Privacy Policy - MerchantFlow
MerchantFlow Privacy Policy explains how we collect, use, store, and protect your personal data, integration information, and business analytics data, on the web platform and the mobile app.
Privacy Policy
Effective Date: December 27, 2025
This Privacy Policy explains how MerchantFlow Pty Ltd ("MerchantFlow", "we", "us", "our"), a company registered in Australia, collects, uses, shares, and protects your information when you use the MerchantFlow platform at merchantflow.ai and the MerchantFlow mobile app for iOS and Android (together, the "Service").
Practices that apply only to the mobile app are set out under MerchantFlow Mobile App below.
By using MerchantFlow, you agree to the collection and use of information as described in this policy.
What Information We Collect
Account Information
When you create a MerchantFlow account, we collect:
- Email address - for login, communication, and notifications
- Name - for personalization and team identification
- Company name - for account organization
- Password - encrypted and securely stored (we never store plaintext passwords)
- Billing information - processed and stored securely by Stripe; MerchantFlow does not store payment card details
Integration Data
When you connect third-party platforms, we access and store data including:
- Google Ads - campaign details, advertising spend, performance metrics, ROAS calculations
- Google Analytics 4 - website traffic data, conversion events, session and engagement data
- Google Search Console - search queries, impressions, click-through rates, keyword positions
- Google Merchant Center - product feed data, listings, pricing, availability
- Shopify - order data, product catalog, revenue and sales metrics
- WooCommerce - order data, product catalog, revenue and sales metrics
- Meta Ads - campaign performance, ad spend, conversion metrics
Usage Data
We automatically collect server logs, device information, analytics data (pages visited, features used, and screens viewed in the mobile app), and error logs for debugging.
OAuth Tokens
OAuth tokens for connected integrations are stored securely and encrypted, used solely to access your authorized data, and revocable at any time by disconnecting the integration.
Mobile App Data
When you pair a phone or tablet with your workspace, we collect:
- A device access token - a long random value issued to that device instead of your password. It carries no personal data. We store only an irreversible hash of it, plus a short non-secret prefix so you can recognize the device in your dashboard
- A device record - the workspace and user it belongs to, the hashed token and its display prefix, a device label supplied by the app, the platform (iOS or Android), and timestamps for creation, expiry, last use, and revocation. The label is a fixed generic string such as "iPhone (MerchantFlow)", not the name you gave your device
- App usage events - which screens you open, and a small number of app events, sent to our own self-hosted analytics
- Camera access - only at the moment you scan a pairing QR code, and only to read that code
What we do not collect from the app - no advertising identifiers, no device identifiers or fingerprints, no push notification tokens, no location, contacts, photos, calendar, or health data. The app has no push notifications.
How mobile sign-in, on-device storage, and app analytics work is described under MerchantFlow Mobile App below.
How We Use Your Data
To Provide the Service
- Display analytics dashboards and reports
- Sync data from connected integrations
- Calculate product profitability, ROAS, and margins
- Generate business insights and recommendations
- Process billing and manage subscriptions
To Improve the Service
- Analyze feature usage patterns (aggregated and not linked to your account)
- Identify and fix bugs and performance issues
- Develop new features based on usage trends
To Communicate With You
We send two categories of electronic communications:
Transactional and Service Communications (sent regardless of marketing preferences):
- Account security alerts (login from new device, password changes, suspicious activity)
- Billing confirmations, receipts, payment failures, and subscription changes
- Integration status notifications (sync failures, disconnected accounts, credential expiry)
- Service disruptions, maintenance windows, and incident updates
- Regulatory or legal notices required by law
- Responses to your support requests
- Onboarding guidance and setup instructions for features you have activated
- Daily performance summaries and anomaly alerts you have configured
- Data export and account deletion confirmations
These communications are essential to the operation, security, and integrity of your account. You cannot opt out of transactional communications while maintaining an active account, as they are necessary to fulfill our contractual obligations to you.
Marketing and Product Communications (opt-out available):
- Product announcements, new feature releases, and platform updates
- Tips, guides, and best practices for using MerchantFlow
- Surveys and feedback requests
- Promotional offers and partnership announcements
You may opt out of marketing communications at any time by clicking the "Unsubscribe" link in any marketing email, updating your preferences in Settings > Notifications, or emailing [email protected]. Opting out of marketing communications does not affect transactional communications.
Data Sharing
Third-Party Service Providers
We share data only with service providers necessary to operate MerchantFlow:
- Stripe - for payment processing (PCI-compliant). Receives your email address and billing details
- Hetzner (Finland) - for cloud hosting and infrastructure. Holds all application data
- Postmark - for transactional email delivery. Receives your email address and name
- Customer.io - for transactional and marketing email delivery, lifecycle event tracking, and communication preference management. Receives your email address, name, account status, subscription plan, integration connection states, feature adoption metrics, and team size
- PostHog (EU-hosted) - for web product analytics and error tracking. Receives usage events, page views, user IDs, and error logs. Not used by the mobile app
- Umami (self-hosted on our own infrastructure) - for cookieless aggregate analytics across our marketing pages, the web dashboard, and the mobile app
- OpenRouter - for AI assistant processing, routing to model providers such as Anthropic, OpenAI, or Google. Receives your queries and the business context they need
- Cloudflare - for bot protection (Turnstile) and content delivery. Receives your IP address and browser characteristics
Of these, only our own hosting and our own self-hosted analytics receive any data from the mobile app. The mobile app contains no third-party software development kits for analytics, advertising, attribution, or crash reporting.
