Marsa

Privacy Policy

Last updated: August 10, 2026

Overview

Marsa ("we", "our", "the platform") is a customs clearance and freight forwarding management platform operated by Silk Labs, used by logistics companies ("customers", "tenants") to manage their operations, shipments, quotes, finances, and client relationships. This policy explains what data we collect, why, and how it's protected.

Data We Collect

Account & company data: names, emails, phone numbers, and company details you provide when creating an account or being invited to one.

Operational data: customs operations, shipments, quotes, invoices, and client records that your company enters into the platform to run its business.

Connected email accounts: if you choose to connect a Gmail or Outlook account (Settings → Email), we store an encrypted OAuth token so the platform can send email on your behalf and scan recent inbox metadata (sender, subject, and a short snippet — never full message bodies) to flag messages relevant to your operations or clients. You can disconnect an account at any time, which immediately revokes our access.

Government portal credentials: for customers using our Nafeza customs-portal integration, credentials are encrypted at rest and only decrypted server-side for authorized automated lookups.

How We Use Data

Data is used solely to operate the platform for the account holder: displaying dashboards, generating documents, sending transactional notifications (password resets, invitations, status updates), and — where you've opted in — sending email from your own connected account and surfacing relevant inbox matches. We do not sell personal data, and we do not use connected-email content to train any AI model.

Email Account Access (Gmail / Outlook)

When you connect a Gmail or Outlook account, Marsa requests only the minimum access needed:

  • Permission to send email as you (used only when you explicitly trigger a send, e.g. emailing a quote to a client).
  • Permission to read message metadata only — sender, subject, and Gmail's built-in short snippet — never the full message body or attachments.

Message content is never permanently stored. Only a small pointer record (sender, subject, a short snippet, and which operation or client it appears to relate to) is kept, so re-scanning doesn't duplicate work. OAuth tokens are encrypted at rest with a dedicated encryption key, separate from all other stored secrets, and are deleted immediately if you disconnect the account.

Data Sharing

We do not share your data with third parties for marketing purposes. Data may be processed by infrastructure providers strictly to operate the service (hosting, database, file storage, and email delivery), all under standard data-processing terms, and never sold or repurposed by them.

Data Security

Data is encrypted in transit (HTTPS) and sensitive fields (OAuth tokens, government portal credentials) are encrypted at rest. Access to any company's data is scoped to that company's own users; platform administrators access data only for support or security purposes.

Your Choices

You can disconnect a connected email account at any time from Settings → Email. You can request export or deletion of your account's data by contacting us at the address below.

Contact

Questions about this policy or your data: marsa@silk-labs.net