Legal
Privacy Policy
What Markyard collects, why, and what happens to the customer inquiries that pass through your Gmail inbox once you connect it.
- Last updated
- October 5, 2026
Who we are
Markyard is a web application built for print shops in Germany, to turn a customer inquiry that arrives by email into a quote-ready job in minutes instead of hours. This policy explains what data Markyard collects when you use it, why, and how you can control it.
Markyard does not yet have a published company address, phone number or dedicated privacy email to list here: the product is in early access and those details are not settled yet. The reliable way to reach us about anything in this policy is the contact page.
What we collect and why
We collect five kinds of data. Two of them, Gmail data and inquiry content, belong to a feature that is not live yet: they are described here so this policy is accurate on the day that feature ships, not rewritten in a hurry afterwards.
Account data
When you create a Markyard account we store your email address, an organisation name, and your role within that organisation (owner, admin or member). Your password itself is never stored by Markyard: Supabase Auth, our authentication provider, handles it directly and Markyard's own code never sees the plain value. We use account data to run your account, show you the right organisation's work, and enforce who can do what inside it.
Gmail data
Connecting a Gmail mailbox to Markyard is not live yet. Once it is, connecting one will require your explicit consent through Google's own consent screen, and Markyard will store which mailbox is connected, the scopes you granted, and an encrypted copy of the refresh token Google issues, so it can keep reading and sending on your behalf without asking you to sign in again each time. Markyard will never store your Google password: authentication happens entirely through Google.
Inquiry content and attachments
Once Gmail connection is live, Markyard will read incoming customer inquiries addressed to your connected mailbox, and any attached artwork, so it can extract the product, quantity, print method and other order details and check them against your own product catalogue. That content is processed to produce a draft reply for your review. It is never shared with or pooled across other Markyard customers.
Contact form data
The forms on our marketing pages ask for your name, email address, an optional company name, and your message. We also record which page the form was submitted from, and a salted, one-way hash of the IP address the submission came from. The raw IP address is never stored: it exists only for a moment while the hash is computed. The salt used to build that hash rotates every day, so the same address produces a different hash tomorrow, and the hash cannot be reversed back into an address. We use this data only to answer you and to slow down automated abuse of the forms.
Technical logs
Our hosting provider (Vercel) and database provider (Supabase) generate ordinary operational logs, for example error traces and request timing, as part of running the service. Markyard does not run visitor analytics or advertising trackers of its own on this site.
Legal basis under GDPR
For your own account data, Markyard is the data controller, and our legal basis is the contract between you and Markyard: we need that data to provide the service you signed up for.
Inquiry content is different. Once Gmail connection is live, the customer inquiries in your mailbox will contain personal data about your own customers, not ours. For that data, you, the print shop, remain the data controller, and Markyard acts only as your data processor: you are responsible for having a lawful basis to process your customers' inquiries, just as you already are today when you read and reply to them yourself. Markyard processes that content only under your instructions, to provide you the service.
For the Gmail connection itself, our basis is your consent, given through Google's consent screen, which you can withdraw at any time by disconnecting it. For contact form submissions, our basis is our legitimate interest in responding to the message you chose to send us. For technical logs, our basis is our legitimate interest in keeping Markyard secure and working.
How long we keep it
| Data | Kept for |
|---|---|
| Account data (email, organisation, role) | While your account is active. If you close it, we delete this data within a reasonable period, unless we must keep it longer to meet a legal obligation. |
| Gmail connection details (mailbox, scopes, encrypted token) | Not collected yet: this feature is not live. Once it is, for as long as the connection stays active, deleted immediately if you disconnect it. |
| Inquiry content and attachments | Not collected yet, for the same reason. Once live, for as long as needed to produce a reply, and afterwards as part of your job history until you delete it. |
| Contact form submissions | Until we have answered your message, then for a limited period afterwards in case you follow up, after which it is deleted. The IP hash stops matching after a day regardless, once the daily salt rotates. |
| Technical logs | Held by our hosting and database providers for their standard operational window, then rotated out. |
Who processes your data
We rely on a small number of providers, each doing one job:
| Provider | What it does for us | Location |
|---|---|---|
| Supabase | Hosts our Postgres database and provides authentication: sign-up, login, session and password handling. | European Union |
| Vercel | Hosts and serves the Markyard web application. | Frankfurt, Germany (our deployment target) |
| Google (Gemini API) | Processes the text of an inquiry you ask Markyard to handle, to extract order details and draft a reply. | Google's global infrastructure, including outside the EU |
| Once you connect a mailbox, provides the Gmail account Markyard reads from and sends through, under the permissions you grant. | Managed by Google, not under our control |
International transfers
Our database is hosted in the European Union, and our deployment target for the application itself is Vercel's Frankfurt, Germany region, so most processing stays inside the EU. Google processes Gemini API requests on its global infrastructure, which includes locations outside the EU, so sending inquiry text to it for extraction is an international transfer of personal data outside the EU. Google operates global infrastructure; once Gmail connection is live, your mailbox is subject to Google's own data location practices. Where we rely on a processor located outside the European Economic Area, GDPR requires an appropriate safeguard, such as the European Commission's Standard Contractual Clauses, to cover that transfer, and we require that of our processors.
Google user data
Markyard's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
This applies once you connect a Gmail mailbox, a feature that is not live yet as this policy is published. When it is, connecting one asks for exactly two scopes:
gmail.readonly, to read incoming customer inquiries and any attached artwork files. We considered the narrower gmail.metadata scope, but it does not expose message bodies or attachments, and the order details we extract exist only there.gmail.send, to send the reply you have approved, from your own mailbox, within the original conversation thread.
Markyard requests no other Gmail scope, never accesses a mailbox other than the one you connect, and never sends a message without your explicit approval first. Nothing leaves Markyard automatically.
To extract order details from the free-form text of an inquiry, Markyard sends that text to Google's Gemini API, on a paid plan, for inference. That use is limited to producing a result for you, the same user whose mailbox the inquiry came from: it is never pooled across customers, and it is never used to create, train or improve any machine learning or AI model, generalized or personalized. Google acts as our service provider for this and does not use content submitted through the paid Gemini API to improve its products. Gmail data is never sold, and never shared with advertisers or data brokers.
If our team ever needs to look directly at a stored inquiry to diagnose a fault, for example an extraction that failed, that counts as a human reading your Google user data, and we limit it accordingly: it happens only to fix the specific problem you are experiencing, not as routine access.
Your rights under GDPR
If GDPR or an equivalent protection applies to you, you have the right to:
- Access the personal data we hold about you
- Correct it if it is inaccurate or incomplete
- Ask us to delete it
- Ask us to restrict how we use it
- Receive a copy of it in a portable format
- Object to processing based on our legitimate interests
- Withdraw consent at any time where we rely on it, for example a connected Gmail mailbox, without affecting anything processed before the withdrawal
- Lodge a complaint with your local data protection supervisory authority
To exercise any of these, reach us through the contact page. We will ask enough information to confirm it is really you asking, and respond within the timeframe GDPR requires.
Children
Markyard is a business tool for print shops and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us through the contact page and we will delete it.
Changes to this policy
Markyard is still early, and this policy will change as features like Gmail connection go live. When it does, we update the date at the top of this page. If a change is significant, for example a new category of data or a new processor, we will say so plainly rather than quietly editing the wording.
Contact us
For anything in this policy, including exercising your GDPR rights, reach us through the contact page. We do not yet have a published email address or postal address to list here.