Merge Me

Privacy

Privacy policy

Effective 26 August 2026 · Version 2026-08-26

Merge Me is operated by Marvello Pty Ltd (ABN 72 691 509 261), an Australian private company (Marvello, we, us). This policy explains how we handle personal information in connection with the Merge Me Shopify app, website and support services.

1. Our role

For customer and order information processed to provide Merge Me to a Shopify merchant, the merchant generally decides why and how that information is processed and Marvello acts as its service provider or processor. Customers should ordinarily direct privacy requests to the Shopify merchant from whom they purchased.

Marvello acts as an independent controller for merchant account contacts, billing and entitlement records, website and support communications, security and abuse prevention, legal compliance, and de-identified service analytics. The Data Processing Addendum describes our processor commitments to merchants.

2. Information we handle

Depending on enabled features, merchant settings and Shopify permissions, we may handle:

Merge Me does not require or store customer payment-card numbers. Customer email is not requested or used for app email notifications while that feature remains disabled. We do not intentionally collect sensitive information such as health, biometric, political or religious information; merchants must not submit it unless strictly necessary and lawfully authorised.

3. How we collect information

We receive information from the merchant and its authorised staff, Shopify APIs and webhooks, the merchant’s configured services where a supported connection is enabled, support communications, and the normal operation of our website, app and security infrastructure. We derive limited operational data such as eligibility results, pseudonymous match keys, merge references, audit events, usage totals and safety status from those inputs.

4. Why we handle information

We handle information to:

Where the GDPR or UK GDPR applies to our controller activities, we generally rely on performing our contract with the merchant, our legitimate interests in providing and securing the Service, compliance with legal obligations, and consent where the law requires it. The merchant is responsible for identifying and communicating the lawful basis for customer and order processing it instructs us to perform.

5. How we disclose information

We do not sell personal information, share it for cross-context behavioural advertising, or use customer/order data to advertise to individuals. We disclose information only as reasonably necessary:

We require service providers handling Shopify Merchant Data to protect it, use it only to provide their services to Merge Me, and keep it confidential and secure.

6. International and cross-border processing

The primary Merge Me application and database are designed to operate in Google Cloud’s Australia region. Shopify is a global platform and Cloudflare operates a global network, so information may also be processed in Australia, Canada, the United States and other countries in which those providers operate or route traffic. Privacy protections and government-access rules may differ between countries.

Where applicable, we use contractual and organisational safeguards for overseas processing, including data-processing terms and recognised transfer mechanisms. Australian Privacy Principle 8 may make us accountable for certain overseas disclosures. Merchants requiring a specific transfer mechanism should review the DPA and contact us before enabling live processing.

7. Retention

We keep identifiable information only for as long as needed for the Service, safety, privacy requests, legal obligations and dispute handling. Current operational defaults are:

RecordTypical retention
Closed order-linked merge and operational records30 days after closure
Webhook deduplication metadata7 days
Encrypted privacy-request response and completed request receiptUp to 30 days
Customer-redaction suppression recordUp to 30 days
Sent or terminally failed notification receipt30 days
De-identified safety counters, daily aggregates and retention-run summariesUp to 90 days
Open safety, billing, writer or fulfilment recordsUntil resolved, then the applicable period starts
Expired online staff sessionsDeleted after access and refresh windows have both been expired for 30 days

Short-lived keyed retry tombstones may be retained after deletion to safely acknowledge an exact repeated Shopify privacy webhook without restoring tenant data. Legal holds, unresolved payment obligations or security investigations may require longer retention of the minimum necessary record. Backup copies may persist for a limited rotation period and remain protected until deletion.

8. Shopify privacy requests and uninstall

Merge Me authenticates Shopify’s required customers/data_request, customers/redact and shop/redact requests. A valid request is placed into a tenant-bound deletion or export workflow and is intended to be completed within Shopify’s required period, unless law requires retention. Customer-data results are provided only through an authenticated merchant session.

Uninstalling stops new authorised app access and triggers deletion workflows. Uninstall does not itself reverse order or fulfilment changes already made in Shopify or another system.

9. Security

We use administrative, technical and organisational measures designed for the nature of the information, including tenant separation, least-privilege service roles, encryption in transit and at rest where supported, restricted secrets, authenticated webhooks, pseudonymous operational keys, bounded logs, retention controls, change review, monitoring and incident procedures. No internet or storage system is perfectly secure, and we cannot guarantee absolute security.

10. Cookies and similar technologies

The public marketing site does not currently use advertising cookies or non-essential analytics cookies. Shopify, Merge Me and Cloudflare may use strictly necessary session, authentication, security and load-management technologies in the embedded app or protected console. See the Cookie Notice.

11. Your rights and choices

Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated processing, and to complain to a privacy regulator. These rights are subject to legal exceptions.

Shopify customers should first contact the merchant from whom they purchased because that merchant controls the relevant order relationship and can submit a request through Shopify. Merchants and website visitors may contact us directly. We may need to verify identity and authority before acting. We do not discriminate for exercising a privacy right.

12. Children

Merge Me is a business service for Shopify merchants and is not directed to children. We do not knowingly collect children’s information directly through the website. Order data may include information supplied to a merchant; the merchant is responsible for ensuring that collection and its instructions are lawful.

13. Privacy complaints

Send a request or complaint to help@mergeme.app with “Privacy” in the subject. Describe the issue and your relationship to the relevant store, but do not email identity documents or unnecessary customer data unless we request a secure method. We will acknowledge the complaint, investigate it and aim to respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner or the regulator available in your jurisdiction.

14. Changes

We may update this policy when practices, providers or laws change. The current version and effective date will be posted here. We will give additional notice through Shopify or the Service where a change is material and the law requires notice.

15. Contact

Marvello Pty Ltd · ABN 72 691 509 261 · Queensland 4217, Australia
Email: help@mergeme.app