GDPR Compliance - Data Protection
MerchantFlow GDPR compliance documentation covering data retention policies, user rights, Shopify and Meta GDPR webhooks, and how to exercise data protection rights.
GDPR Compliance
Effective Date: December 27, 2025
MerchantFlow Pty Ltd ("MerchantFlow", "we", "us") is committed to compliance with the General Data Protection Regulation (GDPR). This page outlines our data protection practices, retention policies, and your rights as a data subject. MerchantFlow processes personal data as both a data controller (for account and usage data) and a data processor (for integration data processed on behalf of our users).
Data Retention Policies
Automatic Data Purge
MerchantFlow automatically purges data based on configurable retention policies, ensuring that data is not retained longer than necessary for its intended purpose.
Retention Periods by Entity Type
The purge job runs daily. The default retention period for each configured entity type is:
| Entity Type | Description | Default retention | Purpose |
|---|---|---|---|
| audit_log | User and system audit trails | 365 days | Security and compliance tracking |
| sync_log | Integration synchronization records | 90 days | Debugging and sync history |
| analytics_snapshot | Point-in-time analytics data | 730 days (2 years) | Historical trend analysis |
| notification | In-app notification records | 90 days | Notification history |
| impersonation_session | Records of support access to a workspace | 365 days | Compliance and accountability |
| deleted_tenant | Residual records for a removed workspace | 30 days | Post-deletion cleanup |
Additional entity types - product_metrics_cache, integration_log, sync_checkpoint, and sync_failure - can also be placed under a retention policy for troubleshooting and performance data.
Audit log retention is treated as a floor rather than a target: it cannot be switched off and cannot be reduced below 365 days.
When a retention period expires, the corresponding data is automatically and permanently deleted.
Manual Data Deletion
You can request manual deletion of specific data at any time by contacting [email protected].
Platform-Specific GDPR Compliance
Shopify GDPR Compliance
MerchantFlow subscribes to all three mandatory Shopify compliance webhooks (customers/data_request, customers/redact, shop/redact) and verifies each one's HMAC signature before acting on it:
- Customer Data Requests (
customers/data_request) - MerchantFlow locates every order and customer touchpoint it holds for that customer and emails a summary of them to the store owner's MerchantFlow account address. Because Shopify's requirement is that the merchant responds to their own customer, MerchantFlow supplies the data to the merchant rather than to the customer directly - Customer Data Deletion (
customers/redact) - the customer's personal data is removed from the matching order records: name and email address are overwritten, and phone number, shipping address, tracking details, order notes, and the platform customer ID are cleared. Customer touchpoints and subscription signals for that customer are deleted outright. Order financial totals are retained in anonymized form so your historical revenue, COGS, and P&L reporting stays intact - Store Data Deletion (
shop/redact) - Shopify sends this approximately 48 hours after uninstall. MerchantFlow deletes the workspace and its data, including stored integration credentials. Where a shop domain cannot be resolved to exactly one workspace, the deletion is deliberately skipped and escalated rather than risking deletion of the wrong workspace
Meta Data Deletion
MerchantFlow supports Meta's data deletion requirements. When Meta sends a data deletion request, all associated Meta Ads data is permanently removed.
Your Rights Under GDPR
Right of Access
You have the right to request a copy of all personal data we hold about you, including account information, integration data, and usage logs.
How to exercise: Email [email protected] with the subject "GDPR Data Access Request."
Right to Rectification
You can update most account information directly through Settings > General. For other corrections, contact us.
Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data when the data is no longer necessary, you withdraw consent, you object to processing, or the data has been unlawfully processed.
Exceptions: We may retain data where required by legal obligation or for the defense of legal claims.
Right to Data Portability
MerchantFlow provides an Article 20 data export endpoint that returns a structured JSON file containing the data held for you and your workspace - profile, workspace settings, products, orders, expenses, COGS entries, bank balances, AI conversations, and the list of connected integrations. OAuth tokens and internal record IDs are deliberately excluded. Individual dashboards and reports also offer CSV export, and you can request a full export by contacting us.
Right to Restriction of Processing
You can request that we restrict processing in certain circumstances, including while we verify contested data accuracy or while we consider an objection to processing.
