Privacy
Privacy policy
Effective 26 August 2026 · Version 2026-08-26
Merge Me is operated by Marvello Pty Ltd (ABN 72 691 509 261), an Australian private company (Marvello, we, us). This policy explains how we handle personal information in connection with the Merge Me Shopify app, website and support services.
1. Our role
For customer and order information processed to provide Merge Me to a Shopify merchant, the merchant generally decides why and how that information is processed and Marvello acts as its service provider or processor. Customers should ordinarily direct privacy requests to the Shopify merchant from whom they purchased.
Marvello acts as an independent controller for merchant account contacts, billing and entitlement records, website and support communications, security and abuse prevention, legal compliance, and de-identified service analytics. The Data Processing Addendum describes our processor commitments to merchants.
2. Information we handle
Depending on enabled features, merchant settings and Shopify permissions, we may handle:
- Merchant and staff information: Shopify store domain and identifiers, business and staff identity made available by Shopify, authorised session information, contact details, app settings, permissions, plan, trial, usage, billing status and support communications.
- Order and customer information: order identifiers, dates, status, currency, market, order tags and attributes, notes, line items, variants, quantities, prices, discounts, tax and shipping information; stable Shopify customer identity and tags; and delivery name, address and phone where required for matching and creating or verifying a combined order.
- Fulfilment information: delivery methods, locations, fulfilment services, holds, status, carrier and tracking information, and evidence needed to prevent an order from being changed after fulfilment has started.
- Technical and security information: IP address and request metadata that infrastructure providers necessarily process, authentication and security events, device/browser information, error and performance records, keyed or pseudonymous identifiers, webhook delivery fingerprints and audit events.
- Support information: store domain, Merge Me support references, problem descriptions and attachments you choose to send. Please do not send passwords, access codes, payment-card data or unnecessary customer information.
Merge Me does not require or store customer payment-card numbers. Customer email is not requested or used for app email notifications while that feature remains disabled. We do not intentionally collect sensitive information such as health, biometric, political or religious information; merchants must not submit it unless strictly necessary and lawfully authorised.
3. How we collect information
We receive information from the merchant and its authorised staff, Shopify APIs and webhooks, the merchant’s configured services where a supported connection is enabled, support communications, and the normal operation of our website, app and security infrastructure. We derive limited operational data such as eligibility results, pseudonymous match keys, merge references, audit events, usage totals and safety status from those inputs.
4. Why we handle information
We handle information to:
- authenticate the store and authorised staff;
- identify compatible orders and preview, create, verify, revise or undo combined parcels under merchant settings and instructions;
- apply configured holds, fulfilment, tracking, history, billing and notification workflows;
- provide support, diagnose incidents, enforce usage limits and maintain security and reliability;
- respond to Shopify privacy webhooks and merchant/customer rights requests;
- prevent fraud, abuse, duplicate actions and unauthorised access; and
- comply with law, enforce our terms and establish, exercise or defend legal claims.
Where the GDPR or UK GDPR applies to our controller activities, we generally rely on performing our contract with the merchant, our legitimate interests in providing and securing the Service, compliance with legal obligations, and consent where the law requires it. The merchant is responsible for identifying and communicating the lawful basis for customer and order processing it instructs us to perform.
5. How we disclose information
We do not sell personal information, share it for cross-context behavioural advertising, or use customer/order data to advertise to individuals. We disclose information only as reasonably necessary:
- to the merchant and its authorised Shopify staff;
- to Shopify, including to read and update permitted store records and handle app billing and privacy requests;
- to the infrastructure providers identified on our Subprocessors page, subject to contractual confidentiality, security and purpose limits;
- to a merchant-authorised fulfilment provider where the merchant enables a supported connection or where Shopify routes order information under the merchant’s own configuration;
- to professional advisers, auditors, insurers or a genuine corporate transaction counterparty under appropriate confidentiality; or
- to authorities or other persons where we reasonably believe disclosure is required by law or necessary to protect rights, safety, security or the integrity of the Service.
