Compliance

Legal & compliance

Review our legal documents and compliance policies governing your use of MerchantFlow.

Privacy Policy

Effective Date: December 27, 2025

Last Updated: December 27, 2025

1. Introduction

MerchantFlow ("we," "our," or "us") provides a SaaS platform for ecommerce merchants to analyze product-level profitability across advertising channels. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services at merchantflow.ai (the "Service").

By using MerchantFlow, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Company name
  • Password (encrypted)
  • Billing information (processed by Stripe)

2.2 Integration Data

When you connect third-party services via OAuth, we collect and store:

  • Google Ads: Campaign metrics, ad spend, product performance data, customer account IDs
  • Google Analytics 4: Website traffic, conversion data, user behavior metrics
  • Google Search Console: Search queries, impressions, click-through rates
  • Google Merchant Center: Product feed data, listing issues
  • Shopify/WooCommerce: Product catalog, orders, revenue, inventory
  • Meta Ads: Campaign performance, ad spend, account IDs

2.3 Usage Data

We automatically collect:

  • Log data (IP address, browser type, pages visited)
  • Device information
  • Usage analytics (features used, time spent)
  • Error logs and performance metrics

2.4 OAuth Tokens

We store OAuth access tokens and refresh tokens to maintain connections to your integrated services. These tokens are encrypted at rest using AES-256 encryption.

3. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Sync and display analytics data from your connected platforms
  • Calculate product-level profitability metrics
  • Process payments and manage subscriptions
  • Send service notifications and updates
  • Provide customer support
  • Detect and prevent fraud or abuse
  • Improve and optimize our Service
  • Comply with legal obligations

We will never sell your data to third parties or use your business data for advertising purposes.

4. Data Sharing and Disclosure

4.1 Service Providers

We share data with trusted service providers:

  • Stripe: Payment processing (subject to Stripe's Privacy Policy)
  • Cloud Infrastructure: AWS/GCP for hosting and storage
  • Email Services: Mailjet for transactional emails

4.2 Legal Requirements

We may disclose your information if required by:

  • Legal process (subpoena, court order)
  • Government requests
  • Protection of our rights or safety of others
  • Investigation of fraud or security issues

4.3 Business Transfers

If MerchantFlow is acquired or merged, your information may be transferred to the new entity. You will be notified of any such change.

5. Data Storage and Security

5.1 Storage Location

Data is hosted on OVH cloud infrastructure in Canada. MerchantFlow is operated from Adelaide, South Australia. International users' data may be transferred and processed in Canada.

5.2 Security Measures

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Multi-tenant database isolation
  • Regular security audits and penetration testing
  • Role-based access controls
  • Automated backups with encryption
  • Two-factor authentication support

5.3 Data Retention

  • Active Accounts: Data retained while account is active
  • Analytics Data: 90 days of detailed metrics, monthly aggregates stored indefinitely
  • After Account Deletion: Data deleted within 30 days (except as required by law)
  • Backup Data: Removed from backups within 90 days

6. Your Rights and Controls

6.1 Access and Portability

You have the right to:

  • Access your personal data
  • Export your data in CSV format
  • Request a copy of your information

6.2 Correction and Deletion

You can:

  • Update account information in Settings
  • Disconnect integrations at any time
  • Delete your account (Settings → Delete Account)
  • Request data deletion by contacting [email protected]

6.3 Marketing Communications

You can opt out of marketing emails via the unsubscribe link. Transactional emails (billing, security) cannot be disabled.

6.4 GDPR Rights (EU Users)

EU users have additional rights under GDPR:

  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

To exercise these rights, contact [email protected]

7. Cookies and Tracking

We use cookies for:

  • Essential: Authentication, session management
  • Analytics: Usage patterns, feature adoption (anonymized)
  • Preferences: Dashboard settings, theme selection

You can control cookies through your browser settings. Disabling essential cookies may affect functionality.

8. Third-Party Services

Our Service integrates with:

We are not responsible for the privacy practices of these third-party services.

9. Children's Privacy

MerchantFlow is not intended for users under 18 years of age. We do not knowingly collect information from children. If you believe we have collected data from a child, contact us immediately at [email protected]

10. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via email or dashboard notification.

Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related questions or requests:

Data Protection Officer: For GDPR-related inquiries, contact our DPO at [email protected]

12. California Privacy Rights (CCPA)

California residents have the right to:

  • Know what personal information is collected
  • Know if personal information is sold or disclosed
  • Access personal information
  • Delete personal information
  • Opt-out of sale of personal information

We do not sell personal information to third parties.

To exercise CCPA rights, email [email protected] with subject line "California Privacy Rights Request."