Skip to main content

Privacy Policy

Maker Privacy Policy

Last Updated: August 5, 2026

This Privacy Policy applies to maker.co, ai.maker.co, app.maker.co, nav.maker.co, and Maker’s software-as-a-service offerings.

This Policy at a Glance

Here is the short version. The numbered sections below have the details.

  • What we collect. Information you give us, such as your name, email address, company, billing details, and support messages, plus technical information collected automatically when you use our websites, such as IP address, browser and device information, usage data, and cookies (see Sections 3 and 4).
  • Our two roles. For our own websites, marketing, and customer accounts, Maker decides how personal information is used: we are the “controller” under European data protection law and the “business” under California law. For the content and data a business customer (a “Subscriber”, as defined in Section 1) submits to or publishes through the Services, and for the technical data we process when that content is served, Maker acts on the Subscriber’s behalf, and the Subscriber’s own privacy policy governs its End Users (see Section 2).
  • We do not store form submissions made on Subscriber sites. Forms embedded in Maker-served content submit End-User data directly to the destination or destinations the Subscriber configures. Maker does not receive or store form-submission content (see Section 2).
  • How to reach us. Email privacy@maker.co with “Privacy Inquiry” in the subject line, or write to us at the postal address in Section 13.

1. Who We Are and What This Policy Covers

Maker, Inc. (“Maker,” “we,” “us,” or “our”) is a software company headquartered at 548 Market St PMB 35672, San Francisco, CA 94104-5401. We provide an AI-native software-as-a-service platform that businesses use to create, edit, moderate, and host web content: landing pages, page sections, images and video, and interactive web experiences, embedded into their own websites. Our products include Maker AI, Maker Pages, and Maker Nav.

This Policy explains what Personal Information we collect, how we use and share it, and the choices and rights you have. It covers:

  • Our websites, including maker.co, ai.maker.co, app.maker.co, and nav.maker.co, and any other websites we operate that link to this Policy (together, the "Websites");
  • The Services, meaning our software-as-a-service platform (including Maker AI, Maker Pages, and Maker Nav) and related tools provided under an agreement with a business customer (each, a "Subscriber"); and
  • Our business operations, such as marketing, sales, billing, and customer support.

This Policy does not cover Subscriber websites or apps, including sites that embed content created or served with Maker. Those sites belong to the Subscriber, and the Subscriber’s own privacy policy governs them. Section 2 explains how this works.

Links to other sites. Our Websites and the Services contain links to third-party websites and services that we do not operate, for example documentation, integration partners, and social media platforms. This Policy does not cover those third parties, and we are not responsible for their privacy practices. The information you provide to them is governed by their own privacy policies, which we encourage you to read.

A few terms we use throughout:

  • “Personal Information” means information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual. It is meant to have the same scope as “personal data” under the EU General Data Protection Regulation and its UK equivalent (together, the “GDPR”) and “personal information” under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the “CCPA”).
  • “End User” means an individual who visits or interacts with a Subscriber’s website or with content delivered through the Services on the Subscriber’s behalf.
  • “Customer Data” means the content and materials a Subscriber or its authorized users upload to, import into, create in, or publish through the Services, including prompts and inputs to AI features and AI Output the Subscriber incorporates. Our Terms of Service call this “Customer Content.”
  • “AI Output” means content generated by our AI features in response to inputs submitted through the Services.

2. Our Two Roles: Our Own Visitors and Customers, and Data We Handle for Subscribers

Maker handles Personal Information in two distinct roles. Which role applies, and who is responsible for your data, depends on how you interact with us.

2.1 Our Websites, Marketing, and Accounts: Maker Is the Controller

When you visit our Websites, receive our marketing, create or use a Maker account, purchase a subscription, or communicate with us, Maker decides how and why your Personal Information is used. In this context we are the “controller” under the GDPR and the “business” under the CCPA, and this Policy applies in full.

2.2 The Services: Maker Processes Customer Data and Telemetry on the Subscriber’s Behalf

When a Subscriber uses the Services, Maker processes two kinds of information on that Subscriber’s behalf. First, Customer Data: the content and materials the Subscriber or its authorized users upload to, import into, create in, or publish through the Services, including prompts and inputs to AI features and AI Output the Subscriber incorporates. Section 6 describes how we handle Customer Data in AI features. Second, when we deliver published content to an End User’s browser, a limited set of technical telemetry: IP address, user agent (the technical description your browser sends about itself), timestamps, and page or embed identifiers. We use this information only to:

  • deliver the content;
  • measure usage (for example, counting content load events for billing);
  • secure the Services and prevent abuse;
  • diagnose and fix technical problems;
  • produce aggregated statistics that do not relate to the Subscriber, any End User, or any other individual, and use those statistics to operate, secure, and improve the Services as our agreement with the Subscriber permits (see Section 5). We do not use this telemetry to build or change a profile about you, and we do not use it to clean or add to data we obtained from any other source; and
  • comply with applicable law and respond to lawful requests.

In this context, the Subscriber is the controller (or “business”) and Maker acts as a processor (or “service provider”) on the Subscriber’s behalf. Our agreements with Subscribers, including our data processing terms, define each party’s roles and responsibilities, and we process this information in accordance with those agreements.

Technical telemetry is not anonymous. Data such as IP addresses can identify individuals under laws like the GDPR and the CCPA, so we treat it as Personal Information and protect it accordingly.

2.3 Embedded Forms Submit Directly to the Destination the Subscriber Configures

Forms embedded in Maker-served content submit End-User data directly to the destination or destinations the Subscriber configures. Maker does not receive or store form-submission content. If you fill out a form on a Subscriber’s website, even one built or delivered with Maker, your submission goes to the destination that Subscriber configured, and the Subscriber’s privacy policy governs it.

2.4 If You Are an End User, Contact the Subscriber

If your Personal Information reached Maker through a Subscriber’s use of the Services and you want to access, correct, delete, or otherwise exercise privacy rights over it, direct your request to that Subscriber. The Subscriber controls the data and is best placed to act on your request. We will reasonably assist Subscribers in responding to End-User requests, consistent with our agreements and applicable law.

3. Information We Collect

This section describes the information Maker collects for its own purposes, that is, where Maker is the controller (see Section 2.1). Data we process on a Subscriber’s behalf is described in Section 2.2. Where the same kind of information also reaches us because a Subscriber uses the Services, Section 2.2 governs our handling of it and this Section 3 does not. We collect information in three ways: you provide it to us, we collect it automatically, and we receive it from third parties.

