurt, Germany region — that is, inside the European Economic Area.
When you uninstall Marqly, we delete your store's sessions, AI-usage counters and audit logs. Shopify also sends a shop-redaction request about 48 hours after uninstall, at which point we run a second deletion pass to ensure nothing shop-related remains in our database. Data held inside your Shopify store (metafields) is governed by Shopify's own data handling once our access is revoked.
We use the following subprocessors:
A current list of subprocessors is available on request, and we will give notice before adding a new one.
Marqly is operated by Box02 LLC in the United States, and some of our subprocessors process data outside the European Economic Area (EEA). Where we transfer personal data of individuals in the EEA or UK to a country without an EU adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs), together with any supplementary measures required, as the transfer safeguard. In particular, Anthropic PBC processes AI-feature inputs under its Data Processing Addendum (which incorporates the SCCs), and Shopify processes app and merchant data under its Data Processing Addendum (which incorporates the SCCs). You can request a copy of the relevant transfer safeguards by emailing us at the address in section 1. Note that the Marqly application server and database themselves are hosted within the EEA (Render, Frankfurt), so the data described in section 6 is not transferred outside the EEA by us for hosting purposes.
For the limited merchant-account data we hold to run the App - your store URL and the store owner's name and email provided by Shopify - Box02 LLC acts as a data controller. For the compliance configuration you enter (manufacturer and EU responsible-person details, warnings) and the product data you submit to the optional AI feature, Box02 LLC acts as a data processor acting on your instructions, and you are the controller. If you need a Data Processing Agreement to meet your own GDPR obligations, contact us and we will make our standard DPA available.
Under GDPR you have the right to access, correct, delete and export your personal data, and to object to or restrict processing. Write to hello@marqly.app.
The marqly.app marketing site does not use analytics, advertising, or tracking cookies. The embedded Marqly admin runs inside Shopify and uses only the strictly necessary session tokens Shopify provides to keep you signed in; we do not set our own tracking cookies.
Marqly processes business/merchant account data and product information; it does not collect the personal information of your customers. If you are a US resident and believe we hold personal information about you, you may contact us to exercise any access or deletion rights available under applicable US state privacy laws.
We will notify users by email of material changes. The "effective" date at the top reflects the current version.
Box02 LLC
30 N Gould St., #5377
Sheridan, WY 82801
United States
hello@marqly.app