Privacy Policy
Last updated: June 30, 2026
This policy covers Marshl.ai (the “Service”), operated by Awaire Technologies LLC, a California limited liability company (“Marshl,” “we,” “us”). It explains what we collect, why, who we share it with, and the rights people have over it.
1. Two kinds of people this policy covers
Marshl is a B2B tool: a company (an event planner, a DMC, a corporate travel team, the “Customer”) signs up, and their coordinators upload data about travelers and drivers who never sign up themselves and never see this policy directly. That split matters:
If you’re a Customer (you or your coordinators have a Marshl login): we are collecting your account data directly from you: your name, work email, and how you use the product. For this data, Marshl is the controller: we decide why it’s collected and this policy describes that relationship normally.
If you’re a traveler or driver whose name, flight, or phone number was added to Marshl by an event organizer: your organization is the one who decided to share your information with us. For this data, Marshl is the processor: we act on the organization’s instructions, not our own. If you want your data corrected or removed, start with the organization that added you; we’ll act on their instruction. You can also contact us directly (§10) and we’ll route the request appropriately.
2. What we collect
From Customers (coordinators):
Name, work email, and password (hashed; we never see it in plain text) via Supabase Auth.
Organization name and the events, drivers, pickup groups, and travelers they create.
Basic usage data: what actions were taken in the console and when, kept in an append-only audit log for accountability (who approved/dismissed a recommendation, who invited whom).
About travelers (entered by a Customer, not by the traveler):
Full name, flight number(s) and date(s), origin/destination airport, and which pickup group/shuttle they’re assigned to. Optionally an email, if the Customer provides one.
About drivers (entered by a Customer, not by the driver):
Full name and mobile phone number, used to send SMS notifications and to generate a private, token-gated link showing that driver’s own assigned pickups. Drivers never create an account or a password.
We do not collect: payment card numbers (if Marshl introduces paid billing, a payment processor will handle card data directly; we never store it), government ID numbers, or any data beyond what a pickup coordination actually needs.
Automatically collected: standard web server logs (IP address, browser type, timestamps) for security and debugging. Marshl does not currently use advertising or analytics cookies/trackers. Coordinator sessions are handled via browser storage (not a tracking cookie). If that changes, this policy will be updated first.
3. How we use it
To run the actual service: resolve flight status, detect delays/cancellations, compute pickup timing, and text drivers when something changes.
To generate coordination recommendations using an AI model (see §4, Anthropic). We deliberately send that model only flight and pickup context, not more traveler contact detail than the recommendation requires.
To secure the product: audit logging, rate limiting, fraud/abuse prevention.
To communicate with Customers about their account or the Service (not marketing, unless someone opts in separately).
We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined under state privacy laws like the CCPA. We do not use traveler or driver data for advertising at all.
4. Who we share it with
We use a small number of subprocessors to run Marshl. Each only sees what it needs to do its job:
AWS — Compute, secrets, background flight-polling. App data in transit/processing.
Supabase — Database + coordinator authentication. All tenant data + coordinator credentials.
Vercel — Frontend hosting. No persistent customer data (static site + API proxy).
Twilio — Sends driver SMS notifications. Driver phone numbers + message content.
Anthropic — Powers the coordination-recommendation AI. Flight/pickup context per recommendation only, not raw contact details.
FlightAware (AeroAPI) — Live flight status. Flight numbers + dates (no traveler PII).
FAA / NOAA (public data) — Airport delay programs, weather. Public aviation data only, no PII.
We don’t share data with anyone outside this list without telling you, except when required by law (e.g., a valid subpoena) or to protect the safety of a Marshl user or the public.
On Anthropic specifically: the data we send is not used to train Anthropic’s models. Standard commercial-API inputs and outputs are automatically deleted within 30 days, with a longer retention window only if content is flagged for a legal or policy-violation review.
5. How long we keep it, and deletion
Event data (travelers, pickups, flight watches) is retained for the duration of the event plus a reasonable window afterward for the Customer’s own record-keeping, then eligible for deletion.
A Customer admin can request deletion of their organization’s data at any time.
Audit log entries are append-only and retained longer, since they exist specifically to prove what happened and when. This is disclosed here so it isn’t a surprise.
6. Security
Multi-tenant data is isolated at the database level (Postgres Row-Level Security, not just app code) so one organization’s data is never visible to another. Data is encrypted in transit (TLS) and at rest, secrets are managed centrally rather than stored in code, and every coordinator action is recorded in an append-only audit trail.
We’ll notify affected Customers without undue delay if we become aware of a breach affecting their data.
7. Your rights
Depending on where you’re located, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing, for example under the CCPA/CPRA in California or the GDPR in the EU/UK. Customers can exercise these rights directly in the product (Setup screen) or by contacting us. Travelers and drivers should start with the organization that added them (§1); we’ll support that organization in fulfilling the request.
8. Children’s privacy
Marshl is a business tool, not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we’ve collected a child’s data, we’ll delete it.
9. International use
The Service is operated from the United States. If you or the data an organization submits about you originates outside the U.S., it will be transferred to and processed in the United States, which may have different data protection laws than your country.
10. Contact
Questions about this policy or a privacy request: admin@marshl-ai.com
11. Changes to this policy
We’ll update the “Last updated” date above when this changes, and for material changes we’ll make a reasonable effort to notify active Customers directly rather than relying on a silent page edit.