MerchantFlowMerchantFlow Docs

GDPR Compliance - Data Protection

MerchantFlow GDPR compliance documentation covering data retention policies, user rights, Shopify and Meta GDPR webhooks, and how to exercise data protection rights.

GDPR Compliance

Effective Date: December 27, 2025

MerchantFlow Pty Ltd ("MerchantFlow", "we", "us") is committed to compliance with the General Data Protection Regulation (GDPR). This page outlines our data protection practices, retention policies, and your rights as a data subject. MerchantFlow processes personal data as both a data controller (for account and usage data) and a data processor (for integration data processed on behalf of our users).

Data Retention Policies

Automatic Data Purge

MerchantFlow automatically purges data based on configurable retention policies, ensuring that data is not retained longer than necessary for its intended purpose.

Retention Periods by Entity Type

The purge job runs daily. The default retention period for each configured entity type is:

Entity TypeDescriptionDefault retentionPurpose
audit_logUser and system audit trails365 daysSecurity and compliance tracking
sync_logIntegration synchronization records90 daysDebugging and sync history
analytics_snapshotPoint-in-time analytics data730 days (2 years)Historical trend analysis
notificationIn-app notification records90 daysNotification history
impersonation_sessionRecords of support access to a workspace365 daysCompliance and accountability
deleted_tenantResidual records for a removed workspace30 daysPost-deletion cleanup

Additional entity types - product_metrics_cache, integration_log, sync_checkpoint, and sync_failure - can also be placed under a retention policy for troubleshooting and performance data.

Audit log retention is treated as a floor rather than a target: it cannot be switched off and cannot be reduced below 365 days.

When a retention period expires, the corresponding data is automatically and permanently deleted.

Manual Data Deletion

You can request manual deletion of specific data at any time by contacting [email protected].

Platform-Specific GDPR Compliance

Shopify GDPR Compliance

MerchantFlow subscribes to all three mandatory Shopify compliance webhooks (customers/data_request, customers/redact, shop/redact) and verifies each one's HMAC signature before acting on it:

  • Customer Data Requests (customers/data_request) - MerchantFlow locates every order and customer touchpoint it holds for that customer and emails a summary of them to the store owner's MerchantFlow account address. Because Shopify's requirement is that the merchant responds to their own customer, MerchantFlow supplies the data to the merchant rather than to the customer directly
  • Customer Data Deletion (customers/redact) - the customer's personal data is removed from the matching order records: name and email address are overwritten, and phone number, shipping address, tracking details, order notes, and the platform customer ID are cleared. Customer touchpoints and subscription signals for that customer are deleted outright. Order financial totals are retained in anonymized form so your historical revenue, COGS, and P&L reporting stays intact
  • Store Data Deletion (shop/redact) - Shopify sends this approximately 48 hours after uninstall. MerchantFlow deletes the workspace and its data, including stored integration credentials. Where a shop domain cannot be resolved to exactly one workspace, the deletion is deliberately skipped and escalated rather than risking deletion of the wrong workspace

Meta Data Deletion

MerchantFlow supports Meta's data deletion requirements. When Meta sends a data deletion request, all associated Meta Ads data is permanently removed.

Your Rights Under GDPR

Right of Access

You have the right to request a copy of all personal data we hold about you, including account information, integration data, and usage logs.

How to exercise: Email [email protected] with the subject "GDPR Data Access Request."

Right to Rectification

You can update most account information directly through Settings > General. For other corrections, contact us.

Right to Erasure (Right to be Forgotten)

You can request deletion of your personal data when the data is no longer necessary, you withdraw consent, you object to processing, or the data has been unlawfully processed.

Exceptions: We may retain data where required by legal obligation or for the defense of legal claims.

Right to Data Portability

MerchantFlow provides an Article 20 data export endpoint that returns a structured JSON file containing the data held for you and your workspace - profile, workspace settings, products, orders, expenses, COGS entries, bank balances, AI conversations, and the list of connected integrations. OAuth tokens and internal record IDs are deliberately excluded. Individual dashboards and reports also offer CSV export, and you can request a full export by contacting us.