3.1 Information You Provide to Us

  • Account and registration information. When you or your organization create a Maker account, we collect information such as your name, email address, telephone number, company or organization name, and login credentials. Where you enable it, we use your telephone number for SMS-based two-factor authentication through a telephony provider (see Section 7).
  • Billing information. If you purchase a paid subscription, we collect billing contact details and keep records of your transactions. Payment card information is collected and processed by our payment processor and is not stored on Maker’s systems.
  • Support requests and other communications. When you contact us, for support, sales, a demo, or anything else, including through forms on our Websites, we collect your contact details, the contents of your messages, and any information you choose to include, such as screenshots or files.

You can choose not to provide certain information, but some features, like creating an account or purchasing a subscription, require it.

3.2 Information We Collect Automatically

When you visit or use our Websites or interact with content we serve, we and our service providers automatically collect certain technical information. This includes:

  • Device and connection information. Your IP address, browser type and version, operating system, device identifiers, and language settings.
  • Usage information. The pages you view, the features you use, the links you click, the page or site that referred you to us, and the dates, times, and duration of your visits.
  • Server logs. Like most online services, our servers automatically record technical log entries when you access our Websites and the Services. We retain server logs for 15 days, as stated in Section 8.
  • Content-delivery telemetry. When content we host loads on our Websites, our systems receive limited technical information about that load event, such as the IP address, user agent, timestamp, and page or embed identifiers involved. We use this information to deliver the content, keep the Services secure, and diagnose problems. When the same content loads on a Subscriber’s website, we receive the equivalent information as a processor acting for that Subscriber, and Section 2.2 governs it.

Some of this information, an IP address for example, is Personal Information under laws such as the GDPR and the CCPA, and we treat it that way.

We collect much of the information above through cookies and similar technologies. Section 4 explains those technologies and the choices you have.

3.3 Information We Receive from Third Parties

  • Your organization. If a Subscriber gives you access to the Services, for example a colleague invites you to your company’s Maker workspace, we receive information about you from that Subscriber, such as your name, work email address, and role.
  • Single sign-on providers. If you register or sign in using a third-party single sign-on service, that service sends us information such as your name and email address, as permitted by your settings with that provider.
  • Service providers. Vendors acting on our behalf give us information in the course of their work for us. For example, our payment processor confirms whether a transaction succeeded, and our email vendors report delivery and engagement, such as whether a message was opened or a link was clicked.
  • Analytics technologies. The technologies described in Section 4 tell us about your device and how you found and use our Websites. We use them to measure and improve our Websites and products, not to build advertising profiles about you. You can decline optional technologies through the cookie preference center (Section 9).
  • Social media. If you interact with Maker on a social media platform, for example by following our page, commenting, or sending us a message, that platform’s privacy policy governs your activity there, and we receive the information you make available to us, such as your public profile details and the contents of messages you send us.

We use information from these sources for the purposes described in Section 5, and where we combine it with information we already hold, this Policy applies to the combined information.

Public areas. If you choose to post content in a public area of our Websites, such as a public profile, gallery, or comments, that content, and any Personal Information you include in it, is public. It can be read, collected, and used by others, and we cannot control what they do with it. California residents under 18 can request removal of content they posted, as described in Section 10.

4. Cookies, Analytics, and Similar Technologies

This section covers our Websites, including maker.co, ai.maker.co, app.maker.co, and nav.maker.co. For the Customer Data and technical information we handle on a Subscriber’s behalf, see Section 2.2.

The technologies we use. Cookies are small text files stored on your browser or device. We and the providers described below also use related technologies such as pixels, scripts, and local storage. Together, these technologies help our Websites function, keep them secure, remember your preferences, and show us how the Websites are used.

Your cookie choices. We use OneTrust as our consent-management platform. When you first visit, a cookie banner lets you accept or decline optional cookies, and you can change your choices at any time through the cookie preference center on our Websites. Essential cookies that the Websites need in order to function remain active.

Google Analytics 4. We use Google Analytics 4 to understand how visitors find and use our Websites, for example which pages people visit, how long they stay, and which site or search engine referred them. Google Analytics runs on our AI application (ai.maker.co). We do not use Google Analytics on our marketing site, on Pages, or on content published through the Services. Advertising features and ads personalization are not enabled on any Maker Google Analytics property. Google Analytics uses cookies and similar identifiers and processes information about your device, browser, and site activity. Google explains how it handles this data at https://policies.google.com/technologies/partner-sites. You can opt out through our cookie preference center, or by installing Google’s opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.

Ahrefs Analytics. We use Ahrefs Analytics, a web-analytics service, to measure site traffic.

PostHog. We use PostHog, a product-analytics service, to understand how visitors and signed-in users interact with our Websites and products, for example which features are used and where people run into problems. PostHog processes usage events and the pages and URLs involved. You can opt out on our Websites through the cookie preference center.

Heap Analytics. Maker Pages uses Heap Analytics in the application and the editor. Heap receives user, visitor, and session identifiers, the current and previous page paths, the page title, and browser information. Heap is not used on content published through the Services.

Separately, where a Subscriber has installed its own Heap instance, we forward events to that Subscriber’s account. Those events go to the Subscriber, not to us, and the Subscriber’s own agreement with Heap governs them. Section 7 describes customer-configured integrations.

Other product analytics. Some of our products also use Mixpanel, a usage-analytics service.

Session replay. We use two session-replay services inside our applications: FullStory in Maker Pages and Microsoft Clarity in Maker AI. They record how signed-in users move through the editing interface, so that our support team can see where someone ran into a problem.

Session replay is not enabled on content published through the Services. Visitors to a Subscriber’s published pages are not recorded.

Form field values are masked in the browser before anything is captured. Text inputs, text areas, and dropdown selections are masked, and radio buttons, checkboxes, password fields, hidden fields, and payment-card fields are excluded from capture altogether. Recordings are associated with the signed-in user’s account identifier, name, and email address, so that support can find the right session when a customer reports an issue.

One category of text is captured: the content a Subscriber is working on in the authoring canvas. That is the Subscriber’s own content, including drafts that have not yet been published. It is Customer Content under the Subscriber’s agreement with us, and the session-replay providers are Services subprocessors in respect of it.

Browser controls. Most browsers let you block or delete cookies through their settings. If you block cookies, parts of our Websites may not work properly, and some opt-outs that rely on cookies may stop working.

Global Privacy Control. Section 9 explains how we treat Global Privacy Control (GPC) signals sent by browsers and extensions.

