Privacy policy - Margot
Privacy policy
This is Margot's own privacy policy, covering your Margot account and the service we provide. The privacy notice on a website we've built for a customer is a different document, published on that site.
New to Margot? See what we do.
Last updated: 6 July 2026
Margot is a managed website builder for small businesses in the United Kingdom. This Privacy Policy explains how we collect, use, and protect personal data for which we are the controller, and sets out your rights under UK data protection law. Our philosophy is to keep the smallest privacy footprint we can and to be open and straightforward about how we handle your data.
This policy covers personal data we hold as a controller - meaning we decide what it is used for, and we answer for it - principally about the people who register for and use Margot ("account holders", "you"). Where visitors submit an enquiry through the contact form on a website built with Margot, that personal data is processed on our customer's behalf and the customer is the controller for it; Margot acts as a processor, meaning we handle it only on their instructions. That relationship is governed by our Data Processing Agreement, not this policy.
Who we are
Margot is operated by Tamperan Ltd, a company registered in England and Wales (company number 17324867) whose registered office is at Piccadilly Business Centre, Aldow Enterprise Park, Manchester M12 6AE, the data controller for the personal data described in this policy. We are registering with the UK Information Commissioner's Office (ICO); our registration number will be shown here once it is issued.
You can contact us about privacy, or exercise your rights, by emailing [email protected] or via our contact form.
What we collect and why
Account and profile data
When you create an account, we collect the information needed to set it up and identify you: your name, email address, and (depending on how you sign in) basic profile information such as your locale and avatar image. Where you sign in through a third-party provider (currently Google), we receive that basic profile information from them, subject to your consent at the point of sign-in and to that provider's own terms.
We use this data to create and administer your account, to provide the Services, to communicate with you about your account and support requests, and to keep the Services secure.
Your website content
The content you create in Margot (your business information, text, images, logos, page designs, and the domains you connect) may itself contain personal data, for example if you include the name, photograph, or contact details of yourself or colleagues. We host and process this content to provide the Services to you. You control this content and are responsible for having the right to use it.
Billing data
When you make a payment, Stripe is the merchant of record (seller of record) for the transaction. Stripe, not Margot, is the seller of record: it collects and processes your payment details, completes the sale, and handles any applicable taxes on it, as an independent controller of the payment and billing personal data it collects for that purpose, under Stripe's own privacy terms. We do not collect, store, or have access to your full card details, and we do not handle the payment or its taxes. We receive only limited billing metadata from Stripe (for example, the amount, date, plan, invoice records, and partial card information such as the last four digits and card type) so that we can administer your subscription and meet our own accounting obligations.
Enquiries you send us and support
If you contact us for support or otherwise correspond with us, we keep a record of that correspondence so that we can help you and improve the Services.
Product analytics
We use PostHog (PostHog Cloud EU, eu.i.posthog.com) to understand how the Margot application is used so that we can improve it. This may include basic usage data such as page views and feature interactions. Product analytics run only with your consent, given through our cookie banner; if you do not consent, we do not collect analytics. We do not carry out device fingerprinting.
Contact-form enquiries on your published website
Where a visitor submits the contact form on a website you have built with Margot, we process the enquiry (the visitor's name, email address, and message) in order to email it to you. For that data, our customer is the controller and Margot is the processor; this is covered by our Data Processing Agreement. If you are a member of the public who has submitted such an enquiry, the business whose website you contacted is responsible for how your data is used, and you should contact them.
Lawful bases
We rely on the following lawful bases under the UK GDPR:
- Performance of a contract - to create and administer your account, provide the Services, host and publish your website, deliver managed updates, and process payments and subscriptions.
- Legitimate interests - to secure and improve the Services, prevent fraud and abuse, keep records, and communicate with you about your account and service matters. Where we rely on legitimate interests, we have considered your rights and interests and will only do so where they are not overridden.
- Consent - for optional product analytics and any non-essential cookies, and for any marketing communications. You can withdraw consent at any time.
- Legal obligation - to meet our accounting, tax, and other legal and regulatory obligations.
