marketingmarkdown.
ProductHow it worksPricingDocs
Book a walkthroughGet started

Marketing Markdown
Privacy Policy

Last updated: 26 July 2026  ·  Effective from: 26 July 2026

Marketing Markdown ("we", "us", "our") operates Marketing Markdown, a marketing software service. This policy explains how we collect, hold, use and disclose personal information, and how you can access, correct or complain about our handling of it.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). Where we handle personal information about individuals in the European Economic Area or the United Kingdom, we also comply with the GDPR and UK GDPR as applicable.

Contact: michael@marketingmarkdown.com

1. Two different roles

This is the most important thing to understand about how we handle data, because it determines whose privacy policy governs what.

When we act for ourselves. We collect personal information about our own customers and website visitors — the people who sign up, pay us, contact support, and browse our site. We decide how that information is used. This policy governs that information, and we are the controller of it.

When we act for our customers. Our customers use Marketing Markdown to manage their own marketing activity, and in doing so they upload or generate data that may include personal information about their contacts, subscribers, leads and customers. We call this Customer Data. We hold and process Customer Data on our customer's instructions, as their service provider. We do not own it, we do not decide what it is used for, and we do not use it for our own purposes except as described in clause 8.

If you are an individual whose details appear in a Marketing Markdown account because you interacted with one of our customers, that customer is responsible for how your information is handled, and you should direct access, correction and deletion requests to them. We will assist them in responding, and if you contact us directly we will refer you to the relevant customer or pass your request on.

2. What personal information we collect

2.1 Account and identity information

Name, business name, job title, email address, phone number, account username, password (stored in hashed form), and your communication preferences.

2.2 Billing information

Billing name, billing address, ABN or tax identifier, subscription plan and history, invoices, and payment records.

We do not collect or store full credit card numbers. Card details are entered directly with our payment processor, Stripe, and we receive only a token, the card type, the last four digits, and the expiry date. Stripe processes this information in the United States.

2.3 Usage and technical information

IP address, browser type and version, device and operating system, timezone and language settings, referring page, pages viewed, features used, session duration, click and navigation events, and error and diagnostic logs.

Note that under Australian privacy law an IP address or device identifier can be personal information where it is reasonably capable of identifying an individual, and we treat it accordingly.

2.4 Communications

The content of emails, support tickets, chat messages, and any feedback, survey responses or bug reports you send us, together with our replies.

2.5 Configuration Workshop information

Where you purchase the Configuration Workshop, we collect scheduling details, attendee names and email addresses, notes taken during sessions, and any configuration or business context you share with us in order for the sessions to be useful. We also collect session recordings and transcripts. We will tell you before any recording begins and will not record without consent.

2.6 Marketing and prospect information

Where you subscribe to our mailing list, download a resource, attend a webinar or request a demo, we collect the details you provide and your engagement with our marketing emails, including whether they were opened and which links were clicked.

2.7 Customer Data

Whatever our customers choose to upload or generate in the Service. This may include names, email addresses, phone numbers, company details, engagement history and campaign records relating to their contacts. See clause 1 and clause 8.

2.8 Sensitive information

We do not seek sensitive information (as defined in the Privacy Act — including health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal record). Please do not submit it to the Service. If sensitive information is provided to us incidentally, we will handle it in accordance with this policy and the Privacy Act, and may delete it.

3. How we collect personal information

We collect personal information:

  • directly from you — when you create an account, subscribe, pay, attend a workshop, contact us, or fill in a form;
  • automatically — through cookies, log files and analytics as you use our website and the Service (see clause 9);
  • from your organisation — where a colleague creates an account or adds you as a User;
  • from third parties — our payment processor, and
  • from our customers — where they upload Customer Data containing information about you.

Where it is reasonable and practicable, we collect personal information directly from the individual concerned. Where we collect it from someone else, we take reasonable steps to ensure the individual is notified.