We Do Not Sell Your Data
MerchantFlow does not sell, rent, or trade your personal information or business data to any third party.
Legal Requirements
We may disclose data when required by court orders, government investigations, protection of rights and safety, or enforcement of our Terms of Service.
Data Security
We implement multiple layers of protection:
- Encrypted tokens - all OAuth integration tokens encrypted at rest
- Data isolation - your data is isolated from other accounts through tenant isolation
- Session management - secure session handling with automatic expiry
- Password encryption - all passwords hashed and salted
- HTTPS - all data transmitted over encrypted connections (TLS 1.2+)
- Access controls - role-based access within your team
- Device credentials - mobile access tokens are stored as irreversible hashes on our servers, and in your device's operating system secure credential store on the device itself
- Device revocation - every paired mobile device is listed in your dashboard and can be revoked individually
For full details, see our Data Security page.
Your Rights
Access Your Data
Request a copy of all personal data we hold. Contact [email protected].
Delete Your Data
Delete your account from Settings > Delete Account in the web dashboard, or email [email protected] to request deletion. This is also the route to use if you installed the mobile app - the app itself does not create or delete accounts. Integration data is removed when integrations are disconnected, deleting your account removes every paired device, and backups are purged according to our retention schedule.
Export Your Data
Export your data at any time using built-in dashboard export features (CSV, JSON) or request a full data export via [email protected].
Correct Your Data
Update account information through Settings > Profile. For other corrections, contact us.
Object to Processing
Object to certain types of data processing by contacting us.
Manage Connected Devices
Every phone or tablet paired with your workspace is listed at Settings > Developer > Mobile in the web dashboard, where you can revoke any of them individually.
Revoking your browser sessions with "Log Out All Devices" does not revoke paired mobile devices. They are separate mechanisms. If you lose, sell, or replace a device, revoke it at Settings > Developer > Mobile.
GDPR Compliance
If you are located in the European Union or European Economic Area, additional rights apply under GDPR including right to rectification, erasure, data portability, restriction of processing, objection, and withdrawal of consent.
Legal basis for processing: Contract performance, legitimate interests, consent, and legal obligation.
For full GDPR details, see our GDPR Compliance page.
Cookies
Cookies We Use
- Essential cookies - authentication, session management, security (CSRF protection)
- Analytics cookies - aggregated usage statistics, feature adoption, performance monitoring
- Preference cookies - dashboard settings, timezone, currency preferences
No Advertising Cookies
MerchantFlow does not use advertising or tracking cookies.
Cookies and the Mobile App
Cookies apply to the web dashboard and marketing site only. The mobile app does not use cookies or any similar storage, and it does not run PostHog or Google Analytics. What the app does send is described under Mobile App Analytics below.
MerchantFlow Mobile App
The MerchantFlow mobile app for iOS and Android is a companion to the web dashboard. It requires an existing MerchantFlow account, and no account can be created from within the app.
How the App Signs You In
There are two ways to sign in:
- QR pairing - you generate a pairing code in the web dashboard and scan it with the app. This is the primary path, and the only one available if your workspace has no password (for example, Shopify-embedded merchants)
- Email and password - plus a time-based code or a backup code if you have two-factor authentication enabled
The QR code contains only the address of our API and a one-time pairing code. It contains no email address, no name, and no workspace identifier.
A pairing code is valid for a short period (currently five minutes) and can be used once. We store only an irreversible hash of it, never the code itself.
Once paired, the app holds a device access token rather than your password. The token expires 90 days after it is issued and is not renewed; when it expires you sign in or pair again.
What the App Stores on Your Device
The app stores exactly two values on your device - the access token and the address of our API - both in your operating system's secure credential store (the iOS Keychain, or Android Keystore-backed encrypted storage).
No business data is written to your device. Figures, orders, and metrics are held in memory only while the app is running, and are discarded when it closes.
The stored credential is bound to the device it was issued to and is not included in device backups. If you lose, sell, or replace a device, revoke it at Settings > Developer > Mobile.
What the App Receives From Us
Over an encrypted connection, the app receives your own profile and workspace settings, dashboard metrics, revenue history and trends, top products, AI-written summaries of your own figures, a per-country breakdown, integration status, and pages of your orders.
Order records sent to the app exclude customer contact details. Customer names, email addresses, phone numbers, shipping addresses, and tracking numbers are not transmitted to paired devices.
Camera Access
The app uses your camera only to read the pairing QR code. Permission is requested the first time you open the pairing screen, after we explain why it is needed. Camera frames are read on your device by the barcode reader; no photo or video is saved or transmitted. You can decline camera access and type the pairing code in by hand instead.