Do Not Track. Some browsers can send a Do Not Track signal. There is no common industry standard for how to respond to it, and our Websites do not currently respond to Do Not Track signals.

Section 9 summarizes all of your choices and controls in one place.

5. How We Use Information

We use the information described in Section 3 for the following purposes:

  • To provide and operate the Services. We deliver our Websites and the Services; host and serve content; remember your settings; personalize your experience; and meter usage, including Views (content-load events that meter delivery of published content) and Credits (the units that meter consumption of AI features across the underlying AI models; see Section 6). Where the load event or the AI usage arises from a Subscriber’s use of the Services, Section 2.2 and the paragraph below explain our role.
  • Accounts and billing. We create and manage accounts, process subscription payments through our payment processor, calculate usage-based charges, and send transactional messages such as receipts and renewal notices.
  • Support. We respond to your questions and requests and troubleshoot problems.
  • Product improvement and analytics. We analyze how the Services are used so we can develop, test, and improve features and fix what is broken. Section 6 describes how this applies to our AI features.
  • Security and fraud prevention. We verify accounts and activity, monitor for and investigate suspicious or abusive behavior, and protect the Services, our customers, and others.
  • Legal compliance. We comply with applicable law, respond to lawful requests from courts and authorities, and maintain records we are required to keep, such as tax and accounting records.
  • Communications and marketing. We send service announcements about the Services. With your permission where the law requires it, we also send marketing about our products and features. You can opt out of marketing at any time (see Section 9); service messages about your account continue while you have one.
  • Enforcing agreements. We enforce our Terms of Service and other agreements, and we establish, exercise, and defend legal claims.

Data we handle for Subscribers is different. When we process information on behalf of a Subscriber, including the Customer Data and technical telemetry described in Section 2.2, we use it only to provide the Services under our agreement with that Subscriber: to deliver content, measure usage (including for billing), keep the Services secure, diagnose problems, produce aggregated statistics that do not relate to any individual and improve the Services using those statistics, and comply with applicable law. We do not use it for our own marketing. We do not use this information to build or change a profile about you, and we do not use it to clean or add to data we obtained from any other source.

De-identified and aggregated data. We may create de-identified or aggregated data from the information we collect and use it for lawful business purposes, such as analytics and service improvement. Where we rely on de-identified data, we maintain and use it in de-identified form and do not attempt to re-identify it, except as the law permits in order to test that it remains de-identified. Under the GDPR and its UK equivalent, information counts as Personal Information for as long as an individual can still be singled out from it, whether by us or by anyone else. Where that is the case we treat it as Personal Information and this Policy continues to apply to it, whatever we call it. We use the word “aggregated” for information that no longer relates to any individual.

No surprise purposes. We do not use Personal Information for purposes that are materially different from those described in this Policy. If that ever changes, we will tell you at or before the time we collect the information, as applicable law requires.

If you are in the European Economic Area, the United Kingdom, or Switzerland, Section 11 explains the legal bases we rely on for these uses.

6. AI Features

The Services include AI-assisted features that help Subscribers create and edit content, for example generating landing pages, page sections, images, video, and copy. AI usage is metered through Credits (see Section 5).

What we process. When you use AI features, we process the prompts and other inputs you submit, the content you ask the AI to work with, the output that is generated, and related usage data such as the feature used, tokens consumed, and timestamps. We use this information to deliver the feature, meter and bill Credits, keep the Services secure, and troubleshoot problems.

Our role. Prompts, inputs, the content submitted for the AI to work with, and the output generated are processed on the Subscriber’s behalf: the Subscriber is the controller and Maker is a processor, as Section 2.2 describes. The usage records we keep in order to meter and bill Credits to the Subscriber are handled for our own account-management purposes, where Maker is the controller.

Third-party model providers. We rely on third-party AI model providers to power some AI features. Your prompts, inputs, and content may be transmitted to those providers so they can generate the requested output. Our current model providers are Anthropic, OpenAI, Google Gemini, fal.ai, xAI, and BytePlus/ByteDance Ark. fal.ai in turn routes some requests to downstream models it hosts, for example third-party video-generation models. These providers appear on the list of Services subprocessors described in Section 7.

Your content stays yours. As between Maker and the Subscriber, the Subscriber owns the content it submits and the output generated for it. The Subscriber’s agreement with us, our Terms of Service or a negotiated services agreement, governs ownership and permitted uses of that content. If you use the Services through a Subscriber, your agreement with that Subscriber governs your rights in that content.

Training. We do not use Customer Data, identifying telemetry, prompts, inputs, or content (including AI Output) to train, fine-tune, or otherwise improve any artificial-intelligence or machine-learning model, or any generally available product, without the Subscriber’s written consent. We do not sell or license that information to anyone else for that purpose, and we do not authorize human review or annotation of it for that purpose.

Our model providers. When we engage a third-party AI model provider we require either a contractual prohibition on training with your inputs and content or an enabled opt-out from that training, and we will not knowingly engage a provider that offers neither. If we find that a provider has trained on your inputs or content, we will notify affected Subscribers and either remediate the issue or replace the provider.

We may use aggregated usage data, for example feature-adoption and Credit-consumption statistics, to operate, secure, and improve the Services.

7. How We Share Information; Storage and International Transfers

We do not sell Personal Information for monetary consideration. U.S. state privacy laws define “sale” and “sharing” more broadly than that: in most states a disclosure made for other valuable consideration is also a sale, and a disclosure for cross-context behavioral advertising is “sharing.” We address those definitions at the end of this section, and none of our arrangements fall inside them.

A note on data we handle for our customers. For Personal Information we process on behalf of Subscribers, the Customer Data and technical telemetry described in Section 2.2, we disclose it only to the Subscriber it relates to, to the subprocessors described below, and as our agreements with Subscribers or applicable law permit or require. We do not sell or share that information, as U.S. state privacy laws define those terms, and we do not retain, use, or disclose it outside our direct business relationship with the Subscriber or for any purpose other than providing the Services, complying with law, or producing aggregated or de-identified statistics. Forms embedded in Maker-served content submit End-User data directly to the destination or destinations the Subscriber configures. Maker does not receive or store form-submission content, so we have no form-submission content to share with anyone.

The rest of this section covers information for which Maker is the responsible party (the “controller” or “business”): information about visitors to our Websites, our account holders, and the people we market and sell to. We share that information with the following categories of recipients.