Right to Restriction of Processing

You can request that we restrict processing in certain circumstances, including while we verify contested data accuracy or while we consider an objection to processing.

Right to Object

You can object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.

Legal BasisData ProcessedPurpose
Contract performanceAccount data, integration dataProviding the MerchantFlow service
Contract performanceMobile device credentials and device recordsPairing a device, authenticating it, and delivering your workspace data to it
Legitimate interestsUsage data, analyticsService improvement, security
Legitimate interestsMobile app screen views and app eventsUnderstanding which screens are used so we can improve the app, and preventing abuse
ConsentMarketing communicationsProduct updates, newsletters
Legal obligationFinancial records, audit logsTax compliance, regulatory requirements

Mobile app analytics rely on legitimate interests rather than consent, and there is no in-app toggle. To exercise your right to object to that processing under Article 21, email [email protected]. See the Privacy Policy for exactly what the app sends.

Data Processing Agreements

MerchantFlow enters into Data Processing Agreements (DPAs) with sub-processors who handle personal data and with customers who require a DPA for their own GDPR compliance.

To request a DPA, contact [email protected].

Sub-Processors

  • Hetzner (Finland) - cloud hosting and infrastructure; holds all application data
  • Stripe - payment processing (PCI-compliant)
  • Postmark - transactional email delivery
  • Customer.io - transactional and marketing email delivery, lifecycle event tracking, communication preferences
  • PostHog (EU-hosted) - web product analytics and error tracking; not used by the mobile app
  • OpenRouter - AI assistant processing, routing to model providers such as Anthropic, OpenAI, or Google
  • Cloudflare - bot protection (Turnstile) and CDN

Aggregate, cookieless analytics run on a Umami instance MerchantFlow hosts on its own infrastructure, so no third party receives that data.

Cross-Border Data Transfers

When personal data is transferred outside the European Economic Area (EEA):

  • Transfers are governed by Standard Contractual Clauses (SCCs)
  • Adequate safeguards are in place as required by GDPR
  • Data protection impact assessments are conducted where necessary

Data Protection Officer

For GDPR-specific inquiries:

Breach Notification

In the event of a personal data breach:

  1. We assess the breach within 24 hours of discovery
  2. Supervisory authorities are notified within 72 hours where required
  3. Affected data subjects are notified without undue delay when the breach poses a high risk
  4. Full documentation of the breach, its effects, and remedial actions is maintained

How to Exercise Your Rights

  1. Email [email protected]
  2. Subject line: Include "GDPR" and the specific right (e.g., "GDPR Data Access Request")
  3. Identification: We may need to verify your identity before processing
  4. Response time: Within 30 days of receiving your verified request
  5. No charge: Exercising your rights is free, except in cases of manifestly unfounded or excessive requests

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence.

Frequently Asked Questions

Is MerchantFlow a data controller or data processor?

MerchantFlow acts as a data controller for account and usage data, and as a data processor for integration data processed on behalf of users.

Can I get a Data Processing Agreement?

Yes. Contact [email protected] to request a DPA. Standard DPAs include GDPR compliance clauses and are available for all customers.

How long does MerchantFlow retain my data after account deletion?

When the workspace owner deletes the account from Settings > Delete Account, the workspace and its data are deleted immediately - there is no grace period and no self-service reactivation. Backups are removed within 90 days. Where an account is terminated rather than self-deleted, data is removed from active systems within 30 days.

Does MerchantFlow comply with Shopify's mandatory GDPR webhooks?

Yes. MerchantFlow subscribes to and handles all three: customers/data_request, customers/redact, and shop/redact (sent about 48 hours after app uninstall). Each webhook's HMAC signature is verified before it is acted on.


Last updated: August 23, 2026

Last updated on

On this page