Marshl.ai
Last updated: August 18, 2026

Privacy Policy

This policy covers Marshl.ai (the "Service"), operated by Awaire Technologies LLC, a California limited liability company ("Marshl," "we," "us"). It explains what we collect, why, who we share it with, and the rights people have over it.

1. Two kinds of people this policy covers

Marshl is a B2B tool: a company (an event planner, a DMC, a corporate travel team, the "Customer") signs up, and their coordinators upload data about travelers and drivers who never sign up themselves and never see this policy directly. That split matters:

2. What we collect

From Customers (coordinators):

About travelers (entered by a Customer, not by the traveler):

About drivers (entered by a Customer, not by the driver):

We do not collect: payment card numbers (if Marshl introduces paid billing, a payment processor will handle card data directly; we never store it), government ID numbers, or any data beyond what a pickup coordination actually needs.

Automatically collected: standard web server logs (IP address, browser type, timestamps) for security and debugging. Marshl does not currently use advertising or analytics cookies/trackers. Coordinator sessions are handled via browser storage (not a tracking cookie). If that changes, this policy will be updated first.

3. How we use it

We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined under state privacy laws like the CCPA. We do not use traveler or driver data for advertising at all.

4. Who we share it with

We use a small number of subprocessors to run Marshl. Each only sees what it needs to do its job:

SubprocessorPurposeWhat it sees
AWSCompute, secrets, background flight-pollingApp data in transit/processing
SupabaseDatabase + coordinator authenticationAll tenant data + coordinator credentials
VercelFrontend hostingNo persistent customer data (static site + API proxy)
AnthropicPowers the coordination-recommendation AIFlight/pickup context per recommendation, not raw contact details beyond what's needed
FlightAware (AeroAPI)Live flight statusFlight numbers + dates (no traveler PII)
FAA / NOAA (public data)Airport delay programs, weatherPublic aviation data only, no PII

We don't share data with anyone outside this list without telling you, except when required by law (e.g., a valid subpoena) or to protect the safety of a Marshl user or the public.

On Anthropic specifically: the data we send is not used to train Anthropic's models. Standard commercial-API inputs and outputs are automatically deleted within 30 days, with a longer retention window only if content is flagged for a legal or policy-violation review.

5. How long we keep it, and deletion

6. Security

Multi-tenant data is isolated at the database level (Postgres Row-Level Security, not just app code) so one organization's data is never visible to another. Data is encrypted in transit (TLS) and at rest, secrets are managed centrally rather than stored in code, and every coordinator action is recorded in an append-only audit trail.

We'll notify affected Customers without undue delay if we become aware of a breach affecting their data.

7. Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing, for example under the CCPA/CPRA in California or the GDPR in the EU/UK. Customers can exercise these rights directly in the product (Setup screen) or by contacting us. Travelers and drivers should start with the organization that added them (§1); we'll support that organization in fulfilling the request.

8. Children's privacy

Marshl is a business tool, not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we've collected a child's data, we'll delete it.

9. International use

The Service is operated from the United States. If you or the data an organization submits about you originates outside the U.S., it will be transferred to and processed in the United States, which may have different data protection laws than your country.

10. Contact

Questions about this policy or a privacy request: admin@marshl-ai.com

11. Changes to this policy

We'll update the "Last updated" date above when this changes, and for material changes we'll make a reasonable effort to notify active Customers directly rather than relying on a silent page edit.

← Back to Marshl