Service providers and subprocessors. Vendors that perform services for us, in these categories:

  • hosting and infrastructure;
  • content delivery;
  • databases and caching;
  • secrets management for customer integration credentials;
  • media processing and delivery;
  • search;
  • AI tracing, logging, and observability;
  • payment processing;
  • identity and sign-in;
  • customer support;
  • email and SMS delivery;
  • analytics and consent management (named in Section 4);
  • session replay (named in Section 4);
  • error and performance monitoring; and
  • the AI model providers named in Section 6.

Our payment processor. Subscription payments are processed by Stripe. Stripe is not a typical service provider: under its data processing terms it acts as our processor for some of its services and as an independent controller for others, for example fraud prevention, financial compliance, and its obligations to card networks and financial partners. Stripe’s own privacy policy describes how it handles information in that independent role.

Professional advisers. Lawyers, accountants, and other professional advisers, where reasonably necessary to obtain advice or to protect our legal rights.

Legal process, safety, and law enforcement. We may disclose Personal Information if we reasonably believe disclosure is required by law, regulation, or legal process (for example, a court order or subpoena); to respond to lawful requests from public authorities, including law enforcement; or where necessary to detect, investigate, or prevent fraud, abuse, security incidents, or other harm, to protect the rights, property, or safety of Maker, our Subscribers, End Users, or the public, or to enforce our agreements.

Business transfers. If Maker is involved in a merger, acquisition, financing, reorganization, bankruptcy, or a sale of some or all of our assets, Personal Information may be disclosed to the parties involved (for example, during due diligence) and transferred as part of that transaction. This Policy will continue to apply to your Personal Information until a successor policy takes effect; Section 13 explains how we announce changes.

With your consent or at your direction. We share Personal Information for other purposes when you direct us to or when you give us your consent.

Aggregated and de-identified information. We may share information that has been aggregated or de-identified so that it can no longer reasonably be linked to you. Section 5 describes how we maintain de-identified data, our commitment not to re-identify it, and how the GDPR treats information from which an individual can still be singled out.

Contractual limits on our service providers. Service providers and subprocessors that process Personal Information on our behalf do so under contracts that limit processing to our documented instructions, require confidentiality and appropriate security, and prohibit use of the information for their own purposes.

Customer-selected integrations are different. Subscribers can connect the Services to third-party platforms they choose, for example commerce platforms, design tools, social and advertising platforms, marketing platforms, and embedded video providers. When a Subscriber connects one, data flows to that platform at the Subscriber’s direction and under the Subscriber’s own agreement with that platform. Those providers act for the Subscriber or as independent controllers. They are not Maker’s subprocessors.

Our subprocessor list and notice of changes. We maintain a current list of the subprocessors that process data on behalf of Subscribers in providing the Services, set out in Section 14 of this Policy and published at https://www.maker.co/privacy-policy. Vendors that support Maker’s own business, for example payments, identity, support, and email delivery, are described by category above and are not on that list. We add a subprocessor to the list at least 30 days before it begins processing data we handle on behalf of Subscribers. Where a Subscriber’s agreement with us provides a right to object to a new subprocessor, that agreement governs the grounds for objection, the window for raising it, and the remedy, including any termination of the affected Services. Where a subprocessor must be replaced urgently, we may make the change on shorter notice and will notify Subscribers as soon as reasonably practicable.

Where we store information. Maker is based in the United States, and we primarily store and process Personal Information in the United States. Content that Subscribers publish through the Services is delivered through content delivery networks, which may cache published content at locations closer to End Users.

International transfers. If you access our Websites or the Services from outside the United States, your Personal Information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those of your jurisdiction. Where we transfer Personal Information out of the European Economic Area, the United Kingdom, or Switzerland to a country that is not covered by an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, together with the addendum or equivalent required for transfers from the United Kingdom and from Switzerland. The same safeguards apply where a service provider acting for us processes Personal Information outside the United States, including where a content delivery network caches content at a location closer to the person who requested it. You can contact us (Section 13) to request more information about, or a copy of, the safeguards that apply to a specific transfer (redacted where necessary to protect confidential terms), and Section 11 describes your rights if you are in the EEA, the UK, or Switzerland.

Analytics technologies and state-law “sale” and “sharing.” As described in Section 4, our Websites use analytics and product-analytics technologies that collect identifiers such as cookie IDs, device identifiers, and IP addresses. Every analytics, consent-management, and session-replay provider named in Section 4 acts as our service provider or processor under a contract that limits it to processing on our documented instructions, requires it to give the information the same level of privacy protection the law requires of us, and prohibits it from using the information for its own purposes or combining it with information from other sources. We do not use advertising pixels on our Websites. We do not disclose Personal Information for monetary consideration, and we do not disclose it for cross-context behavioral advertising. You can decline optional analytics at any time through the cookie preference center (Section 9), and Section 10 describes your state-law rights.

8. How Long We Keep Information; How We Protect It

How long we keep information

We keep Personal Information only as long as we need it. Instead of one fixed schedule, we decide retention using these criteria:

  • Active relationship. Whether your account is open, or your organization’s subscription is active.
  • Providing the Services. Whether we need the information to provide the Services and perform our contracts.
  • Legal obligations. Legal, tax, and accounting requirements that oblige us to keep certain records for set periods.
  • Disputes and enforcement. Whether the information is needed to resolve disputes or enforce our agreements.
  • Security and backups. Security needs (for example, investigating abuse) and the cycles on which backups are created and retired.

The periods we apply

Subject to the criteria above and to our agreement with the Subscriber, we apply the following periods:

  • Customer Data and identifying telemetry after termination. After a subscription ends we make Customer Content available for export for 60 days. After that period we delete or de-identify Customer Data and any telemetry that identifies the Subscriber or its users, except where we must keep it to comply with law or to establish, exercise, or defend legal claims. Residual copies in backups expire on the backup cycle described below.
  • Product analytics and telemetry. We retain product-analytics events for no longer than seven years. This period is a maximum for active accounts. For a terminated account, identifying telemetry is deleted or de-identified on the post-termination clock stated above, whether or not seven years have passed.
  • AI tracing records. We retain AI tracing records for 14 days.
  • Server logs. We retain server logs for 15 days.
  • Backups. Backup copies are retained for no longer than 7 days.

Data we process for Subscribers. Where a Subscriber’s agreement with us sets a different period, that agreement governs how long we retain Personal Information processed through the Services on that Subscriber’s behalf and how that information is handled when the subscription ends. Forms embedded in Maker-served content submit End-User data directly to the destination or destinations the Subscriber configures. Maker does not receive or store form-submission content, so there is no form-submission content for us to retain or delete (see Section 2).

