Privacy Policy
Effective Date: March 23, 2026 · Last Updated: July 14, 2026
Marin Labs Inc. is committed to protecting the privacy and security of information entrusted to us by our clients, partners, and website visitors.
Marin Labs builds software solutions for commercial insurance organizations. In providing those services, we process commercial insurance data and may process personal information contained in submissions, correspondence, connected mailboxes, attachments, and other records that our clients and authorized users provide or direct us to access. We process this information only to provide the services described in our client agreements and this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
When you interact with our website or contact us, we may collect the following categories of information:
- Business Contact Information: Name, job title, company name, business email address, phone number, and mailing address provided when you submit a contact form, request a demo, or otherwise reach out to us.
- Communications: Records and content of correspondence when you contact us via email, phone, or through our website.
- Contractual Information: Information necessary to establish and manage client relationships, including billing details, contract terms, and engagement history.
- Service and Insurance Information: Commercial insurance submissions, applications, loss information, policy and quote records, correspondence, attachments, and related business or personal information that authorized users provide to the Marin service.
1.2 Information Collected Automatically
When you visit our website, we may automatically collect certain technical information, including:
- Log Data: IP address, browser type and version, operating system, referring URLs, pages visited, date and time of access, and time spent on pages.
- Device Information: Device type, screen resolution, and unique device identifiers.
- Cookies and Similar Technologies: We use cookies, web beacons, and similar tracking technologies to enhance your browsing experience, analyze website traffic, and understand usage patterns. See Section 7 for details.
1.3 Google User Data and Connected Mailboxes
If an authorized user connects a Google Workspace or Gmail mailbox, Marin requests read-only Gmail access. We receive the user’s Google account email address, OAuth authorization credentials, and messages within the mailbox scope selected for synchronization, including message identifiers, sender and recipient information, subject lines, message content, timestamps, thread information, and attachments. Marin does not request permission to send, modify, or delete Gmail messages.
Marin uses Google user data only to provide the user-facing mailbox synchronization and commercial-insurance workflow requested by the user and the user’s organization. This includes identifying relevant inbox messages, importing authorized messages and attachments, creating or updating insurance submission records, extracting and organizing submission information, preventing duplicate processing, displaying the resulting records to authorized users, and providing support or security for those features.
OAuth access and refresh tokens are stored securely and used only to maintain the authorized connection. Disconnecting a mailbox stops future access and clears the stored OAuth credentials. Disconnecting does not automatically delete messages or insurance records previously imported into Marin; an authorized user or customer administrator may request deletion as described in Section 6.4.
Marin does not sell Google user data, use it for advertising, transfer it to data brokers or information resellers, use it to determine creditworthiness or for lending, or use it to train or improve generalized or foundation artificial-intelligence models. Human access to Google user data is limited to circumstances authorized by the user or customer, necessary to provide requested support, necessary for security or abuse investigation, or required by law.
Marin’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. How We Use Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our software development, configuration, integration, and related professional services as described in our client agreements.
- Client Relationship Management: To manage our business relationships, communicate with clients and prospects, respond to inquiries, and process transactions.
- Website Operations: To operate, maintain, and improve our website, including analyzing usage patterns and optimizing user experience.
- Security and Compliance: To protect our systems, detect and prevent fraud or unauthorized access, and comply with legal obligations.
- Legal Obligations: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
We do not use client data for training machine learning or artificial intelligence models, benchmarking, aggregate analytics, product development, or any purpose unrelated to a specific client engagement, unless the client provides prior written consent.
Regardless of any client consent applicable to other client data, Google user data is never used to create, train, or improve a generalized or foundation artificial-intelligence model.
3. How We Share Information
We do not sell, rent, or trade your information to third parties. We may share information in the following limited circumstances:
- Service Providers: We may share information with trusted third-party vendors and service providers who assist us in operating our business, subject to contractual obligations that require them to protect the confidentiality of the information.
- Legal Requirements: We may disclose information if required by law, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction.
- With Your Consent: We may share your information for other purposes with your explicit consent.
3.1 Google User Data
We disclose Google user data only to service providers that process it on our behalf as necessary to operate, secure, store, and deliver the user-facing Marin features described above; when an authorized user or customer directs us to do so; for security or abuse investigation; when required by law; or in connection with a business transfer after obtaining any consent required by Google policy. Service providers are contractually restricted from using the data for their own purposes. We do not otherwise transfer, disclose, or sell Google user data.
