Legal

Privacy policy

How Mercentia handles personal data across the marketing site, the dashboard, and the storefronts we host for merchants. Mercentia is used by merchants and shoppers worldwide: we apply one standard everywhere — collect what running the product requires, never sell personal data — and honour whichever regional law gives you more.

Last updated · August 2026

Who is responsible for what

Mercentia sits in two different legal roles at once, and which one applies decides who you should contact.

Whose dataOur roleWho to ask
A merchant's own account — signup, billing, staff, supportController. We decide why and how it is processed.Us, at [email protected]
A shopper who buys from a store we hostProcessor. The merchant is the controller; we act on their instructions under the DPA. The merchant. We will pass a request on if you contact us and cannot reach them.
A visitor to mercentia.comController.Us

What we collect

Merchant account data (we are the controller)

  • Name, email, password hash (argon2id), organisation and store details
  • Business address, company number and VAT number where you enter them — these appear on your invoices and in your storefront's legal pages
  • Billing: subscription state and a payment-method token. Card numbers go directly to Stripe; they never reach our servers
  • Staff members and their roles, invitations, and the audit log of what each did
  • Support conversations, bug reports you submit, and error diagnostics attached to your account
  • Credentials for services you connect — encrypted at rest, and only ever used to call that service on your behalf

Shopper data (the merchant is the controller)

Held inside the merchant's store and visible only to that store's staff. Tenant isolation is enforced in the database with row-level security, not only in application code.

  • Name, email, phone, shipping and billing address
  • Orders, line items, returns, refunds and subscriptions
  • Carts, including abandoned ones where an email address was entered
  • Wishlists, reviews, loyalty balances and store-account credentials
  • Marketing consent per channel, and the record of when it was given or withdrawn
  • Buyer-assistant and conversational-search messages, where the merchant has enabled those features
  • Order risk signals — IP country, whether the email is disposable, and hashed device and address fingerprints used to spot repeat fraud

Visitors to mercentia.com

  • Nothing beyond what you submit in a form
  • Waitlist: email, and optionally first name, current platform, monthly-sales band
  • Pricing calculator: nothing stored unless you submit a form
  • Server and edge logs: IP, user agent, request path — kept 30 days

How we use it

  • Run the dashboard, the storefronts, checkout, and the marketing site
  • Authenticate sessions and protect requests against cross-site forgery
  • Take payments, calculate tax and shipping, and produce invoices
  • Send transactional messages — order confirmations, shipping updates, refunds, password resets, account and billing notices
  • Send marketing messages, opt-in only, with an unsubscribe link and a physical address in every one
  • Detect and prevent fraud and abuse — rate limits, risk scoring, suppression lists
  • Provide the AI features described below
  • Diagnose errors and monitor availability
  • Produce aggregate analytics. We do not build advertising profiles of individuals

We do not sell personal data, and we do not "share" it for cross-context behavioural advertising as CCPA/CPRA defines that term.

AI features

Mercentia uses AI to build stores, write product copy, translate content, answer shopper questions and help with support. The following is what that means for your data, and it is also our transparency statement under Article 50 of the EU AI Act, which has applied since 2 August 2026.

  • You are told when you are talking to an AI. The buyer assistant and the support agent identify themselves as automated. So does AI-generated storefront copy, in the merchant's dashboard, before it is published.
  • What is sent. The prompt, and the store content relevant to it — a catalogue, a page, a support thread. Where a merchant has enabled the buyer assistant, the shopper's messages to it are sent too.
  • Who processes it. Anthropic and OpenAI, listed on /subprocessors with the data each receives.
  • Training. Your prompts and content are not used to train the providers' models, and we do not train models on your data either.
  • Cross-tenant safety. Anything promoted into our shared support-knowledge library is stripped of identifiers first — emails, phone numbers, postcodes, order and store IDs, keys — and a second pass rejects it outright if any identifier survives.
  • No autonomous decisions with legal effect. AI suggests; a human confirms. We do not auto-publish, auto-refund, auto-discount or auto-cancel. Nothing here amounts to automated decision-making under GDPR Article 22.
  • It can be wrong. AI output is a draft. Merchants are responsible for what they publish, and we say so in the terms.

Lawful basis (GDPR Article 6)

PurposeLawful basis
Operating your Mercentia accountContract performance
Transactional email and SMSContract performance
Marketing email and SMSConsent (opt-in), withdrawable at any time
Fraud prevention, security and abuse detectionLegitimate interests
Error monitoring and service availabilityLegitimate interests
AI features you or your merchant switch onContract performance (merchant-facing); legitimate interests (shopper-facing)
Tax, accounting and financial reportingLegal obligation
Aggregate analyticsLegitimate interests

Who we share it with

Our sub-processors — hosting, database, payments, email, SMS, AI, error monitoring — are listed in full, with what each receives and where it is processed, at mercentia.com/subprocessors. We give account owners 30 days' notice before adding one.

Services a merchant connects to their own store — a marketing platform, a helpdesk, their own carrier or accounting account, an ad platform's conversion API — receive data on that merchant's instruction and are the merchant's processors, not ours. Each store's own privacy policy lists the ones it has connected.

We also disclose personal data where the law requires it: a valid court order, a regulator's request, or to establish or defend a legal claim. If we can lawfully tell you first, we will.

Cookies

Full detail, including how to change your choice, is on the cookie policy. In short: the cookies Mercentia sets are strictly necessary ones — session, security and preference. We set no advertising cookies of our own, and no third-party analytics or marketing script loads on this site until you opt in on the banner.

Cookies set inside a merchant's storefront are governed by that merchant's own cookie settings and consent banner, which they control from their dashboard.

