PRIVACY
Privacy Policy
Last updated
September 13, 2026.
Operator
MARVIN is operated by TCM Strategy LLC.
Scope
This policy explains how MARVIN collects, uses, discloses, and protects information through the MARVIN website, hosted application, reporting tools, chat features, MCP tools, support channels, and related services. It applies to information MARVIN controls and to customer data that MARVIN processes for an agency under the customer agreement for that account. This policy does not replace the terms of third-party services that customers connect to MARVIN or control outside MARVIN.
Information collected
We collect information customers provide, information generated by use of MARVIN, and information received from customer-authorized integrations. This may include account details, user names, business contact information, agency and client names, ad account identifiers, campaign metrics, GHL location data, calls, appointments, pipeline dispositions, sales outcomes, support requests, MCP token metadata, logs, device data, and usage data. Existing CRM and call data can contain personal information because customers choose what they connect; that customer data is separate from the limited Meta Platform Data scope described below.
Categories
The categories may include identifiers, business contact information, commercial information, internet or network activity, approximate location from device or network data, audio data if call features are enabled, professional information, customer relationship records, inferences from performance data, and sensitive information only when a customer chooses to provide or connect it.
Sources
Information may come from users, agency administrators, connected platforms, customer-configured workflows, support communications, browser or device interactions, and service providers that help operate MARVIN.
Customer responsibility
Customers decide what locations, ad accounts, pipelines, calls, contacts, users, agents, and integrations are connected to MARVIN. Customers are responsible for giving required notices, getting required consents, and confirming they have the right to send customer data to MARVIN and connected services.
Ad connections and Meta Platform Data
MARVIN supports reporting through customer-authorized connections configured for the service. MARVIN is currently testing a direct Meta reporting connection privately; it is not generally available. The connection uses a personal Facebook user OAuth flow with a user access token and the read-only ads_read and public_profile permissions. The user selects the permitted ad accounts to import inside MARVIN. The connection may process the Facebook user ID and name associated with that token, permitted ad account identifiers, campaign, ad set, and ad metadata, and aggregated daily performance data. MARVIN does not use this connection to create or edit ads or to collect individual Meta Lead Ads submissions.
For this connection, MARVIN processes the user access token required by Meta to maintain authorized reporting calls, together with the authorized reporting data. The token is used only for those calls and to protect the connection. Meta Platform Data includes the source data and any aggregated, anonymized, or derived data made from it.
Direct Google Ads connection
MARVIN is privately testing a Google Ads connection. You authorize it through Google and choose which advertiser accounts to import in MARVIN. Google's Ads permission includes ad management, but MARVIN only reads account details, campaign, ad group, ad and asset group metadata, and daily performance reports. It does not create or change ads, or request access to Gmail or Google Drive.
MARVIN stores authorization tokens encrypted on its servers to refresh access and run scheduled imports. Tokens are not sent to browser code or AI providers. Reporting data is stored to provide your reports, historical comparisons and customer-requested analysis. If you request chat or external tool analysis, relevant reporting data may be sent to the processors or tools described below. Google data is not used for advertising, sale, credit decisions or general model training.
MARVIN's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect Google or delete imported direct Google data in Agency Setup. Disconnecting stops retrieval; deletion also removes known local reporting and chat copies. See the data deletion process for details and broader requests.
Use
MARVIN uses information to provide the reporting, analytics, attribution, chat, MCP tools, historical backfills, integrations, account administration, customer support, billing support, security, fraud prevention, product operation, troubleshooting, and compliance functions the customer requests or enables. MARVIN may use limited operational information that is not Meta Platform Data to maintain and improve the service where the customer agreement and law allow. MARVIN does not use Meta Platform Data, including aggregated, anonymized, or derived Meta Platform Data, for service improvement, advertising, model training, or other unrelated purposes.
Sale and sharing
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We may disclose information to service providers and processors that help provide MARVIN, to integrations and external tools selected or directed by the customer, to professional advisors, to authorities when legally required, and to parties involved in a business transfer. Meta Platform Data is disclosed only to the client, to service providers necessary to provide the authorized service at the client's direction, or when legally required, and remains subject to Meta terms and restrictions. It is not disclosed to an advisor, business-transfer recipient, or other third party for an unrelated purpose. A customer-directed transfer does not remove MARVIN's obligations under this policy or applicable Meta requirements.
