Privacy policy
Last updated: October 3, 2026. Plain-language summary: we collect as little as possible, never sell it, and you can leave anytime.
Who is responsible
Quentin Fankrache EI, the publisher listed in the legal notice, is the data controller. Contact: [email protected].
What we collect and why
- Waitlist: your e-mail address, the referral code you came with, the site that referred you, the campaign tag of the link you followed (
utm_source) and your country (from the hosting network). Purpose: tell you when Marvelous UI launches, send launch offers and product news, and credit referrals. Legal basis: your consent when you submit the form (GDPR art. 6.1.a). Kept until you unsubscribe, or 24 months without interaction. - Confirmation e-mail (double opt-in): when you join, Brevo sends you an e-mail with a confirmation link. You join our mailing list, get your place in line and count as a referral only once you click it. Until then, that confirmation is the only e-mail you get from us (sent again only if you join again).
- Bot check: the waitlist form uses Cloudflare Turnstile to tell people from bots. It runs when you use the form and processes technical data about your browser and connection, including your IP address, for that check only. Legal basis: our legitimate interest in keeping the waitlist free of spam and fake signups (GDPR art. 6.1.f).
- Customers: name, e-mail, billing country and order details, handled by our merchant of record Polar (polar.sh), which processes payments as an independent controller and issues your license key. We receive from Polar your name, e-mail, country, company and order details, and keep them while your license runs and for 5 years after, then only what accounting law requires (10 years). Legal basis: contract and legal obligations.
- Order confirmation e-mail: right after each order, Polar notifies our server, and Brevo sends the e-mail address of the order a confirmation that you asked for immediate access and acknowledged losing your right of withdrawal, with our terms and license. Legal basis: legal obligation (French Consumer Code, art. L221-13; GDPR art. 6.1.c).
- Seat certification: the names of seat holders you send us when we ask you to certify your seats are kept for the same period as your customer data. Legal basis: contract.
- Refunds: to apply our once-per-customer refund rule, we keep the name, e-mail, company and order number of refunded customers for 3 years after the refund. Legal basis: our legitimate interest in preventing refund abuse (GDPR art. 6.1.f).
- Withdrawal form: if you use our withdrawal form, we receive your name, e-mail, order number and message, and Brevo sends you an acknowledgement with its content, date and time. We keep the request (name, e-mail, order number, message, date) for 3 years as proof. Legal basis: legal obligation (French Consumer Code, art. L221-21; GDPR art. 6.1.c) and our legitimate interest in keeping proof (GDPR art. 6.1.f).
- Playground: your pages are stored only in your own browser (localStorage). A license key you enter is sent to our server, and from it to Polar, only to check it. Your browser is identified by a random id, which reaches Polar only as a hash, with a label (browser family, operating system, date) so you can recognize it in your customer portal.
- Purchase identifier: the Pro pack you download with the CLI or from our download page, and every playground export, carry a purchase identifier: a code derived from your license with a keyed hash, never your license key. It sends nothing: your site makes no request to us and runs no license check. Our server keeps, with our host Cloudflare, the link between that code and your license (license type, the Polar id of your license key or, for a key we issued directly, a hash of that key, and the date of the first delivery), so that a copy of Marvelous UI found online can be traced to the license it was delivered under. Kept for the same period as your customer data. Legal basis: contract (GDPR art. 6.1.b) and our legitimate interest in protecting the license against redistribution (GDPR art. 6.1.f).
- License sharing: each time a license key downloads the Pro pack or a playground export, our server adds a keyed hash of the request's IP address, which changes every day, to that day's count of distinct networks for the license's purchase identifier. These counts are kept by Cloudflare and expire after 48 hours. If a license is used from an unusual number of networks in one day, our server sends PostHog (EU cloud) an alert event with the purchase identifier, the number of networks, the date and the kind of delivery, never your IP address, license key, name or e-mail. PostHog keeps it for 12 months at most. Legal basis: our legitimate interest in detecting a shared license key (GDPR art. 6.1.f).
- Security: our server uses your IP address, hashed, to limit abuse (rate limits). It is not stored with your e-mail address. Rate-limit and cache entries expire within minutes.
- Analytics: Cloudflare Web Analytics counts page views and measures page-load performance. It sets no cookie, stores nothing in your browser, does not track you across sites and does not collect query strings (such as
?ref=). Legal basis: our legitimate interest in knowing how the site is used (GDPR art. 6.1.f). - Conversion counts: the site counts page views and the use of certain buttons (waitlist, Free pack, Playground, pricing, plans, checkout, Done for you), with the page language and path, the site you came from and the campaign tags of the link (
utm_source,utm_medium,utm_campaign,utm_content). Cloudflare keeps these counts for about 3 months (Workers Analytics Engine). To see which steps lead to a purchase, our server also sends these events to PostHog (EU cloud) with a visitor id: a keyed hash of your IP address and browser that changes every day, is never stored and cannot be reversed without our key. Neither your IP address nor any cookie reaches PostHog, and nothing is stored in your browser. PostHog also receives the name and version of your browser and operating system, as your browser announces them (its user agent), so that visits from people can be told apart from bots. If you buy, the checkout link passes that day's id and the campaign tags to Polar, so that the order can be matched to the visit: PostHog then receives the order number, plan and amount, never your name, e-mail or license key. PostHog keeps these events for 12 months at most. If your browser sends the Global Privacy Control signal, nothing is sent to PostHog. Legal basis: our legitimate interest in knowing which parts of the site are useful (GDPR art. 6.1.f).
Who we share it with
Only the providers needed to run the service: Cloudflare (hosting, storage, bot check, analytics), PostHog (product analytics and license-sharing alerts, EU cloud), Brevo (e-mail sending, EU) and Polar (merchant of record: payments, invoices and license keys). Transfers outside the EU rely on the European Commission's standard contractual clauses or adequacy decisions. We never sell or rent your data.
Your rights
You can access, correct, delete or export your data, withdraw consent and object at any time: e-mail us, or use the unsubscribe link in every e-mail. You can also complain to the CNIL (cnil.fr).