4. Data Security
Marin Labs maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, or disclosure, consistent with industry standards and applicable law. Our information security program includes:
- Access Controls: Role-based access controls to limit information access to authorized personnel with a legitimate business need.
- Encryption: Encryption of data in transit and at rest, including AES-256 or equivalent encryption for sensitive data.
- Security Assessments: Regular security assessments, including annual penetration testing conducted by qualified independent third parties.
- Employee Training: Ongoing employee security awareness training.
- Incident Response: Documented incident response procedures to address security incidents promptly.
- SOC 2 Certification: Marin Labs is pursuing SOC 2 Type I certification as a step toward Type II. Upon written request, Marin Labs will provide its most recent available SOC 2 report and a written timeline for achieving Type II certification.
While we strive to protect your information, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to implementing and maintaining appropriate safeguards.
5. Data Retention
We retain information only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:
- Client Data: Retained for the duration of the client engagement and returned or securely destroyed within thirty (30) days of termination or expiration of the applicable agreement, at the client’s election.
- Google OAuth Credentials: Retained while the mailbox connection remains active. Access and refresh tokens are cleared when the user disconnects the mailbox or Google revokes the grant.
- Imported Google User Data: Messages, attachments, and records imported into Marin are retained as client data according to the applicable client agreement and legal or regulatory requirements. Disconnecting stops future collection but does not automatically delete previously imported records. Authorized users and customer administrators may request deletion by contacting us as described below.
- Regulatory Records: Records related to our services are retained for a minimum of seven (7) years following termination of the applicable engagement, or as otherwise specified in the client agreement, to support regulatory compliance obligations.
- Website Data: Log data and analytics information are retained for up to twenty-four (24) months.
- Business Contact Information: Retained for the duration of the business relationship and for a reasonable period thereafter, unless you request deletion.
6. Your Rights and Choices
Depending on your location and applicable law, you may have certain rights regarding your personal information:
6.1 Rights Under the CCPA/CPRA
If you are a California resident, you may have the right to: know what personal information we collect and how we use it; request deletion of your personal information; opt out of the sale or sharing of your personal information (note: we do not sell personal information); request correction of inaccurate personal information; and not be discriminated against for exercising your privacy rights.
6.2 Rights Under the GDPR
If you are located in the European Economic Area or the United Kingdom, you may have the right to: access, correct, or delete your personal data; restrict or object to processing; data portability; and lodge a complaint with a supervisory authority. Our lawful bases for processing include performance of a contract, legitimate interests (such as operating our business and improving our services), and compliance with legal obligations.
6.3 Rights Under Other US State Privacy Laws
Residents of states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, and others) may have similar rights to access, correct, delete, and opt out of certain processing activities. We will honor your requests in accordance with applicable law.
6.4 How to Exercise Your Rights
To exercise any of these rights, please contact us using the information provided in Section 12. We will respond to verified requests within the timeframes required by applicable law. We may need to verify your identity before processing your request.
You may stop Marin’s future access to a connected Google mailbox at any time from Settings → Mail in Marin or from your Google Account’s third-party connections page. To request deletion of Google user data previously imported into Marin, contact security@marinlabs.ai and identify the connected mailbox and customer organization. We will verify the request and delete or return data as required by the applicable client agreement and law.
7. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to collect and use information about you and your interactions with our website. Essential Cookies: Required for the website to function properly and cannot be disabled. Analytics Cookies: Help us understand how visitors interact with our website, allowing us to improve functionality and user experience. Functional Cookies: Enable enhanced functionality and personalization, such as remembering your preferences.
You can control cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our website. We do not use cookies to track you across third-party websites for advertising purposes.
8. Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.
9. Children’s Privacy
Our website and services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.
10. International Data Transfers
Marin Labs is based in the United States. If you are accessing our website or services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using our website or services, you consent to the transfer of your information to the United States. Where required by applicable law, we implement appropriate safeguards for international data transfers, such as Standard Contractual Clauses.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the “Last Updated” date at the top of this policy and, where appropriate, notify you through our website or by other means. We encourage you to review this policy periodically.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Marin Labs Inc. — security@marinlabs.ai
Or reach the team at team@marinlabs.ai