Transparency You Can Trust
We take your privacy and data security seriously. Review our policies governing your use of MerchantFlow.
Privacy Policy
1. Introduction
MerchantFlow Pty Ltd (ABN 94 693 972 208) ("we," "our," or "us") provides a SaaS platform for ecommerce merchants to analyse product-level profitability across advertising channels. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our services at merchantflow.ai (the "Service").
We are committed to handling personal information in accordance with applicable privacy laws, including the Australian Privacy Act 1988 (Cth). Where applicable, we also aim to support privacy rights that may apply under other laws, such as the GDPR and CCPA.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address and name
- Company/business name
- Password (securely hashed - we never store plaintext passwords)
- Billing information (processed and stored by Stripe - we do not store card details)
2.2 Integration Data
When you connect third-party services via OAuth, we access and store:
- Google Analytics 4: Website traffic, conversion data, user behavior metrics, property IDs
- Google Search Console: Search queries, impressions, click-through rates, site URLs
- Google Merchant Center: Product feed data, listing issues, merchant IDs
- Google Ads: Campaign metrics, ad spend, product performance data, customer account IDs
- Shopify: Product catalog, orders (including customer names, email addresses, phone numbers, and shipping addresses), revenue, inventory, cost data, shop domain
- WooCommerce: Product catalog, orders (including customer names, email addresses, and shipping addresses), revenue
- Meta Ads: Campaign performance, ad spend, account IDs
- Snapchat Ads: Campaign metrics, ad spend, account IDs
- TikTok Ads: Campaign metrics, ad spend, account IDs
2.3 Usage Data
We automatically collect:
- Log data (IP address, browser type, pages visited)
- Device information
- Product usage analytics via PostHog (EU-hosted) - includes page views, feature usage, button clicks, and DOM interactions via autocapture
- Error tracking and performance monitoring via PostHog (EU-hosted) - captures unhandled errors and stack traces
2.4 OAuth Tokens
We store OAuth access tokens and refresh tokens to maintain connections to your integrated services. These tokens are encrypted at rest using AES-256 encryption with a dedicated encryption key.
2.5 Order and Customer Data
When you connect a commerce platform (Shopify, WooCommerce), we sync and store order data to calculate profitability and attribution metrics. This includes:
- Order details (amounts, dates, payment status, line items)
- Customer names and email addresses (stored for order search and GDPR compliance)
- Customer phone numbers and shipping addresses (encrypted at rest using AES-256)
- Attribution data (UTM parameters, referrer, landing page)
We store this data solely to provide accurate P&L reporting, margin calculations, and order-level analytics. Sensitive personal data (phone numbers, shipping addresses) is encrypted at rest. We support Shopify-mandated customer data redaction and deletion requests.
2.6 AI Assistant Data
If you use AI-powered features, your prompts and contextual business data (including revenue figures, product margins, channel performance, ad spend, and cohort data) may be sent to OpenRouter, which routes requests to underlying AI model providers such as Anthropic, OpenAI, or Google. We do not use your MerchantFlow customer data to train our own AI models. The specific model provider handling your request depends on our configuration at the time of the query.
3. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Service
- Sync and display analytics data from your connected platforms
- Calculate product-level profitability metrics
- Process payments and manage subscriptions
- Communicate with you (see Section 3.1 below)
- Provide customer support
- Detect and prevent fraud or abuse
- Monitor platform performance and errors
- Comply with legal obligations
We will never sell your data to third parties or use your business data for advertising purposes.
3.1 Communications
We send two categories of electronic communications:
Transactional and Service Communications (sent regardless of marketing preferences):
- Account security alerts (login from new device, password changes, suspicious activity)
- Billing confirmations, receipts, payment failures, and subscription changes
- Integration status notifications (sync failures, disconnected accounts, credential expiry)
- Service disruptions, maintenance windows, and incident updates
- Regulatory or legal notices required by law
- Responses to your support requests
- Onboarding guidance and setup instructions for features you have activated
- Daily performance summaries and anomaly alerts you have configured
- Data export and account deletion confirmations
These communications are essential to the operation, security, and integrity of your account. You cannot opt out of transactional communications while maintaining an active account, as they are necessary to fulfill our contractual obligations to you.
Marketing and Product Communications (opt-out available):
- Product announcements, new feature releases, and platform updates
- Tips, guides, and best practices for using MerchantFlow
- Surveys and feedback requests
- Promotional offers and partnership announcements
You may opt out of marketing communications at any time by clicking the "Unsubscribe" link in any marketing email, updating your preferences in Settings → Notifications, or emailing [email protected]. Opting out of marketing communications does not affect transactional communications.
