Security and Privacy
Your Marketing Data Stays Yours.
Connect your commerce and marketing platforms without giving up control of your data. Every sensitive action waits for approval, and your data never trains a model.
AI & YOUR DATA
Your data does not train AI models.
Marklo uses third-party LLM APIs, including OpenAI and Anthropic, to generate outputs. Marklo does not train or fine-tune models on customer personal data.
No training
Customer data is not used to train or fine-tune AI models.
Minimum necessary data
Only the information required to generate the requested output is used.
Customer-controlled AI connections
You choose which platforms connect to Marklo and can revoke access at any time.
Available on platforms you trust.
Find Marklo in the Shopify App Store and Klaviyo App Marketplace.
The campaign planning system for Shopify DTC brands
Stay up to date on the latest findings, launches and insights.


What Marklo does.
What Marklo does not.
Does
Connects only to platforms you authorize
Marklo only accesses the platforms you choose to connect — integrations are opt-in and revocable anytime.
Requests only the permissions it needs
Marklo uses the minimum access needed — read-only by default, write access only where a feature requires it.
Keeps your workspace separate
Your data and Marklo's outputs are logically separated from other customers and accessible only within your workspace.
Protects your data throughout its lifecycle
Data is encrypted in transit and at rest, with access controls limiting internal access.
Does Not
Train AI with your data
Marklo does not train or fine-tune AI models on customer personal data.
Access your internal systems
Marklo connects only through customer-authorized APIs; not internal databases or corporate networks.
Take control of other workspaces
Connecting Marklo does not warrant unrestricted administrative access to your other platforms.
Read your secrets
Marklo does not access sensitive financial systems, HR information, or source code.
YOUR DATA, CLEARLY MAPPED
How your data moves
through Marklo
A secure, permissioned path from the platforms you choose to insights inside your workspace.
1
CONNECT
Customer authorizes an integration
2
SECURELY INGEST
Credentials are securely stored
3
ANALYZE
Marklo pulls
permitted data
4
INSIGHTS
Marklo generates workspace outputs
SECURITY BY DESIGN
Built to keep your data protected
Encryption
Customer data is protected with TLS 1.2+ in transit and AES-256 at rest.
Access controls
Internal access follows least-privilege principles, with MFA and restricted production access.
Secure development
Production changes go through peer review, automated testing and staging before deployment.
Incident response
Marklo maintains a documented incident response for detecting and investigating security incidents.
DATA RETENTION & DELETION

Your data doesn’t stay with Marklo forever.
If your relationship with Marklo ends, live account and customer content is deleted or anonymized within 30 days. Data remaining in backups ages out through Marklo’s standard backup rotation within up to 35 additional days.
DOCUMENTS & CONTACT
Need to go deeper? We’ll share the details.
Policies, agreements, and the people to contact if you have questions about how Marklo handles your data.
PRIVACY & SECURITY
FAQs
Does Marklo sell or share our data?
What access do your integrations actually have?
What happens if we connect Claude or another AI assistant to our workspace?
Are you SOC 2 or ISO 27001 certified?
What happens if there’s a security incident?
What rights do we have over our data, and how fast will you respond?
Who are your subprocessors?
Where is our data hosted?
Security and Privacy
Your Marketing Data Stays Yours.
Connect your commerce and marketing platforms without giving up control of your data. Every sensitive action waits for approval, and your data never trains a model.
AI & YOUR DATA
Your data does not train AI models.
Marklo uses third-party LLM APIs, including OpenAI and Anthropic, to generate outputs. Marklo does not train or fine-tune models on customer personal data.
No training
Customer data is not used to train or fine-tune AI models.
Minimum necessary data
Only the information required to generate the requested output is used.
Customer-controlled AI connections
You choose which platforms connect to Marklo and can revoke access at any time.
Available on platforms you trust.
Find Marklo in the Shopify App Store and Klaviyo App Marketplace.
The campaign planning system for Shopify DTC brands
Stay up to date on the latest findings, launches and insights.


