← Back to site

Privacy Policy

Last updated: 24 September 2026

This policy explains what MerchMesh does with personal data when you use the MerchMesh app in Canva, the MerchMesh app in Shopify, our plan and billing pages, or this website. It also explains what happens to the data of shoppers who visit a store that runs a MerchMesh A/B test.

1. Who we are

MerchMesh is operated by DALI GAMES Prosta Spółka Akcyjna, doing business as MerchMesh, ul. Na Ostatnim Groszu 3, 54-207 Wrocław, Poland, NIP 8943202508, KRS 0001011601.

For the data of the people who use MerchMesh (sellers, store owners and their staff) we are the controller under the EU General Data Protection Regulation (GDPR). For the data of shoppers in a store that runs a MerchMesh A/B test, the store owner is the controller and we process that data on the store owner's behalf (see section 5).

Contact for anything in this policy: contact@merchmesh.eu.

2. What we collect about sellers and store owners

CategoryWhat it isWhere it comes from
Account identifiersYour Canva user and brand identifiers; if you use Shopify, your store's domain and the Shopify identifier of the staff member using the app; the link between a Canva account and a Shopify store when you connect them. We do not store your email address, name or a password.Canva or Shopify, when you open the app.
Store connectionThe access tokens Shopify issues when you install or connect the app, and the permissions you granted. Tokens are stored encrypted.Shopify.
Product dataProducts you import from your store (title, vendor, type, description, tags, options, images, variant titles, SKUs and prices), photos you upload, details you type, and the product facts you confirm, with who confirmed them and when. Location and camera metadata are removed from uploaded JPEG photos.You, or your Shopify store at your request.
Brand profileBrand colours, fonts, voice notes, description style and logo.You.
Generated contentThe images, product descriptions and other copy MerchMesh creates, and the kits they belong to.Created by us from your product data.
Canva design dataWhen you use the app in Canva and grant the permissions Canva shows you, the app reads and changes the design you have open and receives the exports you ask for.Canva, with your permission.
A/B test resultsFor tests you run: impressions, add-to-cart and purchase counts per variant, and for purchases the order ID, order number, order total and currency. We do not receive shoppers' names, email addresses or postal addresses.Your storefront and your Shopify store (see section 5).
Billing dataYour plan, subscription status, and the identifiers our payment provider or Shopify use for your subscription. We never receive your card details.Dodo Payments or Shopify.
Technical logsRecords of requests to our servers, such as time, request path, status and errors. Our hosting provider's logs may include IP addresses.Automatically, when you use MerchMesh.

Please do not upload photos of identifiable people, identity documents, or anything showing health, biometric or similarly sensitive information. MerchMesh is built for product photos.

3. Why we use it, and on what legal basis

PurposeData usedLegal basis
Providing MerchMesh: importing products, generating images and copy, saving kits, publishing to your store, running your A/B testsAccount identifiers, store connection, product data, brand profile, generated content, Canva design data, A/B test resultsPerformance of a contract (Art. 6(1)(b))
Keeping MerchMesh reliable and secure, and finding out why a generation failedTechnical logs, and the traces described in section 4 (LangSmith)Legitimate interests (Art. 6(1)(f)): running a reliable, secure service
Subscriptions, plan limits and accountingAccount identifiers, billing dataContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))

We do not send marketing emails and we do not sell personal data or share it for advertising.

AI and your content. We do not use your photos, product data or generated content to train AI models of our own. To create your kit we send them to the AI providers listed in section 4, which process them to return a result. How long each provider keeps a request, and whether it may use it for its own purposes, is set by that provider's terms.

4. Who processes it for us

ProviderWhat it doesWhat it receivesWhere
Google Cloud and Firebase (Google)Runs our servers, database, file storage and A/B test analytics; hosts the Canva app and the plan pagesAll data described in this policyEU (Warsaw, Poland); Firebase Hosting serves pages from a global network
OpenRouterRoutes requests to the AI models that read your photos and write copy and image instructions (currently models from OpenAI, Anthropic and DeepSeek)Product photos, product data, confirmed facts, brand voiceUSA; the model provider may process the request in the USA or another country
ReplicateGenerates kit images (with an OpenAI image model) and removes photo backgroundsProduct photos and image instructionsUSA
LangSmith (LangChain)Records each generation step so we can find and fix failuresInstructions sent to the AI models and their answers, including product data and links to photos; never passwords or access tokensEU
NetlifyHosts this websiteStandard web request data, such as IP address and browser typeUSA

Independent controllers. These companies decide for themselves how they use the data they hold, under their own privacy policies:

We may also disclose data where the law requires it, or to establish or defend legal claims. If MerchMesh is sold or merged, data may transfer to the new owner, and we will tell you before that happens.

5. Shoppers in stores that run a MerchMesh A/B test

When a store owner runs a MerchMesh A/B test, the store's product pages show shoppers one of the variants being tested and measure which one sells better. The store owner is the controller of this data; we process it only to run the store owner's tests.

Shoppers who want to exercise their rights should contact the store. We will help the store owner answer any request.

6. How long we keep it

DataHow long
Product data, brand profiles, generated content, kits and A/B test resultsWhile you use MerchMesh, so you can come back to your kits and tests. You can ask us to delete any of it, or all of it, at any time.
Store connection tokensWhile the app is installed. Shopify invalidates them when you uninstall the app.
Billing recordsAs long as tax and accounting law requires (in Poland, 5 years from the end of the year the payment was made).
Technical logsAbout 30 days, under our hosting provider's standard log retention.

To delete your data, write to contact@merchmesh.eu from the Canva account or store you use MerchMesh with, or tell us which store it is. We complete deletions within 30 days and confirm when it is done. Generated images already published to your store or saved in your Canva designs stay there; you control them in Shopify or Canva.

7. Transfers outside the European Economic Area

Some providers in section 4 are in the United States, and an AI model provider may process a request in another country. For these transfers we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards at contact@merchmesh.eu.

8. Your rights

Under GDPR you have the right to access your data, to correct it, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. Exercising these rights is free.

Write to contact@merchmesh.eu and we will answer within 30 days. You can also complain to a data protection authority. In Poland that is the Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

9. Security

Data travels over encrypted connections (TLS) and is encrypted at rest by our hosting provider. Store access tokens are additionally encrypted with AES-256-GCM before they are saved. Generated kit images are stored at long, unguessable web addresses so Canva and your store can load them; anyone who has such an address can open that image. No system is perfectly secure. If a breach is likely to put your rights at risk, we will tell you and the supervisory authority as GDPR requires.

10. Cookies and similar storage

11. Children

MerchMesh is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

12. Changes to this policy

When we change this policy we update the date at the top. If a change materially affects your rights, we will tell you in the app before it takes effect.

13. Contact

Questions, requests and complaints: contact@merchmesh.eu. Postal address: DALI GAMES Prosta Spółka Akcyjna, ul. Na Ostatnim Groszu 3, 54-207 Wrocław, Poland.