4. Data Sharing and Service Providers
We share data with the following trusted service providers, solely for the purposes of operating the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, billing details |
| Hetzner (Finland) | Cloud hosting & infrastructure | All application data |
| Postmark | Transactional emails | Email address, name |
| PostHog (EU) | Product analytics, error tracking & monitoring | Usage events, page views, user IDs, error logs |
| Customer.io | Transactional and marketing email delivery, lifecycle event tracking, communication preference management | Email, name, account status, subscription plan, integration connection states, feature adoption metrics, team size |
| OpenRouter | AI assistant processing (routes to Anthropic, OpenAI, Google, or other model providers) | User queries, business context (revenue, margins, ad spend, product data, cohort data) |
| Cloudflare | CAPTCHA (Turnstile) & CDN | IP address, browser fingerprint |
4.1 Legal Requirements
We may disclose your information if required by:
- Legal process (subpoena, court order)
- Government requests
- Protection of our rights or safety of others
- Investigation of fraud or security issues
4.2 Business Transfers
If MerchantFlow is acquired or merged, your information may be transferred to the new entity. You will be notified via email and dashboard notification of any such change at least 30 days in advance.
5. Google API Services Disclosure
MerchantFlow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we only use Google user data (GA4 analytics, Search Console metrics, Merchant Center feeds, Google Ads performance) to provide and improve the Service for you. We do not use Google user data for serving advertisements, and we do not allow humans to read your Google data except with your consent, for security purposes, to comply with applicable law, or for our internal operations where the data has been aggregated and anonymized.
6. Data Storage and Security
6.1 Storage Location
Your information may be processed in Australia, the European Union, the United States, and other countries where we or our service providers operate. MerchantFlow is operated by MerchantFlow Pty Ltd from Adelaide, South Australia.
6.2 Security Measures
We use technical and organisational safeguards designed to protect data, including:
- AES-256-GCM encryption at rest for OAuth tokens, customer phone numbers, and shipping addresses
- Tenant isolation at the database layer (all queries are scoped to your tenant)
- Rate limiting on API endpoints
- Security headers (CSP, HSTS, X-Frame-Options)
- Passwords hashed with bcrypt
- Automated monitoring, error tracking, and encrypted backups
6.3 Data Breach Notification
In compliance with the Australian Notifiable Data Breaches (NDB) scheme, if we experience a data breach that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and all affected individuals as soon as practicable.
6.4 Data Retention
See our Data Retention Policy for full details. Summary:
- Active Accounts: Data retained while account is active
- After Account Deletion: Personal information deleted or de-identified from active systems within a reasonable period, generally within 30 days, subject to backup retention, legal obligations, dispute resolution, fraud prevention, and legitimate business record-keeping requirements
- Backup Data: Removed from backups within 90 days
7. Your Rights and Controls
7.1 Access and Portability
You have the right to:
- Access your personal data
- Export your analytics data in CSV format
- Request a machine-readable copy of your information
7.2 Correction and Deletion
You can:
- Update account information in Settings
- Disconnect integrations at any time
- Delete your account through your account settings or by contacting support
- Request data deletion by contacting [email protected]
7.3 Communication Preferences
You can opt out of marketing communications at any time by:
- Clicking the "Unsubscribe" link in any marketing email
- Updating your preferences in Settings → Notifications
- Emailing [email protected]
Transactional and service communications (account security, billing, integration status, configured alerts) cannot be opted out of while your account is active, as they are necessary to fulfill our contractual obligations. See Section 3.1 for the full list of communication types.
7.4 GDPR Rights (EU/EEA Users)
If you are located in the EU/EEA, you have additional rights under GDPR:
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
See our GDPR & Data Rights page for more details.
7.5 Australian Privacy Principles
Under the Australian Privacy Act 1988, you have the right to access and correct your personal information. If you believe we have breached the APPs, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
7.6 California Privacy Rights (CCPA)
California residents have the right to:
- Know what personal information is collected
- Know if personal information is sold or disclosed
- Access personal information
- Correct inaccurate personal information
- Delete personal information
- Opt-out of sale of personal information
- Non-discrimination for exercising privacy rights
We do not sell personal information to third parties.
8. Cookies and Tracking
We use cookies and similar technologies for:
- Essential: Authentication (JWT session token in
auth-tokencookie), CSRF protection - Analytics & Error Monitoring: PostHog (EU-hosted) for product usage analytics, feature adoption, autocaptured DOM interactions, and error tracking. Analytics cookies require your consent via our cookie consent banner before being set.
- Security: Cloudflare Turnstile for bot detection during signup
We display a cookie consent banner on your first visit. You may accept all cookies, accept only essential cookies, or manage your preferences. Analytics cookies (PostHog) are not set until you provide consent. You can also control cookies through your browser settings. Disabling essential cookies will prevent you from logging in.
9. Third-Party Integrations
Our Service integrates with the following platforms. By using our Service with these integrations, you acknowledge that the privacy policies of these third-party platforms are incorporated by reference into this Privacy Policy and apply to data they hold:
10. Children's Privacy
MerchantFlow is a business-to-business service not intended for users under 18 years of age. We do not knowingly collect information from children. If you believe we have collected data from a minor, contact us immediately at [email protected]
11. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via email and dashboard notification at least 14 days before they take effect.
Where required, we will notify you of material changes and obtain any required consent.
12. Contact Us
For privacy-related questions or requests:
Company
MerchantFlow Pty Ltd
PO Box Plus, Suite 115
Shop 17, 2 Wilkinson Road
Para Hills SA 5096, Australia