Privacy Policy

Last updated: August 2026

This policy explains what data Merccho collects, why we collect it, who we share it with, and how you can have it deleted. It covers the Merccho web application and the Merccho app for Shopify.

Who we are

Merccho provides commerce analytics and automation for online stores. It is operated by Bytecode Technologies Private Limited, a company registered in India, whose registered office is given at the foot of this page. For anything in this policy, including data requests, contact us at support@merccho.com.

For the data in your Shopify store and your advertising accounts, you are the data controller and Merccho acts as your processor — we handle it on your instructions to provide the service. For your own Merccho account details (your name, email and login credentials) we are the controller.

Store data we read from Shopify

When you connect a store, you approve a specific list of read permissions. Merccho requests read access only — we never request permission to change your products, orders, inventory or pricing. We read:

  • Products, variants, images and product listings
  • Collections and store content
  • Inventory levels and locations
  • Discounts, price rules and markets
  • Orders, including line items and totals
  • Customers linked to those orders, which can include names, email addresses, phone numbers and shipping addresses

We read this data to give you margin and cost-of-goods analysis, inventory and stock alerts, discount performance, and AI-assisted search across your own catalogue.

Advertising data we read from Meta

If you connect a Meta advertising account, Merccho reads, for the ad accounts you select:

  • Ad account name, ID, currency and time zone
  • Campaign, ad set and ad names, IDs and status
  • Daily performance metrics — spend, impressions, clicks, conversions and return on ad spend

This access is read-only. Merccho does not create, edit, pause, or change budgets on any campaign, and does not post anything to your Facebook or Instagram accounts. We use this data to show your advertising performance alongside your store revenue so you can see true profitability.

We do not read your Facebook Pages, your personal profile beyond basic account identification, or the personal data of anyone who saw or clicked your ads.

Account data

To run your Merccho account we store your name, email address, and either a hashed password or a Google sign-in identifier. We never store your password in a readable form. We also keep records of team members you invite and their access level.

How we use AI

Merccho uses AI to power features inside your own account — for example, semantic search across your product catalogue. To do this, product text from your store is sent to our AI provider to generate a numeric representation used for search. Customer personal data is not sent for this purpose.

We may produce aggregated, anonymised statistics across merchants to improve our products and to publish industry benchmarks. Aggregated data cannot be traced back to you, your store, your customers or any individual order. We do not use identifiable customer data, or your advertising data, to train models for other merchants.

What we never do

  • We do not sell your data, or your customers’ data, to anyone.
  • We do not share your data with other merchants or let them see it.
  • We do not use your data for advertising or retargeting.
  • We do not send marketing email to your customers. Emails we send go only to you and the team members on your account.

Who we share data with

We share data only with the service providers needed to run Merccho, and only to the extent they need it:

  • Amazon Web Services — application hosting, databases, file storage and email delivery. Data is stored in the United States (us-east-1).
  • Vercel — hosting for the Merccho web interface.
  • OpenAI — generating search representations from product text. Data sent for this purpose is not used to train their models.
  • Shopify and Meta — the platforms you connect, which are the source of the data described above.

Requests from public authorities

We may be required by law to disclose data to a government body, regulator, court or law-enforcement agency. When that happens:

  • We check that the request is lawful before we disclose anything — that the requester is who they say they are, that there is a valid legal instrument, and that it covers the data being asked for.
  • We challenge requests we believe are unlawful or overbroad, rather than complying quietly.
  • We disclose the minimum the law compels — only the named accounts, only the fields specified, only the period specified. We never disclose your Shopify or Meta access credentials.
  • We record every request and our response to it, including the ones we refuse.

We will tell you before we disclose, unless we are legally prevented from doing so — and where a prohibition expires, we will tell you then. Where the data belongs to your own customers, you are the controller of it, and we will direct the request to you unless we are compelled to answer it ourselves.

As of August 2026, Merccho has received no requests of any kind from any public authority.

International transfers

Merccho stores and processes data in the United States. If you are in the United Kingdom, the European Economic Area, or another region with data transfer rules, this means your data is transferred outside your region. We rely on standard contractual clauses with our providers to protect it.

How long we keep data

  • While connected — we keep your store and advertising data for as long as your account is active, so the app can show it to you.
  • After you uninstall — Shopify notifies us, and we delete your store data, including all customer and order records, within 30 days.
  • After you disconnect Meta — your stored Meta access is removed immediately and we stop reading any further advertising data.
  • Compliance records — we keep a log of deletion and data requests for up to 7 years. These records show that a request was made and actioned; they do not contain your customers’ personal data.

Security

All data is encrypted in transit using TLS and encrypted at rest. Access tokens for Shopify and Meta are encrypted with AES-256-GCM before being stored, and are never exposed in the interface or in logs. Access to production systems is restricted and logged.

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to how we process it. You can exercise any of these by emailing support@merccho.com. We respond within 30 days.

For deletion specifically, see our data deletion instructions.

If your customers contact you with a data request about their own information, Shopify forwards it to us automatically and we action it against your store data.

Cookies

Merccho uses cookies only to keep you signed in and to protect against cross-site request forgery. We do not use advertising or tracking cookies, and we do not place cookies on your storefront or track your shoppers.

Children

Merccho is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.

Changes to this policy

If we make a material change we will update the date at the top of this page and notify account owners by email before it takes effect. Questions go to support@merccho.com.

Merccho is operated by Bytecode Technologies Private Limited, World TECH 67 ITC 10, Sector 67, Sahibzada Ajit Singh Nagar (Mohali), Punjab 160062, India.

Contact: support@merccho.com