Right to Object
You can object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
Legal Basis for Processing
| Legal Basis | Data Processed | Purpose |
|---|---|---|
| Contract performance | Account data, integration data | Providing the MerchantFlow service |
| Contract performance | Mobile device credentials and device records | Pairing a device, authenticating it, and delivering your workspace data to it |
| Legitimate interests | Usage data, analytics | Service improvement, security |
| Legitimate interests | Mobile app screen views and app events | Understanding which screens are used so we can improve the app, and preventing abuse |
| Consent | Marketing communications | Product updates, newsletters |
| Legal obligation | Financial records, audit logs | Tax compliance, regulatory requirements |
Mobile app analytics rely on legitimate interests rather than consent, and there is no in-app toggle. To exercise your right to object to that processing under Article 21, email [email protected]. See the Privacy Policy for exactly what the app sends.
Data Processing Agreements
MerchantFlow enters into Data Processing Agreements (DPAs) with sub-processors who handle personal data and with customers who require a DPA for their own GDPR compliance.
To request a DPA, contact [email protected].
Sub-Processors
- Hetzner (Finland) - cloud hosting and infrastructure; holds all application data
- Stripe - payment processing (PCI-compliant)
- Postmark - transactional email delivery
- Customer.io - transactional and marketing email delivery, lifecycle event tracking, communication preferences
- PostHog (EU-hosted) - web product analytics and error tracking; not used by the mobile app
- OpenRouter - AI assistant processing, routing to model providers such as Anthropic, OpenAI, or Google
- Cloudflare - bot protection (Turnstile) and CDN
Aggregate, cookieless analytics run on a Umami instance MerchantFlow hosts on its own infrastructure, so no third party receives that data.
Cross-Border Data Transfers
When personal data is transferred outside the European Economic Area (EEA):
- Transfers are governed by Standard Contractual Clauses (SCCs)
- Adequate safeguards are in place as required by GDPR
- Data protection impact assessments are conducted where necessary
Data Protection Officer
For GDPR-specific inquiries:
- Email: [email protected]
- Response time: within 72 hours
- GDPR requests: [email protected] with subject "GDPR Request"
Breach Notification
In the event of a personal data breach:
- We assess the breach within 24 hours of discovery
- Supervisory authorities are notified within 72 hours where required
- Affected data subjects are notified without undue delay when the breach poses a high risk
- Full documentation of the breach, its effects, and remedial actions is maintained
How to Exercise Your Rights
- Email [email protected]
- Subject line: Include "GDPR" and the specific right (e.g., "GDPR Data Access Request")
- Identification: We may need to verify your identity before processing
- Response time: Within 30 days of receiving your verified request
- No charge: Exercising your rights is free, except in cases of manifestly unfounded or excessive requests
Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence.
Frequently Asked Questions
Is MerchantFlow a data controller or data processor?
MerchantFlow acts as a data controller for account and usage data, and as a data processor for integration data processed on behalf of users.
Can I get a Data Processing Agreement?
Yes. Contact [email protected] to request a DPA. Standard DPAs include GDPR compliance clauses and are available for all customers.
How long does MerchantFlow retain my data after account deletion?
When the workspace owner deletes the account from Settings > Delete Account, the workspace and its data are deleted immediately - there is no grace period and no self-service reactivation. Backups are removed within 90 days. Where an account is terminated rather than self-deleted, data is removed from active systems within 30 days.
Does MerchantFlow comply with Shopify's mandatory GDPR webhooks?
Yes. MerchantFlow subscribes to and handles all three: customers/data_request, customers/redact, and shop/redact (sent about 48 hours after app uninstall). Each webhook's HMAC signature is verified before it is acted on.
Related Resources
Last updated: August 23, 2026
Last updated on
Terms of Service - MerchantFlow
MerchantFlow Terms of Service covering service usage, the mobile app, subscription billing, acceptable use, intellectual property, liability limitations, and termination.
Data Security Practices
MerchantFlow data security practices including 2FA authentication, AES-256 encryption, session management, mobile device tokens, tenant isolation, and OAuth token security.