Legal
What we collect, who receives it, how long we keep it, and how to make us stop.
Last updated: 9 September 2026
Marvellous Performance Marketing Agency (“we”, “us”) is the data controller for personal data collected through marvellousperformance.com. We are based in Lagos, Nigeria, and work with clients in Nigeria, Ghana, Uganda, Kenya, the United Kingdom and the United States.
Contact: hello@marvellousperformance.com
What we collect, and why
When you submit a form. Our discovery brief, recruitment brief and mentorship application collect your name, email address, phone number where you give one, your company, and details about your business: revenue band, monthly marketing budget, the channels you use, your goals and timing. We collect this to assess whether we can help you and to reply. Legal basis: steps taken at your request before entering a contract, and our legitimate interest in responding to enquiries.
When you complete the Growth Audit. We collect your name, email, company, optionally a WhatsApp number, the region and business category you select, and your answers to the diagnostic questions. We also record which country your request came from, so we can apply the right privacy rules to what happens next. Your answers produce a score and a written diagnosis, which we email to you. Legal basis: your request for the diagnosis, and consent for the email.
When you subscribe to our newsletter. Your email address and, optionally, your first name. We use double opt-in: nothing is sent until you click a confirmation link, and no address joins the list until you do. Legal basis: consent. You can withdraw it from any email.
When you use our free tools. The UTM builder runs entirely in your browser and sends nothing to us. The break-even ROAS, CAC payback and ad waste tools are the same — nothing you type leaves your device. The Landing Page Check is different: it sends us the web address you enter, fetches that page once, and stores what it found so you have a shareable link. We do not associate it with you.
When you use the assistant (Damiti). Your name, email, an optional WhatsApp number, and your answers to three questions about your business. Legal basis: your request to be contacted.
When you visit the site. Analytics only if you allow it. See our cookie policy. We record your consent choice, the country your request came from and the page you were on, against a random identifier that tells us nothing about you.
What we do not collect
We do not collect special category data. We do not buy personal data from third parties. We do not use fingerprinting, session recording or heat mapping.
Our free tools are free with no email gate. We do not require an account or an address to use them.
Who we share it with
We use these processors. Each receives only what it needs.
| Processor | What it receives | Where |
|---|---|---|
| Supabase | Everything above, stored in our database | EU (Paris) |
| Vercel | Hosting; requests to the site | EU/global edge |
| Resend | Your email address and the content of emails we send you | EU (Ireland) |
| Cal.id | Your name and email when you book a call | Per their policy |
| Google Analytics 4 | Site usage, only with your consent | |
| A one-way hash of your email for conversion measurement, only with consent and only if you are outside the UK and EU; and, if you allow marketing cookies, the LinkedIn Insight Tag |
On LinkedIn specifically. When someone completes an audit, submits a brief or books a call, we may tell LinkedIn that a conversion happened so we can measure our advertising. We send a one-way hash of the email address, never the address itself. We do not do this for visitors in the UK or the EU, because we do not yet have a consent mechanism that would make it lawful there. Those conversions are recorded as skipped and never sent.
Separately, if you allow marketing cookies we load the LinkedIn Insight Tag, which tells LinkedIn you visited. That is covered by your cookie choice and you can withdraw it at any time from Cookie settings.
We do not sell personal data.
International transfers
Our database and email provider are in the EU. Vercel serves the site from edge locations worldwide. Google and LinkedIn are US-based and process data under their own transfer mechanisms.
How long we keep it
We keep personal data only as long as the purpose we collected it for requires. These are the periods we work to.
| Data | Retention | Why |
|---|---|---|
| Discovery, recruitment and mentorship briefs | 24 months | From your last contact with us. A retainer decision at our price point commonly takes six to eighteen months, and enquiries frequently resume after a gap |
| Growth Audit submissions | 24 months | Then your identifying details are deleted. The follow-up sequence runs 21 days; the longer period covers a realistic sales cycle |
| Anonymised audit scores | Kept indefinitely | With nothing identifying attached. Benchmarking each result against comparable businesses needs history. Once name, email and company are removed the record identifies nobody |
| Assistant (Damiti) leads | 24 months | From your last contact. Same reasoning as the briefs |
| Newsletter subscribers | Until you unsubscribe | Consent lasts until withdrawn |
| Record that you unsubscribed | Indefinitely | We cannot honour an unsubscribe if we delete the record of it. This record holds your address and nothing else, and exists solely to keep us from contacting you again |
| Landing Page Check results | 12 months | The result is about a website, not a person. Shared links keep working for a year |
| Consent records | 24 months | We must be able to show consent was given for as long as we rely on it, and consent this old should be refreshed anyway |
| Email delivery logs | 12 months | To investigate a message that did not arrive |
| LinkedIn conversion records | 12 months | These hold a one-way hash of an email address, never the address |
| Rate-limiting records | 24 hours | Deleted automatically. Only to stop abuse of our free tools |
If you ask us to delete your data we will do so, subject to anything we are required to keep by law.
Your rights
If you are in the UK or EU, you have the right to access your data, correct it, have it erased, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent at any time. Withdrawal does not affect what was lawful before it.
If you are in Nigeria, the Nigeria Data Protection Act 2023 gives you substantially the same rights.
To exercise any of them, email hello@marvellousperformance.com. We respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ico.org.uk) in the UK, your national supervisory authority in the EU, or the Nigeria Data Protection Commission (ndpc.gov.ng) in Nigeria.
Security
Data is stored in Supabase with row-level security enabled and no public access. Only authorised administrators can read it. Newsletter confirmation tokens are stored as hashes, never in plain form. Where we send an email address to LinkedIn it is hashed one-way first. Rate-limiting records store a keyed hash of the visitor’s IP address rather than the address itself.
Changes
We will update this page when what we collect changes, and update the date at the top. Material changes affecting what you consented to will trigger a fresh consent request.