We require service providers handling Shopify Merchant Data to protect it, use it only to provide their services to Merge Me, and keep it confidential and secure.
6. International and cross-border processing
The primary Merge Me application and database are designed to operate in Google Cloud’s Australia region. Shopify is a global platform and Cloudflare operates a global network, so information may also be processed in Australia, Canada, the United States and other countries in which those providers operate or route traffic. Privacy protections and government-access rules may differ between countries.
Where applicable, we use contractual and organisational safeguards for overseas processing, including data-processing terms and recognised transfer mechanisms. Australian Privacy Principle 8 may make us accountable for certain overseas disclosures. Merchants requiring a specific transfer mechanism should review the DPA and contact us before enabling live processing.
7. Retention
We keep identifiable information only for as long as needed for the Service, safety, privacy requests, legal obligations and dispute handling. Current operational defaults are:
| Record | Typical retention |
|---|---|
| Closed order-linked merge and operational records | 30 days after closure |
| Webhook deduplication metadata | 7 days |
| Encrypted privacy-request response and completed request receipt | Up to 30 days |
| Customer-redaction suppression record | Up to 30 days |
| Sent or terminally failed notification receipt | 30 days |
| De-identified safety counters, daily aggregates and retention-run summaries | Up to 90 days |
| Open safety, billing, writer or fulfilment records | Until resolved, then the applicable period starts |
| Expired online staff sessions | Deleted after access and refresh windows have both been expired for 30 days |
Short-lived keyed retry tombstones may be retained after deletion to safely acknowledge an exact repeated Shopify privacy webhook without restoring tenant data. Legal holds, unresolved payment obligations or security investigations may require longer retention of the minimum necessary record. Backup copies may persist for a limited rotation period and remain protected until deletion.
8. Shopify privacy requests and uninstall
Merge Me authenticates Shopify’s required customers/data_request, customers/redact and shop/redact requests. A valid request is placed into a tenant-bound deletion or export workflow and is intended to be completed within Shopify’s required period, unless law requires retention. Customer-data results are provided only through an authenticated merchant session.
Uninstalling stops new authorised app access and triggers deletion workflows. Uninstall does not itself reverse order or fulfilment changes already made in Shopify or another system.
9. Security
We use administrative, technical and organisational measures designed for the nature of the information, including tenant separation, least-privilege service roles, encryption in transit and at rest where supported, restricted secrets, authenticated webhooks, pseudonymous operational keys, bounded logs, retention controls, change review, monitoring and incident procedures. No internet or storage system is perfectly secure, and we cannot guarantee absolute security.
10. Cookies and similar technologies
The public marketing site does not currently use advertising cookies or non-essential analytics cookies. Shopify, Merge Me and Cloudflare may use strictly necessary session, authentication, security and load-management technologies in the embedded app or protected console. See the Cookie Notice.
11. Your rights and choices
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated processing, and to complain to a privacy regulator. These rights are subject to legal exceptions.
Shopify customers should first contact the merchant from whom they purchased because that merchant controls the relevant order relationship and can submit a request through Shopify. Merchants and website visitors may contact us directly. We may need to verify identity and authority before acting. We do not discriminate for exercising a privacy right.
12. Children
Merge Me is a business service for Shopify merchants and is not directed to children. We do not knowingly collect children’s information directly through the website. Order data may include information supplied to a merchant; the merchant is responsible for ensuring that collection and its instructions are lawful.
13. Privacy complaints
Send a request or complaint to help@mergeme.app with “Privacy” in the subject. Describe the issue and your relationship to the relevant store, but do not email identity documents or unnecessary customer data unless we request a secure method. We will acknowledge the complaint, investigate it and aim to respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner or the regulator available in your jurisdiction.
14. Changes
We may update this policy when practices, providers or laws change. The current version and effective date will be posted here. We will give additional notice through Shopify or the Service where a change is material and the law requires notice.
15. Contact
Marvello Pty Ltd · ABN 72 691 509 261 · Queensland 4217, Australia
Email: help@mergeme.app