Security and Privacy

Your Marketing Data Stays Yours.

Connect your commerce and marketing platforms without giving up control of your data. Every sensitive action waits for approval, and your data never trains a model.

AI & YOUR DATA

Your data does not train AI models.

Marklo uses third-party LLM APIs, including OpenAI and Anthropic, to generate outputs. Marklo does not train or fine-tune models on customer personal data.

No training

Customer data is not used to train or fine-tune AI models.

Minimum necessary data

Only the information required to generate the requested output is used.

Customer-controlled AI connections

You choose which platforms connect to Marklo and can revoke access at any time.

Available on platforms you trust.

Find Marklo in the Shopify App Store and Klaviyo App Marketplace.

The campaign planning system for Shopify DTC brands

Stay up to date on the latest findings, launches and insights.

© 2026 - Marklo

What Marklo does.
What Marklo does not.

Does

Connects only to platforms you authorize

Marklo only accesses the platforms you choose to connect — integrations are opt-in and revocable anytime.

Requests only the permissions it needs

Marklo uses the minimum access needed — read-only by default, write access only where a feature requires it.

Keeps your workspace separate

Your data and Marklo's outputs are logically separated from other customers and accessible only within your workspace.

Protects your data throughout its lifecycle

Data is encrypted in transit and at rest, with access controls limiting internal access.

Does Not

Train AI with your data

Marklo does not train or fine-tune AI models on customer personal data.

Access your internal systems

Marklo connects only through customer-authorized APIs; not internal databases or corporate networks.

Take control of other workspaces

Connecting Marklo does not warrant unrestricted administrative access to your other platforms.

Read your secrets

Marklo does not access sensitive financial systems, HR information, or source code.

YOUR DATA, CLEARLY MAPPED

How your data moves
through Marklo

A secure, permissioned path from the platforms you choose to insights inside your workspace.

1

CONNECT

Customer authorizes an integration

2

SECURELY INGEST

Credentials are securely stored

3

ANALYZE

Marklo pulls
permitted data

4

INSIGHTS

Marklo generates workspace outputs

SECURITY BY DESIGN

Built to keep your data protected

Encryption

Customer data is protected with TLS 1.2+ in transit and AES-256 at rest.

Access controls

Internal access follows least-privilege principles, with MFA and restricted production access.

Secure development

Production changes go through peer review, automated testing and staging before deployment.

Incident response

Marklo maintains a documented incident response for detecting and investigating security incidents.

DATA RETENTION & DELETION

Your data doesn’t stay with Marklo forever.

If your relationship with Marklo ends, live account and customer content is deleted or anonymized within 30 days. Data remaining in backups ages out through Marklo’s standard backup rotation within up to 35 additional days.

PRIVACY & SECURITY

FAQs

Does Marklo sell or share our data?

What access do your integrations actually have?

What happens if we connect Claude or another AI assistant to our workspace?

Are you SOC 2 or ISO 27001 certified?

What happens if there’s a security incident?

What rights do we have over our data, and how fast will you respond?

Who are your subprocessors?

Where is our data hosted?

Security and Privacy

Your Marketing Data Stays Yours.

Connect your commerce and marketing platforms without giving up control of your data. Every sensitive action waits for approval, and your data never trains a model.

AI & YOUR DATA

Your data does not train AI models.

Marklo uses third-party LLM APIs, including OpenAI and Anthropic, to generate outputs. Marklo does not train or fine-tune models on customer personal data.

No training

Customer data is not used to train or fine-tune AI models.

Minimum necessary data

Only the information required to generate the requested output is used.

Customer-controlled AI connections

You choose which platforms connect to Marklo and can revoke access at any time.

Available on platforms you trust.

Find Marklo in the Shopify App Store and Klaviyo App Marketplace.

The campaign planning system for Shopify DTC brands

Stay up to date on the latest findings, launches and insights.

© 2026 - Marklo

What Marklo does.
What Marklo does not.

Does

Connects only to platforms you authorize

Marklo only accesses the platforms you choose to connect — integrations are opt-in and revocable anytime.

Requests only the permissions it needs

Marklo uses the minimum access needed — read-only by default, write access only where a feature requires it.

Keeps your workspace separate

Your data and Marklo's outputs are logically separated from other customers and accessible only within your workspace.

Protects your data throughout its lifecycle

Data is encrypted in transit and at rest, with access controls limiting internal access.

Does Not

Train AI with your data

Marklo does not train or fine-tune AI models on customer personal data.

Access your internal systems

Marklo connects only through customer-authorized APIs; not internal databases or corporate networks.

Take control of other workspaces

Connecting Marklo does not warrant unrestricted administrative access to your other platforms.

