Marketing Markdown ("we", "us", "our") operates Marketing Markdown, a marketing software service. This policy explains how we collect, hold, use and disclose personal information, and how you can access, correct or complain about our handling of it.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). Where we handle personal information about individuals in the European Economic Area or the United Kingdom, we also comply with the GDPR and UK GDPR as applicable.
Contact: michael@marketingmarkdown.com
This is the most important thing to understand about how we handle data, because it determines whose privacy policy governs what.
When we act for ourselves. We collect personal information about our own customers and website visitors — the people who sign up, pay us, contact support, and browse our site. We decide how that information is used. This policy governs that information, and we are the controller of it.
When we act for our customers. Our customers use Marketing Markdown to manage their own marketing activity, and in doing so they upload or generate data that may include personal information about their contacts, subscribers, leads and customers. We call this Customer Data. We hold and process Customer Data on our customer's instructions, as their service provider. We do not own it, we do not decide what it is used for, and we do not use it for our own purposes except as described in clause 8.
If you are an individual whose details appear in a Marketing Markdown account because you interacted with one of our customers, that customer is responsible for how your information is handled, and you should direct access, correction and deletion requests to them. We will assist them in responding, and if you contact us directly we will refer you to the relevant customer or pass your request on.
Name, business name, job title, email address, phone number, account username, password (stored in hashed form), and your communication preferences.
Billing name, billing address, ABN or tax identifier, subscription plan and history, invoices, and payment records.
We do not collect or store full credit card numbers. Card details are entered directly with our payment processor, Stripe, and we receive only a token, the card type, the last four digits, and the expiry date. Stripe processes this information in the United States.
IP address, browser type and version, device and operating system, timezone and language settings, referring page, pages viewed, features used, session duration, click and navigation events, and error and diagnostic logs.
Note that under Australian privacy law an IP address or device identifier can be personal information where it is reasonably capable of identifying an individual, and we treat it accordingly.
The content of emails, support tickets, chat messages, and any feedback, survey responses or bug reports you send us, together with our replies.
Where you purchase the Configuration Workshop, we collect scheduling details, attendee names and email addresses, notes taken during sessions, and any configuration or business context you share with us in order for the sessions to be useful. We also collect session recordings and transcripts. We will tell you before any recording begins and will not record without consent.
Where you subscribe to our mailing list, download a resource, attend a webinar or request a demo, we collect the details you provide and your engagement with our marketing emails, including whether they were opened and which links were clicked.
Whatever our customers choose to upload or generate in the Service. This may include names, email addresses, phone numbers, company details, engagement history and campaign records relating to their contacts. See clause 1 and clause 8.
We do not seek sensitive information (as defined in the Privacy Act — including health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal record). Please do not submit it to the Service. If sensitive information is provided to us incidentally, we will handle it in accordance with this policy and the Privacy Act, and may delete it.
We collect personal information:
Where it is reasonable and practicable, we collect personal information directly from the individual concerned. Where we collect it from someone else, we take reasonable steps to ensure the individual is notified.
We use personal information for the following purposes:
| Purpose | Examples |
| Providing the Service | Creating and administering your account, authenticating logins, delivering features, storing your data |
| Billing | Charging subscription fees, processing the Configuration Workshop fee, issuing invoices and receipts, recovering unpaid amounts |
| Support | Responding to enquiries, diagnosing faults, delivering workshop sessions |
| Service communications | Renewal reminders, price change notices, security alerts, changes to our terms, outage notifications |
| Improving the Service | Understanding which features are used, identifying bugs and performance problems, developing new functionality |
| Security and integrity | Detecting and preventing fraud, abuse, unauthorised access and breaches of our terms |
| Marketing | Sending you information about our products, offers and content, subject to clause 7 |
| Legal and compliance | Meeting tax, accounting and record-keeping obligations, responding to lawful requests, establishing or defending legal claims |
We will not use your personal information for an unrelated secondary purpose unless you would reasonably expect it, you have consented, or the law permits or requires it.
Where the GDPR or UK GDPR applies, we rely on:
We disclose personal information to the following categories of recipient, and only as necessary for the purposes in clause 4:
| Recipient type | Purpose | Examples |
| Cloud hosting and infrastructure | Running the Service, storing data | Google Firebase / Google Cloud Platform — database hosted in Sydney, Australia |
| Payment processing | Taking payment, preventing fraud | Stripe (United States) |
| Email delivery | Sending transactional and marketing email | Attio, Gmail |
| Analytics and product telemetry | Understanding usage, diagnosing errors | Google Analytics, Firebase Crashlytics |
| Customer support tooling | Managing enquiries | Attio |
| Accounting and tax | Bookkeeping, statutory reporting | Xero |
| Professional advisers | Legal and financial advice | Lawyers, auditors, insurers |
| Acquirers | Due diligence and transfer in a sale of the business | Prospective purchasers, subject to confidentiality |
| Law enforcement and regulators | Where required or authorised by law | Courts, the OAIC, police |
We do not sell personal information, and we do not disclose it to third parties for their own direct marketing purposes.