When retention ends. When we no longer need Personal Information, we delete it or de-identify it. Residual copies may remain in backups until those backups are deleted or overwritten in the ordinary course.

How we protect information

We maintain administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, use, disclosure, alteration, and destruction. The measures below describe our current program.

Separation between accounts. Every record that holds Customer Data carries an identifier for the account that owns it, and every read and every write is filtered by that identifier. The identifier is derived on the server from the authenticated session; it is never taken from anything the browser sends. Background work behaves the same way: queued and scheduled jobs carry the account identifier set by the request that authorized them. Incoming webhooks are authenticated by the sending provider’s signature and resolved to a single account before any data is touched. An export produces only the requesting account’s content.

How that separation is enforced. Account scoping is applied to each query through a dedicated data-access layer rather than left to individual developers. The places where raw database queries bypass that layer are enumerated, and a continuous-integration check fails the build if a new unscoped query is introduced. Loading a record by identifier before its ownership has been checked is prevented at compile time.

Stored files. Keys in object storage are namespaced by an account-scoped prefix plus a random component. Callers pass an object reference, never a path. Ownership is re-checked on every operation. Private objects are served through short-lived signed URLs bound to a single named object.

Caches, search, and content delivery. The account identifier forms part of every cache key that holds Customer Data, and cache invalidation is per account. Search records are held in a separate index for each account rather than in one shared index; Maker AI uses no external search index. Our content delivery network caches only publicly published content and static assets. Authenticated responses containing Customer Data are not cached at the edge.

Who can reach Customer Data. Access is role-based and limited to a named list of people. Support access is granted through a list held in version-controlled source code, so adding a person is a change that has to be reviewed and merged. Administrative access is a per-user flag in our identity provider and requires multi-factor authentication. Neither support access nor administrative access is granted by holding a deployment credential.

Audit logging. We log administrative and support access to Customer Data: who acted, what they did, which account and which record, and when. Reads are logged as well as changes, and in Pages the prior values are retained when a record is changed.

In transit. We encrypt data in transit using Transport Layer Security (TLS).

At rest. Our production databases encrypt data at rest using AES-256, and database backups are held in encrypted storage.

Your account. You play a part in keeping your information safe. Use a strong, unique password, keep it confidential, and sign out after using a shared device. If you believe your account has been compromised, contact us right away at support@maker.co.

If a breach happens. If a breach of security affects your Personal Information, we will notify you and the relevant supervisory authorities where and when applicable law requires, and within the time limits that law sets. Where we act as a processor for a Subscriber, we notify that Subscriber without undue delay after we confirm the incident, and the Subscriber decides what notice its End Users and its supervisory authority receive.

No system is perfectly secure. We work to protect your information, but no method of transmitting or storing data is completely secure, and we cannot guarantee its security.

9. Your Choices and Controls

You have choices about how we collect, use, and keep your information. This section covers the everyday controls. Your legal rights, including access, deletion, and correction rights under U.S. state privacy laws and the GDPR, are described in Section 10 and Section 11.

Your account. If you have a Maker account, you can review and update your account and profile information in your account settings.

Deleting your account. To close your account or request deletion of the Personal Information associated with it, email us at privacy@maker.co. We do not offer an in-product deletion control; we handle these requests manually. We will act on deletion requests. We may keep some information where the law allows or requires it, for example to meet legal, tax, and accounting obligations, to resolve disputes, to keep our systems secure, or to establish or defend legal claims; Section 8 describes how we decide. If you are in the European Economic Area, the United Kingdom, or Switzerland, the grounds on which we may keep information despite an erasure request are the ones the GDPR sets out, and we will tell you which one we are relying on.

Email preferences. Every marketing email we send includes an unsubscribe link. Use it, or email us at privacy@maker.co, and we will stop sending you marketing messages. We will still send non-promotional messages you cannot opt out of while you hold an account, for example billing receipts, security alerts, and notices about the Services.

Cookies. You can accept or reject non-essential cookies at any time through our cookie preference center, provided by OneTrust. Your browser also lets you block or delete cookies; see its help menu for instructions. If you block or clear cookies, parts of our Websites may not work as intended, and opt-outs that rely on cookies may be lost, so you may need to set them again. Section 4 describes the cookies and analytics technologies we use.

Global Privacy Control. Some browsers and extensions can send a Global Privacy Control (GPC) signal, which communicates an opt-out preference automatically. Because we do not sell Personal Information and do not share it for cross-context behavioral advertising, there is no sale or sharing for a GPC signal to opt out of. You can decline optional cookies and analytics technologies at any time through the cookie preference center.

Opting out of “sale” or “sharing.” Section 10 explains your right under U.S. state privacy laws to opt out of the “sale” or “sharing” of Personal Information, and why it does not apply to us.

If you do not have an account. Email us at privacy@maker.co to ask us to review, update, or delete Personal Information we hold about you. We may take reasonable steps to verify your identity before acting on a request. We do not verify identity for opt-out requests.

If you are an End User of a Subscriber’s service. If a Subscriber collected your information using Maker, for example through a form or content embedded on that Subscriber’s website, that Subscriber, not Maker, decides how your information is handled. Send your request to that Subscriber directly. Section 2 explains our role and how we will reasonably assist.

10. U.S. State Privacy Rights (California and Other States)

This section supplements the rest of this Policy. It applies if you are a resident of California or another U.S. state with a comprehensive privacy law, and it describes rights under the CCPA and similar laws.

Scope: our role matters. This section covers Personal Information we handle as a “business”: information about visitors to our Websites, our account holders, and the people we market and sell to. When we process information as a service provider or processor on behalf of the Subscribers that use our Services, for example the Customer Data and technical telemetry described in Section 2.2, the Subscriber that collected your information is responsible for responding to your request. Contact that Subscriber directly; we will assist it as the law and our agreements require (Section 2).

What we collect, where it comes from, and how we handle it. The table below shows the categories of Personal Information (as the CCPA defines them) that we have collected in the 12 months before this Policy’s “Last Updated” date. Section 3 describes what we collect in more detail. The retention column repeats the periods stated in Section 8.

Notice at collection. This table, read with Sections 3, 5, 7, and 8, is our notice at collection under California law, and we link to it from the pages where we collect Personal Information.