What Marklo does.
What Marklo does not.
Does
Connects only to platforms you authorize
Marklo only accesses the platforms you choose to connect — integrations are opt-in and revocable anytime.
Requests only the permissions it needs
Marklo uses the minimum access needed — read-only by default, write access only where a feature requires it.
Keeps your workspace separate
Your data and Marklo's outputs are logically separated from other customers and accessible only within your workspace.
Protects your data throughout its lifecycle
Data is encrypted in transit and at rest, with access controls limiting internal access.
Does Not
Train AI with your data
Marklo does not train or fine-tune AI models on customer personal data.
Access your internal systems
Marklo connects only through customer-authorized APIs; not internal databases or corporate networks.
Take control of other workspaces
Connecting Marklo does not warrant unrestricted administrative access to your other platforms.
Read your secrets
Marklo does not access sensitive financial systems, HR information, or source code.
YOUR DATA, CLEARLY MAPPED
How your data moves
through Marklo
A secure, permissioned path from the platforms you choose to insights inside your workspace.
1
CONNECT
Customer authorizes an integration
2
SECURELY INGEST
Credentials are securely stored
3
ANALYZE
Marklo pulls
permitted data
4
INSIGHTS
Marklo generates workspace outputs
SECURITY BY DESIGN
Built to keep your data protected
Encryption
Customer data is protected with TLS 1.2+ in transit and AES-256 at rest.
Access controls
Internal access follows least-privilege principles, with MFA and restricted production access.
Secure development
Production changes go through peer review, automated testing and staging before deployment.
Incident response
Marklo maintains a documented incident response for detecting and investigating security incidents.
DATA RETENTION & DELETION

Your data doesn’t stay with Marklo forever.
If your relationship with Marklo ends, live account and customer content is deleted or anonymized within 30 days. Data remaining in backups ages out through Marklo’s standard backup rotation within up to 35 additional days.
DOCUMENTS & CONTACT
Need to go deeper? We’ll share the details.
Policies, agreements, and the people to contact if you have questions about how Marklo handles your data.
PRIVACY & SECURITY
FAQs
Does Marklo sell or share our data?
What access do your integrations actually have?
What happens if we connect Claude or another AI assistant to our workspace?
Are you SOC 2 or ISO 27001 certified?
What happens if there’s a security incident?
What rights do we have over our data, and how fast will you respond?
Who are your subprocessors?
Where is our data hosted?
Security and Privacy
Your Marketing Data Stays Yours.
Connect your commerce and marketing platforms without giving up control. Every sensitive action waits for approval, and your data never trains a model.
AI & YOUR DATA
Your data does not train AI models.
Marklo uses third-party LLM APIs, including OpenAI and Anthropic, to generate outputs. Marklo does not train or fine-tune models on customer personal data.
No training
Customer data is not used to train or fine-tune AI models.
Minimum necessary data
Only the information required to generate the requested output is used.
Customer-controlled AI connections
You choose which platforms connect to Marklo and can revoke access at any time.
Available on platforms you trust.
Find Marklo in the Shopify App Store and Klaviyo App Marketplace.
The campaign planning system for Shopify DTC brands
Stay up to date on the latest findings, launches and insights.


What Marklo does.
What Marklo does not.
Does
Connects only to platforms you authorize
Marklo only accesses the platforms you choose to connect — integrations are opt-in and revocable anytime.
Requests only the permissions it needs
Marklo uses the minimum access needed — read-only by default, write access only where a feature requires it.
Keeps your workspace separate
Your data and Marklo's outputs are logically separated from other customers and accessible only within your workspace.
Protects your data throughout its lifecycle
Data is encrypted in transit and at rest, with access controls limiting internal access.
Does Not
Train AI with your data
Marklo does not train or fine-tune AI models on customer personal data.
Access your internal systems
Marklo connects only through customer-authorized APIs; not internal databases or corporate networks.
Take control of other workspaces
Connecting Marklo does not warrant unrestricted administrative access to your other platforms.
Read your secrets
Marklo does not access sensitive financial systems, HR information, or source code.
YOUR DATA, CLEARLY MAPPED
How your data moves
through Marklo
A secure, permissioned path from the platforms you choose to insights inside your workspace.
1
CONNECT
Customer authorizes an integration
2
SECURELY INGEST
Credentials are securely stored
3
ANALYZE
Marklo pulls
permitted data
4
INSIGHTS
Marklo generates workspace outputs
SECURITY BY DESIGN
Built to keep your data protected
Encryption
Customer data is protected with TLS 1.2+ in transit and AES-256 at rest.
Access controls
Internal access follows least-privilege principles, with MFA and restricted production access.
Secure development
Production changes go through peer review, automated testing and staging before deployment.
Incident response
Marklo maintains a documented incident response for detecting and investigating security incidents.
DATA RETENTION & DELETION

Your data doesn’t stay with Marklo forever.
If your relationship with Marklo ends, live account and customer content is deleted or anonymized within 30 days. Data remaining in backups ages out through Marklo’s standard backup rotation within up to 35 additional days.
DOCUMENTS & CONTACT
Need to go deeper? We’ll share the details.
Policies, agreements, and the people to contact if you have questions about how Marklo handles your data.
PRIVACY & SECURITY
FAQs
Does Marklo sell or share our data?
What access do your integrations actually have?
What happens if we connect Claude or another AI assistant to our workspace?
Are you SOC 2 or ISO 27001 certified?
What happens if there’s a security incident?
What rights do we have over our data, and how fast will you respond?
Who are your subprocessors?
Where is our data hosted?