Mariscal.ai

Privacy Policy

Last updated: March 9, 2026

1. Data Controller

The data controller for your personal data is Frontier Digital Creations LLC, located at 407 Lincoln Road Suite 708, Miami Beach, FL 33139, United States ("we," "us," or "our").

Contact for privacy inquiries: privacy@mariscal.ai

2. Information We Collect

Account Information:

  • Name and email address
  • Password (encrypted)
  • Language preference

Business Information:

  • Business name, address, and contact details
  • Business description, services, and industry
  • Content provided during website generation conversations

Payment Information:

  • Payment is processed by Stripe, Inc. We do not store credit card numbers
  • We store your Stripe customer ID and subscription status

Usage Data:

  • Pages visited, features used, and interaction patterns
  • Device type, browser, IP address, and approximate location
  • Performance metrics and error logs

3. How We Use Your Information

  • To provide and maintain the Service, including generating your website
  • To process payments and manage your subscription
  • To communicate with you about your account and the Service
  • To improve and optimize the Service through analytics
  • To detect and prevent fraud or security incidents
  • To comply with legal obligations

4. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your personal data based on:

  • Contract performance: Processing necessary to provide the Service you subscribed to
  • Legitimate interest: Analytics and service improvement, fraud prevention, and security
  • Consent: Marketing communications (you may opt out at any time)
  • Legal obligation: Compliance with applicable laws and regulations

5. Your Rights (GDPR)

If you are located in the EEA, you have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data
  • Restriction: Request limited processing of your data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Withdraw consent: Where processing is based on consent

To exercise these rights, contact us at privacy@mariscal.ai. We will respond within 30 days.

6. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected
  • Right to Delete: You may request deletion of your personal information
  • Right to Opt-Out: You may opt out of the sale of your personal information. We do not sell your personal information
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data: retained until account deletion, then deleted within 30 days
  • Business and website data: retained until account deletion
  • Payment records: retained for 7 years for tax and legal compliance
  • Usage analytics: aggregated and anonymized after 24 months
  • Server logs: automatically deleted after 90 days

8. Third-Party Services

We use the following third-party services that may process your data:

  • Supabase (database and authentication) — data stored in EU region
  • Stripe (payment processing) — PCI DSS Level 1 certified
  • Vercel (hosting and CDN) — data processed in edge locations worldwide
  • OpenAI / Anthropic (AI content generation) — business data sent for processing, not used for model training

Each provider operates under their own privacy policy and data processing agreements.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States. When we transfer data from the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

10. Cookies

We use essential cookies required for authentication and session management. We do not use tracking cookies or third-party advertising cookies. Essential cookies cannot be disabled as they are necessary for the Service to function.

11. Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS) and at rest, access controls, and regular security assessments. However, no method of transmission over the Internet is 100% secure.

12. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date at the top indicates when the policy was last revised.

14. Contact Us

For privacy-related questions or to exercise your rights, contact us at:

Frontier Digital Creations LLC

407 Lincoln Road Suite 708

Miami Beach, FL 33139

Email: privacy@mariscal.ai