Read your secrets

Marklo does not access sensitive financial systems, HR information, or source code.

YOUR DATA, CLEARLY MAPPED

How your data moves
through Marklo

A secure, permissioned path from the platforms you choose to insights inside your workspace.

1

CONNECT

Customer authorizes an integration

2

SECURELY INGEST

Credentials are securely stored

3

ANALYZE

Marklo pulls
permitted data

4

INSIGHTS

Marklo generates workspace outputs

SECURITY BY DESIGN

Built to keep your data protected

Encryption

Customer data is protected with TLS 1.2+ in transit and AES-256 at rest.

Access controls

Internal access follows least-privilege principles, with MFA and restricted production access.

Secure development

Production changes go through peer review, automated testing and staging before deployment.

Incident response

Marklo maintains a documented incident response for detecting and investigating security incidents.

DATA RETENTION & DELETION

Your data doesn’t stay with Marklo forever.

If your relationship with Marklo ends, live account and customer content is deleted or anonymized within 30 days. Data remaining in backups ages out through Marklo’s standard backup rotation within up to 35 additional days.

PRIVACY & SECURITY

FAQs

Does Marklo sell or share our data?

What access do your integrations actually have?

What happens if we connect Claude or another AI assistant to our workspace?

Are you SOC 2 or ISO 27001 certified?

What happens if there’s a security incident?

What rights do we have over our data, and how fast will you respond?

Who are your subprocessors?

Where is our data hosted?

Security and Privacy

Your Marketing Data Stays Yours.

Connect your commerce and marketing platforms without giving up control. Every sensitive action waits for approval, and your data never trains a model.

AI & YOUR DATA

Your data does not train AI models.

Marklo uses third-party LLM APIs, including OpenAI and Anthropic, to generate outputs. Marklo does not train or fine-tune models on customer personal data.

No training

Customer data is not used to train or fine-tune AI models.

Minimum necessary data

Only the information required to generate the requested output is used.

Customer-controlled AI connections

You choose which platforms connect to Marklo and can revoke access at any time.

Available on platforms you trust.

Find Marklo in the Shopify App Store and Klaviyo App Marketplace.

The campaign planning system for Shopify DTC brands

Stay up to date on the latest findings, launches and insights.

© 2026 - Marklo

What Marklo does.
What Marklo does not.

Does

Connects only to platforms you authorize

Marklo only accesses the platforms you choose to connect — integrations are opt-in and revocable anytime.

Requests only the permissions it needs

Marklo uses the minimum access needed — read-only by default, write access only where a feature requires it.

Keeps your workspace separate

Your data and Marklo's outputs are logically separated from other customers and accessible only within your workspace.

Protects your data throughout its lifecycle

Data is encrypted in transit and at rest, with access controls limiting internal access.

Does Not

Train AI with your data

Marklo does not train or fine-tune AI models on customer personal data.

Access your internal systems

Marklo connects only through customer-authorized APIs; not internal databases or corporate networks.

Take control of other workspaces

Connecting Marklo does not warrant unrestricted administrative access to your other platforms.

Read your secrets

Marklo does not access sensitive financial systems, HR information, or source code.

YOUR DATA, CLEARLY MAPPED

How your data moves
through Marklo

A secure, permissioned path from the platforms you choose to insights inside your workspace.

1

CONNECT

Customer authorizes an integration

2

SECURELY INGEST

Credentials are securely stored

3

ANALYZE

Marklo pulls
permitted data

4

INSIGHTS

Marklo generates workspace outputs

SECURITY BY DESIGN

Built to keep your data protected

Encryption

Customer data is protected with TLS 1.2+ in transit and AES-256 at rest.

Access controls

Internal access follows least-privilege principles, with MFA and restricted production access.

Secure development

Production changes go through peer review, automated testing and staging before deployment.

Incident response

Marklo maintains a documented incident response for detecting and investigating security incidents.

DATA RETENTION & DELETION

Your data doesn’t stay with Marklo forever.

If your relationship with Marklo ends, live account and customer content is deleted or anonymized within 30 days. Data remaining in backups ages out through Marklo’s standard backup rotation within up to 35 additional days.

DOCUMENTS & CONTACT

Need to go deeper? We’ll share the details.

Policies, agreements, and the people to contact if you have questions about how Marklo handles your data.

PRIVACY & SECURITY

FAQs

Does Marklo sell or share our data?

What access do your integrations actually have?

What happens if we connect Claude or another AI assistant to our workspace?

Are you SOC 2 or ISO 27001 certified?

What happens if there’s a security incident?

What rights do we have over our data, and how fast will you respond?

Who are your subprocessors?

Where is our data hosted?