Cookies and analytics
MARVIN may use cookies, local storage, pixels, logs, and similar technologies for login, security, preferences, analytics, site performance, and product operation. Browser settings may block some of these technologies, but blocking required cookies can break account access or product features.
Service providers
MARVIN may use vendors for hosting, storage, security, analytics, email, support, payment administration, transcription, AI processing, and other operations needed to provide the service. We require service providers to use customer information only for authorized service purposes, at MARVIN's or the customer's direction as applicable, and to protect it using reasonable safeguards. For Meta Platform Data, providers receive only the data needed for the permitted purpose and remain subject to the same applicable restrictions.
AI and LLM processing
MARVIN's chat, AI, and MCP features may send prompts that contain personal information, and requested reporting inputs or outputs, to configured external providers to generate responses or complete a requested tool call. The actual providers depend on the feature and configuration and may change. MARVIN selects and configures providers for the service and applies the obligations that govern those transfers. Do not place unnecessary personal, health, financial, confidential, or regulated information into prompts, notes, files, or external tools. MARVIN currently blocks Meta Platform Data from chat and MCP processing pending processor approval. It may be sent to a provider through those features only after that processing is approved and where the provider and transfer are permitted by applicable Meta restrictions and the customer-directed service purpose; an incompatible provider cannot receive it.
MCP and external agents
MCP allows customer-controlled clients, models, agents, and tools to request MARVIN data. After information leaves MARVIN through an MCP client, external agent, downloaded export, or customer-controlled integration, the customer controls that environment, its prompts, its connected tools, its retention, and its downstream disclosures. Customer direction does not authorize a use that the customer or recipient cannot lawfully make, and it does not remove MARVIN's obligations for an allowed transfer of Meta Platform Data.
Call recordings
If call transcription or call analysis is enabled, call recordings may be sent to external transcription or analysis services. Those services may receive personal information, sensitive information, or health-related information contained in calls. Customers are responsible for call recording consent, notice, retention, industry rules, and vendor-risk review before enabling those features.
Health and regulated data
MARVIN is not a medical record system. Unless MARVIN signs a separate Business Associate Agreement with a covered entity or business associate, customers must not use MARVIN to create, receive, maintain, or transmit protected health information or other regulated data that requires a special written agreement. Customers are responsible for determining whether HIPAA, state health privacy laws, call recording laws, financial privacy laws, advertising rules, or other sector-specific rules apply to their use.
Security
MARVIN uses administrative, technical, and organizational safeguards designed to protect information. No system can guarantee perfect security. Users are responsible for protecting passwords, API keys, MCP tokens, connected accounts, devices, exports, downloaded reports, and agent configurations. If a user believes an account, token, or integration is compromised, they should contact alex@tcmstrategy.com promptly.
Retention
MARVIN keeps information only for as long as needed for the permitted service purpose, a valid customer instruction, security, legal or accounting requirements, dispute resolution, or agreement enforcement. When Meta Platform Data is no longer necessary for a permitted purpose, when service ends, when a valid client or user request requires deletion, when the client leaves, or when law or Meta requirements require deletion, MARVIN will promptly delete it, subject only to a specific lawful continuing retention obligation. Any data retained for that obligation remains limited to the required purpose and is deleted when the obligation ends. Stopping imports or disconnecting an integration does not itself delete historical data. See the data deletion process to make a request.
Privacy rights
Depending on location and relationship to MARVIN, individuals may have rights to request access, correction, deletion, portability, restriction, opt-out of certain processing, limit use of sensitive personal information, or information about certain disclosures. MARVIN will not discriminate against individuals for exercising rights required by applicable law. Customers remain responsible for handling requests from their own clients, leads, patients, callers, and contacts unless a separate agreement says otherwise. Requests can be sent to alex@tcmstrategy.com. Any user or authorized agency representative can use the manual data deletion process.
International use
MARVIN is operated from the United States. If information is accessed from outside the United States, it may be processed in the United States or other locations where MARVIN or its service providers operate.
Children
MARVIN is not intended for children under 13 and does not knowingly collect personal information directly from children.
Changes
MARVIN may update this policy as the services, law, or operations change. Material changes will be posted on this page or communicated through another reasonable method.
Contact
Questions: alex@tcmstrategy.com.