Who we share data with (sub-processors and recipients)
We do not sell your personal data. We share it only with the service providers we rely on to run Margot, and only as needed to provide the Services. Our current providers are:
- Stripe - merchant of record (seller of record) for the purchase, handling the sale, payment, invoicing, and applicable taxes (activated when paid plans go live). As the seller, Stripe is an independent controller of the payment and billing personal data it collects to complete and tax the sale, and for its own fraud-prevention, anti-money-laundering, and regulatory purposes, under Stripe's own privacy terms. Margot is not the seller of record and receives only limited billing metadata, not card data.
- Amazon Web Services (AWS), including Amazon SES - sending transactional email and delivering contact-form enquiries; email is sent from the UK (London, eu-west-2) region.
- Cloudflare - DNS, content delivery, TLS certificates, custom-hostname routing, and reverse-proxy ingress, including bot/abuse protection.
- PostHog - product analytics, using PostHog Cloud EU (eu.i.posthog.com); analytics run only with your consent.
- Google - sign-in (OAuth/OIDC authentication); when you sign in with Google we receive your subject identifier, name, email address, and avatar.
Our website hosting and application infrastructure are operated by us on our own self-hosted infrastructure (a self-hosted Proxmox host), with public ingress via a Cloudflare tunnel. Your data at rest is held on-premises, not in a third-party cloud region. The physical location of that infrastructure is the United Kingdom.
We may also disclose personal data where we are required to do so by law, to respond to valid requests from public authorities, to enforce our terms, to protect against fraud, or to protect the rights, safety, or property of Margot, our customers, or others. If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.
International transfers
We aim to keep personal data within the UK or the European Economic Area. Where a provider processes personal data outside the UK/EEA, we put in place an appropriate safeguard recognised under UK data protection law (for example, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, and/or reliance on a UK adequacy regulation), so that your data continues to receive an equivalent level of protection. In practice, our hosting and transactional email keep data in the UK, and our product analytics is held in the EEA (Frankfurt); the providers that may process personal data outside the UK, namely Stripe, Cloudflare and Google, rely on such safeguards in their own terms.
Retention
We keep personal data only for as long as we need it for the purposes described above. In general:
- account and profile data is kept for the life of your account, and for up to 90 days after you close it, to allow for reactivation, dispute resolution, and our records;
- your website content is kept until you delete it and, once your account is closed, for a short further period while it clears our backup rotation;
- billing and transaction records are kept for 6 years to meet our legal, accounting, and tax obligations; and
- support correspondence is kept for as long as needed to handle and learn from the matter.
We will delete or anonymise personal data when we no longer need it, unless we are required to retain it by law.
Your rights
Under UK data protection law you have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased in certain circumstances; restrict or object to our processing; data portability; and to withdraw consent where we rely on it. You will not usually have to pay to exercise these rights, and we will respond within the time limits set by law.
To exercise any of these rights, contact us at [email protected] or via our contact form. Where your request concerns an enquiry you submitted through a Margot-built website, please contact the business that operates that website, as they are the controller for that data.
Cookies and consent
We use a small number of strictly necessary cookies that do not require consent: one to keep you signed in (your authenticated session), and one that remembers your cookie choices.
With your consent, given through our cookie banner, we may also set analytics cookies (PostHog) to understand how the application is used so we can improve it. We do not set analytics or non-essential cookies without your consent. You can accept, reject, or change your choices at any time using the "Manage cookies" option, and we honour Global Privacy Control (GPC) signals from your browser.
Marketing
If you consent, we may occasionally contact you by email about new features or products. You can withdraw consent and opt out at any time, using the link in any such message or by contacting us. We do not sell or share your personal data with third parties for their own marketing.
Children
The Services are intended for businesses and for users aged 18 or over. We do not knowingly collect personal data from children through the Margot application.
Changes to this policy
We may update this policy from time to time. Any change takes effect when published, and we will update the "Last updated" date above. Where a change materially affects how we handle your personal data, we will give you advance notice and, where required, seek your consent.
How to complain
If you have a concern about how we handle your personal data, please contact us first and we will try to resolve it. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, telephone 0303 123 1113. Our ICO registration number will be shown here once our registration is complete.