4. Why we collect, hold and use personal information

We use personal information for the following purposes:

PurposeExamples
Providing the ServiceCreating and administering your account, authenticating logins, delivering features, storing your data
BillingCharging subscription fees, processing the Configuration Workshop fee, issuing invoices and receipts, recovering unpaid amounts
SupportResponding to enquiries, diagnosing faults, delivering workshop sessions
Service communicationsRenewal reminders, price change notices, security alerts, changes to our terms, outage notifications
Improving the ServiceUnderstanding which features are used, identifying bugs and performance problems, developing new functionality
Security and integrityDetecting and preventing fraud, abuse, unauthorised access and breaches of our terms
MarketingSending you information about our products, offers and content, subject to clause 7
Legal and complianceMeeting tax, accounting and record-keeping obligations, responding to lawful requests, establishing or defending legal claims

We will not use your personal information for an unrelated secondary purpose unless you would reasonably expect it, you have consented, or the law permits or requires it.

4.1 Legal bases (EEA and UK individuals only)

Where the GDPR or UK GDPR applies, we rely on:

  • contract — to provide the Service and administer your subscription;
  • legitimate interests — to secure and improve the Service, prevent fraud, and market to existing business customers, balanced against your rights;
  • consent — for optional cookies and, where required, marketing to prospects (withdrawable at any time); and
  • legal obligation — for tax, accounting and regulatory records.

5. Who we disclose personal information to

We disclose personal information to the following categories of recipient, and only as necessary for the purposes in clause 4:

Recipient typePurposeExamples
Cloud hosting and infrastructureRunning the Service, storing dataGoogle Firebase / Google Cloud Platform — database hosted in Sydney, Australia
Payment processingTaking payment, preventing fraudStripe (United States)
Email deliverySending transactional and marketing emailAttio, Gmail
Analytics and product telemetryUnderstanding usage, diagnosing errorsGoogle Analytics, Firebase Crashlytics
Customer support toolingManaging enquiriesAttio
Accounting and taxBookkeeping, statutory reportingXero
Professional advisersLegal and financial adviceLawyers, auditors, insurers
AcquirersDue diligence and transfer in a sale of the businessProspective purchasers, subject to confidentiality
Law enforcement and regulatorsWhere required or authorised by lawCourts, the OAIC, police

We do not sell personal information, and we do not disclose it to third parties for their own direct marketing purposes.

6. Overseas disclosure

Our infrastructure is a mix of Australian and overseas components. The table below sets out where each kind of information is held.

ComponentWhat it holdsWhere it is held
Cloud FirestoreCustomer Data, account records, application dataSydney, Australia (australia-southeast1)
Firebase AuthenticationLogin credentials — email addresses, phone numbers, password hashesUnited States
Cloud FunctionsTransient processing of data in flightSydney, Australia (australia-southeast1)
Google Analytics and Firebase CrashlyticsUsage, performance and crash telemetryGoogle's global infrastructure, including outside Australia
StripeBilling details, payment recordsUnited States

Customer Data is stored in Australia. Login credentials, billing information and usage telemetry are held or processed overseas as set out above.

Personal information is likely to be disclosed to recipients in the United States. In addition, telemetry collected by Google Analytics and Firebase Crashlytics is processed across Google's global infrastructure, and it is not practicable for us to specify every country in which that processing may occur.

Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it in a way consistent with the APPs. We rely on the contractual protections in Google's Cloud Data Processing Addendum and Stripe's data processing terms. Where we transfer personal information out of the EEA or UK, we rely on Standard Contractual Clauses or another approved transfer mechanism.

7. Direct marketing

7.1 We may send you marketing communications about Marketing Markdown where you are an existing customer, or where you have opted in.

7.2 Every marketing email contains an unsubscribe link that works. You can also opt out at any time by emailing michael@marketingmarkdown.com. We will action opt-outs promptly and at no cost, as required by the Spam Act 2003 (Cth).

