Privacy Policy

How Margixa collects, uses, protects and retains data · written in plain language, because a privacy policy you cannot understand protects nobody.

Last updated · 3 August 2026

1 · Who we are

Margixa is a cloud-based ERP platform for electronics merchants selling new and refurbished devices, operated by Margixa B.V., registered in the Netherlands (KvK 42101008 · VAT NL869729834B01), with its registered office at Veldlaan 16 · 3956 RH Leersum · The Netherlands.

This policy covers both this website (margixa.com) and the Margixa platform (app.margixa.com). For questions about this policy or your data, contact us at support@margixa.com.

2 · Our two roles under the GDPR

Margixa processes data in two distinct capacities, and the distinction matters:

  • As a controller · for the data of our own customers (merchants) and their staff accounts, billing details, and website visitors.
  • As a processor· for the business data our merchants manage inside Margixa (inventory, orders, suppliers, their end-customer records) and for marketplace buyer data processed on the merchant's behalf and instruction. Here the merchant is the controller and Margixa acts strictly under their instructions.

3 · Marketplace buyer data · our zero-storage architecture

Margixa connects to sales channels (Amazon, Back Market, Refurbed, Shopify and others) on the merchant's behalf. We designed the platform so that buyer personal data is never stored in our database:

  • Order records mirrored into Margixa contain no buyer identity · only order identifiers, line items, quantities, amounts and order state.
  • When a merchant fulfils an order, the buyer's name and delivery address are fetched from the marketplace on demand, processed transiently in memory to generate the shipping label, and discarded. They are not written to our database, logs or backups.
  • The buyer's delivery details are shared only with the shipping carrier the merchant has contracted (for example DHL Express or Sendcloud), solely to produce the label for that one shipment, at the merchant's instruction.
  • Where a marketplace requires it (for example Amazon's Data Protection Policy), we comply with the marketplace's own data-handling requirements in addition to the GDPR.

4 · Data we process and why

Merchant accountsCompany name, staff names and work email addresses, hashed authentication credentials, role and permission settings. Legal basis · performance of our contract with the merchant.
Merchant business dataInventory, product catalogs, orders, suppliers, pricing rules, warehouse records and the merchant's own customer records · processed on the merchant's instruction as their processor.
Marketplace credentialsAPI keys and tokens the merchant connects · sealed with public-key encryption before storage; only our backend workers can decrypt them (see the Security page).
Website visitorsNo advertising or tracking cookies. We use essential cookies only. If you join the waitlist we store the email address you submit, for that purpose only. Legal basis · consent.
Support requestsThe content of your message and contact details, used to resolve your request. Legal basis · legitimate interest in supporting our customers.

5 · Subprocessors and sharing

We never sell personal data. We share data only with the service providers below, under data-processing agreements, and with shipping carriers at the merchant's instruction:

SupabaseDatabase and authentication · EU region · buyer PII is never stored here.
VercelApplication hosting and delivery.
RailwayBackground workers · EU region · transient order processing.
UpstashTask queue · carries job references, not personal data content.
ResendTransactional email (account and operational notifications).
Shipping carriersSendcloud, DHL Express and marketplace-provided label services · receive the delivery details for a specific shipment, at the merchant's instruction.
PrintNodeOptional label-printing bridge configured by the merchant · transmits the merchant's own label documents to the merchant's own printer.

We may also disclose data where required by law or to protect our legal rights. Our infrastructure runs in EU regions; where a provider processes data outside the EEA, transfers are covered by the European Commission's Standard Contractual Clauses or an adequacy decision.

6 · Retention

  • Marketplace buyer data · not retained. Processed transiently at fulfilment time only (well within the strictest marketplace limit of 30 days).
  • Merchant business data· retained for as long as the merchant's account is active, then deleted or returned per the contract.
  • Invoices and financial records · retained as required by EU and Dutch tax law (up to 10 years).
  • Waitlist emails · until launch communication is sent or you ask us to remove you, whichever comes first.

7 · Cookies

This website and the platform use essential cookies only · they keep you signed in and the site functioning. We run no advertising cookies, no cross-site tracking and no third-party analytics profiles on visitors. Because these cookies are strictly necessary, no consent banner gymnastics are needed · we simply tell you they exist. You can delete or block cookies in your browser settings at any time; blocking essential cookies may prevent signing in to the platform.

8 · Security and breach notification

Security measures include encryption in transit (TLS) and at rest (AES-256), public-key sealing of marketplace credentials, per-tenant row-level isolation in the database, role-based access control, multi-factor authentication, audit logging and a documented incident-response plan. The full overview lives on our Security page.

If a personal-data breach occurs despite these measures, we notify the competent supervisory authority within 72 hours where required by the GDPR, inform affected merchants without undue delay, and honour the notification windows of the marketplaces involved.

9 · Automated decision-making and children

Margixa makes no automated decisions that produce legal or similarly significant effects on individuals. Automation in the platform (such as repricing or stock synchronization) operates on products and orders under rules the merchant configures · not on people. The service is built for businesses and is not directed at children; we do not knowingly process children's data.

10 · Your rights

Under the GDPR you can request access, rectification, erasure, restriction, portability of your data, and you can object to processing based on legitimate interest. Where Margixa acts as a processor, we will route your request to the responsible merchant and assist them in answering it.

To exercise a right, email support@margixa.com. We respond within one month. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

11 · Changes to this policy

When we change this policy we update the date at the top of this page. For material changes affecting merchants we give advance notice through the platform.