Privacy Policy
MelQart is a competitive intelligence and pricing platform for e-commerce merchants. Most personal data we handle relates to the people who run merchant accounts with us. Where we access data from a merchant's connected store (for example, order or customer records via Salla, Zid, Shopify, or WooCommerce), we act as a Processor on that merchant's behalf, governed by our Data Processing Agreement with the merchant rather than by this Policy (see Section 8).
1. Who we are and how to reach us
The data Controller is MelQart. For any privacy question or to exercise your rights, contact us at support@melqart.me.
2. Who this Policy applies to
- Account users: people who register, log in, or are invited to a MelQart workspace.
- Website visitors: people who visit our marketing site or contact us.
- Prospects and contacts: people we communicate with about MelQart.
It does not govern personal data we process on a merchant's instructions through their connected store (Section 8).
3. The personal data we collect
Account and identity data. Name, work email, phone number, role, workspace name, business name, and authentication data.
Billing data. Business name, VAT/tax identifiers, billing contact, and transaction records. Card details are handled by our payment processor; we do not store full card numbers.
Store and integration data. When you connect a store, we receive access credentials (tokens) and the catalogue, pricing, inventory, and order data needed to run the Service. Where this includes personal data of your customers (for example, in orders), we process it as your Processor (Section 8).
Competitive market data. Publicly available product, price, and listing information from third-party marketplaces and stores. This is predominantly non-personal commercial data; where it incidentally contains personal data, we minimise it and limit our use to operating the Service.
Usage and technical data. Log data, device and browser information, IP address, features used, and diagnostic data.
Communications data. Messages, support requests, and feedback you send us.
We do not intend to collect Special Category Data as defined by UK GDPR Article 9 (for example, data revealing health, religion, or ethnicity). If any is provided, we handle it only where a valid legal basis and a specific Article 9 condition applies.
4. How we use personal data and our legal basis
Under UK GDPR Article 6, we process personal data only where a legal basis applies:
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Creating and administering your account; providing the Service | Performance of a contract |
| Billing, invoicing, and collecting fees | Performance of a contract; legal obligation |
| Securing the Service, preventing fraud and abuse, logging | Legitimate interests |
| Improving and developing features, aggregated analytics | Legitimate interests / de-identified data |
| Customer support and service communications | Performance of a contract |
| Marketing to business prospects | Consent, or legitimate interests with an opt-out |
| Collecting publicly available competitive market data | Legitimate interests, applying data minimisation |
| Meeting legal or regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we assess that our interest is not overridden by your rights and reasonable expectations. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
5. AI and automated processing
MelQart uses AI and automated logic in features including competitor price tracking, repricing recommendations, listing optimisation, and reporting. Consistent with UK GDPR Article 22 and the Information Commissioner's guidance on automated decision-making and profiling:
- MelQart produces repricing recommendations, not automated decisions. Price changes require human review and approval before they take effect; the Service does not push prices to your store without that approval. These features therefore do not make significant decisions about individuals based solely on automated processing.
- The market and pricing data these features rely on is overwhelmingly commercial and non-personal, and does not involve Special Category Data.
- If we introduce features that produce legal or similarly significant effects on an individual based solely on automated processing, we will provide clear information about the logic, offer human intervention and a route to contest the outcome, and carry out a data protection impact assessment first.
6. When we share personal data
- Service providers (Processors) acting on our instructions: cloud hosting and database infrastructure, analytics, error monitoring, email, payment processing, and AI model providers, each bound by a written contract meeting UK GDPR Article 28 requirements.
- Within your organisation: with other authorised users of your workspace.
- Legal and regulatory: where required by law, judicial order, or a competent authority in the United Kingdom or other relevant jurisdiction.
- Business transfers: in connection with a merger, acquisition, or financing, subject to confidentiality and to this Policy.
We do not sell personal data.
7. International data transfers
We and our service providers may process personal data in the United Kingdom, the European Economic Area, and other countries, including the United States. Where we transfer personal data outside the UK, we rely on an adequacy regulation, Standard Contractual Clauses with the UK International Data Transfer Addendum, or another transfer mechanism recognised under UK GDPR Chapter V, together with any additional safeguards a transfer risk assessment identifies as necessary. You can ask us for detail on the safeguards we use for a specific transfer.
8. When we act as a Processor (connected stores)
When you connect your store, MelQart accesses data from that store to operate the Service for you. To the extent that data includes personal data of your own customers, you are the Controller and MelQart is your Processor under UK GDPR. We process that data only on your documented instructions, to provide the Service, and apply appropriate security measures. The governing terms, including security, sub-processors, breach notification, transfers, and deletion on termination, are set out in our Data Processing Agreement, which forms part of your contract with us.
9. How long we keep data
- Account data: for the life of the account and a limited period afterwards.
- Billing records: for the period required by UK tax and accounting law (currently up to 6 years).
- Logs and diagnostics: a limited retention window for security and reliability.
- Store/integration data: deleted or returned on termination per the Data Processing Agreement.
10. How we protect data
We apply appropriate technical and organisational measures, including access controls, encryption in transit, segregation of credentials, tenant isolation, monitoring, and incident-response procedures. If a personal data breach occurs, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, where required under UK GDPR, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
11. Your rights
Subject to the conditions and exemptions in UK GDPR and the Data Protection Act 2018, you have the right to:
- Be informed of the legal basis and purpose for collecting your personal data.
- Access your personal data held by us.
- Obtain a copy of your personal data in a readable format.
- Request correction (rectification) of inaccurate, incomplete, or outdated data.
- Request erasure of your personal data where UK GDPR conditions apply.
- Request restriction of processing in certain circumstances.
- Data portability: receive personal data you provided to us in a structured, machine-readable format, or ask us to transmit it to another controller, where technically feasible.
- Object to processing based on legitimate interests, or to direct marketing at any time.
- Withdraw consent at any time where consent is the basis.
To exercise any right, contact support@melqart.me. If you believe your rights have not been respected, you may complain to the ICO at ico.org.uk; we would welcome the chance to resolve your concern first.
12. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. In line with the UK Privacy and Electronic Communications Regulations (PECR), we obtain consent for non-essential cookies and provide an opt-out for analytics cookies. You can control cookies through your browser; disabling some may affect functionality.
13. Children
The Service is for business use by adults. We do not knowingly collect personal data from minors. If you believe a minor's data has reached us, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy as the Service or the law changes. We will post the updated version with a new "Last updated" date and, for material changes, take reasonable steps to notify you.
15. Contact
MelQart, support@melqart.me