CategoryWhat we collectWhere we get itWhy we use itWho receives itHow long we keep it
Identifiers (including customer-records information)Name, email address, telephone number, username, business and billing contact details, IP address, device identifiersYou (registration, forms, purchases, support); your devices, automatically; single sign-on providers you connect (Section 3); the Subscriber that gives you access to the Services (Section 3)Providing and operating the Services; account setup; billing; support; security and fraud prevention; service and marketing communications (opt out, Section 9); legal complianceHosting and infrastructure, databases and caching, payment processing, identity and sign-in, customer support, and email and SMS delivery providers; analytics, consent management, and session-replay providers (Section 4); AI tracing, logging, and observability providers; error and performance monitoring providers; professional advisers; authorities where required (Section 7)While your account or your organization's subscription is active, then for the post-termination period stated in Section 8, and afterward only as needed for legal, tax, and accounting obligations, dispute resolution, enforcement of agreements, and backup cycles (Section 8)
Commercial informationSubscription details, purchase and transaction history, billing records; payment card details are collected by our payment processor (Section 3)You; our payment processorBilling and account management; records and accounting; support; enforcing agreements; legal compliancePayment processing, hosting, and infrastructure providers; professional advisers (Section 7)For the life of your subscription and afterward as needed for legal, tax, and accounting obligations and dispute resolution (Section 8)
Internet or other electronic network activity informationPages viewed, referring URLs, browser and operating system details, language preferences, usage and session activity on our Websites, server logs, cookie and similar identifiers (Section 4)Your devices and browsers, automatically; our service providers (for example, email vendors reporting message opens and clicks, Section 3.3)Operating, securing, and debugging the Services; measuring usage and performance; analytics and product improvementAnalytics and product-analytics providers (Google Analytics 4, Ahrefs Analytics, PostHog, Mixpanel); session-replay providers; consent management (OneTrust); AI tracing, logging, and observability providers; hosting, infrastructure, and content-delivery providers; error and performance monitoring providersFor the product-analytics and telemetry, server-log, and backup periods stated in Section 8
Professional or employment-related informationJob role or title and company affiliationThe Subscriber that gives you access to the Services (Section 3)Providing and operating the Services; account administration; business-to-business sales and marketing (opt out, Section 9)Service providers in the categories listed in Section 7; professional advisers where needed (Section 7)While your account or your organization's subscription is active, then for the post-termination period stated in Section 8, and afterward only as needed for legal, tax, and accounting obligations, dispute resolution, enforcement of agreements, and backup cycles (Section 8)
Sensitive personal informationAccount log-in credentials in combination with a password; and credentials that allow access to an account, such as API keys and OAuth tokens for third-party platforms you or your organization connect to the ServicesYou, at registration; you or your organization, when you connect a third-party platform to the ServicesAuthenticating you and securing your account; operating the connection you asked for, nothing elseThe hosting, infrastructure, identity, and secrets-management providers that operate our systems (Section 7)While your account or your organization's subscription is active, then for the post-termination period stated in Section 8, and afterward only as needed for legal, tax, and accounting obligations, dispute resolution, enforcement of agreements, and backup cycles (Section 8)

Sensitive personal information. California law treats an account log-in in combination with a password, and other credentials that allow access to an account, as “sensitive personal information.” We collect two kinds: the credentials you set when you register, and the credentials you or your organization supply when you connect a third-party platform to the Services. We use registration credentials only to authenticate you and secure your account. We use connected-platform credentials only to operate the connection you asked for. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use or disclose it for any purpose outside those the law permits without a “Limit the Use of My Sensitive Personal Information” control, so no such control is required. Session replay masks text inputs, text areas, and dropdown selections, and excludes password, hidden, and payment-card fields from capture entirely, so it does not record credentials or payment data.

Do we “sell” or “share” Personal Information? No. We do not sell Personal Information in exchange for money or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law and comparable laws in other states. We have not done so in the twelve months before this Policy’s Last Updated date. Because we do not sell or share Personal Information, no “Do Not Sell or Share My Personal Information” link is required, and none is provided.

We do not sell or share the Personal Information of any consumer, including any consumer under 16. Some state laws prohibit selling a known minor’s Personal Information or using it for targeted advertising outright, and we follow those laws.

Your rights. Subject to certain conditions and exceptions, you have the right to:

  • Know and access. Ask us to disclose the Personal Information we have collected about you, the categories of sources, our purposes, and the categories of recipients, and receive a copy of your Personal Information in a portable, readily usable format. By default this covers the 12 months before your request; you may ask us to go back further for information collected on or after January 1, 2022, where the law provides.
  • Delete. Ask us to delete the Personal Information we have collected from you, subject to the exceptions the law allows (for example, records we must keep for legal, security, or accounting reasons).
  • Correct. Ask us to correct inaccurate Personal Information.
  • Opt out of “sale” or “sharing.” You have this right, but it does not apply to us: as stated above, we do not sell Personal Information and we do not share it for cross-context behavioral advertising.
  • Limit sensitive personal information. You have this right where a business uses or discloses sensitive personal information to infer characteristics about you, or for purposes beyond those the law permits without a limit-use control. We do neither, so no separate control is required.
  • Non-discrimination. We will not deny you services, charge you a different price, or provide a different level of quality because you exercised any of these rights.

How to exercise your rights. Email us at privacy@maker.co with “California Privacy Request” in the subject line, and tell us which right you want to exercise. We act on a clear request however it reaches us, even if it does not use a subject line we suggested.

  • Verification. For access, deletion, and correction requests, we will verify your identity, for example by asking you to respond from the email address associated with your account or to provide information that matches our records. If we cannot verify your request, we will tell you why.
  • Authorized agents. You may use an authorized agent to submit a request. For requests to know, delete, or correct, we will ask the agent for your signed permission, and we may ask you to verify your identity with us or to confirm directly with us that you gave permission. We will not ask for either of those if the agent holds a power of attorney from you under California Probate Code sections 4000 to 4465. For opt-out requests, we will ask the agent only for written permission from you: we will not ask you to verify your identity and we will not ask you to confirm the request separately.
  • Timing and cost. We will confirm receipt of your request and respond within 45 days. If we need up to 45 additional days, we will tell you and explain why. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

“Shine the Light.” Under California Civil Code section 1798.83, California residents may request details about Personal Information disclosed to third parties for those parties’ own direct-marketing purposes; we do not disclose Personal Information to third parties for their own direct-marketing purposes.

Content removal for California minors. If you are a California resident under 18 and a registered user, you can ask us to remove content or information you posted on our Websites by emailing privacy@maker.co and telling us where it is posted. We will remove it from public view or anonymize it as the law requires. Removal may not be complete or comprehensive; for example, copies may remain in backups or in content reposted by others.

