Compliance
Legal & compliance
Review our legal documents and compliance policies governing your use of MerchantFlow.
Privacy Policy
Effective Date: December 27, 2025
Last Updated: December 27, 2025
1. Introduction
MerchantFlow ("we," "our," or "us") provides a SaaS platform for ecommerce merchants to analyze product-level profitability across advertising channels. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services at merchantflow.ai (the "Service").
By using MerchantFlow, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Company name
- Password (encrypted)
- Billing information (processed by Stripe)
2.2 Integration Data
When you connect third-party services via OAuth, we collect and store:
- Google Ads: Campaign metrics, ad spend, product performance data, customer account IDs
- Google Analytics 4: Website traffic, conversion data, user behavior metrics
- Google Search Console: Search queries, impressions, click-through rates
- Google Merchant Center: Product feed data, listing issues
- Shopify/WooCommerce: Product catalog, orders, revenue, inventory
- Meta Ads: Campaign performance, ad spend, account IDs
2.3 Usage Data
We automatically collect:
- Log data (IP address, browser type, pages visited)
- Device information
- Usage analytics (features used, time spent)
- Error logs and performance metrics
2.4 OAuth Tokens
We store OAuth access tokens and refresh tokens to maintain connections to your integrated services. These tokens are encrypted at rest using AES-256 encryption.
3. How We Use Your Information
We use collected information to:
- Provide and maintain the Service
- Sync and display analytics data from your connected platforms
- Calculate product-level profitability metrics
- Process payments and manage subscriptions
- Send service notifications and updates
- Provide customer support
- Detect and prevent fraud or abuse
- Improve and optimize our Service
- Comply with legal obligations
We will never sell your data to third parties or use your business data for advertising purposes.
4. Data Sharing and Disclosure
4.1 Service Providers
We share data with trusted service providers:
- Stripe: Payment processing (subject to Stripe's Privacy Policy)
- Cloud Infrastructure: AWS/GCP for hosting and storage
- Email Services: Mailjet for transactional emails
4.2 Legal Requirements
We may disclose your information if required by:
- Legal process (subpoena, court order)
- Government requests
- Protection of our rights or safety of others
- Investigation of fraud or security issues
4.3 Business Transfers
If MerchantFlow is acquired or merged, your information may be transferred to the new entity. You will be notified of any such change.
5. Data Storage and Security
5.1 Storage Location
Data is hosted on OVH cloud infrastructure in Canada. MerchantFlow is operated from Adelaide, South Australia. International users' data may be transferred and processed in Canada.
5.2 Security Measures
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-tenant database isolation
- Regular security audits and penetration testing
- Role-based access controls
- Automated backups with encryption
- Two-factor authentication support
5.3 Data Retention
- Active Accounts: Data retained while account is active
- Analytics Data: 90 days of detailed metrics, monthly aggregates stored indefinitely
- After Account Deletion: Data deleted within 30 days (except as required by law)
- Backup Data: Removed from backups within 90 days
6. Your Rights and Controls
6.1 Access and Portability
You have the right to:
- Access your personal data
- Export your data in CSV format
- Request a copy of your information
6.2 Correction and Deletion
You can:
- Update account information in Settings
- Disconnect integrations at any time
- Delete your account (Settings → Delete Account)
- Request data deletion by contacting [email protected]
6.3 Marketing Communications
You can opt out of marketing emails via the unsubscribe link. Transactional emails (billing, security) cannot be disabled.
6.4 GDPR Rights (EU Users)
EU users have additional rights under GDPR:
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
To exercise these rights, contact [email protected]
7. Cookies and Tracking
We use cookies for:
- Essential: Authentication, session management
- Analytics: Usage patterns, feature adoption (anonymized)
- Preferences: Dashboard settings, theme selection
You can control cookies through your browser settings. Disabling essential cookies may affect functionality.
8. Third-Party Services
Our Service integrates with:
- Google Services: Subject to Google's Privacy Policy
- Shopify: Subject to Shopify's Privacy Policy
- Meta: Subject to Meta's Privacy Policy
We are not responsible for the privacy practices of these third-party services.
9. Children's Privacy
MerchantFlow is not intended for users under 18 years of age. We do not knowingly collect information from children. If you believe we have collected data from a child, contact us immediately at [email protected]
10. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via email or dashboard notification.
Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related questions or requests:
- Business Location: Adelaide, South Australia, Australia
- Email: [email protected]
- Support: [email protected]
- Website: merchantflow.ai
Data Protection Officer: For GDPR-related inquiries, contact our DPO at [email protected]
12. California Privacy Rights (CCPA)
California residents have the right to:
- Know what personal information is collected
- Know if personal information is sold or disclosed
- Access personal information
- Delete personal information
- Opt-out of sale of personal information
We do not sell personal information to third parties.
To exercise CCPA rights, email [email protected] with subject line "California Privacy Rights Request."