Privacy Policy
This policy explains what MerchMesh does with personal data when you use the MerchMesh app in Canva, the MerchMesh app in Shopify, our plan and billing pages, or this website. It also explains what happens to the data of shoppers who visit a store that runs a MerchMesh A/B test.
1. Who we are
MerchMesh is operated by DALI GAMES Prosta Spółka Akcyjna, doing business as MerchMesh, ul. Na Ostatnim Groszu 3, 54-207 Wrocław, Poland, NIP 8943202508, KRS 0001011601.
For the data of the people who use MerchMesh (sellers, store owners and their staff) we are the controller under the EU General Data Protection Regulation (GDPR). For the data of shoppers in a store that runs a MerchMesh A/B test, the store owner is the controller and we process that data on the store owner's behalf (see section 5).
Contact for anything in this policy: contact@merchmesh.eu.
2. What we collect about sellers and store owners
| Category | What it is | Where it comes from |
|---|---|---|
| Account identifiers | Your Canva user and brand identifiers; if you use Shopify, your store's domain and the Shopify identifier of the staff member using the app; the link between a Canva account and a Shopify store when you connect them. We do not store your email address, name or a password. | Canva or Shopify, when you open the app. |
| Store connection | The access tokens Shopify issues when you install or connect the app, and the permissions you granted. Tokens are stored encrypted. | Shopify. |
| Product data | Products you import from your store (title, vendor, type, description, tags, options, images, variant titles, SKUs and prices), photos you upload, details you type, and the product facts you confirm, with who confirmed them and when. Location and camera metadata are removed from uploaded JPEG photos. | You, or your Shopify store at your request. |
| Brand profile | Brand colours, fonts, voice notes, description style and logo. | You. |
| Generated content | The images, product descriptions and other copy MerchMesh creates, and the kits they belong to. | Created by us from your product data. |
| Canva design data | When you use the app in Canva and grant the permissions Canva shows you, the app reads and changes the design you have open and receives the exports you ask for. | Canva, with your permission. |
| A/B test results | For tests you run: impressions, add-to-cart and purchase counts per variant, and for purchases the order ID, order number, order total and currency. We do not receive shoppers' names, email addresses or postal addresses. | Your storefront and your Shopify store (see section 5). |
| Billing data | Your plan, subscription status, and the identifiers our payment provider or Shopify use for your subscription. We never receive your card details. | Dodo Payments or Shopify. |
| Technical logs | Records of requests to our servers, such as time, request path, status and errors. Our hosting provider's logs may include IP addresses. | Automatically, when you use MerchMesh. |
Please do not upload photos of identifiable people, identity documents, or anything showing health, biometric or similarly sensitive information. MerchMesh is built for product photos.
3. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing MerchMesh: importing products, generating images and copy, saving kits, publishing to your store, running your A/B tests | Account identifiers, store connection, product data, brand profile, generated content, Canva design data, A/B test results | Performance of a contract (Art. 6(1)(b)) |
| Keeping MerchMesh reliable and secure, and finding out why a generation failed | Technical logs, and the traces described in section 4 (LangSmith) | Legitimate interests (Art. 6(1)(f)): running a reliable, secure service |
| Subscriptions, plan limits and accounting | Account identifiers, billing data | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
We do not send marketing emails and we do not sell personal data or share it for advertising.
AI and your content. We do not use your photos, product data or generated content to train AI models of our own. To create your kit we send them to the AI providers listed in section 4, which process them to return a result. How long each provider keeps a request, and whether it may use it for its own purposes, is set by that provider's terms.
4. Who processes it for us
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Google Cloud and Firebase (Google) | Runs our servers, database, file storage and A/B test analytics; hosts the Canva app and the plan pages | All data described in this policy | EU (Warsaw, Poland); Firebase Hosting serves pages from a global network |
| OpenRouter | Routes requests to the AI models that read your photos and write copy and image instructions (currently models from OpenAI, Anthropic and DeepSeek) | Product photos, product data, confirmed facts, brand voice | USA; the model provider may process the request in the USA or another country |
| Replicate | Generates kit images (with an OpenAI image model) and removes photo backgrounds | Product photos and image instructions | USA |
| LangSmith (LangChain) | Records each generation step so we can find and fix failures | Instructions sent to the AI models and their answers, including product data and links to photos; never passwords or access tokens | EU |
| Netlify | Hosts this website | Standard web request data, such as IP address and browser type | USA |
Independent controllers. These companies decide for themselves how they use the data they hold, under their own privacy policies:
- Canva, for the data it holds about you as a Canva user (Canva privacy policy).