Other U.S. states. If you live in Virginia, Colorado, Connecticut, Texas, or another state with a comprehensive privacy law, you may have similar rights, including access, correction, deletion, portability, and the right to opt out of targeted advertising, “sales,” and certain profiling. Depending on your state, you may also have the right to a list of the specific third parties to which we have disclosed your Personal Information, and the right to question the result of a decision made about you by automated profiling and to be told the reason for it. If you live in Oregon or Minnesota, ask us for the specific-third-parties list and we will provide it. We will honor rights requests as required by the law that applies to you; submit them the same way as California requests, above. If we deny your request and your state’s law gives you a right of appeal, you may appeal by replying to our response or by emailing privacy@maker.co with “Privacy Appeal” in the subject line. We will respond to an appeal within 60 days of receiving it, and our response will explain in writing the reasons for our decision. If we deny the appeal, we will give you a way to submit a complaint to your state’s attorney general, including a link where one is available.

11. EEA, UK, and Swiss Privacy Rights (GDPR)

This section applies if you are in the European Economic Area, the United Kingdom, or Switzerland. It describes rights under the GDPR (see Section 1) and the Swiss Federal Act on Data Protection; in this section, “Personal Information” means the same thing as “personal data” under those laws.

Who is responsible for your information. Maker, Inc. is the controller of Personal Information collected through our Websites, marketing, and account registration; our contact details are in Section 13. For Personal Information processed in the Services on behalf of Subscribers, including the Customer Data and technical telemetry described in Section 2.2, the Subscriber is the controller and Maker is a processor. In that case, direct your request to the Subscriber whose website or content you interacted with; we will assist as our agreements and the law require (Section 2).

Our legal bases. We process Personal Information only where we have a legal basis to do so:

PurposeLegal basis
Providing and operating the Services; creating and managing accounts; billing; supportPerformance of a contract
AI features: generating output from prompts, inputs, and content, and keeping the usage records we bill Credits against (Section 6)Performance of a contract, for our own account holders. Where the prompts, inputs, and content belong to a Subscriber, the Subscriber is the controller and decides the basis (Sections 2.2 and 6)
Securing and improving the Services; preventing fraud and abuse; measuring performance; communicating with business contacts; enforcing agreements and establishing or defending legal claimsLegitimate interests (ours or our Subscribers’), balanced against your interests and rights. You can object, as described below
Non-essential cookies and similar technologies (Section 4); marketing where the law requires consentConsent. You can withdraw it at any time
Session replay of interactions with our Websites (Section 4)Consent, given through our cookie preference center. You can withdraw it at any time
Keeping tax and accounting records; responding to lawful requests (Section 7)Legal obligation

Where a purpose above rests on consent, we ask for your consent before the technology runs and we stop when you withdraw it.

Your rights. Subject to certain conditions and exceptions, you have the right to:

  • Access. Ask whether we process your Personal Information, receive a copy of it, and be told the purposes, the categories of information, how long we keep it, where it came from, and who receives it. If you ask us to identify the individual recipients rather than the categories, we will do that unless we are unable to identify them.
  • Rectification. Have inaccurate Personal Information corrected and incomplete Personal Information completed.
  • Erasure. Have your Personal Information deleted in certain circumstances, for example when it is no longer needed for the purposes it was collected for.
  • Restriction. Have processing of your Personal Information restricted in certain circumstances, for example while we verify its accuracy or consider an objection.
  • Portability. Receive the Personal Information you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Objection. Object to processing based on legitimate interests. Where you object to direct marketing, the right is absolute: we will stop.
  • Withdrawal of consent. Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Automated decisions. Where a decision about you is made solely by automated means and has legal effects for you or similarly significant effects, ask for human involvement, put your point of view to us, and contest the decision.
  • Complaint. Lodge a complaint with a supervisory authority: your local data protection authority in the EEA, the Information Commissioner’s Office in the UK, or the Federal Data Protection and Information Commissioner in Switzerland. We would welcome the chance to address your concern first: contact us as described in Section 13.

Automated decision-making and profiling. We do not make decisions about you solely by automated means that have legal effects for you or similarly significant effects. Our AI features generate content at a user’s request; they do not decide anything about you. We do not use the information described in this Policy to build advertising profiles about you, and we do not buy business information about you from an identity-resolution provider.

How to exercise your rights. Email us at privacy@maker.co. We may need to verify your identity before acting on your request. We will respond within one month of receiving your request. If your request is complex, or if you have made a number of requests, we may take up to two further months; we will tell you within that first month if we need to, and why. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

International transfers. We are based in the United States and process Personal Information there. Section 7 states the safeguards we rely on when Personal Information is transferred out of the European Economic Area, the United Kingdom, or Switzerland, how they apply to service providers acting for us outside the United States, and how to request a copy of them.

12. Children's Privacy

Our Websites and Services are built for businesses and their teams. They are not directed at children, and we do not knowingly collect Personal Information from children under 13. If we learn that we have collected Personal Information from a child under 13, we will delete it in accordance with applicable law. If you believe a child under 13 has provided us Personal Information, contact us at privacy@maker.co. California residents under 18 have the content-removal right described in Section 10.

13. Changes to This Policy; Language; How to Contact Us

Changes to this Policy. We may update this Policy from time to time as our Services, our vendors, or our legal obligations change. When we do:

  • We will post the updated Policy on our Websites and revise the "Last Updated" date at the top.
  • If the changes are material, we will give you more prominent notice before they take effect, for example a notice on our Websites.
  • We review this Policy at least once every 12 months and update it, including the "Last Updated" date and the categories, sources, recipients, and 12-month lookback in Section 10, whether or not anything else has changed.

We encourage you to review this Policy from time to time so you stay informed about how we handle your information.

English language controls. This Policy is written in English, and we may translate it into other languages for convenience. If a translated version conflicts with the English version, the English version controls to the fullest extent permitted by applicable law.

How to contact us. If you have a question, concern, or request about this Policy or about how we handle your Personal Information, contact us:

  • Email: privacy@maker.co, with "Privacy Inquiry" in the subject line.
  • Mail: Maker, Inc., Attn: Privacy, 548 Market St PMB 35672, San Francisco, CA 94104-5401, United States.

To help us respond, tell us who you are, how to reach you, and what you are asking us to do.

If your question concerns information that one of our Subscribers collected from you, for example through a form or content on that Subscriber’s website, please contact that Subscriber first. Section 2 explains why, and how we will assist. If you are in the EEA, the UK, or Switzerland, you can also contact your local data protection authority, as described in Section 11.

