Legal · last updated 6 October 2026

Privacy Policy

What personal data Mercify processes, why, with whom it is shared, how long it is kept and what your rights are.

1. Who is responsible

Cogenta B.V., St. Janstraat 11-A, 4811 ZK Breda, the Netherlands (KvK 42142544), operates Mercify.ai and is the controller for the personal data you share with us through the website and the app. Questions about privacy: hello@mercify.ai.

For the customers, orders and visitors of the Shopify store we build for you, you are the controller. Mercify only processes that data on your instructions while building, transferring or supporting your store.

2. What we process and why

DataPurposeLegal basis
Account data: name, e-mail address, password (hashed), login codes, team invitationsCreating and securing your account, logging in, team accessPerformance of the contract
Business and billing data: company name, address, VAT number, orders, payment statusSelling stores and credits, invoicing, bookkeepingContract and legal obligation (7-year retention)
Intake and store content: niche, market, preferred name, style, colours, uploaded logo, proposals, generated texts and images, Shopify store addressPreparing, building and transferring your store; showing progressPerformance of the contract
Support messages and attachmentsHelping you, handling complaints and replacementsContract and legitimate interest
Technical data: IP address, browser, timestamps, error logsOperation, security, fraud and abuse preventionLegitimate interest

We do not sell personal data and do not use it for advertising profiles. We do not make automated decisions with legal effect about you; AI is used to generate store content, not to assess you.

3. Artificial intelligence

Mercify uses AI models to propose store names, write product texts, select products and create logos and images. For that purpose we send your intake (niche, market, style preferences, optional name and logo) and product information to our AI providers (currently Anthropic and OpenAI) under contracts that prohibit them from using the data to train their models. We do not send your login or payment details to AI providers. Generated content is stored in your account as part of your store.

4. Service providers

We use these providers, each under a data processing agreement or equivalent contractual terms:

  • Supabase (database, authentication and file storage) and Vercel (hosting, EU region) run the platform.
  • Mollie processes payments. Mollie receives your name, e-mail address, amount and order reference, and handles your payment details under its own privacy policy as an independent payment institution.
  • Shopify hosts the store we build. When we transfer the store to you, your name and e-mail address are shared with Shopify, and Shopify's terms and privacy policy apply to your use of Shopify.
  • Product suppliers (such as CJ Dropshipping) provide product data and images; we do not share your personal data with them unless you connect your own supplier account.
  • Anthropic and OpenAI provide AI models (see section 3).
  • Resend delivers our e-mails (login codes, confirmations, invoices, support).
  • MoneyBird stores our invoices and bookkeeping records.

Some providers process data outside the European Economic Area, in particular in the United States. In those cases we rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

5. How long we keep data

Your account, intake and store content are kept as long as your account exists. You can delete concepts, uploaded files and your account in the app; after deletion we erase your account data within 30 days, and provider back-ups expire according to their policies (at most 30 days thereafter). Orders, invoices and payment records are kept for 7 years because of Dutch tax law, decoupled from the deleted account where possible. Technical logs are kept for at most 90 days; login codes expire after a few minutes. Stores already transferred to your Shopify account are yours and are not affected by deleting your Mercify account.

6. Cookies

mercify.ai uses only strictly necessary cookies and similar storage: a session cookie to keep you logged in, security tokens, and browser storage that remembers choices you make before creating an account (such as your niche and style). We do not use analytics or advertising cookies, so no cookie consent is requested. If that changes, we will ask for your consent first and update this policy.

7. Your rights

You can access, correct, export (as JSON) and delete your data, object to processing based on legitimate interest, and ask us to restrict processing. Most of this you can do yourself in your account; for the rest, e-mail hello@mercify.ai. We respond within one month. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your own country.

8. Security

Data is encrypted in transit (TLS) and at rest by our providers. Access to production data is limited to team members who need it, protected by strong authentication. Shopify access tokens are stored encrypted and are never shown in the app. If a data breach would affect you, we inform you and the supervisory authority as required by law.

9. Changes

We update this policy when our processing changes and announce material changes in the app or by e-mail. The date at the top shows the current version.

Cogenta B.V. · St. Janstraat 11-A, 4811 ZK Breda, the Netherlands · KvK 42142544 · VAT NL869907438B01 · hello@mercify.ai