The short version
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use customer data to train foundation models, and our model providers are configured not to either.
- When a customer uploads a guest list or a target account list, that customer is the controller. We process it on their instructions.
- Section 07 lists every category of vendor that touches personal information. The named list is available on request.
- You can reach a human at legal@themarvelo.us and we answer within the timeframe the law requires.
01. Scope
This Privacy Policy describes how Marvelous United, Inc. ("Marvelous," "we," "us") handles personal information when you use the Marvelous platform, visit our websites, register for or attend an event we operate or help operate, subscribe to a Marvelous or AI Insiders publication, or otherwise communicate with us.
It does not apply to the practices of our customers, our sponsors, or the venues and partners who run their own registration and communications. When you interact with those parties, their own privacy notices govern.
02. Controller and processor roles
Marvelous plays two distinct roles, and your rights depend on which one applies.
2.1 Where we are the controller
We decide how information is handled when it concerns our own accounts, users, prospects, subscribers, guests at Marvelous-hosted events, website visitors, and job applicants. This section of our practices is what most of this policy describes.
2.2 Where we are the processor
When a customer uses Marvelous to run its own go-to-market motion, it uploads or connects information about its contacts, guests, and target accounts ("Customer Data"). The customer is the controller of that data. We process it only to provide the Services, under the customer's instructions and a written data processing agreement. If you want your information corrected or removed from a customer's account, contact that customer directly. If you contact us, we will route your request to them and support them in responding.
03. Information we collect
3.1 Account and business contact information
Name, work email, phone number, job title, company, and the credentials or single sign-on identifiers you use to authenticate. Where you connect a mailbox or calendar, we also receive the account identifier and the scopes you granted.
3.2 Customer Data
Contact records, guest lists, RSVP and attendance status, dietary or accessibility notes you choose to submit, meeting notes, email and calendar content you sync, CRM fields, and the pipeline and deal records our attribution layer produces. Sensitive categories are not required to use the Services and should not be uploaded except where strictly necessary for hospitality accommodations.
3.3 Event information
Registration details, check-in records, session participation, and photography or video captured at events. Where we photograph an event, we post notice on site and honor opt-out requests.
3.4 Usage and device information
IP address, browser and device characteristics, pages and features used, timestamps, referring URLs, and diagnostic logs. We use this to operate, secure, and improve the Services.
3.5 Payment information
Billing contact, billing address, invoice history, and the last four digits and brand of a payment card. Full card numbers are collected and stored by our payment processor. We never see or store them.
3.6 Information from third parties
Business contact and firmographic data from enrichment providers and public sources, referral information from partners, and the content of integrations you authorize. We only use enrichment data for business-to-business purposes and where we have a lawful basis to do so.
04. How we use information
- Provide, operate, secure, and support the Services, including running agent workflows you configure.
- Authenticate users, provision accounts, and enforce access controls.
- Manage event registration, curation, check-in, seating, and follow-up.
- Produce attribution and reporting that connects in-person activity to pipeline outcomes.
- Process payments, issue invoices, and collect amounts owed.
- Communicate about the Services, including service notices, security alerts, and billing.
- Send marketing and community communications where permitted, subject to section 15.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Improve and develop features, measure usage, and debug. We use aggregated or de-identified data for this wherever it is sufficient.
- Comply with law, respond to lawful requests, and enforce our agreements.
05. Legal bases
For people in the European Economic Area, the United Kingdom, and Switzerland, we rely on the following bases where we act as controller.
Article 6 bases
| Basis | Applied to |
|---|---|
| Contract | Providing the Services, account administration, billing, event delivery you registered for. |
| Legitimate interests | Security, fraud prevention, product improvement, business-to-business outreach that is relevant to your professional role and balanced against your interests. |
| Consent | Non-essential cookies, certain marketing, event photography where notice-and-objection is not sufficient. |
| Legal obligation | Tax and accounting records, responses to lawful requests. |
Where we rely on consent, you can withdraw it at any time without affecting processing that already took place.
06. AI and model development
The Services use large language models to draft outreach, research accounts, sequence invitations, and summarize signals.
We train on our own data. Marvelous operates the AI Insiders network and produces its own events. We use the outcome data from that activity, including invitation performance, attendance patterns, and engagement history, to train and improve our models. We are the controller of that data and process it on the basis of our legitimate interest in improving the Services.
We do not train on Customer Data by default. Where we process personal information on a customer's behalf, we use it only to provide the Services to that customer. We do not use it to train models that serve other customers unless the customer opts in through its Order Form.
We do not train on mailbox or calendar content. Where you connect a mailbox or calendar, we access it at the time of a request to perform the task you asked for. That content is not added to any training set.
We train on pseudonymized structural signals. We derive non-content signals from Services activity, such as message timing, sequence structure, and response rates, and use them to improve model performance. These records are pseudonymized rather than anonymous, and we treat them as personal information.
Agent output is reviewable. Where an agent drafts a message, schedules outreach, or scores a contact, the account holder can inspect and override it. We do not use these systems to make decisions producing legal or similarly significant effects about individuals.
07. Subprocessors
We use third-party vendors to operate the Services. The categories below describe every type of vendor that may process personal information on our behalf, what it does, and where it processes data. Each is bound by a written agreement imposing confidentiality and security obligations at least as protective as ours.
