Last updated: May 21, 2026
MarginShield is operated by A2E Group Pty Ltd, trading as MarginShield (“MarginShield”, “we”, “us”). This policy explains how we collect, use, store and disclose personal information when you use the MarginShield true-margin platform. It is written to align with the Australian Privacy Principles (APPs) and, where applicable, the EU General Data Protection Regulation (GDPR).
We collect the following categories of data:
We do not knowingly collect sensitive personal information (health, biometric, political, religious, or trade-union data) and you agree not to upload it.
We do not train AI models on your data. We do not sell or share your data, your competitor observations, or your supplier-funding terms with any third party.
Tenant isolation is enforced by PostgreSQL row-level security, which is enabled and forced on every business-data table. Most carry an org_id column; the rest inherit tenancy through a parent record. Buying-group clean rooms compute aggregates server-side without materialising cross-member joins. Your catalog, costs, rebates, and decisions are visible only to your organisation and the users you grant access to.
We implement encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, append-only audit logging, Argon2id password hashing, and incident response. Full posture published at /security.
We retain your data while your account is active. On termination, you may export data via the available export endpoints for 30 days, after which active-system data is permanently deleted within 90 days. Encrypted backups roll off within a further 90 days. Some records (billing, audit events tied to legal obligations) may be retained longer where required by law.
MarginShield uses a limited set of sub-processors to deliver the service: Railway (hosting), Neon (database, AU region), Stripe (billing), Anthropic (narrative AI only — never margin calculation), Sentry (error monitoring, PII-scrubbed), Resend (transactional email). Full list and regional details in the Data Processing Agreement.
Your primary database and application services are hosted in the Asia-Pacific (Singapore) region. Limited transfers occur to the United States and other regions via the sub-processors above, under contractual clauses substantially equivalent to the EU Standard Contractual Clauses where the GDPR applies. A2E Group Pty Ltd is an Australian company and handles your personal information in accordance with the Australian Privacy Principles regardless of the region in which it is processed.
You may access, correct, port, restrict, or delete the personal information we hold about you, and object to processing. You can export your business data from the dashboard at any time. To exercise rights, email privacy@marginshield.io and we will respond within 30 days. If you are unhappy with how we have handled your data, you may complain to the Office of the Australian Information Commissioner (OAIC).
We use first-party cookies for authentication and session management. We use anonymised analytics (PostHog) to understand product usage at an aggregate level — no personally identifying fields, no cross-site tracking. You can opt out via your browser settings.
MarginShield is a B2B platform not directed at children. We do not knowingly collect personal information from anyone under 18.
We may update this policy as the service evolves. Material changes will be notified by email to the registered admin and surfaced in-app at least 14 days before they take effect.
Privacy questions or requests: privacy@marginshield.io.
A2E Group Pty Ltd, Sydney, Australia.