7.3 Opting out of marketing does not stop service communications — renewal reminders, billing notices, security alerts and changes to our terms. Those are part of providing the Service and cannot be unsubscribed from while your account is active.

7.4 On request, we will tell you the source of the personal information we used to contact you.

8. How we use Customer Data

8.1 We access Customer Data only to provide, secure and support the Service, to fix faults, at our customer's instruction, or where required by law.

8.2 We may generate aggregated and de-identified statistics from usage of the Service — for example, benchmark figures on campaign performance across our customer base — and use them to improve and market the Service. These statistics never identify a customer or any individual, and we do not attempt to re-identify them.

8.3 We do not use Customer Data to train machine learning or artificial intelligence models, and we do not permit our service providers to do so.

8.4 Our handling of Customer Data is also governed by our agreement with the relevant customer, including any Data Processing Addendum. Where those terms conflict with this policy in relation to Customer Data, those terms prevail.

9. Cookies and similar technologies

9.1 We use cookies and similar technologies on our website and in the Service:

  • Strictly necessary — authentication, session management, security and load balancing. These cannot be disabled without breaking the Service.
  • Functional — remembering preferences such as language and layout.
  • Analytics — understanding how the site and Service are used, in aggregate.
  • Marketing — measuring advertising effectiveness and attributing signups.

9.2 You can control cookies through your browser settings, and through our cookie banner where one is shown. Blocking strictly necessary cookies will prevent you from logging in.

10. Automated decision-making

We do not use automated decision-making that produces legal effects or similarly significantly affects individuals. Where the Service uses automation or AI to generate suggestions, drafts or scores, those outputs are recommendations for our customers to review and act on, and are not decisions we make about any individual.

11. Security

11.1 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure.

11.2 No system is completely secure, and we cannot guarantee the security of information transmitted to us over the internet.

11.3 Data breaches. If we suffer a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours where required, and assist our customers with their own notification obligations.

12. How long we keep information

InformationRetention
Account and profileFor the life of the account, then [30] days after termination
Customer DataFor the life of the account, then [30] days to allow export, then deleted
Billing and tax records7 years, as required by Australian tax law
Support correspondence2 years from last contact
Marketing listsUntil you unsubscribe, then a suppression record is kept indefinitely so we do not contact you again
Server and security logs90 days
BackupsDeleted data persists in backups for up to 30 days before being overwritten

We destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it.

13. Accessing and correcting your information

13.1 You can view and update most of your information directly in your account settings.

13.2 You may also request access to, or correction of, the personal information we hold about you by emailing michael@marketingmarkdown.com. We will respond within 30 days.

13.3 We do not charge for making a request. We may charge a reasonable cost-based fee for giving access to a large volume of information, and we will tell you before any fee applies.

13.4 We may refuse access or correction in the limited circumstances permitted by the Privacy Act — for example, where granting access would unreasonably affect another person's privacy. If we refuse, we will tell you why in writing and explain how to complain.

13.5 We may need to verify your identity before acting on a request.

14. Additional rights for overseas individuals

EEA and UK. Where the GDPR or UK GDPR applies, you also have rights to erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent. You may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office.

California. Where the CCPA/CPRA applies, you have rights to know, delete, correct, and opt out of sale or sharing of personal information, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined.

To exercise any of these rights, email michael@marketingmarkdown.com.

15. Children

The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.

16. Complaints

16.1 If you are concerned about how we have handled your personal information, email michael@marketingmarkdown.com with the details. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If we need longer, we will tell you why and give you a revised timeframe.

16.2 If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

  • Online: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

17. Changes to this policy

We may update this policy from time to time. The current version is always available at www.marketingmarkdown.com/privacy-policy and is dated at the top. Where a change materially affects how we handle your personal information, we will notify you by email or in-app notice before it takes effect.

18. Contact us

Marketing Markdown
Privacy contact: michael@marketingmarkdown.com