- Shopify, for your store and its customers, and for subscriptions billed through Shopify (Shopify privacy policy).
- Dodo Payments, which sells MerchMesh subscriptions bought outside Shopify as merchant of record and collects your payment and invoicing details on its own checkout page (Dodo Payments privacy policy).
- Google Fonts: our plan pages load fonts from Google, which receives your IP address when they load.
We may also disclose data where the law requires it, or to establish or defend legal claims. If MerchMesh is sold or merged, data may transfer to the new owner, and we will tell you before that happens.
5. Shoppers in stores that run a MerchMesh A/B test
When a store owner runs a MerchMesh A/B test, the store's product pages show shoppers one of the variants being tested and measure which one sells better. The store owner is the controller of this data; we process it only to run the store owner's tests.
- What is collected: a random visitor ID, which variant the shopper saw, the page path, and the time of each impression, button click and add-to-cart. If the shopper buys, the visitor ID and the variants they saw are attached to the order, and we receive the order ID, order number, total, currency and the products bought.
- What is not collected: the shopper's name, email, phone number or address. The visitor ID is random and is not linked to a Shopify customer account.
- Cookies:
_mmab_vid(the random visitor ID) and_mmab_seen(which variants the shopper has seen). Both last up to 365 days, so a returning shopper sees the same variant. A session-only entry limits error reports to one per visit. - Retention: results are kept while the store uses MerchMesh so the store owner can see past tests, and are deleted as described in section 6.
Shoppers who want to exercise their rights should contact the store. We will help the store owner answer any request.
6. How long we keep it
| Data | How long |
|---|---|
| Product data, brand profiles, generated content, kits and A/B test results | While you use MerchMesh, so you can come back to your kits and tests. You can ask us to delete any of it, or all of it, at any time. |
| Store connection tokens | While the app is installed. Shopify invalidates them when you uninstall the app. |
| Billing records | As long as tax and accounting law requires (in Poland, 5 years from the end of the year the payment was made). |
| Technical logs | About 30 days, under our hosting provider's standard log retention. |
To delete your data, write to contact@merchmesh.eu from the Canva account or store you use MerchMesh with, or tell us which store it is. We complete deletions within 30 days and confirm when it is done. Generated images already published to your store or saved in your Canva designs stay there; you control them in Shopify or Canva.
7. Transfers outside the European Economic Area
Some providers in section 4 are in the United States, and an AI model provider may process a request in another country. For these transfers we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards at contact@merchmesh.eu.
8. Your rights
Under GDPR you have the right to access your data, to correct it, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. Exercising these rights is free.
Write to contact@merchmesh.eu and we will answer within 30 days. You can also complain to a data protection authority. In Poland that is the Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
9. Security
Data travels over encrypted connections (TLS) and is encrypted at rest by our hosting provider. Store access tokens are additionally encrypted with AES-256-GCM before they are saved. Generated kit images are stored at long, unguessable web addresses so Canva and your store can load them; anyone who has such an address can open that image. No system is perfectly secure. If a breach is likely to put your rights at risk, we will tell you and the supervisory authority as GDPR requires.
10. Cookies and similar storage
- This website sets no cookies. It loads fonts from Google Fonts.
- The MerchMesh app in Canva remembers the last store domain you connected in your browser's local storage, so you do not have to type it again. It sets no cookies.
- The MerchMesh app in Shopify and our plan pages set no cookies. The plan pages receive a short-lived sign-in code in their address, which expires within minutes.
- Storefronts running an A/B test use the cookies described in section 5.
11. Children
MerchMesh is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.
12. Changes to this policy
When we change this policy we update the date at the top. If a change materially affects your rights, we will tell you in the app before it takes effect.
13. Contact
Questions, requests and complaints: contact@merchmesh.eu. Postal address: DALI GAMES Prosta Spółka Akcyjna, ul. Na Ostatnim Groszu 3, 54-207 Wrocław, Poland.