Privacy Policy
Last updated: 3 October 2026
Raşit İlk, trading as RST, Tekirdağ, Türkiye, is the controller of personal data processed through MarginMise. Contact: [email protected].
What we collect
- Account data: your email address and sign-in records.
- Workspace data: ingredients, recipes, prices and settings you enter. This is business information; please don't add personal data about other people.
- Billing status: plan, subscription status and Paddle customer/subscription IDs. Card details are handled by Paddle; we never see them.
- Technical data: basic server logs (IP address, browser, time) for security, kept for up to 30 days.
In demo mode, data you enter is stored only in your own browser and never sent to us.
Why we use it (legal basis)
- To provide the Service you signed up for (contract).
- To keep the Service secure and prevent abuse (legitimate interests).
- To send essential service emails such as sign-in links and billing notices (contract). We send marketing emails only if you opt in, and every one has an unsubscribe link.
- To meet legal and tax obligations (legal obligation).
Who processes it for us
- Supabase — database and authentication hosting (EU region).
- Cloudflare — website hosting, security and cookie-free visit statistics.
- Paddle — payments, invoicing and tax as Merchant of Record (independent controller for payment data; see paddle.com/legal/privacy).
Some of these providers may process data outside the UK/EEA under appropriate safeguards such as Standard Contractual Clauses. We do not sell personal data or use it for advertising.
Cookies and storage
We use only what is strictly necessary: your browser's local storage keeps your sign-in session and demo data. No advertising or tracking cookies.
How long we keep it
Account and workspace data are kept while your account is open. If you delete your data or close your account, it is removed within 30 days (backups roll off within a further 30 days). Billing records are kept as long as tax law requires.
Your rights
You can access, correct, export or delete your data, object to or restrict processing, and complain to your data-protection authority (in the UK, the ICO). Email [email protected] and we will respond within one month.
Security
Data is encrypted in transit (TLS) and at rest, and each account can only read its own workspace (row-level security).