Skip to main content
Privacy & ComplianceEffective: September 6, 2026 • Version 1.2

Privacy Policy & Data Disclosures

How MeritSKU Inc., a Delaware corporation, collects, protects, isolates, and purges personal data and proprietary e-commerce intelligence under the European General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), and enterprise cryptographic standards.

At a Glance: Our Institutional Privacy Commitments

Zero Data Sale

We never sell, rent, or trade customer information, sourcing proposals, or product catalog data.

AES-256-GCM + AAD

Store OAuth credentials encrypted with workspace-bound AAD. Sub-500ms cryptographic revocation.

No Model Training

Customer data and supplier quotes are strictly never used to train public foundation AI models.

Self-Service Erasure

On-demand GDPR/CCPA purge with cryptographic SHA-256 proof certificate of data destruction.

1. Information We Collect

Account & Identity Identifiers: Name, business email, workspace role, and authentication tokens issued via secure session cookies (__Host-msku_session).

E-Commerce Intelligence Data: Merchant store domains ({shop}.myshopify.com), candidate product URLs, supplier quotations, landed cost calculations, and ad budget ceiling parameters ($200 to $1,000).

Technical & Telemetry Data: IP addresses (utilized strictly for rate limiting, DDoS mitigation, and geographic fraud checks), browser headers, and anonymized interaction events via PostHog with strict PII masking.

2. Authorized Third-Party Subprocessors

To provide our service, MeritSKU engages vetted infrastructure, database, billing, and AI inference providers under binding Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs).

Review our complete, real-time register of infrastructure partners, geographic hosting locations, and transfer safeguards in our Subprocessor Directory →

3. Data Retention Schedules

MeritSKU adheres to strict data minimization principles. Data is retained only for the period necessary to fulfill its operational purpose:

Data ClassificationRetention WindowPurge / Shredding Mechanism
Account & Identity RecordsActive tenancy + 30 days post-cancellationPermanent cryptographic purge from primary database
Product Analyses & Sourcing QuotesActive tenancy + 90 days post-cancellationCascading database purge; automated backup roll-off
Commerce OAuth CredentialsImmediate upon store disconnection<500ms cryptographic token shredding
Immutable Audit Logs365 daysWrite-once append-only storage for SOC 2 compliance
Telemetry & Health Metrics90 daysAutomated TTL expiration with PII masking
AI Inference TranscriptsZero Retention (ZDR)Stateless inference; no upstream caching or training

4. Multi-Tenant Isolation & Cryptographic Standards

Row-Level Security (RLS): Multi-tenancy is enforced directly within PostgreSQL 16. Each query runs within a transaction bound to the caller's authenticated workspace ID (app.current_workspace_id). Cross-tenant access is physically impossible at the database engine layer.

Encryption at Rest & Transit: All data in transit is encrypted using TLS 1.3 with HTTP Strict Transport Security (HSTS). Sensitive third-party credentials (including Shopify and Amazon OAuth secrets) are encrypted at rest using AES-256-GCM with workspace-bound Additional Authenticated Data (AAD).

Stealth Anti-Enumeration: Private workspace and administrative routes (/admin/**) return stealth HTTP 404 responses to unauthenticated or unauthorized callers, preventing tenant enumeration and route discovery.

AI Nonce-Framed Prompt Isolation: Untrusted external supplier texts are encapsulated in 128-bit hex cryptographic nonces before LLM inference, neutralizing prompt injection attacks.

5. European Data Subject Rights (GDPR Articles 15–21)

If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, you possess the following statutory rights under Regulation (EU) 2016/679:

  • Right of Access (Art. 15 GDPR): You may request full confirmation and a copy of all personal data processed by MeritSKU.
  • Right to Rectification (Art. 16 GDPR): You may correct inaccurate or incomplete profile records directly in your workspace settings.
  • Right to Erasure (Art. 17 GDPR): You may trigger automated, irreversible tenant workspace erasure. MeritSKU issues a cryptographically signed SHA-256 certificate of data destruction upon completion.
  • Right to Restriction of Processing (Art. 18 GDPR): You may request temporary suspension of data processing during verification disputes.
  • Right to Data Portability (Art. 20 GDPR): You may download all workspace candidate data in standard, structured JSON or CSV format.
  • Right to Object (Art. 21 GDPR): You may object at any time to processing based on legitimate business interests.

6. California Privacy Disclosures (CCPA & CPRA)

Under the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act of 2020), California residents have specific privacy protections:

Statutory Confirmation: MeritSKU has not sold or shared any consumer personal information for cross-context behavioral advertising in the preceding 12 months, and has no actual knowledge of any sale or sharing of personal data of consumers under 16 years of age.

To exercise your California privacy rights (Right to Know, Delete, or Correct), submit a request to privacy@meritsku.com or use our self-service workspace settings. We will acknowledge receipt within 10 days and respond substantively within 45 calendar days without discrimination.

7. Commercial Disclaimers & FTC Notice

FTC Disclosure

Commercial Risk & FTC No-Revenue-Guarantee Notice

MeritSKU provides analytical product intelligence and theoretical simulations based on user assumptions and historical market benchmarks. MeritSKU makes no promise, representation, or guarantee of commercial revenue, profitability, conversion rates, or return on ad spend (ROAS). Past performance and MeritScore benchmarks do not guarantee future results. Paid advertising campaigns carry capital risk, including the possible loss of 100% of allocated ad spend. Recommended ad ceilings ($200 to $1,000) are stop-loss risk mitigation bounds, not earnings promises. Merchants are solely responsible for supplier quality, regulatory compliance, and storefront publishing decisions.

Stop-loss ad ceilings ($200–$1,000) cap financial downside. Past data does not guarantee sales.Learn more about our methodology →

8. Contacting Our Data Protection Officer

If you have questions regarding this Privacy Policy or our security architecture, contact:

MeritSKU Inc. — Privacy & Data Protection

548 Market St, Suite 32000, San Francisco, CA 94104

Email: privacy@meritsku.com

Security Vulnerabilities: security@meritsku.com