ManyMuse (“ManyMuse”, the “Service”) is a customer-support operations platform. It connects a merchant’s existing services — such as their storefront, helpdesk, and shipping providers — and surfaces a unified view of a customer’s orders, conversations, and returns to that merchant’s own support agents. This policy explains what data we handle, why, and how we protect it.
Who we are
The Service is operated by Going Marketplaces B.V. (“we”, “us”), the data controller responsible for this policy:
- Controller: Going Marketplaces B.V.
- Registered address: De Nieuwe Erven 3, Unit 10942, 5431NV Cuijk, Netherlands
- Contact: merlijn@commo-dore.com
- VAT: NL860870170B01
- Chamber of Commerce (KvK): 77005848
Who this policy is for
ManyMuse is a business-to-business tool used by a merchant (the “workspace”) and its agents. We process end-customer data on behalf of that workspace, as a data processor, under the workspace’s instructions. Each workspace controls its own data and its relationship with its customers.
Data we handle
- Account data — the email address and role of each agent who signs in.
- Data imported from connected services, only for the workspace that connected them: order and fulfillment details, product and inventory data, customer contact details (name, email, shipping address), and support conversations. This is imported from services the workspace explicitly connects — currently Amazon (Selling Partner API), Shopify, Etsy, OrderDesk, Intercom, SendCloud and ShipStation.
- Operational records — an append-only event log of meaningful actions (for audit), and settings the workspace configures.
Intercom integration
When a workspace connects Intercom, ManyMuse reads support conversations and contact records to identify the customer on the open conversation and display their related orders and returns to the agent. The Intercom sidebar panel is read-only: ManyMuse does not create, edit, or delete Intercom conversations or contacts. We request only the minimum scopes needed for this (reading conversations, and reading/listing users and companies).
How we use data
Solely to provide the service to the workspace that owns it: resolving a customer’s identity across their connected services, displaying their history to agents, and operating support workflows (such as returns). We do not sell data, and we do not use one workspace’s data to serve another. Any AI-assisted features operate only within the workspace’s own data.
How we store and protect it
- Data is isolated per workspace and access is enforced at the database level (row-level security).
- Integration credentials are stored encrypted in a dedicated secrets vault, never exposed to the browser.
- Access is limited to the workspace’s authenticated agents and to cross-customer admin reads that are audited.
Sub-processors
These are the providers that process data on our behalf in order to run the Service. Each is bound by data-processing terms, and each was assessed against data-security standards at least as strict as our own before we shared any data with it. This list is complete and is kept current here rather than supplied on request.
- Vercel — application hosting and edge network. Deployed in the EU (Frankfurt).
- Supabase — managed PostgreSQL database, authentication, and the encrypted secrets vault.
- Anthropic — AI model provider, for optional AI-assisted reply drafting and categorisation. Contractually barred from using the data to train models.
- OpenAI — text embeddings, used for search and retrieval within a workspace’s own data.
- Resend — transactional email delivery (for example, sending a return label to a customer).
That is the complete list. Each is bound by a data processing agreement, and personal data leaving the EU is covered by Standard Contractual Clauses, an adequacy decision, or the EU–US Data Privacy Framework.
What we share, and with whom
Beyond the sub-processors above, we share workspace data with nobody. Specifically: we do not share it with advertisers or data brokers, we do not share one workspace’s data with another workspace, and we do not aggregate data across workspaces to produce or sell insights to anyone. We do not sell data.
The services a workspace connects — Amazon, Shopify, Etsy, OrderDesk, Intercom, SendCloud, ShipStation — are a different relationship: the workspace chooses them, holds its own account with each, and authorises us to read from and write to that account on its behalf. We act on the workspace’s instruction there; we do not disclose one connected service’s data to another except where doing so is what the workspace asked for (for example, generating a shipping label for an order).
Retention and deletion
We retain workspace data for as long as the workspace maintains its account, and delete or anonymize it on request or on account closure, subject to legal retention requirements. A workspace can request export or deletion of its data, including erasure of a specific customer’s records.
Your rights
Depending on your jurisdiction (including under the GDPR), individuals may have rights to access, correct, delete, or restrict processing of their personal data. Because we act as a processor for the workspace, we will direct such requests to the relevant workspace and assist them in responding.
Contact
Questions about this policy or your data, or to reach the data controller (Going Marketplaces B.V.): merlijn@commo-dore.com. For general product support: support@manymuse.com.