No microphone access is requested, and no other device permissions are requested.
Mobile App Analytics
App analytics go to a Umami instance we host ourselves at analytics.merchantflow.ai. No third party receives them.
Each event carries a website identifier, a fixed hostname of mobile.merchantflow.ai, your screen size, your device language, the in-app screen you are on and its title, and the previous screen. The request also carries a browser-style user-agent string the app builds, which states the operating system and version and, on Android, the device model, because the analytics endpoint requires one.
The events recorded are:
- Screen views - which screen you opened
- Sign-in - which method was used (password, password with two-factor, or QR pairing), and nothing else
- Sign-out
- Metric customization - how many metrics you selected, and nothing else
There are no cookies and no user, device, advertising, or installation identifier. Events are not linked to your account in our analytics records. They are not used for advertising, not used to build a profile of you, and never sold or shared.
As with any request over the internet, our analytics server receives the IP address of the connection at the network layer, and may derive a coarse location such as your country from it.
Our legal basis for app analytics is our legitimate interest in understanding which screens are used so we can improve the app. There is no in-app toggle for this. If you wish to object to this processing, email [email protected].
The app contains no third-party analytics, advertising, attribution, or crash-reporting software. It does not use PostHog or Google Analytics, which run on the web platform only. There is no advertising identifier and no App Tracking Transparency prompt. Apple and Google act as distributors of the app and collect their own download, purchase, and crash telemetry under their own privacy policies.
Removing a Device
A device's access stops working when you sign out in the app, when you revoke the device in the dashboard, or when your user or workspace is deleted.
Revoking your browser sessions with "Log Out All Devices" does not revoke paired mobile devices. Revoke those at Settings > Developer > Mobile.
Device records, including expired and revoked ones, are kept for the life of the account so that your device list and its history remain available to you, and are deleted when the user or workspace is deleted.
To delete your account entirely, use Settings > Delete Account in the web dashboard or email [email protected]. The app does not create accounts and has no deletion control of its own; deleting your account removes all paired devices.
Data Retention
Active accounts: Data retained for the duration of your subscription.
Closed accounts: 30-day grace period for reactivation, then permanently deleted. Backups removed within 90 days.
Mobile device records: Kept for the life of the account, including expired and revoked devices, so that your device list and its history remain available to you. Deleted when the user or workspace is deleted.
Automatic purge: Certain data types, principally log data, are subject to automatic retention policies. See GDPR Compliance for details.
Children's Privacy
MerchantFlow is not directed at individuals under the age of 18. We do not knowingly collect personal information from children.
Changes to This Policy
Material changes are communicated via email and in-app notification with 30 days' notice. Continued use after changes constitutes acceptance. Previous versions available upon request.
Contact
- Email: [email protected]
- Privacy inquiries: [email protected]
- Response time: within 30 days
Frequently Asked Questions
What personal data does MerchantFlow collect?
MerchantFlow collects your email address, name, and company name for account purposes. We also collect integration data (analytics, orders, products) through read-only OAuth connections. Order data includes limited customer details - see the answer below for exactly what and why.
Does MerchantFlow use my data for advertising?
No. We do not use advertising cookies and do not use your data for any advertising purpose. Your data is used solely to provide and improve the MerchantFlow service.
How can I delete my MerchantFlow data?
Cancel your subscription and email [email protected] requesting data deletion. After a 30-day grace period, all data is permanently deleted.
Does MerchantFlow access my customers' personal information?
Yes, to a limited extent. When you connect a commerce platform, the order data we sync includes customer names and email addresses, which we store so that order search works and so we can service data-deletion requests. Customer phone numbers and shipping addresses are encrypted at rest.
This data exists only to power your order-level reporting. It is never used for marketing, never sold, and never shared with advertisers. We honor Shopify-mandated customer data redaction and deletion requests. Order records sent to the mobile app exclude customer contact details entirely.
What does the MerchantFlow mobile app collect?
Which screens you open, plus a sign-in event, a sign-out event, and a metric-customization event, all sent to analytics we host ourselves. The app also holds a device access token and a device record so you can identify and revoke it. There are no third-party analytics, advertising, or crash-reporting components in the app, no advertising identifier, and no push notifications. Camera access is used only to read the pairing QR code. See MerchantFlow Mobile App for the full detail.
Does signing out of all my web sessions also sign out my phone?
No. "Log Out All Devices" revokes browser sessions only. Paired mobile devices are a separate mechanism, listed and revocable at Settings > Developer > Mobile. Revoke a device there if you lose, sell, or replace it.
Related Resources
Last updated: July 26, 2026
Legal & Privacy - MerchantFlow Policies
MerchantFlow legal documents including terms of service, privacy policy, GDPR compliance, data security practices, and cookie policies.
Terms of Service - MerchantFlow
MerchantFlow Terms of Service covering service usage, the mobile app, subscription billing, acceptable use, intellectual property, liability limitations, and termination.