Your rights

These rights are given to everyone who uses Mercentia, wherever they live, rather than only to people whose local law compels us. It is simpler to operate one standard than to ask where someone is sitting before deciding what they are owed, and where a regional law grants more than the list below, that law wins.

  • Know what we hold about you and why
  • Get a copy in a portable, machine-readable format
  • Correct anything inaccurate
  • Delete it, except where the law requires us to keep a record
  • Object to or restrict a particular use
  • Withdraw consent at any time, as easily as it was given
  • Not be discriminated against for exercising any of them — no worse price, no degraded service

We do not sell personal data and do not share it for cross-context behavioural advertising, so the opt-out those laws provide is our default for everyone. Exercising a right is free.

If you are a merchant

Email [email protected] from your account address. We verify it is you, and respond within 30 days (GDPR Article 12). You can also correct most profile, organisation and store details yourself in the dashboard at any time.

If you are a shopper

Contact the store you bought from — they are the controller, and their dashboard has the tools to export or erase your record. If they do not respond, contact us and we will pass the request on and follow it up.

An erasure removes the shopper record, addresses, order contact details, reviews, wishlists, carts, marketing preferences and storefront login. Financial records are kept where tax law requires, with the personal fields cleared; suppression-list entries are kept because deleting one would re-subscribe the person, which is the opposite of what they asked for.

Complaints

You can complain to your national data protection authority — the ICO in the UK, your member state's authority in the EU, the OAIC in Australia, the OPC in Canada, the PDPC in Singapore or the equivalent where you live. We would rather you told us first.

Regional rights

The rights above are what we give everyone. Some regions add specific mechanics on top, and this is how they apply here.

Where you areLawWhat it adds
United KingdomUK GDPR + Data Protection Act 2018 We respond within one month. Our transfers out of the UK use the IDTA. Complaints go to the ICO.
European Economic Area & SwitzerlandGDPR One month to respond, Standard Contractual Clauses for transfers, and the right to lodge a complaint with your national authority.
CaliforniaCCPA / CPRA Right to know, delete, correct, and to limit use of sensitive personal information. We do not sell or share personal data, so that opt-out is already in force. An authorised agent may act for you.
Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other US states with comprehensive privacy laws State privacy acts The same access, deletion, correction and portability rights, plus an appeal if we refuse a request — write to the same address and we will escalate it to someone who was not involved in the first decision.
CanadaPIPEDA and provincial equivalents Access and correction rights; complaints to the OPC or your provincial regulator.
Australia & New ZealandPrivacy Act 1988 (APPs) / Privacy Act 2020 Access and correction, and notifiable-breach reporting to the OAIC or the New Zealand Privacy Commissioner.
IndiaDigital Personal Data Protection Act 2023 Access, correction, erasure and grievance redressal. Merchants selling into India can use Razorpay, which processes locally.
BrazilLGPD Confirmation of processing, access, correction, anonymisation, portability and information about the parties we share with.
Japan & South KoreaAPPI / PIPA Disclosure, correction and suspension of use, and notice of cross-border transfers.
Singapore & MalaysiaPDPAAccess and correction, and withdrawal of consent for marketing.
South Africa & NigeriaPOPIA / NDPA Access, correction and objection, with complaints to the Information Regulator or the NDPC.
UAE & Saudi ArabiaPDPLAccess, correction, erasure and restriction of processing.

Not an exhaustive list of every law that might apply to you, and not legal advice for your own store — as the controller of your shoppers' data, your obligations are yours. If your region is not named, write to us anyway: the rights at the top of this section are given to everyone regardless.

Data retention

DataKept forWhy
Merchant accountWhile active, then 90 daysRecovery from accidental closure
Orders, invoices and payment records7 yearsTax and financial reporting (legal obligation)
Audit log7 yearsSecurity investigations and dispute resolution
Server and edge logs30 daysSecurity and diagnostics
Error reports90 daysDiagnosing faults
Abandoned cartsPer the merchant's recovery settingsThe merchant sets this
Email suppression listIndefiniteDeleting it would resume mail someone opted out of
Database backupsRolling 30 daysA deletion reaches backups within this window

International transfers

Mercentia is operated from the United Kingdom and used worldwide. The primary database is in the EU (Frankfurt); some sub-processors are in the United States, India or elsewhere, and the region for each is named on the sub-processor page.

Wherever you are, your data may be processed in a country other than your own. Transfers out of the UK and EEA rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, with a transfer risk assessment on file, and on the EU–US Data Privacy Framework where the recipient is certified. For other regions we rely on the equivalent mechanism their law provides — standard contractual clauses, consent, or the necessity of the transfer to perform your contract — and apply the same technical protections in every case: encryption in transit and at rest, and access limited to what the service needs.

Security

Detailed on the security page, including where we are with external attestations rather than where we would like to be. In short: TLS 1.2+ in transit, AES-256 at rest, row-level security for tenant isolation, argon2id password hashing, encrypted third-party credentials, an immutable audit log, and no card data on Mercentia servers.

If a breach affects your personal data we notify the relevant supervisory authority within 72 hours and, where the risk to you is high, we tell you directly.

Children

Mercentia is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 — or under 13 where that is the local threshold, as in the United States. If you believe we hold a child's data, email [email protected] and we will delete it.

Changes to this policy

Material changes — a new category of data, a new purpose, a new sub-processor — are notified to account owners by email 30 days before they take effect. The date at the top of this page always reflects the current version, and previous versions are available on request.

Contact

Mercentia Ltd, registered in England & Wales. Privacy questions and data subject requests: [email protected]. Security matters: [email protected]. We respond to data subject requests within 30 days.