MerchantDeck AI Install MerchantDeck

Privacy policy

Effective date: August 19, 2026

This Privacy Policy explains how Martin Dimitrov Golemanov ("MerchantDeck AI", "we", "us", or "our") processes personal data when you visit https://merchantdeckai.com, join our waitlist, contact us, install or use the MerchantDeck AI Shopify app, or otherwise interact with our services.

Operator address: 58 Balgarska Morava St., 1303 Sofia, Bulgaria Privacy and support email: prjctmilly@gmail.com
Operator country: Bulgaria

1. Scope and roles

This policy covers the MerchantDeck AI public website, waitlist and support forms, and the MerchantDeck AI Shopify app (together, the "Services").

The website may describe approved roadmap capabilities that are planned for later development. A roadmap description does not mean that a feature is active, that we currently process the data associated with it, or that a specific release date is guaranteed. Before enabling a feature that materially changes data collection, permissions, providers, or purposes, we will update this policy and complete any required consent, platform-review, and security steps.

For website, account, billing, security, and support information, we generally act as a data controller. When we process Shopify store data to provide app features on a merchant's instructions, we may act as a processor or service provider for that merchant. Shopify merchants remain responsible for their own privacy notices and lawful use of the Services.

2. Information we process

Website, waitlist, and support

  • Waitlist email address, consent choice, signup source, and Shopify customer tags used to record the early-access request.
  • Support form details: name, email address, optional Shopify store URL, request topic, message, and privacy acknowledgement.
  • Technical information such as IP address, browser and device information, pages or features used, timestamps, cookie choices, security events, and diagnostic logs.
  • Analytics information only when an approved analytics tool is configured and the visitor's applicable Shopify privacy choice permits analytics processing.

Please do not submit passwords, API keys, payment card details, health information, or other sensitive data through the support form.

Shopify app

  • Store and account identifiers, including shop domain, Shopify identifiers, installation status, subscription entitlement, and encrypted access credentials.
  • Catalog information available under the approved read_products scope, including products, variants, collections, descriptions, pricing, inventory-related fields, and publication state.
  • Merchant-provided goals, brand guidance, protected terms, risk preferences, audit requests, decisions, and support communications.
  • Generated recommendations, quality-assurance results, workflow state, usage counters, and limited security and diagnostic logs.
  • Identifiers necessary to authenticate and honor Shopify's mandatory data-request and redaction webhooks.

The current commercial V1 app does not request Shopify permissions for customer or order data. If this changes, we will update the policy and obtain any required approvals before using the additional data.

Billing

Shopify presents and processes app subscription approval and billing. We receive the subscription and entitlement information needed to provide the selected plan; we do not receive full payment card details from Shopify.

3. Why we use information

We process information to:

  • provide the website, waitlist, support, app, and subscribed features;
  • authenticate stores, sync approved catalog fields, and run merchant-requested audits;
  • generate, validate, prioritize, and display recommendations;
  • manage subscriptions, usage limits, service communications, and support;
  • secure, debug, maintain, and improve the Services;
  • prevent misuse and enforce our Terms; and
  • comply with Shopify requirements and applicable law.

Depending on the context and applicable law, our legal bases may include performance of a contract, legitimate interests in operating and securing the Services, compliance with legal obligations, and consent for optional marketing or analytics. You can withdraw consent at any time without affecting processing that occurred before withdrawal.

4. AI-assisted processing and merchant control

Selected store context and merchant instructions may be sent to Anthropic's API to generate analysis and recommendations. During the current public beta, MerchantDeck AI is read-only: it does not automatically change products, themes, advertisements, campaigns, emails, or customer communications. Merchants decide whether and how to use any output.

AI-generated output may be incomplete or inaccurate. Do not submit unnecessary personal data or sensitive information in free-text instructions.

5. Service providers and disclosures

We disclose information only as needed to operate, secure, or lawfully administer the Services.

