Privacy Policy
MerchandiserOS. Last updated 27 June 2026.
1. Who we are
MerchandiserOS (“the Service”, “we”, “us”) is an operations platform for apparel factories and brands. This policy explains what personal information we collect, why, how we handle it, and your choices. For any privacy question or request, contact merchandiseros@merchandiseros.online.
2. Who this applies to
It applies to (a) visitors who register interest on our website, and (b) users of the MerchandiserOS application and the people whose business contact details our customers enter into it (for example a buyer or supplier contact). Our customers are businesses; the Service is intended for business use.
3. What we collect
- Registration / early-access details — your name, email, phone or WhatsApp number, optionally your company and what would help you most.
- Account details — name, work email, role, and a securely hashed password (we never store passwords in readable form), or a Google sign-in identifier if you sign in with Google.
- Business data you enter or upload — orders, styles, tech packs and files, materials, suppliers, buyers, costs, production and quality records, messages, and similar operational data.
- Email data (only if you connect Gmail) — see section 5.
- Technical data — basic logs needed to run and secure the Service (e.g. session cookies, IP address, error and access logs).
4. How we use information
- To provide, operate, secure and improve the Service.
- To contact you about access, support, and important service notices.
- To generate the AI drafts and document extractions you ask for (section 6).
- To meet legal, security and fraud-prevention obligations.
We do not sell your personal information, and we do not use it for advertising.
5. Google user data (Gmail), if you connect it
Connecting Gmail is optional. If you choose to, we request read-only access (the gmail.readonly scope) solely to read incoming messages you direct to the Service so it can recognise order-related emails and surface them for your review. We do not send, modify, label, or delete your email.
MerchandiserOS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide and improve the features above.
- We do not transfer it to others except as needed to provide the Service, for security, or to comply with law.
- We do not use it for advertising, and we do not allow humans to read it except with your consent, for security, to comply with law, or where the data is aggregated/anonymised.
- You can disconnect Gmail at any time in Settings, or revoke access at your Google account permissions; we then stop accessing it and delete stored access tokens.
6. AI features
Some features (for example tech-pack extraction and draft messages) send the relevant content to our AI provider, Anthropic, to generate a result you review before use. This content is processed only to produce that result and is not used to train AI models. AI output is a draft suggestion and may contain errors — a human always reviews and decides before anything is sent or committed.
7. Service providers (sub-processors)
We share data only with providers that help us run the Service, under appropriate confidentiality and data-protection terms:
- Vercel — application hosting.
- Turso — database hosting.
- Anthropic — AI processing for the features in section 6.
- Resend — transactional email delivery.
- Google — sign-in and, if you connect it, Gmail (section 5).
8. Where data is held & international transfers
Data is held with the providers above and may be processed in countries other than yours. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers.
9. How long we keep it
We keep registration details while we are in touch about access; account and business data for as long as your account is active or as needed to provide the Service; and we delete or anonymise data when it is no longer needed, or on your verified request, subject to any legal retention obligations.
10. Security
We protect data with measures including encrypted connections, hashed passwords, signed sessions, role-based access controls, and an isolated database per environment. No system is perfectly secure, but we work to keep your data safe.
11. Your rights & choices
Depending on your location (including under the EU/UK GDPR and applicable local law), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email merchandiseros@merchandiseros.online and we will respond promptly. Where we process business-contact data on behalf of a customer, we will direct such requests to that customer.
12. Cookies
We use only essential cookies needed to sign you in and keep your session secure. We do not use advertising or cross-site tracking cookies.
13. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their data.
14. Changes
We may update this policy; we will change the “Last updated” date above and, for material changes, give reasonable notice.
15. Contact
MerchandiserOS — merchandiseros@merchandiseros.online