MerchantFlowMerchantFlow Docs

Legal & Privacy - MerchantFlow Policies

MerchantFlow legal documents including terms of service, privacy policy, GDPR compliance, data security practices, and cookie policies.

MerchantFlow legal and privacy documentation covers all policies, compliance standards, and data protection practices that govern your use of the platform. MerchantFlow is committed to transparent data handling, enterprise-grade security, and full regulatory compliance.

Our Privacy Commitments

What We Never Do

  • Sell your data to third parties
  • Share data with advertisers
  • Use your data for unrelated purposes
  • Access your data without permission

What We Always Do

  • Encrypt data in transit (TLS 1.2 or higher), and encrypt OAuth tokens and customer contact and address fields at rest with AES-256-GCM
  • Request minimum necessary permissions (read-only access for all integrations)
  • Provide transparent privacy practices
  • Give you control over your data (access, export, delete)

Security Standards

MerchantFlow meets industry security standards:

  • GDPR compliant - full European data protection compliance
  • PCI DSS compliant - payment processing through Stripe
  • Regular security audits and penetration testing
  • OAuth 2.0 for all third-party integrations with encrypted token storage

Learn more about security

Compliance

MerchantFlow complies with:

  • General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA)
  • CAN-SPAM Act
  • Payment Card Industry Data Security Standard (PCI DSS)

What Data We Collect

Account information: Email address, name, company name, password (encrypted).

Integration data: Product information, analytics metrics, order data, advertising performance. All accessed through read-only OAuth connections.

Order-level customer data: Order records synced from your store include limited customer details - name, email address, phone number, and shipping address - which are stored so order search works and so we can service data-deletion requests. Phone numbers, addresses, names, and email addresses are encrypted at rest. This data is never used for marketing, never sold, and never shared with advertisers. See the Privacy Policy for the full explanation.

Usage data: Pages viewed, features used, session duration, device and browser info.

What we do NOT collect: Payment card details (handled by Stripe) or personal information beyond what the Service requires.

Full Privacy Policy

Your Privacy Rights

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Delete your data (with exceptions for legal compliance)
  • Export your data in standard formats (CSV, JSON)
  • Object to processing
  • Withdraw consent for marketing communications

Exercise rights: Email [email protected] with your specific request. We respond within 30 days.

Data Retention

Active accounts: Data retained for the duration of your subscription.

Deleting your account: Using Settings > Delete Account in the dashboard deletes the workspace and all of its data immediately - there is no grace period and no self-service reactivation. Backups are removed within 90 days.

Terminated accounts: Where an account is terminated rather than self-deleted, data is removed from active systems within 30 days, subject to our retention policy.

Automatic purge: Certain data types (audit logs, sync logs, analytics snapshots) are subject to automatic retention policies. See GDPR Compliance for details.

Essential cookies: Authentication, security features, load balancing.

Analytics cookies: Aggregated usage statistics, feature adoption, performance monitoring.

Preference cookies: Dashboard settings, timezone, currency preferences.

No advertising cookies are used.

Frequently Asked Questions

Is MerchantFlow GDPR compliant?

Yes. MerchantFlow is fully GDPR compliant as both a data controller and data processor. We offer Data Processing Agreements, support data subject rights (access, rectification, erasure, portability), and implement Standard Contractual Clauses for cross-border transfers.

Does MerchantFlow sell my data?

Never. MerchantFlow does not sell, rent, or trade your personal information or business data to any third party. Data is shared only with the essential service providers listed in the Privacy Policy - Hetzner for hosting, Stripe for payments, Postmark and Customer.io for email, PostHog for web analytics, OpenRouter for AI processing, and Cloudflare for bot protection and CDN - and as required by law.

Where is my data stored?

Application data and backups are hosted with Hetzner in Finland (EU). Your information may also be processed in Australia, the European Union, the United States, and other countries where we or our service providers operate.

Can I delete all my data from MerchantFlow?

Yes. The workspace owner can delete everything immediately from Settings > Delete Account in the dashboard, or you can email [email protected] to request deletion. Deletion is permanent and cannot be undone. Backups are removed within 90 days.

Does MerchantFlow have write access to my store or ad accounts?

No. MerchantFlow requests read-only access for all integrations. We never modify your data, create campaigns, or make changes to your connected platforms.


Last updated: August 24, 2026

Last updated on

On this page