Provider/category Purpose Typical data involved
Shopify Website platform, forms, app installation, merchant authentication, subscription billing, and privacy requests Website interactions and submissions, privacy choices, shop identifiers, catalog fields, subscription state
Anthropic AI-assisted analysis and recommendation generation Selected catalog context and merchant instructions
Render Application hosting, managed database, private cache/orchestration infrastructure, logs App records, encrypted credentials, workflow state, operational logs
Google Analytics 4, only if enabled Consent-gated website measurement Online identifiers and usage events permitted by the visitor's privacy choice
Professional advisers and authorities Legal, security, fraud prevention, or compliance purposes Only information reasonably necessary for the request or obligation

We may also disclose information in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and applicable law.

We do not sell personal data for money. Some laws use broader definitions of "sale," "sharing," or targeted advertising. Shopify Network Intelligence and the Shopify Shop remarketing controls are disabled for the marketing store. Shopify's automated cookie banner and data-sharing opt-out page remain available so visitors can exercise applicable privacy choices. See the Shopify Consumer Privacy Policy for more information. We will update this policy and complete any required consent and launch QA before enabling optional targeting or enhanced-data services.

6. International transfers

We and our providers may process information outside your country. Where required, transfers rely on an adequacy decision, contractual safeguards, or another lawful transfer mechanism. Provider locations and safeguards may change with their services.

7. Retention and deletion

We keep information only as long as reasonably needed for the purposes described above, security, dispute resolution, and legal obligations. The operating retention schedule approved on 2026-08-18 is below.

Record type Approved operating retention rule
Waitlist records Until unsubscribe, invalidation, or 24 months after the final meaningful interaction, whichever occurs first
Support requests 24 months after closure unless needed for an active account, dispute, security event, or legal obligation
Active merchant app data For the subscription/installation term and as needed to provide the Services
Uninstalled-shop data Delete or anonymize when the authenticated Shopify shop/redact request is processed, subject only to legal exceptions and protected backup expiry
Security and operational audit records 12 months, unless a longer period is reasonably required for an active incident, dispute, abuse investigation, or legal obligation
Subscription and billing evidence Only the entitlement and transaction evidence needed to operate the service, for the period required by applicable accounting, tax, dispute, or legal obligations; Shopify processes the underlying payment details
Analytics data Not intentionally collected through GA4 at launch. If GA4 is later approved and enabled, use the shortest approved property retention setting and update this policy before activation

Valid Shopify privacy requests are authenticated and handled through the mandatory compliance webhooks. Backups may retain residual data for a limited, protected period before normal deletion cycles complete.

8. Security

We use safeguards designed to protect information, including encrypted app credentials, tenant isolation, authenticated internal requests, private infrastructure, restricted production secrets, dependency monitoring, and operational logging designed to avoid raw credentials and unnecessary content. No system is completely secure, and we cannot guarantee absolute security.

9. Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, withdraw consent, and complain to a competent data protection authority.

  • Use the unsubscribe option in a marketing email or contact us to leave the waitlist.
  • Use the website privacy controls to manage optional cookies where available.
  • Contact us at prjctmilly@gmail.com for a privacy request relating to your account or website interaction.
  • If you are a customer of a Shopify merchant, submit requests to that merchant. The merchant can use Shopify's required privacy-request process where MerchantDeck AI is involved.

We may need to verify identity and authority before completing a request. Rights can be subject to lawful exceptions.

10. Cookies and similar technologies

Shopify and its providers use cookies and similar technologies needed to run and secure the website. Optional analytics will not be intentionally loaded by the theme unless an approved measurement ID is configured and Shopify indicates that analytics processing is allowed. See our Cookie Notice and the on-site privacy controls for more information.

11. Children's data

MerchantDeck AI is a business service intended for adults authorized to act for a Shopify merchant. It is not directed to children, and we do not knowingly collect children's personal data through the Services.

12. Changes and contact

We may update this policy when our Services, providers, data scope, or legal obligations change. We will post the new effective date and provide additional notice when required.

Questions and privacy requests can be sent to prjctmilly@gmail.com or by post to 58 Balgarska Morava St., 1303 Sofia, Bulgaria. The supervisory authority for our establishment is Bulgaria's Commission for Personal Data Protection (CPDP); official contact details are available at https://cpdp.bg/en/contacts/.