Effective date. This Policy takes effect on the “Last Updated” date shown at the top and replaces all earlier versions of the Maker Privacy Policy.

14. Services Subprocessors

Maker, Inc. uses a small set of third-party service providers to run the Services. This Section lists the ones that sit in the processing chain for data we handle on behalf of our customers, meaning data that reaches a provider because a customer uses Maker AI or Pages, or because content a customer published through the Services is being served.

This is a narrower list than a full vendor inventory, and that is deliberate. Vendors that support Maker’s own business, for example billing, customer support, marketing email, and our own website tooling, are not listed here unless they also sit in that processing chain. Third-party platforms a customer chooses to connect to the Services are also not listed here: those receive data at the customer’s direction, under the customer’s own agreement with that platform, and they are not Maker’s subprocessors.

This is the current subprocessor list referred to in Section 7 of this Policy and in our customer agreements. “Changes to this list” at the end of this Section explains how additions are notified and what a customer can do about one.

Location and transfers

Where we store and process information, and the transfer mechanisms we rely on, are described in Section 7. In addition, on request to privacy@maker.co we will tell a customer where a given subprocessor processes data we handle on that customer’s behalf, and which transfer mechanism we rely on for it.

Infrastructure, hosting, and delivery

VendorPurposeCategory of data received
Amazon Web ServicesCloud infrastructure and file and object storageApplication databases; stored files and media; logs; request and IP metadata
Salesforce (Heroku)Application hostingApplication databases; cache data; logs; request metadata
VercelApplication hosting and edge deliveryRequest, IP and device metadata; application content; account records; media
CloudflareContent delivery, edge storage, and media deliveryRequest and IP metadata; edge-stored content and media; domain configuration
FastlyContent deliveryRequest and IP metadata; cached content; domain configuration
Google CloudCloud infrastructure, application services, and data warehousingWarehoused application and analytics data; stored content and media; identifiers

Databases and caching

VendorPurposeCategory of data received
UpstashManaged Redis and cachingCached account and session data; cached content; identifiers
NeonManaged PostgresAccount and authentication records; content and media metadata

Identity and sign-in

VendorPurposeCategory of data received
ClerkIdentity, sign-in, and access tokens for Subscriber accounts and administratorsName; email address; sign-in identifiers and authentication data; organization membership and role

Clerk covers people who sign in to Maker: our Subscribers, their Authorized Users, and our own administrators. Visitors to content published through the Services are not signed in and are not identified to Clerk.

Secrets management

VendorPurposeCategory of data received
HashiCorp (HCP Vault)Storage of credentials for customer-configured integrationsCustomer API keys; OAuth tokens; integration credentials

Media processing and delivery

VendorPurposeCategory of data received
CloudinaryImage and video processing and deliveryImages and video; source URLs; request and IP metadata
ImgixImage transformation and deliveryImage URLs; transformation parameters; request metadata

Search

VendorPurposeCategory of data received
UpstashProduct catalog search indexing and query servingIndexed product catalog records; search queries

Each store’s catalog is held in its own search index rather than in a shared one. The records in it are product catalog fields: product and variant names and descriptions, brands, SKUs, prices, product types, and tags. Maker AI uses no external search index.

AI model providers

VendorPurposeCategory of data received
AnthropicAI modelsPrompts; conversations; submitted files and content; generated output
OpenAIAI models, including image and content generationPrompts; uploaded and reference images; generated output
Google GeminiAI modelsPrompts; conversations; images; generated output
fal.aiHosted media-generation modelsPrompts; input and output media; source URLs
xAIAI modelsPrompts; conversations; generated output
BytePlus / ByteDance ArkVideo-generation modelsPrompts; input and output media; source URLs

fal.ai routes some requests to downstream models it hosts.

Section 6 describes what these providers may and may not do with customer prompts and content.

AI tracing and observability

VendorPurposeCategory of data received
LangSmith (LangChain)Tracing and evaluation of AI requests in Maker AITraces; prompts and messages; tool calls; evaluation data

Product analytics and session replay

VendorPurposeCategory of data received
PostHogProduct analytics across the Services and published contentOnline identifiers; page and embed identifiers; feature and usage events; device information; URLs
Heap AnalyticsProduct analytics in the Maker Pages application and editorUser, visitor, and session identifiers; current and previous page paths; page title; browser information
FullStorySession replay in the Maker Pages editor, for support and diagnosticsInteraction events; the content being edited in the authoring canvas; signed-in user identifier, name, and email address
Microsoft ClaritySession replay in the Maker AI editor, for support and diagnosticsInteraction events; the content being edited in the authoring canvas; signed-in user identifier, name, and email address
MixpanelUsage analyticsUsage events; account and user identifiers

Session replay is not enabled on content published through the Services. Form field values are masked before capture, and password, hidden, and payment-card fields are excluded entirely. The one category of content captured is what a Subscriber is working on in the authoring canvas, including drafts that have not been published, which is why the session-replay providers appear on this list.

Where a Subscriber has installed its own analytics instance, we forward events to that Subscriber’s own account. Those providers act for the Subscriber, not as our subprocessors, and are not listed here.

Error and performance monitoring

VendorPurposeCategory of data received
RollbarError monitoringError and exception reports; stack traces; request context and URLs; user identifiers
BugsnagError monitoringError reports; request and session metadata; device metadata
New RelicApplication performance monitoringTraces; request metadata; database statements; logs
SentryError monitoringError reports; traces; request metadata
SigNozObservabilityLogs and traces; database and cache statements; request metadata
AxiomLog managementLogs; request metadata; application events

Monitoring tools can capture statement arguments, which may include customer content. That is why they are listed here rather than treated as internal operational tooling.

Changes to this list

We keep this list current. We add a Services subprocessor to this list at least 30 days before it begins processing data we handle on behalf of customers. Where we have to replace a subprocessor urgently, for example to address a security, legal, or operational need, we may do so on shorter notice and will notify customers as soon as reasonably practicable.

Where a customer’s agreement with Maker provides a right to object to a new subprocessor, that agreement governs the grounds for objection, the window for raising it, and the remedy. If your organization has no such agreement and requires one, email legal@maker.co for our then-current data processing addendum.

If you would like us to email you when this list changes, email privacy@maker.co with “Subprocessor notice” in the subject line and we will add you to that list.

Questions about this list, or a request for copies of our transfer mechanisms, go to privacy@maker.co.