Privacy Policy
Last updated: September 3, 2026 · Operated by Quine Studios LLC
This Privacy Policy explains what Quine Studios LLC collects when you use Marutap (the "Service"), why, and your choices.
What we collect
- Account data — the username and email you sign up with, and passkeys you register.
- Payment data — we do not store your card number. When you connect a card, it is collected and stored by our payment processor (Stripe); we keep only a token reference, plus non-sensitive details like the card brand, last four digits, and billing ZIP code (used for address verification).
- Transaction data — the purchases you approve: merchant, amount, line items your agent supplied, timestamps, approval method, and status. This powers your dashboard and receipts.
- Technical data — logs and standard request metadata needed to operate and secure the Service.
How we use it
- To present charges for approval, issue scoped cards, and complete the purchases you authorize.
- To show your spending dashboard, send notifications on charges, and enforce your rules and caps.
- To prevent fraud and abuse, and to comply with legal and card-network obligations.
Who we share it with
We share data with service providers that make the Service work — principally Stripe, our payment processor and card issuer, which handles card data and money movement under its own privacy policy. When you approve a charge, the issued card's details are transmitted to your agent so it can complete that purchase; we do not store them. We do not sell your personal information. We may disclose data when required by law or to protect the Service.
Cookies
We use only the cookies needed to operate the Service: a session cookie (to keep you signed in) and a CSRF cookie (to protect forms). We do not use advertising or tracking cookies.
Retention and security
We retain account and transaction records for as long as your account is active and as required for legal, tax, and anti-fraud purposes. Because card data lives with Stripe and each issued card is single-use and purpose-scoped, we minimize the sensitive data we hold. All traffic is encrypted in transit (HTTPS), connect tokens are stored only as hashes, and approvals can be protected with passkeys (WebAuthn).
Your choices
- Access, correct, or delete your account data by contacting us.
- Disconnect a card or revoke connect tokens from your dashboard at any time.
- Cancel auto-approval rules and subscription mandates at any time.
- Depending on where you live (for example, California or the EEA/UK), you may have additional rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Contact us to exercise them; we will not discriminate against you for doing so.
Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
Contact
For privacy requests, see the Contact page.
Questions? Contact us.