Skip to content

Legal

Privacy Policy

Marcantonio Global LLC wrote this policy to say what this website collects, who receives it, and how you can ask to see or delete it.

Last updated

Who we are

This policy covers the public website and the member sign-in on it, operated by Marcantonio Global LLC. Contact about privacy goes through the contact form.

What we collect

What we collect depends on what you use.

  • Contact form. Name, email address, and the message. Company, organization type, capability area, and urgency if you provide them. Some information-request dialogs also ask for an optional phone number and job title. Those optional fields are included in the message we email to our reviewers.
  • Company enrollment. The profile you submit, including the contact name, email address, phone number if you provide one, and the company details on that form.
  • General newsletter. The email address you type into the footer form. When the email service is configured, that address is added to the general newsletter list when the form succeeds. The form does not send a confirmation link before the add. This is not double opt-in.
  • SIN Pro. When paid newsletter signup is available (scheduled for November 9, 2026), the intended flow confirms the email address before the paid subscription starts. That second step is double opt-in. It is not what the footer form does today.
  • Account. The email address you use to sign in, the one-time code we email you, and a signed session cookie. There is no password stored for this site login. When the Nimbus sign-in path is turned on, the application database stores an account identifier, sign-in status, and grant timing for that login.
  • Payment. Card payments will be processed by Stripe. Marcantonio Global LLC does not store full card numbers. When checkout is on, Stripe receives the card number, expiration date, and security code. We may receive a token, the last four digits, the card brand, a billing email, and the payment status. Checkout is not turned on in this repository yet, so the site does not send card numbers to Stripe today.
  • Technical data. The host receives the IP address, browser type, and the page requested in order to deliver the site. Form routes use the IP address only to slow repeated submissions. That counter stays in server memory and is not written to a file.

How we use it

We use this information to:

  • Reply to a contact or enrollment request.
  • Send the newsletter you joined, and the trial, renewal, cancellation, and price-change emails described in the Subscription & Cancellation Policy.
  • Run accounts, trials, and subscriptions, and bill the amounts you agreed to.
  • Limit abuse, such as repeated form posts or a second free trial for the same person.
  • See which public pages are used, through the analytics described below.
  • Do the work named in a statement of work.

Signed-in tools that draft or assess text can send the text you submit to the model provider configured on the server. The server environment names Groq, NVIDIA, and Gemini for that role, and a call happens only when that provider's key is set. Do not submit classified or controlled information. The provider's own terms describe what it keeps.

Processors

These are the processors this repository is set up to use. We do not send your information to a processor that is not listed here for the purpose described.

  • Brevo (Sendinblue). Present. The site uses the Brevo client to send email and to store newsletter and enrollment contacts when BREVO_API_KEY is set. Login codes, contact-form mail, enrollment mail, and the newsletter list go through Brevo.
  • Vercel. Present. Vercel hosts the site. The root layout loads Vercel Web Analytics. This repository does not set a marketing cookie for that component. Pages can also send a first-party event name, such as a contact submission, to /api/analytics. That route writes the event to the server log and does not set a cookie.
  • Stripe. Named for payments, and named in the site content-security policy as allowed hosts (api.stripe.com, js.stripe.com, hooks.stripe.com). The Stripe software package is not installed, and the sample environment file has no Stripe secret. We will use Stripe for card charges. We will not store full card numbers. No card data is sent to Stripe until checkout exists.
  • Model providers, when a signed-in tool is used. The sample environment names Groq, NVIDIA, and Gemini. A tool sends the text you submit only when that provider's key is set. Public marketing pages do not call them.
  • SAM.gov, only if you look up a UEI during company enrollment. We send that identifier to retrieve the public entity record. SAM.gov is a U.S. government source, not a marketing list.

Upstash Redis is described in older deployment notes. It is not a dependency of this repository, and the sample environment file does not configure it. It is not a current processor of personal information for this site.

No sale of personal information

We do not sell personal information. We do not share it for cross-context behavioral advertising. Processors above receive information only to perform the service described.

Cookies and browser storage

The site uses first-party cookies for sign-in and for short checks. They are httpOnly, so page scripts cannot read them. In production the session cookie is sent over HTTPS. This repository does not set an advertising cookie.

  • mg_member_token. Signed member session. It lasts about 8 hours.
  • mg_member_subject. Cleared when a session is issued. It is not used as your identity.
  • mg_login_challenge. Holds the login attempt for about 10 minutes.
  • mg_enrollment_challenge and mg_enrollment_proof. Company-enrollment email check, about 10 minutes, sent only to the enrollment API.
  • Nimbus cookies, only when that sign-in path is on: __Host-mg_nimbus_pending, __Host-mg_nimbus_transaction, __Host-mg_nimbus_email_reauth, and __Host-mg_nimbus_admission. A local development profile uses mg_nimbus_local_ names instead.
  • __Host-mg_presenter or mg_presenter. Presenter pairing, for up to 2 hours, when that feature is on.

The browser also stores a few values in local storage. Those are not cookies.

  • mg-ecosystem-explorer-v1. Progress on the public access-points explorer, on that browser only.
  • mg_company_draft. A draft of the company enrollment form, on that browser only.
  • mg:private:session:v1 and keys starting with mg:private:v1:. Encrypted notes for a signed-in session, on that browser only.
  • mg:jag:scenarios:v1. An older key some browsers may still hold. Current member pages do not read it for member content.

Retention

Contact messages are kept in the mailboxes that receive the form. This site does not add them to a separate contact database. Newsletter and enrollment contacts stored with Brevo stay there until you ask us to delete them or, for the newsletter, until the list removes the address.

Login and enrollment cookies expire on the timers above. The member session cookie expires in about 8 hours. Nimbus sign-in attempts are written to expire within minutes. An approved Nimbus account link stays while the account is active. Ask us if you want that record deleted.

Browser storage stays until you clear it. In-memory rate-limit counters are dropped when the server process restarts.

Your rights, including California

You can ask to see the personal information we hold about you, to correct it, or to delete it. Send the request through the contact form and say it is a privacy request. Use the email address you want us to look up. We may need to confirm that you control that email before we act.

California residents can also ask to know, delete, or correct personal information, and to opt out of sale or sharing, under the California Consumer Privacy Act as amended by the CPRA. We do not sell personal information, and we do not share it for cross-context behavioral advertising, so there is no sale or share to opt out of. We will respond within 45 days. We will tell you if we need the additional time the statute allows. We will not charge a different price because you asked.

You may send the request through an authorized agent. We may ask for proof that the agent is allowed to act for you.

This section describes the requests we will honor. It is not a legal opinion about which statute applies to a given person.

Children

This site is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe we have, write through the contact form and we will delete it.

Security

The site is served over HTTPS. Session cookies are httpOnly. We do not store full card numbers. These measures reduce ordinary exposure. They are not a certification, an Authority to Operate, or a claim that the site meets a government security standard.

Changes

We will change the date at the top of this page when this policy changes. If a change materially expands how we use personal information, we will also say so at the top of this page.

Contact

Privacy requests and questions go through the contact form. We do not publish a separate postal address on this page.

    NINA

    Marcantonio Global’s Defense Acquisition Navigator