Our infrastructure is a mix of Australian and overseas components. The table below sets out where each kind of information is held.
| Component | What it holds | Where it is held |
| Cloud Firestore | Customer Data, account records, application data | Sydney, Australia (australia-southeast1) |
| Firebase Authentication | Login credentials — email addresses, phone numbers, password hashes | United States |
| Cloud Functions | Transient processing of data in flight | Sydney, Australia (australia-southeast1) |
| Google Analytics and Firebase Crashlytics | Usage, performance and crash telemetry | Google's global infrastructure, including outside Australia |
| Stripe | Billing details, payment records | United States |
Customer Data is stored in Australia. Login credentials, billing information and usage telemetry are held or processed overseas as set out above.
Personal information is likely to be disclosed to recipients in the United States. In addition, telemetry collected by Google Analytics and Firebase Crashlytics is processed across Google's global infrastructure, and it is not practicable for us to specify every country in which that processing may occur.
Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it in a way consistent with the APPs. We rely on the contractual protections in Google's Cloud Data Processing Addendum and Stripe's data processing terms. Where we transfer personal information out of the EEA or UK, we rely on Standard Contractual Clauses or another approved transfer mechanism.
7.1 We may send you marketing communications about Marketing Markdown where you are an existing customer, or where you have opted in.
7.2 Every marketing email contains an unsubscribe link that works. You can also opt out at any time by emailing michael@marketingmarkdown.com. We will action opt-outs promptly and at no cost, as required by the Spam Act 2003 (Cth).
7.3 Opting out of marketing does not stop service communications — renewal reminders, billing notices, security alerts and changes to our terms. Those are part of providing the Service and cannot be unsubscribed from while your account is active.
7.4 On request, we will tell you the source of the personal information we used to contact you.
8.1 We access Customer Data only to provide, secure and support the Service, to fix faults, at our customer's instruction, or where required by law.
8.2 We may generate aggregated and de-identified statistics from usage of the Service — for example, benchmark figures on campaign performance across our customer base — and use them to improve and market the Service. These statistics never identify a customer or any individual, and we do not attempt to re-identify them.
8.3 We do not use Customer Data to train machine learning or artificial intelligence models, and we do not permit our service providers to do so.
8.4 Our handling of Customer Data is also governed by our agreement with the relevant customer, including any Data Processing Addendum. Where those terms conflict with this policy in relation to Customer Data, those terms prevail.
9.1 We use cookies and similar technologies on our website and in the Service:
9.2 You can control cookies through your browser settings, and through our cookie banner where one is shown. Blocking strictly necessary cookies will prevent you from logging in.
We do not use automated decision-making that produces legal effects or similarly significantly affects individuals. Where the Service uses automation or AI to generate suggestions, drafts or scores, those outputs are recommendations for our customers to review and act on, and are not decisions we make about any individual.
11.1 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure.
11.2 No system is completely secure, and we cannot guarantee the security of information transmitted to us over the internet.
11.3 Data breaches. If we suffer a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours where required, and assist our customers with their own notification obligations.
| Information | Retention |
| Account and profile | For the life of the account, then [30] days after termination |
| Customer Data | For the life of the account, then [30] days to allow export, then deleted |
| Billing and tax records | 7 years, as required by Australian tax law |
| Support correspondence | 2 years from last contact |
| Marketing lists | Until you unsubscribe, then a suppression record is kept indefinitely so we do not contact you again |
| Server and security logs | 90 days |
| Backups | Deleted data persists in backups for up to 30 days before being overwritten |
We destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it.
13.1 You can view and update most of your information directly in your account settings.
13.2 You may also request access to, or correction of, the personal information we hold about you by emailing michael@marketingmarkdown.com. We will respond within 30 days.
13.3 We do not charge for making a request. We may charge a reasonable cost-based fee for giving access to a large volume of information, and we will tell you before any fee applies.
13.4 We may refuse access or correction in the limited circumstances permitted by the Privacy Act — for example, where granting access would unreasonably affect another person's privacy. If we refuse, we will tell you why in writing and explain how to complain.
13.5 We may need to verify your identity before acting on a request.
EEA and UK. Where the GDPR or UK GDPR applies, you also have rights to erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent. You may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office.
California. Where the CCPA/CPRA applies, you have rights to know, delete, correct, and opt out of sale or sharing of personal information, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined.
To exercise any of these rights, email michael@marketingmarkdown.com.
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
16.1 If you are concerned about how we have handled your personal information, email michael@marketingmarkdown.com with the details. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If we need longer, we will tell you why and give you a revised timeframe.
16.2 If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
We may update this policy from time to time. The current version is always available at www.marketingmarkdown.com/privacy-policy and is dated at the top. Where a change materially affects how we handle your personal information, we will notify you by email or in-app notice before it takes effect.
Marketing Markdown
Privacy contact: michael@marketingmarkdown.com