Categories of subprocessor
| Category | Function | Primary location |
|---|---|---|
| Cloud infrastructure | Application hosting, database storage, and foundation model inference | United States |
| Network and edge security | DNS, content delivery, web application firewall | Global edge network |
| Agent observability | Tracing and evaluation of agent workflows | United States |
| Payments | Card processing, subscription billing, invoicing | United States |
| Email delivery | Transactional and outbound email | United States |
| Event registration | RSVP management and guest check-in | United States |
| CRM and support | Customer relationship management and support communications | United States |
| Product analytics | Usage telemetry and performance measurement | United States |
| Data enrichment | Business contact and firmographic data, business-to-business only | United States |
A named list of current subprocessors, including each vendor’s identity and the data it receives, is available to customers and prospective customers on request at legal@themarvelo.us. Customers under a data processing agreement receive the named list as an exhibit and at least 30 days’ notice of material additions.
08. Other disclosures
Beyond the subprocessors above, we disclose personal information in these circumstances only.
- To the customer whose account it belongs to. Where we process data as a processor, the controlling customer has access to it.
- To co-hosts, sponsors, and venues, where you register for an event and are told at registration who will receive your details. Venues receive the minimum necessary for access and catering.
- To professional advisors, including counsel, accountants, and auditors, under duties of confidentiality.
- In a corporate transaction, such as a financing, merger, or acquisition, subject to this policy continuing to apply to the transferred information.
- To comply with law, including responding to valid legal process. Where we are permitted to notify the affected customer or individual, we do.
We do not sell personal information as that term is defined under California, Virginia, Colorado, Connecticut, Texas, or comparable state law, and we do not share it for cross-context behavioral advertising.
09. International transfers
We are based in the United States and our infrastructure is primarily hosted there. Where we receive personal information from the EEA, the United Kingdom, or Switzerland, we will enter into the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, and we apply supplementary technical measures including encryption in transit and at rest, access logging, and least-privilege access controls. Customers who require executed transfer clauses or a transfer impact assessment can request them at legal@themarvelo.us.
10. Retention
Retention periods
| Category | Period |
|---|---|
| Customer Data | For the subscription term, then deleted or returned within 30 days of termination unless the customer requests otherwise or law requires retention. |
| Account records | Duration of the relationship plus 24 months. |
| Billing and tax records | Seven years, as required for accounting and tax purposes. |
| Event registration records | 24 months after the event, unless you remain a subscriber. |
| Security and access logs | Twelve months. |
| Marketing contacts | Until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again. |
11. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, role-based access control, least-privilege provisioning, single sign-on and multi-factor authentication for internal systems, centralized logging, dependency and vulnerability monitoring, and formal onboarding and offboarding procedures. We are pursuing SOC 2 Type II attestation, administered through a third-party compliance platform. We will make the report available under NDA once it is issued. Our security overview and a completed vendor security questionnaire are available on request at legal@themarvelo.us.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator within the timeframes the law requires, and we will notify affected customers without undue delay.
12. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a portable copy, restrict or object to certain processing, withdraw consent, and lodge a complaint with a supervisory authority.
To exercise any of these, email legal@themarvelo.us with enough detail for us to identify your records. We respond within the period required by applicable law, generally 30 to 45 days depending on your jurisdiction, and we will tell you if we need an extension. We may need to verify your identity before acting, and we will not charge you or treat you differently for making a request.
If your information sits inside a customer's account, see section 2.2. We will forward your request to that customer and support their response.
13. US state rights
California residents have the right to know the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of recipients; to delete and correct; to opt out of sale or sharing; to limit use of sensitive personal information; and to be free from retaliation for exercising these rights. Because we do not sell or share personal information for cross-context behavioral advertising, and because we do not use sensitive personal information for purposes requiring a limitation right, no opt-out mechanism is required. You may still submit any request at legal@themarvelo.us.
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states with comprehensive privacy laws have substantially similar rights, including the right to appeal a denied request. To appeal, reply to our decision with the word "appeal" and we will respond within 45 days with a written explanation.
You may designate an authorized agent to act for you. We will ask for proof of authorization and may ask you to confirm directly.
14. Cookies and similar technologies
We use strictly necessary cookies for authentication, session management, and security. We use first-party analytics to understand product usage and website performance, and marketing cookies where you consent. We do not run third-party advertising networks on our properties.
You can control cookies through your browser settings and, where a consent banner is presented, through your choices there. We honor Global Privacy Control signals where our systems receive them.
15. Marketing and community communications
If you subscribe to a Marvelous or AI Insiders publication, register for an event, or engage with us in a business context, we may send you related communications. Every message includes an unsubscribe link, and unsubscribing takes effect immediately for that program. Transactional and security messages related to an active account continue regardless.
Where the law requires opt-in consent for marketing, we obtain it before sending.
16. Children
The Services are built for business use and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, email legal@themarvelo.us and we will delete it.
17. Changes to this policy
We may update this policy as the Services and the law evolve. When we make a material change, we will update the effective date and version above and give notice by email or in-product at least 14 days before it takes effect, unless a change must apply immediately for legal or security reasons. Continued use after the effective date means the updated policy applies.
18. Contact
Marvelous United, Inc.
1401 Pennsylvania Ave, STE 105, Box 2088
Wilmington, DE 19806, United States
Legal and privacy: legal@themarvelo.us