Legal & Privacy - MerchantFlow Policies
MerchantFlow legal documents including terms of service, privacy policy, GDPR compliance, data security practices, and cookie policies.
Legal & Privacy
MerchantFlow legal and privacy documentation covers all policies, compliance standards, and data protection practices that govern your use of the platform. MerchantFlow is committed to transparent data handling, enterprise-grade security, and full regulatory compliance.
Legal Documents
- Terms of Service - user agreement and service terms
- Privacy Policy - how we collect, use, and protect your data
- GDPR Compliance - European data protection rights and retention policies
- Data Security - technical and organizational security measures
Our Privacy Commitments
What We Never Do
- Sell your data to third parties
- Share data with advertisers
- Use your data for unrelated purposes
- Access your data without permission
What We Always Do
- Encrypt data in transit (TLS 1.2 or higher), and encrypt OAuth tokens and customer contact and address fields at rest with AES-256-GCM
- Request minimum necessary permissions (read-only access for all integrations)
- Provide transparent privacy practices
- Give you control over your data (access, export, delete)
Security Standards
MerchantFlow meets industry security standards:
- GDPR compliant - full European data protection compliance
- PCI DSS compliant - payment processing through Stripe
- Regular security audits and penetration testing
- OAuth 2.0 for all third-party integrations with encrypted token storage
Compliance
MerchantFlow complies with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- CAN-SPAM Act
- Payment Card Industry Data Security Standard (PCI DSS)
What Data We Collect
Account information: Email address, name, company name, password (encrypted).
Integration data: Product information, analytics metrics, order data, advertising performance. All accessed through read-only OAuth connections.
Order-level customer data: Order records synced from your store include limited customer details - name, email address, phone number, and shipping address - which are stored so order search works and so we can service data-deletion requests. Phone numbers, addresses, names, and email addresses are encrypted at rest. This data is never used for marketing, never sold, and never shared with advertisers. See the Privacy Policy for the full explanation.
Usage data: Pages viewed, features used, session duration, device and browser info.
What we do NOT collect: Payment card details (handled by Stripe) or personal information beyond what the Service requires.
Your Privacy Rights
You have the right to:
- Access your data
- Correct inaccurate data
- Delete your data (with exceptions for legal compliance)
- Export your data in standard formats (CSV, JSON)
- Object to processing
- Withdraw consent for marketing communications
Exercise rights: Email [email protected] with your specific request. We respond within 30 days.
Data Retention
Active accounts: Data retained for the duration of your subscription.
Deleting your account: Using Settings > Delete Account in the dashboard deletes the workspace and all of its data immediately - there is no grace period and no self-service reactivation. Backups are removed within 90 days.
Terminated accounts: Where an account is terminated rather than self-deleted, data is removed from active systems within 30 days, subject to our retention policy.
Automatic purge: Certain data types (audit logs, sync logs, analytics snapshots) are subject to automatic retention policies. See GDPR Compliance for details.
Cookie Policy
Essential cookies: Authentication, security features, load balancing.
Analytics cookies: Aggregated usage statistics, feature adoption, performance monitoring.
Preference cookies: Dashboard settings, timezone, currency preferences.
No advertising cookies are used.
Contact for Legal Inquiries
- General legal questions: [email protected]
- Privacy concerns: [email protected]
- GDPR requests: [email protected] (Subject: GDPR Request)
- Security issues: [email protected] (Subject: Security Issue)
Frequently Asked Questions
Is MerchantFlow GDPR compliant?
Yes. MerchantFlow is fully GDPR compliant as both a data controller and data processor. We offer Data Processing Agreements, support data subject rights (access, rectification, erasure, portability), and implement Standard Contractual Clauses for cross-border transfers.
Does MerchantFlow sell my data?
Never. MerchantFlow does not sell, rent, or trade your personal information or business data to any third party. Data is shared only with the essential service providers listed in the Privacy Policy - Hetzner for hosting, Stripe for payments, Postmark and Customer.io for email, PostHog for web analytics, OpenRouter for AI processing, and Cloudflare for bot protection and CDN - and as required by law.
Where is my data stored?
Application data and backups are hosted with Hetzner in Finland (EU). Your information may also be processed in Australia, the European Union, the United States, and other countries where we or our service providers operate.
Can I delete all my data from MerchantFlow?
Yes. The workspace owner can delete everything immediately from Settings > Delete Account in the dashboard, or you can email [email protected] to request deletion. Deletion is permanent and cannot be undone. Backups are removed within 90 days.
Does MerchantFlow have write access to my store or ad accounts?
No. MerchantFlow requests read-only access for all integrations. We never modify your data, create campaigns, or make changes to your connected platforms.
Related Resources
Last updated: August 24, 2026
Last updated on