Privacy Policy
Last updated: 19 September 2026.
Merchant Data is a trading name of RP Digital Marketing Ltd ("we", "us"), a company registered in England and Wales (company number 12265306). Registered office: 9 Pondside Close, Hurworth, Darlington, England, DL2 2NN.
This policy explains what personal information we handle, why, and what your rights are. It has two parts, because we handle two different kinds of information:
- Part A is about people who use our website, dashboard and API.
- Part B is about the information on businesses that makes up the Merchant Data database.
Questions or requests: ryan@merchantdata.in
Part A: People who use our website, dashboard and API
1. What we collect
When you join the waitlist or create an account
- Your email address
- Your name and profile picture if you sign in with Google and Google provides them
- The company name, if you give it to us
When you use the dashboard and API
- The API keys you create. We store a scrambled (hashed) version, not the key itself.
- A log of each API request: which endpoint was called, the search filters or domain requested, the time, whether it succeeded, and how many credits it used
- Your credit balance and the record of credits granted to you
- Your IP address and browser type, recorded in our hosting provider's server logs
When you contact us
- Your email address and whatever you write to us
When you visit the website
- Pages viewed, approximate location (country or city), device and browser type, collected through Google Analytics
We do not collect payment details during the free beta. When paid plans start, payments will be handled by a payment provider and we will update this policy first.
2. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating your account, signing you in, sending login codes | Performing our contract with you |
| Running the API: checking keys, counting credits, applying rate limits | Performing our contract with you |
| Showing you your own usage in the dashboard | Performing our contract with you |
| Preventing abuse, fraud and security problems | Our legitimate interest in keeping the service safe |
| Understanding which parts of the API are used, so we can improve it and set fair prices | Our legitimate interest in improving the service |
| Emails about the service: beta updates, changes to terms or pricing | Our legitimate interest in keeping customers informed. You can opt out of non-essential emails at any time. |
| Website analytics | Your consent, where the law requires it |
We do not sell your personal information. We do not use it for advertising.
3. Who handles it for us
We use these companies to run the service. Each one only handles your information on our instructions.
| Company | What it does | Where |
|---|---|---|
| Supabase | Database and sign-in | India (Mumbai) |
| Vercel | Website, dashboard and API hosting | India and United States |
| Resend | Sending login emails | European Union (Ireland) |
| “Sign in with Google” and website analytics | Worldwide |
We may also share information if the law requires it, or if the business is sold or merged, in which case the new owner must keep to this policy.
4. Transfers outside the UK
Some of the companies above store or process information outside the United Kingdom, including in India and the United States. Where they do, we rely on the legal safeguards those providers offer, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
5. Security
API keys are stored only in hashed form. Access to the database is restricted, and each customer can only see their own keys, usage and credits. No system is perfectly secure; if a breach affects your information we will tell you and the regulator as the law requires.
6. How long we keep it
- Account details: while your account is open, and up to 12 months after it is closed
- API request logs: up to 24 months
- Emails you send us: up to 36 months
- Waitlist email addresses: until you ask us to remove them, or 24 months after the beta opens, whichever is sooner
You can ask us to delete your account and its data sooner at any time.
7. Your rights
Under UK data protection law you can ask us to:
- give you a copy of your information
- correct it
- delete it
- stop or limit how we use it
- give it to you in a portable format
You can also object to uses based on our legitimate interests, and withdraw consent where we rely on consent.
Email ryan@merchantdata.in. We reply within one month.
Part B: Information in the Merchant Data database
8. What the database contains
Merchant Data is a database of online retail businesses in India. We collect information that those businesses publish openly, mainly on their own websites:
- Brand name, website address, business category and description
- Business address, city and PIN code, and GST number, where the business publishes them
- Contact email addresses, phone numbers, WhatsApp numbers and social media links, where the business publishes them for customers
- The ecommerce platform, apps and other technology the website uses
- Payment and delivery options the website advertises, such as cash on delivery
- Products, prices and collections listed in the online store
- How often people search for the brand name, from search data providers
We collect this using automated tools that read public web pages. We do not collect information from behind logins, and we do not collect information about a store's customers.
9. Personal information in the database
Almost all of this is information about businesses, not people. It is possible that a small fraction can relate to an identifiable person, for example where a business is run by one person, or where a published contact email contains someone's name.
Where that is the case, we handle it on the basis of our legitimate interest in providing business information to other businesses, and our customers' legitimate interest in researching and contacting businesses. We limit it to contact details the business itself chose to publish for the public.
10. Who receives it
Our customers are businesses: for example payment companies, logistics companies and agencies. They access the database through our API. Each customer is responsible for using the information lawfully, including following the anti-spam and privacy laws that apply to them. Our Terms of Service require this.
11. Removal and correction
If you run a business in our database and want your details corrected or removed, or you are an individual whose personal information appears in it, email ryan@merchantdata.in with the website address concerned. We will act within 30 days. You do not need to give a reason.
If you are an individual, you also have the rights listed in section 7.
12. Children
Our service is for businesses. It is not intended for anyone under 18.