Marvin XR

Privacy Policy

Last updated: 11 September 2026

Marvin XR provides 3D product visualisation and web augmented reality (AR) for ecommerce. This policy explains what we collect, why, and what you can ask us to do about it. It covers marvinxr.com, the Marvin XR dashboard at admin.marvinxr.com, our published AR campaign pages, and the Marvin XR app for Shopify.

We are the data controller for the information described here. You can reach us at support@marvinxr.com.

The short version

  • We do not sell your data, and we do not share it for advertising.
  • We ask for the minimum we need to run the service.
  • Product images you give us are used to build your 3D models, and nothing else.
  • You can ask us to delete your data and we will.

Information we collect

When you create a Marvin XR account

Your name, email address, company name and password (stored only as a hash, never in readable form). If you subscribe to a paid plan, our payment processor handles your card details — we never see or store a card number.

When you use the platform

The product images you upload, the 3D models generated from them, the dimensions you enter, your campaign names and settings, and the content you publish.

When someone views one of your AR campaigns

We record anonymous engagement events: a page view, whether AR was launched, approximate location derived from IP at city level, device type and referring page. This is what produces your analytics. We do not place advertising cookies and we do not track visitors across other websites.

If you switch on lead capture, we also store the contact details a visitor chooses to submit. Those belong to you; we process them on your behalf.

When you install the Marvin XR app for Shopify

With your permission, the app reads your product titles, product images and product IDs so you can pick which products to turn into 3D models. It writes back a single metafield per product holding the AR campaign URL, which is what makes the “View in your space” button appear on that product page.

We store your shop domain, the access token Shopify issues, and a record of each generation job. We do not read your orders, your customers, or your customer data. The app does not request those permissions, so it could not read them even if it tried.

When you uninstall the app, Shopify notifies us and we delete the stored access token immediately. We also honour Shopify’s mandatory data requests: customers/data_request, customers/redact and shop/redact.

How we use it

  • To provide the service: generating models, publishing campaigns, showing your analytics.
  • To bill you, if you are on a paid plan.
  • To send service email — account confirmations, receipts, and notices about changes that affect you.
  • To send product updates and offers, if you are a customer. Every one of those has an unsubscribe link, and using it stops them.
  • To keep the service secure and to diagnose faults.

We do not use your product images or generated models to train a general-purpose AI model for anyone else’s benefit.

Who we share it with

Only the processors we need to run the service:

  • Amazon Web Services — hosting and email delivery.
  • Tripo — the 3D generation engine. Product images are sent there to produce your model.
  • Stripe and Shopify — payments and subscription billing.

Each is bound to use the data only to provide their service to us. We do not sell personal data, and we have never done so.

Where your data is held

Our servers are in the European Union. Some processors above operate outside the EU; where they do, transfers rely on the European Commission’s Standard Contractual Clauses.

How long we keep it

  • Account data — while your account is open, and for up to 90 days after you close it.
  • Models and campaigns — until you delete them, or 90 days after your account closes.
  • Analytics events — 24 months.
  • Shopify access tokens — deleted the moment you uninstall.
  • Invoices — as long as tax law requires, normally five years.

Your rights

If you are in the EU or UK, the GDPR gives you the right to see the data we hold about you, correct it, delete it, get a portable copy, object to how we use it, and withdraw consent for marketing at any time. These rights are available to everyone we serve, wherever you are.

Email support@marvinxr.com and we will respond within 30 days. If you are a Shopify merchant, you can also use Shopify’s own data request tools and we will answer through those. If you think we have handled your data badly, you may complain to your local supervisory authority — in Denmark, that is Datatilsynet.

Cookies

The dashboard uses a session cookie to keep you logged in and a preference cookie to remember your light or dark theme. Published AR campaign pages use no advertising or cross-site tracking cookies.

Children

Marvin XR is a business product and is not intended for anyone under 16. We do not knowingly collect their data.

Security

Traffic is encrypted in transit with TLS. Passwords are hashed. Captured lead data is encrypted at rest. Access to production systems is limited to people who need it. No system is perfectly secure, and we will tell affected users and the relevant authority without undue delay if a breach puts personal data at risk.

Changes

If we change this policy in a way that materially affects you, we will email account holders and update the date at the top of this page.

Contact

Marvin XR
Ringholmvej 20, 2TH
2700 Brønshøj, Copenhagen, Denmark
support@marvinxr.com