This Privacy Policy explains how MerchantWave ("we", "our", "us") handles information when you use our commerce platform, including our point of sale, online storefront, inventory, customer, marketing, reporting and staff management tools (together, the "Service"). By using the Service you agree to the practices described below.
1. Who this policy applies to
MerchantWave serves two groups of people, and we treat their data differently:
- Business customers: owners and staff who create a MerchantWave workspace to run their business.
- Shoppers: end customers who buy from a merchant that runs on MerchantWave. In that case the merchant is the data controller and we act as their processor.
2. Information we collect
- Account data: name, email address, phone number, business name, industry, country, currency and time zone.
- Business data: products, inventory, prices, customers, orders, promotions, receipts and reports you create inside your workspace.
- Payment data: subscription billing is processed by our payment provider Paddle. We never store your full card number on our servers.
- Usage data: device type, browser, IP address, pages visited and actions taken, used to keep the Service secure and to improve it.
- Communications: messages you send to support, and email delivery logs so we can prove that a receipt or invitation was actually delivered.
3. How we use information
- To provide, secure and improve the Service.
- To process subscription payments and send billing receipts.
- To send transactional email such as sign up verification, password reset, order confirmations and staff invitations.
- To detect fraud, abuse and unauthorized access.
- To provide customer support when you contact us.
- To send occasional product updates, which you can unsubscribe from at any time.
4. Legal bases
Where the GDPR or similar laws apply, we process your data on the basis of contract (to deliver the Service you signed up for), legitimate interests (to secure and improve the Service), consent (marketing email you opt into), and legal obligation (tax, accounting and fraud prevention).
5. Data isolation and security
Every MerchantWave workspace is a separate tenant enforced by row level security at the database layer. Staff of one business cannot see the data of another. All data is encrypted in transit with TLS and at rest on our infrastructure. Access to production systems is restricted, logged and reviewed.
6. Sharing with third parties
We share the minimum data required with the vendors that power the Service:
- Hosting and database: our infrastructure provider stores your workspace data.
- Payments: Paddle acts as merchant of record for subscription billing.
- Email delivery: our transactional email provider sends system messages you trigger.
- Analytics: anonymized product usage to improve the Service.
We do not sell personal information and we do not share it for cross context behavioural advertising.
7. Retention
We keep your workspace data for as long as your account is active. When you close your account we keep a minimal backup for up to 30 days to protect against accidental deletion, after which the data is permanently removed. Financial records may be retained longer where required by tax law.
8. Your rights
Depending on where you live you may have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Request deletion of your account and personal data.
- Export a copy of your workspace data.
- Withdraw consent for marketing communications.
To exercise any of these rights, email reloadedwebsolution@gmail.com.
9. Cookies
We use cookies and local storage to keep you signed in, remember your workspace preferences and measure aggregate usage. You can clear them from your browser at any time; some features will not work while you are signed out.
10. Children
The Service is not intended for anyone under 16. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. When we make material changes we will notify account owners by email or by an in app notice at least 14 days before the change takes effect.
12. Contact
Questions or concerns? Email reloadedwebsolution@gmail.com or write to us at MerchantWave, Kingston, Jamaica.